1.10.txt 37 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006
  1. =============================================
  2. Django 1.10 release notes - UNDER DEVELOPMENT
  3. =============================================
  4. Welcome to Django 1.10!
  5. These release notes cover the `new features`_, as well as some `backwards
  6. incompatible changes`_ you'll want to be aware of when upgrading from Django
  7. 1.9 or older versions. We've :ref:`dropped some features<removed-features-1.10>`
  8. that have reached the end of their deprecation cycle, and we've `begun the
  9. deprecation process for some features`_.
  10. .. _`new features`: `What's new in Django 1.10`_
  11. .. _`backwards incompatible changes`: `Backwards incompatible changes in 1.10`_
  12. .. _`dropped some features`: `Features removed in 1.10`_
  13. .. _`begun the deprecation process for some features`: `Features deprecated in 1.10`_
  14. Python compatibility
  15. ====================
  16. Like Django 1.9, Django 1.10 requires Python 2.7, 3.4, or 3.5. We **highly
  17. recommend** and only officially support the latest release of each series.
  18. What's new in Django 1.10
  19. =========================
  20. ...
  21. Minor features
  22. --------------
  23. :mod:`django.contrib.admin`
  24. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  25. * For sites running on a subpath, the default :attr:`URL for the "View site"
  26. link <django.contrib.admin.AdminSite.site_url>` at the top of each admin page
  27. will now point to ``request.META['SCRIPT_NAME']`` if set, instead of ``/``.
  28. * The success message that appears after adding or editing an object now
  29. contains a link to the object's change form.
  30. * All inline JavaScript is removed so you can enable the
  31. ``Content-Security-Policy`` HTTP header if you wish.
  32. * The new :attr:`InlineModelAdmin.classes
  33. <django.contrib.admin.InlineModelAdmin.classes>` attribute allows specifying
  34. classes on inline fieldsets. Inlines with a ``collapse`` class will be
  35. initially collapsed and their header will have a small "show" link.
  36. * If a user doesn't have the add permission, the ``object-tools`` block on a
  37. model's changelist will now be rendered (without the add button, of course).
  38. This makes it easier to add custom tools in this case.
  39. * The :class:`~django.contrib.admin.models.LogEntry` model now stores change
  40. messages in a JSON structure so that the message can be dynamically translated
  41. using the current active language. A new ``LogEntry.get_change_message()``
  42. method is now the preferred way of retrieving the change message.
  43. * Selected objects for fields in ``ModelAdmin.raw_id_fields`` now have a link
  44. to object's change form.
  45. * Added "No date" and "Has date" choices for ``DateFieldListFilter`` if the
  46. field is nullable.
  47. :mod:`django.contrib.admindocs`
  48. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  49. * ...
  50. :mod:`django.contrib.auth`
  51. ~~~~~~~~~~~~~~~~~~~~~~~~~~
  52. * Added support for the :ref:`Argon2 password hash <argon2_usage>`. It's
  53. recommended over PBKDF2, however, it's not the default as it requires a
  54. third-party library.
  55. * The default iteration count for the PBKDF2 password hasher has been increased
  56. by 25%. This backwards compatible change will not affect users who have
  57. subclassed ``django.contrib.auth.hashers.PBKDF2PasswordHasher`` to change the
  58. default value.
  59. * The :func:`~django.contrib.auth.views.logout` view sends "no-cache" headers
  60. to prevent an issue where Safari caches redirects and prevents a user from
  61. being able to log out.
  62. * Added the optional ``backend`` argument to :func:`~django.contrib.auth.login`
  63. to allow using it without credentials.
  64. * The new :setting:`LOGOUT_REDIRECT_URL` setting controls the redirect of the
  65. :func:`~django.contrib.auth.views.logout` view, if the view doesn't get a
  66. ``next_page`` argument.
  67. * The new ``redirect_authenticated_user`` parameter for the
  68. :func:`~django.contrib.auth.views.login` view allows redirecting
  69. authenticated users visiting the login page.
  70. :mod:`django.contrib.contenttypes`
  71. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  72. * ...
  73. :mod:`django.contrib.gis`
  74. ~~~~~~~~~~~~~~~~~~~~~~~~~
  75. * :ref:`Distance lookups <distance-lookups>` now accept expressions as the
  76. distance value parameter.
  77. * The new :attr:`GEOSGeometry.unary_union
  78. <django.contrib.gis.geos.GEOSGeometry.unary_union>` property computes the
  79. union of all the elements of this geometry.
  80. * Added the :meth:`GEOSGeometry.covers()
  81. <django.contrib.gis.geos.GEOSGeometry.covers>` binary predicate.
