1.10.txt 41 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093
  1. =============================================
  2. Django 1.10 release notes - UNDER DEVELOPMENT
  3. =============================================
  4. Welcome to Django 1.10!
  5. These release notes cover the `new features`_, as well as some `backwards
  6. incompatible changes`_ you'll want to be aware of when upgrading from Django
  7. 1.9 or older versions. We've :ref:`dropped some features<removed-features-1.10>`
  8. that have reached the end of their deprecation cycle, and we've `begun the
  9. deprecation process for some features`_.
  10. .. _`new features`: `What's new in Django 1.10`_
  11. .. _`backwards incompatible changes`: `Backwards incompatible changes in 1.10`_
  12. .. _`dropped some features`: `Features removed in 1.10`_
  13. .. _`begun the deprecation process for some features`: `Features deprecated in 1.10`_
  14. Python compatibility
  15. ====================
  16. Like Django 1.9, Django 1.10 requires Python 2.7, 3.4, or 3.5. We **highly
  17. recommend** and only officially support the latest release of each series.
  18. What's new in Django 1.10
  19. =========================
  20. ...
  21. Minor features
  22. --------------
  23. :mod:`django.contrib.admin`
  24. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  25. * For sites running on a subpath, the default :attr:`URL for the "View site"
  26. link <django.contrib.admin.AdminSite.site_url>` at the top of each admin page
  27. will now point to ``request.META['SCRIPT_NAME']`` if set, instead of ``/``.
  28. * The success message that appears after adding or editing an object now
  29. contains a link to the object's change form.
  30. * All inline JavaScript is removed so you can enable the
  31. ``Content-Security-Policy`` HTTP header if you wish.
  32. * The new :attr:`InlineModelAdmin.classes
  33. <django.contrib.admin.InlineModelAdmin.classes>` attribute allows specifying
  34. classes on inline fieldsets. Inlines with a ``collapse`` class will be
  35. initially collapsed and their header will have a small "show" link.
  36. * If a user doesn't have the add permission, the ``object-tools`` block on a
  37. model's changelist will now be rendered (without the add button, of course).
  38. This makes it easier to add custom tools in this case.
  39. * The :class:`~django.contrib.admin.models.LogEntry` model now stores change
  40. messages in a JSON structure so that the message can be dynamically translated
  41. using the current active language. A new ``LogEntry.get_change_message()``
  42. method is now the preferred way of retrieving the change message.
  43. * Selected objects for fields in ``ModelAdmin.raw_id_fields`` now have a link
  44. to object's change form.
  45. * Added "No date" and "Has date" choices for ``DateFieldListFilter`` if the
  46. field is nullable.
  47. :mod:`django.contrib.admindocs`
  48. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  49. * ...
  50. :mod:`django.contrib.auth`
  51. ~~~~~~~~~~~~~~~~~~~~~~~~~~
  52. * Added support for the :ref:`Argon2 password hash <argon2_usage>`. It's
  53. recommended over PBKDF2, however, it's not the default as it requires a
  54. third-party library.
  55. * The default iteration count for the PBKDF2 password hasher has been increased
  56. by 25%. This backwards compatible change will not affect users who have
  57. subclassed ``django.contrib.auth.hashers.PBKDF2PasswordHasher`` to change the
  58. default value.
  59. * The :func:`~django.contrib.auth.views.logout` view sends "no-cache" headers
  60. to prevent an issue where Safari caches redirects and prevents a user from
  61. being able to log out.
  62. * Added the optional ``backend`` argument to :func:`~django.contrib.auth.login`
  63. to allow using it without credentials.
  64. * The new :setting:`LOGOUT_REDIRECT_URL` setting controls the redirect of the
  65. :func:`~django.contrib.auth.views.logout` view, if the view doesn't get a
  66. ``next_page`` argument.
  67. * The new ``redirect_authenticated_user`` parameter for the
  68. :func:`~django.contrib.auth.views.login` view allows redirecting
  69. authenticated users visiting the login page.
  70. :mod:`django.contrib.contenttypes`
  71. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  72. * ...
  73. :mod:`django.contrib.gis`
  74. ~~~~~~~~~~~~~~~~~~~~~~~~~
  75. * :ref:`Distance lookups <distance-lookups>` now accept expressions as the
  76. distance value parameter.
  77. * The new :attr:`GEOSGeometry.unary_union
  78. <django.contrib.gis.geos.GEOSGeometry.unary_union>` property computes the
  79. union of all the elements of this geometry.
  80. * Added the :meth:`GEOSGeometry.covers()
  81. <django.contrib.gis.geos.GEOSGeometry.covers>` binary predicate.
  82. * Added the :meth:`GDALBand.statistics()
  83. <django.contrib.gis.gdal.GDALBand.statistics>` method and
  84. :attr:`~django.contrib.gis.gdal.GDALBand.mean`
  85. and :attr:`~django.contrib.gis.gdal.GDALBand.std` attributes.
  86. * Added support for the :class:`~django.contrib.gis.db.models.MakeLine`
  87. aggregate and :class:`~django.contrib.gis.db.models.functions.GeoHash`
  88. function on SpatiaLite.
  89. * Added support for the
  90. :class:`~django.contrib.gis.db.models.functions.Difference`,
  91. :class:`~django.contrib.gis.db.models.functions.Intersection`, and
  92. :class:`~django.contrib.gis.db.models.functions.SymDifference`
  93. functions on MySQL.
  94. * Added support for instantiating empty GEOS geometries.
  95. * The new :attr:`~django.contrib.gis.geos.WKTWriter.trim` and
  96. :attr:`~django.contrib.gis.geos.WKTWriter.precision` properties
  97. of :class:`~django.contrib.gis.geos.WKTWriter` allow controlling
  98. output of the fractional part of the coordinates in WKT.