  82. * Added the :meth:`GDALBand.statistics()
  83. <django.contrib.gis.gdal.GDALBand.statistics>` method and
  84. :attr:`~django.contrib.gis.gdal.GDALBand.mean`
  85. and :attr:`~django.contrib.gis.gdal.GDALBand.std` attributes.
  86. * Added support for the :class:`~django.contrib.gis.db.models.MakeLine`
  87. aggregate and :class:`~django.contrib.gis.db.models.functions.GeoHash`
  88. function on SpatiaLite.
  89. * Added support for the
  90. :class:`~django.contrib.gis.db.models.functions.Difference`,
  91. :class:`~django.contrib.gis.db.models.functions.Intersection`, and
  92. :class:`~django.contrib.gis.db.models.functions.SymDifference`
  93. functions on MySQL.
  94. * Added support for instantiating empty GEOS geometries.
  95. * The new :attr:`~django.contrib.gis.geos.WKTWriter.trim` and
  96. :attr:`~django.contrib.gis.geos.WKTWriter.precision` properties
  97. of :class:`~django.contrib.gis.geos.WKTWriter` allow controlling
  98. output of the fractional part of the coordinates in WKT.
  99. * Added the :attr:`LineString.closed
  100. <django.contrib.gis.geos.LineString.closed>` and
  101. :attr:`MultiLineString.closed
  102. <django.contrib.gis.geos.MultiLineString.closed>` properties.
  103. * The :doc:`GeoJSON serializer </ref/contrib/gis/serializers>` now outputs the
  104. primary key of objects in the ``properties`` dictionary if specific fields
  105. aren't specified.
  106. :mod:`django.contrib.messages`
  107. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  108. * ...
  109. :mod:`django.contrib.postgres`
  110. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  111. * For convenience, :class:`~django.contrib.postgres.fields.HStoreField` now
  112. casts its keys and values to strings.
  113. :mod:`django.contrib.redirects`
  114. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  115. * ...
  116. :mod:`django.contrib.sessions`
  117. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  118. * The :djadmin:`clearsessions` management command now removes file-based
  119. sessions.
  120. :mod:`django.contrib.sitemaps`
  121. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  122. * ...
  123. :mod:`django.contrib.sites`
  124. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  125. * The :class:`~django.contrib.sites.models.Site` model now supports
  126. :ref:`natural keys <topics-serialization-natural-keys>`.
  127. :mod:`django.contrib.staticfiles`
  128. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  129. * The :ttag:`static` template tag now uses ``django.contrib.staticfiles``
  130. if it's in ``INSTALLED_APPS``. This is especially useful for third-party apps
  131. which can now always use ``{% load static %}`` (instead of
  132. ``{% load staticfiles %}`` or ``{% load static from staticfiles %}``) and
  133. not worry about whether or not the ``staticfiles`` app is installed.
  134. :mod:`django.contrib.syndication`
  135. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  136. * ...
  137. Cache
  138. ~~~~~
  139. * The file-based cache backend now uses the highest pickling protocol.
  140. CSRF
  141. ~~~~
  142. * The default :setting:`CSRF_FAILURE_VIEW`, ``views.csrf.csrf_failure()`` now
  143. accepts an optional ``template_name`` parameter, defaulting to
  144. ``'403_csrf.html'``, to control the template used to render the page.
  145. Database backends
  146. ~~~~~~~~~~~~~~~~~
  147. * Temporal data subtraction was unified on all backends.
  148. * If the database supports it, backends can set
  149. ``DatabaseFeatures.can_return_ids_from_bulk_insert=True`` and implement
  150. ``DatabaseOperations.fetch_returned_insert_ids()`` to set primary keys
  151. on objects created using ``QuerySet.bulk_create()``.
  152. Email
  153. ~~~~~
  154. * ...
  155. File Storage
  156. ~~~~~~~~~~~~
  157. * Storage backends now present a timezone-aware API with new methods
  158. :meth:`~django.core.files.storage.Storage.get_accessed_time`,
  159. :meth:`~django.core.files.storage.Storage.get_created_time`, and
  160. :meth:`~django.core.files.storage.Storage.get_modified_time`. They return a
  161. timezone-aware ``datetime`` if :setting:`USE_TZ` is ``True`` and a naive
  162. ``datetime`` in the local timezone otherwise.
  163. File Uploads
  164. ~~~~~~~~~~~~
  165. * ...
  166. Forms
  167. ~~~~~
  168. * Form and widget ``Media`` is now served using
  169. :mod:`django.contrib.staticfiles` if installed.
  170. Generic Views
  171. ~~~~~~~~~~~~~
  172. * The :class:`~django.views.generic.base.View` class can now be imported from
  173. ``django.views``.
  174. Internationalization
  175. ~~~~~~~~~~~~~~~~~~~~
  176. * The :func:`~django.conf.urls.i18n.i18n_patterns` helper function can now be
  177. used in a root URLConf specified using :attr:`request.urlconf
  178. <django.http.HttpRequest.urlconf>`.