  99. * Added the :attr:`LineString.closed
  100. <django.contrib.gis.geos.LineString.closed>` and
  101. :attr:`MultiLineString.closed
  102. <django.contrib.gis.geos.MultiLineString.closed>` properties.
  103. * The :doc:`GeoJSON serializer </ref/contrib/gis/serializers>` now outputs the
  104. primary key of objects in the ``properties`` dictionary if specific fields
  105. aren't specified.
  106. * The ability to replicate input data on the :meth:`GDALBand.data()
  107. <django.contrib.gis.gdal.GDALBand.data>` method was added. Band data can
  108. now be updated with repeated values efficiently.
  109. * Added database functions
  110. :class:`~django.contrib.gis.db.models.functions.IsValid` and
  111. :class:`~django.contrib.gis.db.models.functions.MakeValid`, as well as the
  112. :lookup:`isvalid` lookup, all for PostGIS. This allows filtering and
  113. repairing invalid geometries on the database side.
  114. :mod:`django.contrib.messages`
  115. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  116. * ...
  117. :mod:`django.contrib.postgres`
  118. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  119. * For convenience, :class:`~django.contrib.postgres.fields.HStoreField` now
  120. casts its keys and values to strings.
  121. :mod:`django.contrib.redirects`
  122. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  123. * ...
  124. :mod:`django.contrib.sessions`
  125. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  126. * The :djadmin:`clearsessions` management command now removes file-based
  127. sessions.
  128. :mod:`django.contrib.sitemaps`
  129. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  130. * ...
  131. :mod:`django.contrib.sites`
  132. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  133. * The :class:`~django.contrib.sites.models.Site` model now supports
  134. :ref:`natural keys <topics-serialization-natural-keys>`.
  135. :mod:`django.contrib.staticfiles`
  136. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  137. * The :ttag:`static` template tag now uses ``django.contrib.staticfiles``
  138. if it's in ``INSTALLED_APPS``. This is especially useful for third-party apps
  139. which can now always use ``{% load static %}`` (instead of
  140. ``{% load staticfiles %}`` or ``{% load static from staticfiles %}``) and
  141. not worry about whether or not the ``staticfiles`` app is installed.
  142. :mod:`django.contrib.syndication`
  143. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  144. * ...
  145. Cache
  146. ~~~~~
  147. * The file-based cache backend now uses the highest pickling protocol.
  148. CSRF
  149. ~~~~
  150. * The default :setting:`CSRF_FAILURE_VIEW`, ``views.csrf.csrf_failure()`` now
  151. accepts an optional ``template_name`` parameter, defaulting to
  152. ``'403_csrf.html'``, to control the template used to render the page.
  153. Database backends
  154. ~~~~~~~~~~~~~~~~~
  155. * Temporal data subtraction was unified on all backends.
  156. * If the database supports it, backends can set
  157. ``DatabaseFeatures.can_return_ids_from_bulk_insert=True`` and implement
  158. ``DatabaseOperations.fetch_returned_insert_ids()`` to set primary keys
  159. on objects created using ``QuerySet.bulk_create()``.
  160. * Added keyword arguments to the ``as_sql()`` methods of various expressions
  161. (``Func``, ``When``, ``Case``, and ``OrderBy``) to allow database backends to
  162. customize them without mutating ``self``, which isn't safe when using
  163. different database backends. See the ``arg_joiner`` and ``**extra_context``
  164. parameters of :meth:`Func.as_sql() <django.db.models.Func.as_sql>` for an
  165. example.
  166. Email
  167. ~~~~~
  168. * ...
  169. File Storage
  170. ~~~~~~~~~~~~
  171. * Storage backends now present a timezone-aware API with new methods
  172. :meth:`~django.core.files.storage.Storage.get_accessed_time`,
  173. :meth:`~django.core.files.storage.Storage.get_created_time`, and
  174. :meth:`~django.core.files.storage.Storage.get_modified_time`. They return a
  175. timezone-aware ``datetime`` if :setting:`USE_TZ` is ``True`` and a naive
  176. ``datetime`` in the local timezone otherwise.
  177. File Uploads
  178. ~~~~~~~~~~~~
  179. * ...
  180. Forms
  181. ~~~~~
  182. * Form and widget ``Media`` is now served using
  183. :mod:`django.contrib.staticfiles` if installed.
  184. Generic Views
  185. ~~~~~~~~~~~~~
  186. * The :class:`~django.views.generic.base.View` class can now be imported from
  187. ``django.views``.
  188. Internationalization
  189. ~~~~~~~~~~~~~~~~~~~~
  190. * The :func:`~django.conf.urls.i18n.i18n_patterns` helper function can now be
  191. used in a root URLConf specified using :attr:`request.urlconf
  192. <django.http.HttpRequest.urlconf>`.
  193. * By setting the new ``prefix_default_language`` parameter for
  194. :func:`~django.conf.urls.i18n.i18n_patterns` to ``False``, you can allow
  195. accessing the default language without a URL prefix.
  196. * :func:`~django.views.i18n.set_language` now returns a 204 status code (No
  197. Content) for AJAX requests when there is no ``next`` parameter in ``POST`` or
  198. ``GET``.
  199. Management Commands
  200. ~~~~~~~~~~~~~~~~~~~
  201. * :func:`~django.core.management.call_command` now returns the value returned
  202. from the ``command.handle()`` method.
  203. * The new :option:`check --fail-level` option allows specifying the message
  204. level that will cause the command to exit with a non-zero status.
  205. * The new :option:`makemigrations --check` option makes the command exit
  206. with a non-zero status when model changes without migrations are detected.
  207. * :djadmin:`makemigrations` now displays the path to the migration files that
  208. it generates.
  209. * The :option:`shell --interface` option now accepts ``python`` to force use of
  210. the "plain" Python interpreter.
  211. * The new :option:`shell --command` option lets you run a command as Django and
  212. exit, instead of opening the interactive shell.
  213. * Added a warning to :djadmin:`dumpdata` if a proxy model is specified (which
  214. results in no output) without its concrete parent.
  215. * The new :attr:`BaseCommand.requires_migrations_checks
  216. <django.core.management.BaseCommand.requires_migrations_checks>` attribute
  217. may be set to ``True`` if you want your command to print a warning, like
  218. :djadmin:`runserver` does, if the set of migrations on disk don't match the
  219. migrations in the database.
  220. * To assist with testing, :func:`~django.core.management.call_command` now
  221. accepts a command object as the first argument.
  222. * The :djadmin:`shell` command supports tab completion on systems using
  223. ``libedit``, e.g. Mac OSX.
  224. * The :djadmin:`inspectdb` command lets you choose what tables should be
  225. inspected by specifying their names as arguments.
  226. Migrations
  227. ~~~~~~~~~~
  228. * Added support for serialization of ``enum.Enum`` objects.
  229. * Added the ``elidable`` argument to the
  230. :class:`~django.db.migrations.operations.RunSQL` and
  231. :class:`~django.db.migrations.operations.RunPython` operations to allow them
  232. to be removed when squashing migrations.
  233. * Added support for :ref:`non-atomic migrations <non-atomic-migrations>` by
  234. setting the ``atomic`` attribute on a ``Migration``.
  235. * The ``migrate`` and ``makemigrations`` commands now check for a consistent
  236. migration history. If they find some unapplied dependencies of an applied
  237. migration, ``InconsistentMigrationHistory`` is raised.
  238. Models
  239. ~~~~~~
  240. * Reverse foreign keys from proxy models are now propagated to their
  241. concrete class. The reverse relation attached by a
  242. :class:`~django.db.models.ForeignKey` pointing to a proxy model is now
  243. accessible as a descriptor on the proxied model class and may be referenced in
  244. queryset filtering.
  245. * The new :meth:`Field.rel_db_type() <django.db.models.Field.rel_db_type>`
  246. method returns the database column data type for fields such as ``ForeignKey``
  247. and ``OneToOneField`` that point to another field.
  248. * The :attr:`~django.db.models.Func.arity` class attribute is added to
  249. :class:`~django.db.models.Func`. This attribute can be used to set the number
  250. of arguments the function accepts.
  251. * Added :class:`~django.db.models.BigAutoField` which acts much like an
  252. :class:`~django.db.models.AutoField` except that it is guaranteed
  253. to fit numbers from ``1`` to ``9223372036854775807``.
  254. * :meth:`QuerySet.in_bulk() <django.db.models.query.QuerySet.in_bulk>`
  255. may be called without any arguments to return all objects in the queryset.
  256. * :attr:`~django.db.models.ForeignKey.related_query_name` now supports
  257. app label and class interpolation using the ``'%(app_label)s'`` and
  258. ``'%(class)s'`` strings.
  259. * The :func:`~django.db.models.prefetch_related_objects` function is now a
  260. public API.
  261. * :meth:`QuerySet.bulk_create() <django.db.models.query.QuerySet.bulk_create>`
  262. sets the primary key on objects when using PostgreSQL.
  263. * Added the :class:`~django.db.models.functions.Cast` database function.
  264. * A proxy model may now inherit multiple proxy models that share a common
  265. non-abstract parent class.
  266. Requests and Responses
  267. ~~~~~~~~~~~~~~~~~~~~~~
  268. * Added ``request.user`` to the debug view.
  269. * Added :class:`~django.http.HttpResponse` methods
  270. :meth:`~django.http.HttpResponse.readable()` and
  271. :meth:`~django.http.HttpResponse.seekable()` to make an instance a
  272. stream-like object and allow wrapping it with :py:class:`io.TextIOWrapper`.
  273. * Added the :attr:`HttpResponse.content_type
  274. <django.http.HttpRequest.content_type>` and
  275. :attr:`~django.http.HttpRequest.content_params` attributes which are
  276. parsed from the ``CONTENT_TYPE`` header.
  277. * The parser for ``request.COOKIES`` is simplified to better match the behavior
  278. of browsers. ``request.COOKIES`` may now contain cookies that are invalid
  279. according to :rfc:`6265` but are possible to set via ``document.cookie``.
  280. Serialization
  281. ~~~~~~~~~~~~~
  282. * The ``django.core.serializers.json.DjangoJSONEncoder`` now knows how to
  283. serialize lazy strings, typically used for translatable content.
  284. Signals
  285. ~~~~~~~
  286. * ...
  287. Templates
  288. ~~~~~~~~~
  289. * Added the ``autoescape`` option to the
  290. :class:`~django.template.backends.django.DjangoTemplates` backend and the
  291. :class:`~django.template.Engine` class.
  292. * Added the ``is`` and ``is not`` comparison operators to the :ttag:`if` tag.
  293. * Allowed :tfilter:`dictsort` to order a list of lists by an element at a
  294. specified index.
  295. * The :func:`~django.template.context_processors.debug` context processor
  296. contains queries for all database aliases instead of only the default alias.
  297. Tests
  298. ~~~~~
  299. * To better catch bugs, :class:`~django.test.TestCase` now checks deferrable
  300. database constraints at the end of each test.