  179. * By setting the new ``prefix_default_language`` parameter for
  180. :func:`~django.conf.urls.i18n.i18n_patterns` to ``False``, you can allow
  181. accessing the default language without a URL prefix.
  182. Management Commands
  183. ~~~~~~~~~~~~~~~~~~~
  184. * :func:`~django.core.management.call_command` now returns the value returned
  185. from the ``command.handle()`` method.
  186. * The new :option:`check --fail-level` option allows specifying the message
  187. level that will cause the command to exit with a non-zero status.
  188. * The new :option:`makemigrations --check` option makes the command exit
  189. with a non-zero status when model changes without migrations are detected.
  190. * :djadmin:`makemigrations` now displays the path to the migration files that
  191. it generates.
  192. * The :option:`shell --interface` option now accepts ``python`` to force use of
  193. the "plain" Python interpreter.
  194. * The new :option:`shell --command` option lets you run a command as Django and
  195. exit, instead of opening the interactive shell.
  196. * Added a warning to :djadmin:`dumpdata` if a proxy model is specified (which
  197. results in no output) without its concrete parent.
  198. * The new :attr:`BaseCommand.requires_migrations_checks
  199. <django.core.management.BaseCommand.requires_migrations_checks>` attribute
  200. may be set to ``True`` if you want your command to print a warning, like
  201. :djadmin:`runserver` does, if the set of migrations on disk don't match the
  202. migrations in the database.
  203. * To assist with testing, :func:`~django.core.management.call_command` now
  204. accepts a command object as the first argument.
  205. * The :djadmin:`shell` command supports tab completion on systems using
  206. ``libedit``, e.g. Mac OSX.
  207. * The :djadmin:`inspectdb` command lets you choose what tables should be
  208. inspected by specifying their names as arguments.
  209. Migrations
  210. ~~~~~~~~~~
  211. * Added support for serialization of ``enum.Enum`` objects.
  212. * Added the ``elidable`` argument to the
  213. :class:`~django.db.migrations.operations.RunSQL` and
  214. :class:`~django.db.migrations.operations.RunPython` operations to allow them
  215. to be removed when squashing migrations.
  216. * Added support for :ref:`non-atomic migrations <non-atomic-migrations>` by
  217. setting the ``atomic`` attribute on a ``Migration``.
  218. Models
  219. ~~~~~~
  220. * Reverse foreign keys from proxy models are now propagated to their
  221. concrete class. The reverse relation attached by a
  222. :class:`~django.db.models.ForeignKey` pointing to a proxy model is now
  223. accessible as a descriptor on the proxied model class and may be referenced in
  224. queryset filtering.
  225. * The new :meth:`Field.rel_db_type() <django.db.models.Field.rel_db_type>`
  226. method returns the database column data type for fields such as ``ForeignKey``
  227. and ``OneToOneField`` that point to another field.
  228. * The :attr:`~django.db.models.Func.arity` class attribute is added to
  229. :class:`~django.db.models.Func`. This attribute can be used to set the number
  230. of arguments the function accepts.
  231. * Added :class:`~django.db.models.BigAutoField` which acts much like an
  232. :class:`~django.db.models.AutoField` except that it is guaranteed
  233. to fit numbers from ``1`` to ``9223372036854775807``.
  234. * :meth:`QuerySet.in_bulk() <django.db.models.query.QuerySet.in_bulk>`
  235. may be called without any arguments to return all objects in the queryset.
  236. * :attr:`~django.db.models.ForeignKey.related_query_name` now supports
  237. app label and class interpolation using the ``'%(app_label)s'`` and
  238. ``'%(class)s'`` strings.
  239. * The :func:`~django.db.models.prefetch_related_objects` function is now a
  240. public API.
  241. * :meth:`QuerySet.bulk_create() <django.db.models.query.QuerySet.bulk_create>`
  242. sets the primary key on objects when using PostgreSQL.
  243. Requests and Responses
  244. ~~~~~~~~~~~~~~~~~~~~~~
  245. * Added ``request.user`` to the debug view.
  246. * Added :class:`~django.http.HttpResponse` methods
  247. :meth:`~django.http.HttpResponse.readable()` and
  248. :meth:`~django.http.HttpResponse.seekable()` to make an instance a
  249. stream-like object and allow wrapping it with :py:class:`io.TextIOWrapper`.
  250. * Added the :attr:`HttpResponse.content_type
  251. <django.http.HttpRequest.content_type>` and
  252. :attr:`~django.http.HttpRequest.content_params` attributes which are
  253. parsed from the ``CONTENT_TYPE`` header.