  301. * Tests and test cases can be :ref:`marked with tags <topics-tagging-tests>`
  302. and run selectively with the new :option:`test --tag` and :option:`test
  303. --exclude-tag` options.
  304. * Added the :setting:`DATABASES['TEST']['MIGRATE'] <TEST_MIGRATE>` option to
  305. allow disabling of migrations during test database creation.
  306. * You can now login and use sessions with the test client even if
  307. :mod:`django.contrib.sessions` is not in :setting:`INSTALLED_APPS`.
  308. URLs
  309. ~~~~
  310. * An addition in :func:`django.setup()` allows URL resolving that happens
  311. outside of the request/response cycle (e.g. in management commands and
  312. standalone scripts) to take :setting:`FORCE_SCRIPT_NAME` into account when it
  313. is set.
  314. Validators
  315. ~~~~~~~~~~
  316. * :class:`~django.core.validators.URLValidator` now limits the length of
  317. domain name labels to 63 characters and the total length of domain
  318. names to 253 characters per :rfc:`1034`.
  319. * :func:`~django.core.validators.int_list_validator` now accepts an optional
  320. ``allow_negative`` boolean parameter, defaulting to ``False``, to allow
  321. negative integers.
  322. Backwards incompatible changes in 1.10
  323. ======================================
  324. .. warning::
  325. In addition to the changes outlined in this section, be sure to review the
  326. :ref:`removed-features-1.10` for the features that have reached the end of
  327. their deprecation cycle and therefore been removed. If you haven't updated
  328. your code within the deprecation timeline for a given feature, its removal
  329. may appear as a backwards incompatible change.
  330. Database backend API
  331. --------------------
  332. * GIS's ``AreaField`` uses an unspecified underlying numeric type that could in
  333. practice be any numeric Python type. ``decimal.Decimal`` values retrieved
  334. from the database are now converted to ``float`` to make it easier to combine
  335. them with values used by the GIS libraries.
  336. * In order to enable temporal subtraction you must set the
  337. ``supports_temporal_subtraction`` database feature flag to ``True`` and
  338. implement the ``DatabaseOperations.subtract_temporals()`` method. This
  339. method should return the SQL and parameters required to compute the
  340. difference in microseconds between the ``lhs`` and ``rhs`` arguments in the
  341. datatype used to store :class:`~django.db.models.DurationField`.
  342. ``select_related()`` prohibits non-relational fields for nested relations
  343. -------------------------------------------------------------------------
  344. Django 1.8 added validation for non-relational fields in ``select_related()``::
  345. >>> Book.objects.select_related('title')
  346. Traceback (most recent call last):
  347. ...
  348. FieldError: Non-relational field given in select_related: 'title'
  349. But it didn't prohibit nested non-relation fields as it does now::
  350. >>> Book.objects.select_related('author__name')
  351. Traceback (most recent call last):
  352. ...
  353. FieldError: Non-relational field given in select_related: 'name'
  354. ``_meta.get_fields()`` returns consistent reverse fields for proxy models
  355. -------------------------------------------------------------------------
  356. Before Django 1.10, the :meth:`~django.db.models.options.Options.get_fields`
  357. method returned different reverse fields when called on a proxy model compared
  358. to its proxied concrete class. This inconsistency was fixed by returning the
  359. full set of fields pointing to a concrete class or one of its proxies in both
  360. cases.
  361. :attr:`AbstractUser.username <django.contrib.auth.models.User.username>` ``max_length`` increased to 150
  362. --------------------------------------------------------------------------------------------------------
  363. A migration for :attr:`django.contrib.auth.models.User.username` is included.
  364. If you have a custom user model inheriting from ``AbstractUser``, you'll need
  365. to generate and apply a database migration for your user model.
  366. We considered an increase to 254 characters to more easily allow the use of
  367. email addresses (which are limited to 254 characters) as usernames but rejected
  368. it due to a MySQL limitation. When using the ``utf8mb4`` encoding (recommended
  369. for proper Unicode support), MySQL can only create unique indexes with 191
  370. characters by default. Therefore, if you need a longer length, please use a
  371. custom user model.
  372. If you want to preserve the 30 character limit for usernames, use a custom form
  373. when creating a user or changing usernames::
  374. from django.contrib.auth.forms import UserCreationForm
  375. class MyUserCreationForm(UserCreationForm):
  376. username = forms.CharField(
  377. max_length=30,
  378. help_text='Required. 30 characters or fewer. Letters, digits and @/./+/-/_ only.',
  379. )
  380. If you wish to keep this restriction in the admin, set ``UserAdmin.add_form``
  381. to use this form::
  382. from django.contrib.auth.admin import UserAdmin as BaseUserAdmin
  383. from django.contrib.auth.models import User
  384. class UserAdmin(BaseUserAdmin):
  385. add_form = MyUserCreationForm
  386. admin.site.unregister(User)
  387. admin.site.register(User, UserAdmin)
  388. Dropped support for PostgreSQL 9.1
  389. ----------------------------------
  390. Upstream support for PostgreSQL 9.1 ends in September 2016. As a consequence,
  391. Django 1.10 sets PostgreSQL 9.2 as the minimum version it officially supports.
  392. ``runserver`` output goes through logging
  393. -----------------------------------------
  394. Request and response handling of the ``runserver`` command is sent to the
  395. :ref:`django-server-logger` logger instead of to ``sys.stderr``. If you
  396. disable Django's logging configuration or override it with your own, you'll
  397. need to add the appropriate logging configuration if you want to see that
  398. output::
  399. 'formatters': {
  400. 'django.server': {
  401. '()': 'django.utils.log.ServerFormatter',
  402. 'format': '[%(server_time)s] %(message)s',
  403. }
  404. },
  405. 'handlers': {
  406. 'django.server': {
  407. 'level': 'INFO',
  408. 'class': 'logging.StreamHandler',
  409. 'formatter': 'django.server',
  410. },
  411. },
  412. 'loggers': {
  413. 'django.server': {
  414. 'handlers': ['django.server'],
  415. 'level': 'INFO',
  416. 'propagate': False,
  417. }
  418. }
  419. ``auth.CustomUser`` and ``auth.ExtensionUser`` test models were removed
  420. -----------------------------------------------------------------------
  421. Since the introduction of migrations for the contrib apps in Django 1.8, the
  422. tables of these custom user test models were not created anymore making them
  423. unusable in a testing context.
  424. Apps registry is no longer auto-populated when unpickling models outside of Django
  425. ----------------------------------------------------------------------------------
  426. The apps registry is no longer auto-populated when unpickling models. This was
  427. added in Django 1.7.2 as an attempt to allow unpickling models outside of
  428. Django, such as in an RQ worker, without calling ``django.setup()``, but it
  429. creates the possibility of a deadlock. To adapt your code in the case of RQ,
  430. you can `provide your own worker script <http://python-rq.org/docs/workers/>`_
  431. that calls ``django.setup()``.
  432. Removed null assignment check for non-null foreign key fields
  433. -------------------------------------------------------------
  434. In older versions, assigning ``None`` to a non-nullable ``ForeignKey`` or
  435. ``OneToOneField`` raised ``ValueError('Cannot assign None: "model.field" does
  436. not allow null values.')``. For consistency with other model fields which don't
  437. have a similar check, this check is removed.
  438. Removed weak password hashers from the default ``PASSWORD_HASHERS`` setting
  439. ---------------------------------------------------------------------------
  440. Django 0.90 stored passwords as unsalted MD5. Django 0.91 added support for
  441. salted SHA1 with automatic upgrade of passwords when a user logs in. Django 1.4
  442. added PBKDF2 as the default password hasher.
  443. If you have an old Django project with MD5 or SHA1 (even salted) encoded
  444. passwords, be aware that these can be cracked fairly easily with today's
  445. hardware. To make Django users acknowledge continued use of weak hashers, the
  446. following hashers are removed from the default :setting:`PASSWORD_HASHERS`
  447. setting::
  448. 'django.contrib.auth.hashers.SHA1PasswordHasher'
  449. 'django.contrib.auth.hashers.MD5PasswordHasher'
  450. 'django.contrib.auth.hashers.UnsaltedSHA1PasswordHasher'
  451. 'django.contrib.auth.hashers.UnsaltedMD5PasswordHasher'
  452. 'django.contrib.auth.hashers.CryptPasswordHasher'
  453. Consider using a :ref:`wrapped password hasher <wrapping-password-hashers>` to
  454. strengthen the hashes in your database. If that's not feasible, add the
  455. :setting:`PASSWORD_HASHERS` setting to your project and add back any hashers
  456. that you need.
  457. You can check if your database has any of the removed hashers like this::
  458. from django.contrib.auth import get_user_model
  459. User = get_user_model()
  460. # Unsalted MD5/SHA1:
  461. User.objects.filter(password__startswith='md5$$')
  462. User.objects.filter(password__startswith='sha1$$')
  463. # Salted MD5/SHA1:
  464. User.objects.filter(password__startswith='md5$').exclude(password__startswith='md5$$')
  465. User.objects.filter(password__startswith='sha1$').exclude(password__startswith='sha1$$')
  466. # Crypt hasher:
  467. User.objects.filter(password__startswith='crypt$$')
  468. from django.db.models import CharField
  469. from django.db.models.functions import Length
  470. CharField.register_lookup(Length)
  471. # Unsalted MD5 passwords might not have an 'md5$$' prefix:
  472. User.objects.filter(password__length=32)
  473. Miscellaneous
  474. -------------
  475. * The ``repr()`` of a ``QuerySet`` is wrapped in ``<QuerySet >`` to
  476. disambiguate it from a plain list when debugging.
  477. * Support for SpatiaLite < 3.0 and GEOS < 3.3 is dropped.
  478. * ``utils.version.get_version()`` returns :pep:`440` compliant release
  479. candidate versions (e.g. '1.10rc1' instead of '1.10c1').
  480. * The ``LOGOUT_URL`` setting is removed as Django hasn't made use of it
  481. since pre-1.0. If you use it in your project, you can add it to your
  482. project's settings. The default value was ``'/accounts/logout/'``.
  483. * The ``add_postgis_srs()`` backwards compatibility alias for
  484. ``django.contrib.gis.utils.add_srs_entry()`` is removed.
  485. * Objects with a ``close()`` method such as files and generators passed to
  486. :class:`~django.http.HttpResponse` are now closed immediately instead of when
  487. the WSGI server calls ``close()`` on the response.
  488. * A redundant ``transaction.atomic()`` call in ``QuerySet.update_or_create()``
  489. is removed. This may affect query counts tested by
  490. ``TransactionTestCase.assertNumQueries()``.
  491. * Support for ``skip_validation`` in ``BaseCommand.execute(**options)`` is
  492. removed. Use ``skip_checks`` (added in Django 1.7) instead.
  493. * :djadmin:`loaddata` now raises a ``CommandError`` instead of showing a
  494. warning when the specified fixture file is not found.
  495. * Instead of directly accessing the ``LogEntry.change_message`` attribute, it's
  496. now better to call the ``LogEntry.get_change_message()`` method which will
  497. provide the message in the current language.