  254. * The parser for ``request.COOKIES`` is simplified to better match the behavior
  255. of browsers. ``request.COOKIES`` may now contain cookies that are invalid
  256. according to :rfc:`6265` but are possible to set via ``document.cookie``.
  257. Serialization
  258. ~~~~~~~~~~~~~
  259. * The ``django.core.serializers.json.DjangoJSONEncoder`` now knows how to
  260. serialize lazy strings, typically used for translatable content.
  261. Signals
  262. ~~~~~~~
  263. * ...
  264. Templates
  265. ~~~~~~~~~
  266. * Added the ``autoescape`` option to the
  267. :class:`~django.template.backends.django.DjangoTemplates` backend and the
  268. :class:`~django.template.Engine` class.
  269. * Added the ``is`` comparison operator to the :ttag:`if` tag.
  270. * Allowed :tfilter:`dictsort` to order a list of lists by an element at a
  271. specified index.
  272. Tests
  273. ~~~~~
  274. * To better catch bugs, :class:`~django.test.TestCase` now checks deferrable
  275. database constraints at the end of each test.
  276. * Tests and test cases can be :ref:`marked with tags <topics-tagging-tests>`
  277. and run selectively with the new :option:`test --tag` and :option:`test
  278. --exclude-tag` options.
  279. * Added the :setting:`DATABASES['TEST']['MIGRATE'] <TEST_MIGRATE>` option to
  280. allow disabling of migrations during test database creation.
  281. URLs
  282. ~~~~
  283. * An addition in :func:`django.setup()` allows URL resolving that happens
  284. outside of the request/response cycle (e.g. in management commands and
  285. standalone scripts) to take :setting:`FORCE_SCRIPT_NAME` into account when it
  286. is set.
  287. Validators
  288. ~~~~~~~~~~
  289. * :class:`~django.core.validators.URLValidator` now limits the length of
  290. domain name labels to 63 characters and the total length of domain
  291. names to 253 characters per :rfc:`1034`.
  292. * :func:`~django.core.validators.int_list_validator` now accepts an optional
  293. ``allow_negative`` boolean parameter, defaulting to ``False``, to allow
  294. negative integers.
  295. Backwards incompatible changes in 1.10
  296. ======================================
  297. .. warning::
  298. In addition to the changes outlined in this section, be sure to review the
  299. :ref:`removed-features-1.10` for the features that have reached the end of
  300. their deprecation cycle and therefore been removed. If you haven't updated
  301. your code within the deprecation timeline for a given feature, its removal
  302. may appear as a backwards incompatible change.
  303. Database backend API
  304. --------------------
  305. * GIS's ``AreaField`` uses an unspecified underlying numeric type that could in
  306. practice be any numeric Python type. ``decimal.Decimal`` values retrieved
  307. from the database are now converted to ``float`` to make it easier to combine
  308. them with values used by the GIS libraries.
  309. * In order to enable temporal subtraction you must set the
  310. ``supports_temporal_subtraction`` database feature flag to ``True`` and
  311. implement the ``DatabaseOperations.subtract_temporals()`` method. This
  312. method should return the SQL and parameters required to compute the
  313. difference in microseconds between the ``lhs`` and ``rhs`` arguments in the
  314. datatype used to store :class:`~django.db.models.DurationField`.
  315. ``select_related()`` prohibits non-relational fields for nested relations
  316. -------------------------------------------------------------------------
  317. Django 1.8 added validation for non-relational fields in ``select_related()``::
  318. >>> Book.objects.select_related('title')
  319. Traceback (most recent call last):
  320. ...
  321. FieldError: Non-relational field given in select_related: 'title'
  322. But it didn't prohibit nested non-relation fields as it does now::
  323. >>> Book.objects.select_related('author__name')
  324. Traceback (most recent call last):
  325. ...
  326. FieldError: Non-relational field given in select_related: 'name'
  327. ``_meta.get_fields()`` returns consistent reverse fields for proxy models
  328. -------------------------------------------------------------------------
  329. Before Django 1.10, the :meth:`~django.db.models.options.Options.get_fields`
  330. method returned different reverse fields when called on a proxy model compared
  331. to its proxied concrete class. This inconsistency was fixed by returning the
  332. full set of fields pointing to a concrete class or one of its proxies in both
  333. cases.
  334. :attr:`AbstractUser.username <django.contrib.auth.models.User.username>` ``max_length`` increased to 150
  335. --------------------------------------------------------------------------------------------------------
  336. A migration for :attr:`django.contrib.auth.models.User.username` is included.
  337. If you have a custom user model inheriting from ``AbstractUser``, you'll need
  338. to generate and apply a database migration for your user model.
  339. We considered an increase to 254 characters to more easily allow the use of
  340. email addresses (which are limited to 254 characters) as usernames but rejected
  341. it due to a MySQL limitation. When using the ``utf8mb4`` encoding (recommended
  342. for proper Unicode support), MySQL can only create unique indexes with 191
  343. characters by default. Therefore, if you need a longer length, please use a
  344. custom user model.
  345. If you want to preserve the 30 character limit for usernames, use a custom form
  346. when creating a user or changing usernames::
  347. from django.contrib.auth.forms import UserCreationForm
  348. class MyUserCreationForm(UserCreationForm):
  349. username = forms.CharField(
  350. max_length=30,
  351. help_text='Required. 30 characters or fewer. Letters, digits and @/./+/-/_ only.',
  352. )
  353. If you wish to keep this restriction in the admin, set ``UserAdmin.add_form``
  354. to use this form::
  355. from django.contrib.auth.admin import UserAdmin as BaseUserAdmin
  356. from django.contrib.auth.models import User
  357. class UserAdmin(BaseUserAdmin):
  358. add_form = MyUserCreationForm
  359. admin.site.unregister(User)
  360. admin.site.register(User, UserAdmin)
  361. Dropped support for PostgreSQL 9.1
  362. ----------------------------------
  363. Upstream support for PostgreSQL 9.1 ends in September 2016. As a consequence,
  364. Django 1.10 sets PostgreSQL 9.2 as the minimum version it officially supports.
  365. ``runserver`` output goes through logging
  366. -----------------------------------------
  367. Request and response handling of the ``runserver`` command is sent to the
  368. :ref:`django-server-logger` logger instead of to ``sys.stderr``. If you
  369. disable Django's logging configuration or override it with your own, you'll
  370. need to add the appropriate logging configuration if you want to see that
  371. output::
  372. 'formatters': {
  373. 'django.server': {
  374. '()': 'django.utils.log.ServerFormatter',
  375. 'format': '[%(server_time)s] %(message)s',
  376. }
  377. },
  378. 'handlers': {
  379. 'django.server': {
  380. 'level': 'INFO',
  381. 'class': 'logging.StreamHandler',
  382. 'formatter': 'django.server',
  383. },
  384. },
  385. 'loggers': {
  386. 'django.server': {
  387. 'handlers': ['django.server'],
  388. 'level': 'INFO',
  389. 'propagate': False,
  390. }
  391. }
  392. ``auth.CustomUser`` and ``auth.ExtensionUser`` test models were removed
  393. -----------------------------------------------------------------------
  394. Since the introduction of migrations for the contrib apps in Django 1.8, the
  395. tables of these custom user test models were not created anymore making them
  396. unusable in a testing context.
  397. Apps registry is no longer auto-populated when unpickling models outside of Django
  398. ----------------------------------------------------------------------------------
  399. The apps registry is no longer auto-populated when unpickling models. This was
  400. added in Django 1.7.2 as an attempt to allow unpickling models outside of
  401. Django, such as in an RQ worker, without calling ``django.setup()``, but it
  402. creates the possibility of a deadlock. To adapt your code in the case of RQ,
  403. you can `provide your own worker script <http://python-rq.org/docs/workers/>`_
  404. that calls ``django.setup()``.
  405. Removed null assignment check for non-null foreign key fields
  406. -------------------------------------------------------------
  407. In older versions, assigning ``None`` to a non-nullable ``ForeignKey`` or
  408. ``OneToOneField`` raised ``ValueError('Cannot assign None: "model.field" does
  409. not allow null values.')``. For consistency with other model fields which don't
  410. have a similar check, this check is removed.
  411. Removed weak password hashers from the default ``PASSWORD_HASHERS`` setting
  412. ---------------------------------------------------------------------------
  413. Django 0.90 stored passwords as unsalted MD5. Django 0.91 added support for
  414. salted SHA1 with automatic upgrade of passwords when a user logs in. Django 1.4
  415. added PBKDF2 as the default password hasher.
  416. If you have an old Django project with MD5 or SHA1 (even salted) encoded
  417. passwords, be aware that these can be cracked fairly easily with today's
  418. hardware. To make Django users acknowledge continued use of weak hashers, the
  419. following hashers are removed from the default :setting:`PASSWORD_HASHERS`
  420. setting::
  421. 'django.contrib.auth.hashers.SHA1PasswordHasher'
  422. 'django.contrib.auth.hashers.MD5PasswordHasher'
  423. 'django.contrib.auth.hashers.UnsaltedSHA1PasswordHasher'
  424. 'django.contrib.auth.hashers.UnsaltedMD5PasswordHasher'
  425. 'django.contrib.auth.hashers.CryptPasswordHasher'
  426. Consider using a :ref:`wrapped password hasher <wrapping-password-hashers>` to
  427. strengthen the hashes in your database. If that's not feasible, add the
  428. :setting:`PASSWORD_HASHERS` setting to your project and add back any hashers
  429. that you need.