  498. * The default error views now raise ``TemplateDoesNotExist`` if a nonexistent
  499. ``template_name`` is specified.
  500. * The unused ``choices`` keyword argument of the ``Select`` and
  501. ``SelectMultiple`` widgets' ``render()`` method is removed. The ``choices``
  502. argument of the ``render_options()`` method is also removed, making
  503. ``selected_choices`` the first argument.
  504. * On Oracle/GIS, the :class:`~django.contrib.gis.db.models.functions.Area`
  505. aggregate function now returns a ``float`` instead of ``decimal.Decimal``.
  506. (It's still wrapped in a measure of square meters.)
  507. * Tests that violate deferrable database constraints will now error when run on
  508. a database that supports deferrable constraints.
  509. * Built-in management commands now use indexing of keys in ``options``, e.g.
  510. ``options['verbosity']``, instead of ``options.get()`` and no longer perform
  511. any type coercion. This could be a problem if you're calling commands using
  512. ``Command.execute()`` (which bypasses the argument parser that sets a default
  513. value) instead of :func:`~django.core.management.call_command`. Instead of
  514. calling ``Command.execute()``, pass the command object as the first argument
  515. to ``call_command()``.
  516. * :class:`~django.contrib.auth.backends.ModelBackend` and
  517. :class:`~django.contrib.auth.backends.RemoteUserBackend` now reject inactive
  518. users. This means that inactive users can't login and will be logged
  519. out if they are switched from ``is_active=True`` to ``False``. If you need
  520. the previous behavior, use the new
  521. :class:`~django.contrib.auth.backends.AllowAllUsersModelBackend` or
  522. :class:`~django.contrib.auth.backends.AllowAllUsersRemoteUserBackend`
  523. in :setting:`AUTHENTICATION_BACKENDS` instead.
  524. * In light of the previous change, the test client's
  525. :meth:`~django.test.Client.login()` method no longer always rejects inactive
  526. users but instead delegates this decision to the authentication backend.
  527. * :func:`django.views.i18n.set_language` may now return a 204 status code for
  528. AJAX requests.
  529. * The ``base_field`` attribute of
  530. :class:`~django.contrib.postgres.fields.RangeField` is now a type of field,
  531. not an instance of a field. If you have created a custom subclass of
  532. :class:`~django.contrib.postgres.fields.RangeField`, you should change the
  533. ``base_field`` attribute.
  534. * Middleware classes are now initialized when the server starts rather than
  535. during the first request.
  536. * If you override ``is_authenticated()`` or ``is_anonymous()`` in a custom user
  537. model, you must convert them to attributes or properties as described in
  538. :ref:`the deprecation note <user-is-auth-anon-deprecation>`.
  539. .. _deprecated-features-1.10:
  540. Features deprecated in 1.10
  541. ===========================
  542. Direct assignment to a reverse foreign key or many-to-many relation
  543. -------------------------------------------------------------------
  544. Instead of assigning related objects using direct assignment::
  545. >>> new_list = [obj1, obj2, obj3]
  546. >>> e.related_set = new_list
  547. Use the :meth:`~django.db.models.fields.related.RelatedManager.set` method
  548. added in Django 1.9::
  549. >>> e.related_set.set([obj1, obj2, obj3])
  550. This prevents confusion about an assignment resulting in an implicit save.
  551. Non-timezone-aware :class:`~django.core.files.storage.Storage` API
  552. ------------------------------------------------------------------
  553. The old, non-timezone-aware methods ``accessed_time()``, ``created_time()``,
  554. and ``modified_time()`` are deprecated in favor of the new ``get_*_time()``
  555. methods.
  556. Third-party storage backends should implement the new methods and mark the old
  557. ones as deprecated. Until then, the new ``get_*_time()`` methods on the base
  558. :class:`~django.core.files.storage.Storage` class convert ``datetime``\s from
  559. the old methods as required and emit a deprecation warning as they do so.
  560. Third-party storage backends may retain the old methods as long as they
  561. wish to support earlier versions of Django.
  562. :mod:`django.contrib.gis`
  563. -------------------------
  564. * The ``get_srid()`` and ``set_srid()`` methods of
  565. :class:`~django.contrib.gis.geos.GEOSGeometry` are deprecated in favor
  566. of the :attr:`~django.contrib.gis.geos.GEOSGeometry.srid` property.
  567. * The ``get_x()``, ``set_x()``, ``get_y()``, ``set_y()``, ``get_z()``, and
  568. ``set_z()`` methods of :class:`~django.contrib.gis.geos.Point` are deprecated
  569. in favor of the ``x``, ``y``, and ``z`` properties.
  570. * The ``get_coords()`` and ``set_coords()`` methods of
  571. :class:`~django.contrib.gis.geos.Point` are deprecated in favor of the
  572. ``tuple`` property.
  573. * The ``cascaded_union`` property of
  574. :class:`~django.contrib.gis.geos.MultiPolygon` is deprecated in favor of the
  575. :attr:`~django.contrib.gis.geos.GEOSGeometry.unary_union` property.
  576. ``CommaSeparatedIntegerField`` model field
  577. ------------------------------------------
  578. ``CommaSeparatedIntegerField`` is deprecated in favor of
  579. :class:`~django.db.models.CharField` with the
  580. :func:`~django.core.validators.validate_comma_separated_integer_list`
  581. validator::
  582. from django.core.validators import validate_comma_separated_integer_list
  583. from django.db import models
  584. class MyModel(models.Model):
  585. numbers = models.CharField(..., validators=[validate_comma_separated_integer_list])
  586. If you're using Oracle, ``CharField`` uses a different database field type
  587. (``NVARCHAR2``) than ``CommaSeparatedIntegerField`` (``VARCHAR2``). Depending
  588. on your database settings, this might imply a different encoding, and thus a
  589. different length (in bytes) for the same contents. If your stored values are
  590. longer than the 4000 byte limit of ``NVARCHAR2``, you should use ``TextField``
  591. (``NCLOB``) instead. In this case, if you have any queries that group by the
  592. field (e.g. annotating the model with an aggregation or using ``distinct()``)
  593. you'll need to change them (to defer the field).
  594. Using a model name as a query lookup when ``default_related_name`` is set
  595. -------------------------------------------------------------------------
  596. Assume the following models::
  597. from django.db import models
  598. class Foo(models.Model):
  599. pass
  600. class Bar(models.Model):
  601. foo = models.ForeignKey(Foo)
  602. class Meta:
  603. default_related_name = 'bars'
  604. In older versions, :attr:`~django.db.models.Options.default_related_name`
  605. couldn't be used as a query lookup. This is fixed and support for the old
  606. lookup name is deprecated. For example, since ``default_related_name`` is set
  607. in model ``Bar``, instead of using the model name ``bar`` as the lookup::
  608. >>> bar = Bar.objects.get(pk=1)
  609. >>> Foo.objects.get(bar=bar)
  610. use the default_related_name ``bars``::
  611. >>> Foo.objects.get(bars=bar)
  612. .. _search-lookup-replacement:
  613. ``__search`` query lookup
  614. -------------------------
  615. The ``search`` lookup, which supports MySQL only and is extremely limited in
  616. features, is deprecated. Replace it with a custom lookup::
  617. from django.db import models
  618. class Search(models.Lookup):
  619. lookup_name = 'search'
  620. def as_mysql(self, compiler, connection):
  621. lhs, lhs_params = self.process_lhs(compiler, connection)
  622. rhs, rhs_params = self.process_rhs(compiler, connection)
  623. params = lhs_params + rhs_params
  624. return 'MATCH (%s) AGAINST (%s IN BOOLEAN MODE)' % (lhs, rhs), params
  625. models.CharField.register_lookup(Search)
  626. models.TextField.register_lookup(Search)
  627. .. _user-is-auth-anon-deprecation:
  628. Using ``User.is_authenticated()`` and ``User.is_anonymous()`` as methods
  629. ------------------------------------------------------------------------
  630. The ``is_authenticated()`` and ``is_anonymous()`` methods of
  631. :class:`~django.contrib.auth.models.AbstractBaseUser` and
  632. :class:`~django.contrib.auth.models.AnonymousUser` classes are now
  633. properties. They will still work as methods until Django 2.0, but all usage
  634. in Django now uses attribute access.
  635. For example, if you use
  636. :class:`~django.contrib.auth.middleware.AuthenticationMiddleware` and want
  637. to know whether the user is currently logged-in you would use::
  638. if request.user.is_authenticated:
  639. ... # Do something for logged-in users.
  640. else:
  641. ... # Do something for anonymous users.
  642. instead of ``request.user.is_authenticated()``.
  643. This change avoids accidental information leakage if you forget to call the
  644. method, e.g.::
  645. if request.user.is_authenticated:
  646. return sensitive_information
  647. If you override these methods in a custom user model, you must change them to
  648. properties or attributes.
  649. Custom manager classes available through ``prefetch_related`` must define a ``_apply_rel_filters()`` method
  650. -----------------------------------------------------------------------------------------------------------
  651. If you defined a custom manager class available through
  652. :meth:`~django.db.models.query.QuerySet.prefetch_related` you must make sure
  653. it defines a ``_apply_rel_filters()`` method.
  654. This method must accept a :class:`~django.db.models.query.QuerySet` instance
  655. as its single argument and return a filtered version of the queryset for the
  656. model instance the manager is bound to.
  657. Miscellaneous
  658. -------------
  659. * The ``makemigrations --exit`` option is deprecated in favor of the
  660. :option:`makemigrations --check` option.
  661. * ``django.utils.functional.allow_lazy()`` is deprecated in favor of the new
  662. :func:`~django.utils.functional.keep_lazy` function which can be used with a
  663. more natural decorator syntax.
  664. * The ``shell --plain`` option is deprecated in favor of ``-i python`` or
  665. ``--interface python``.
  666. * Importing from the ``django.core.urlresolvers`` module is deprecated in
  667. favor of its new location, :mod:`django.urls`.
  668. * The template ``Context.has_key()`` method is deprecated in favor of ``in``.
  669. .. _removed-features-1.10:
  670. Features removed in 1.10
  671. ========================
  672. These features have reached the end of their deprecation cycle and so have been
  673. removed in Django 1.10 (please see the :ref:`deprecation timeline
  674. <deprecation-removed-in-1.10>` for more details):
  675. * Support for calling a ``SQLCompiler`` directly as an alias for calling its
  676. ``quote_name_unless_alias`` method is removed.
  677. * The ``cycle`` and ``firstof`` template tags are removed from the ``future``
  678. template tag library.
  679. * ``django.conf.urls.patterns()`` is removed.
  680. * Support for the ``prefix`` argument to
  681. ``django.conf.urls.i18n.i18n_patterns()`` is removed.
  682. * ``SimpleTestCase.urls`` is removed.
  683. * Using an incorrect count of unpacked values in the ``for`` template tag
  684. raises an exception rather than failing silently.
  685. * The ability to :func:`~django.urls.reverse` URLs using a dotted Python path
  686. is removed.
  687. * The ability to use a dotted Python path for the ``LOGIN_URL`` and
  688. ``LOGIN_REDIRECT_URL`` settings is removed.