  430. You can check if your database has any of the removed hashers like this::
  431. from django.contrib.auth import get_user_model
  432. User = get_user_model()
  433. # Unsalted MD5/SHA1:
  434. User.objects.filter(password__startswith='md5$$')
  435. User.objects.filter(password__startswith='sha1$$')
  436. # Salted MD5/SHA1:
  437. User.objects.filter(password__startswith='md5$').exclude(password__startswith='md5$$')
  438. User.objects.filter(password__startswith='sha1$').exclude(password__startswith='sha1$$')
  439. # Crypt hasher:
  440. User.objects.filter(password__startswith='crypt$$')
  441. from django.db.models import CharField
  442. from django.db.models.functions import Length
  443. CharField.register_lookup(Length)
  444. # Unsalted MD5 passwords might not have an 'md5$$' prefix:
  445. User.objects.filter(password__length=32)
  446. Miscellaneous
  447. -------------
  448. * The ``repr()`` of a ``QuerySet`` is wrapped in ``<QuerySet >`` to
  449. disambiguate it from a plain list when debugging.
  450. * Support for SpatiaLite < 3.0 and GEOS < 3.3 is dropped.
  451. * ``utils.version.get_version()`` returns :pep:`440` compliant release
  452. candidate versions (e.g. '1.10rc1' instead of '1.10c1').
  453. * The ``LOGOUT_URL`` setting is removed as Django hasn't made use of it
  454. since pre-1.0. If you use it in your project, you can add it to your
  455. project's settings. The default value was ``'/accounts/logout/'``.
  456. * The ``add_postgis_srs()`` backwards compatibility alias for
  457. ``django.contrib.gis.utils.add_srs_entry()`` is removed.
  458. * Objects with a ``close()`` method such as files and generators passed to
  459. :class:`~django.http.HttpResponse` are now closed immediately instead of when
  460. the WSGI server calls ``close()`` on the response.
  461. * A redundant ``transaction.atomic()`` call in ``QuerySet.update_or_create()``
  462. is removed. This may affect query counts tested by
  463. ``TransactionTestCase.assertNumQueries()``.
  464. * Support for ``skip_validation`` in ``BaseCommand.execute(**options)`` is
  465. removed. Use ``skip_checks`` (added in Django 1.7) instead.
  466. * :djadmin:`loaddata` now raises a ``CommandError`` instead of showing a
  467. warning when the specified fixture file is not found.
  468. * Instead of directly accessing the ``LogEntry.change_message`` attribute, it's
  469. now better to call the ``LogEntry.get_change_message()`` method which will
  470. provide the message in the current language.
  471. * The default error views now raise ``TemplateDoesNotExist`` if a nonexistent
  472. ``template_name`` is specified.
  473. * The unused ``choices`` keyword argument of the ``Select`` and
  474. ``SelectMultiple`` widgets' ``render()`` method is removed. The ``choices``
  475. argument of the ``render_options()`` method is also removed, making
  476. ``selected_choices`` the first argument.
  477. * On Oracle/GIS, the :class:`~django.contrib.gis.db.models.functions.Area`
  478. aggregate function now returns a ``float`` instead of ``decimal.Decimal``.
  479. (It's still wrapped in a measure of square meters.)
  480. * Tests that violate deferrable database constraints will now error when run on
  481. a database that supports deferrable constraints.
  482. * Built-in management commands now use indexing of keys in ``options``, e.g.
  483. ``options['verbosity']``, instead of ``options.get()`` and no longer perform
  484. any type coercion. This could be a problem if you're calling commands using
  485. ``Command.execute()`` (which bypasses the argument parser that sets a default
  486. value) instead of :func:`~django.core.management.call_command`. Instead of
  487. calling ``Command.execute()``, pass the command object as the first argument
  488. to ``call_command()``.
  489. * :class:`~django.contrib.auth.backends.ModelBackend` and
  490. :class:`~django.contrib.auth.backends.RemoteUserBackend` now reject inactive
  491. users. This means that inactive users can't login and will be logged
  492. out if they are switched from ``is_active=True`` to ``False``. If you need
  493. the previous behavior, use the new
  494. :class:`~django.contrib.auth.backends.AllowAllUsersModelBackend` or
  495. :class:`~django.contrib.auth.backends.AllowAllUsersRemoteUserBackend`
  496. in :setting:`AUTHENTICATION_BACKENDS` instead.