  689. * Support for ``optparse`` is dropped for custom management commands.
  690. * The class ``django.core.management.NoArgsCommand`` is removed.
  691. * ``django.core.context_processors`` module is removed.
  692. * ``django.db.models.sql.aggregates`` module is removed.
  693. * ``django.contrib.gis.db.models.sql.aggregates`` module is removed.
  694. * The following methods and properties of ``django.db.sql.query.Query`` are
  695. removed:
  696. * Properties: ``aggregates`` and ``aggregate_select``
  697. * Methods: ``add_aggregate``, ``set_aggregate_mask``, and
  698. ``append_aggregate_mask``.
  699. * ``django.template.resolve_variable`` is removed.
  700. * The following private APIs are removed from
  701. :class:`django.db.models.options.Options` (``Model._meta``):
  702. * ``get_field_by_name()``
  703. * ``get_all_field_names()``
  704. * ``get_fields_with_model()``
  705. * ``get_concrete_fields_with_model()``
  706. * ``get_m2m_with_model()``
  707. * ``get_all_related_objects()``
  708. * ``get_all_related_objects_with_model()``
  709. * ``get_all_related_many_to_many_objects()``
  710. * ``get_all_related_m2m_objects_with_model()``
  711. * The ``error_message`` argument of ``django.forms.RegexField`` is removed.
  712. * The ``unordered_list`` filter no longer supports old style lists.
  713. * Support for string ``view`` arguments to ``url()`` is removed.
  714. * The backward compatible shim to rename ``django.forms.Form._has_changed()``
  715. to ``has_changed()`` is removed.
  716. * The ``removetags`` template filter is removed.
  717. * The ``remove_tags()`` and ``strip_entities()`` functions in
  718. ``django.utils.html`` is removed.
  719. * The ``is_admin_site`` argument to
  720. ``django.contrib.auth.views.password_reset()`` is removed.
  721. * ``django.db.models.field.subclassing.SubfieldBase`` is removed.
  722. * ``django.utils.checksums`` is removed.
  723. * The ``original_content_type_id`` attribute on
  724. ``django.contrib.admin.helpers.InlineAdminForm`` is removed.
  725. * The backwards compatibility shim to allow ``FormMixin.get_form()`` to be
  726. defined with no default value for its ``form_class`` argument is removed.
  727. * The following settings are removed:
  728. * ``ALLOWED_INCLUDE_ROOTS``
  729. * ``TEMPLATE_CONTEXT_PROCESSORS``
  730. * ``TEMPLATE_DEBUG``
  731. * ``TEMPLATE_DIRS``
  732. * ``TEMPLATE_LOADERS``
  733. * ``TEMPLATE_STRING_IF_INVALID``
  734. * The backwards compatibility alias ``django.template.loader.BaseLoader`` is
  735. removed.
  736. * Django template objects returned by
  737. :func:`~django.template.loader.get_template` and
  738. :func:`~django.template.loader.select_template` no longer accept a
  739. :class:`~django.template.Context` in their
  740. :meth:`~django.template.backends.base.Template.render()` method.
  741. * :doc:`Template response APIs </ref/template-response>` enforce the use of
  742. :class:`dict` and backend-dependent template objects instead of
  743. :class:`~django.template.Context` and :class:`~django.template.Template`
  744. respectively.
  745. * The ``current_app`` parameter for the following function and classes is
  746. removed:
  747. * ``django.shortcuts.render()``
  748. * ``django.template.Context()``
  749. * ``django.template.RequestContext()``
  750. * ``django.template.response.TemplateResponse()``
  751. * The ``dictionary`` and ``context_instance`` parameters for the following
  752. functions are removed:
  753. * ``django.shortcuts.render()``
  754. * ``django.shortcuts.render_to_response()``
  755. * ``django.template.loader.render_to_string()``
  756. * The ``dirs`` parameter for the following functions is removed:
  757. * ``django.template.loader.get_template()``
  758. * ``django.template.loader.select_template()``
  759. * ``django.shortcuts.render()``
  760. * ``django.shortcuts.render_to_response()``
  761. * Session verification is enabled regardless of whether or not
  762. ``'django.contrib.auth.middleware.SessionAuthenticationMiddleware'`` is in
  763. ``MIDDLEWARE_CLASSES``. ``SessionAuthenticationMiddleware`` no longer has
  764. any purpose and can be removed from ``MIDDLEWARE_CLASSES``. It's kept as
  765. a stub until Django 2.0 as a courtesy for users who don't read this note.
  766. * Private attribute ``django.db.models.Field.related`` is removed.
  767. * The ``--list`` option of the ``migrate`` management command is removed.
  768. * The ``ssi`` template tag is removed.
  769. * Support for the ``=`` comparison operator in the ``if`` template tag is
  770. removed.
  771. * The backwards compatibility shims to allow ``Storage.get_available_name()``
  772. and ``Storage.save()`` to be defined without a ``max_length`` argument are
  773. removed.
  774. * Support for the legacy ``%(<foo>)s`` syntax in ``ModelFormMixin.success_url``
  775. is removed.
  776. * ``GeoQuerySet`` aggregate methods ``collect()``, ``extent()``, ``extent3d()``,
  777. ``make_line()``, and ``unionagg()`` are removed.
  778. * The ability to specify ``ContentType.name`` when creating a content type
  779. instance is removed.
  780. * Support for the old signature of ``allow_migrate`` is removed.
  781. * Support for the syntax of ``{% cycle %}`` that uses comma-separated arguments
  782. is removed.
  783. * The warning that :class:`~django.core.signing.Signer` issued when given an
  784. invalid separator is now a ``ValueError``.