  497. .. _deprecated-features-1.10:
  498. Features deprecated in 1.10
  499. ===========================
  500. Direct assignment to a reverse foreign key or many-to-many relation
  501. -------------------------------------------------------------------
  502. Instead of assigning related objects using direct assignment::
  503. >>> new_list = [obj1, obj2, obj3]
  504. >>> e.related_set = new_list
  505. Use the :meth:`~django.db.models.fields.related.RelatedManager.set` method
  506. added in Django 1.9::
  507. >>> e.related_set.set([obj1, obj2, obj3])
  508. This prevents confusion about an assignment resulting in an implicit save.
  509. Non-timezone-aware :class:`~django.core.files.storage.Storage` API
  510. ------------------------------------------------------------------
  511. The old, non-timezone-aware methods ``accessed_time()``, ``created_time()``,
  512. and ``modified_time()`` are deprecated in favor of the new ``get_*_time()``
  513. methods.
  514. Third-party storage backends should implement the new methods and mark the old
  515. ones as deprecated. Until then, the new ``get_*_time()`` methods on the base
  516. :class:`~django.core.files.storage.Storage` class convert ``datetime``\s from
  517. the old methods as required and emit a deprecation warning as they do so.
  518. Third-party storage backends may retain the old methods as long as they
  519. wish to support earlier versions of Django.
  520. :mod:`django.contrib.gis`
  521. -------------------------
  522. * The ``get_srid()`` and ``set_srid()`` methods of
  523. :class:`~django.contrib.gis.geos.GEOSGeometry` are deprecated in favor
  524. of the :attr:`~django.contrib.gis.geos.GEOSGeometry.srid` property.
  525. * The ``get_x()``, ``set_x()``, ``get_y()``, ``set_y()``, ``get_z()``, and
  526. ``set_z()`` methods of :class:`~django.contrib.gis.geos.Point` are deprecated
  527. in favor of the ``x``, ``y``, and ``z`` properties.
  528. * The ``get_coords()`` and ``set_coords()`` methods of
  529. :class:`~django.contrib.gis.geos.Point` are deprecated in favor of the
  530. ``tuple`` property.
  531. * The ``cascaded_union`` property of
  532. :class:`~django.contrib.gis.geos.MultiPolygon` is deprecated in favor of the
  533. :attr:`~django.contrib.gis.geos.GEOSGeometry.unary_union` property.
  534. ``CommaSeparatedIntegerField`` model field
  535. ------------------------------------------
  536. ``CommaSeparatedIntegerField`` is deprecated in favor of
  537. :class:`~django.db.models.CharField` with the
  538. :func:`~django.core.validators.validate_comma_separated_integer_list`
  539. validator::
  540. from django.core.validators import validate_comma_separated_integer_list
  541. from django.db import models
  542. class MyModel(models.Model):
  543. numbers = models.CharField(..., validators=[validate_comma_separated_integer_list])
  544. If you're using Oracle, ``CharField`` uses a different database field type
  545. (``NVARCHAR2``) than ``CommaSeparatedIntegerField`` (``VARCHAR2``). Depending
  546. on your database settings, this might imply a different encoding, and thus a
  547. different length (in bytes) for the same contents. If your stored values are
  548. longer than the 4000 byte limit of ``NVARCHAR2``, you should use ``TextField``
  549. (``NCLOB``) instead. In this case, if you have any queries that group by the
  550. field (e.g. annotating the model with an aggregation or using ``distinct()``)
  551. you'll need to change them (to defer the field).
  552. Using a model name as a query lookup when ``default_related_name`` is set
  553. -------------------------------------------------------------------------
  554. Assume the following models::
  555. from django.db import models
  556. class Foo(models.Model):
  557. pass
  558. class Bar(models.Model):
  559. foo = models.ForeignKey(Foo)
  560. class Meta:
  561. default_related_name = 'bars'
  562. In older versions, :attr:`~django.db.models.Options.default_related_name`
  563. couldn't be used as a query lookup. This is fixed and support for the old
  564. lookup name is deprecated. For example, since ``default_related_name`` is set
  565. in model ``Bar``, instead of using the model name ``bar`` as the lookup::
  566. >>> bar = Bar.objects.get(pk=1)
  567. >>> Foo.object.get(bar=bar)
  568. use the default_related_name ``bars``::
  569. >>> Foo.object.get(bars=bar)
  570. .. _search-lookup-replacement:
  571. ``__search`` query lookup
  572. -------------------------
  573. The ``search`` lookup, which supports MySQL only and is extremely limited in
  574. features, is deprecated. Replace it with a custom lookup::
  575. from django.db import models
  576. class Search(models.Lookup):
  577. lookup_name = 'search'
  578. def as_mysql(self, compiler, connection):
  579. lhs, lhs_params = self.process_lhs(compiler, connection)
  580. rhs, rhs_params = self.process_rhs(compiler, connection)
  581. params = lhs_params + rhs_params
  582. return 'MATCH (%s) AGAINST (%s IN BOOLEAN MODE)' % (lhs, rhs), params
  583. models.CharField.register_lookup(Search)
  584. models.TextField.register_lookup(Search)
  585. Custom manager classes available through ``prefetch_related`` must define a ``_apply_rel_filters()`` method
  586. -----------------------------------------------------------------------------------------------------------
  587. If you defined a custom manager class available through
  588. :meth:`~django.db.models.query.QuerySet.prefetch_related` you must make sure
  589. it defines a ``_apply_rel_filters()`` method.
  590. This method must accept a :class:`~django.db.models.query.QuerySet` instance
  591. as its single argument and return a filtered version of the queryset for the
  592. model instance the manager is bound to.
  593. Miscellaneous
  594. -------------
  595. * The ``makemigrations --exit`` option is deprecated in favor of the
  596. :option:`makemigrations --check` option.
  597. * ``django.utils.functional.allow_lazy()`` is deprecated in favor of the new
  598. :func:`~django.utils.functional.keep_lazy` function which can be used with a
  599. more natural decorator syntax.
  600. * The ``shell --plain`` option is deprecated in favor of ``-i python`` or
  601. ``--interface python``.
  602. * Importing from the ``django.core.urlresolvers`` module is deprecated in
  603. favor of its new location, :mod:`django.urls`.
  604. * The template ``Context.has_key()`` method is deprecated in favor of ``in``.
  605. .. _removed-features-1.10:
  606. Features removed in 1.10
  607. ========================
  608. These features have reached the end of their deprecation cycle and so have been
  609. removed in Django 1.10 (please see the :ref:`deprecation timeline
  610. <deprecation-removed-in-1.10>` for more details):
  611. * Support for calling a ``SQLCompiler`` directly as an alias for calling its
  612. ``quote_name_unless_alias`` method is removed.
  613. * The ``cycle`` and ``firstof`` template tags are removed from the ``future``
  614. template tag library.
  615. * ``django.conf.urls.patterns()`` is removed.
  616. * Support for the ``prefix`` argument to
  617. ``django.conf.urls.i18n.i18n_patterns()`` is removed.
  618. * ``SimpleTestCase.urls`` is removed.
  619. * Using an incorrect count of unpacked values in the ``for`` template tag
  620. raises an exception rather than failing silently.
  621. * The ability to :func:`~django.urls.reverse` URLs using a dotted Python path
  622. is removed.
  623. * The ability to use a dotted Python path for the ``LOGIN_URL`` and
  624. ``LOGIN_REDIRECT_URL`` settings is removed.
  625. * Support for ``optparse`` is dropped for custom management commands.
  626. * The class ``django.core.management.NoArgsCommand`` is removed.
  627. * ``django.core.context_processors`` module is removed.
  628. * ``django.db.models.sql.aggregates`` module is removed.
  629. * ``django.contrib.gis.db.models.sql.aggregates`` module is removed.
  630. * The following methods and properties of ``django.db.sql.query.Query`` are
  631. removed:
  632. * Properties: ``aggregates`` and ``aggregate_select``
  633. * Methods: ``add_aggregate``, ``set_aggregate_mask``, and
  634. ``append_aggregate_mask``.
  635. * ``django.template.resolve_variable`` is removed.
  636. * The following private APIs are removed from
  637. :class:`django.db.models.options.Options` (``Model._meta``):
  638. * ``get_field_by_name()``
  639. * ``get_all_field_names()``
  640. * ``get_fields_with_model()``
  641. * ``get_concrete_fields_with_model()``
  642. * ``get_m2m_with_model()``
  643. * ``get_all_related_objects()``
  644. * ``get_all_related_objects_with_model()``
  645. * ``get_all_related_many_to_many_objects()``
  646. * ``get_all_related_m2m_objects_with_model()``
  647. * The ``error_message`` argument of ``django.forms.RegexField`` is removed.
  648. * The ``unordered_list`` filter no longer supports old style lists.
  649. * Support for string ``view`` arguments to ``url()`` is removed.
  650. * The backward compatible shim to rename ``django.forms.Form._has_changed()``
  651. to ``has_changed()`` is removed.
  652. * The ``removetags`` template filter is removed.
  653. * The ``remove_tags()`` and ``strip_entities()`` functions in
  654. ``django.utils.html`` is removed.
  655. * The ``is_admin_site`` argument to
  656. ``django.contrib.auth.views.password_reset()`` is removed.
  657. * ``django.db.models.field.subclassing.SubfieldBase`` is removed.
  658. * ``django.utils.checksums`` is removed.
  659. * The ``original_content_type_id`` attribute on
  660. ``django.contrib.admin.helpers.InlineAdminForm`` is removed.
  661. * The backwards compatibility shim to allow ``FormMixin.get_form()`` to be
  662. defined with no default value for its ``form_class`` argument is removed.
  663. * The following settings are removed:
  664. * ``ALLOWED_INCLUDE_ROOTS``
  665. * ``TEMPLATE_CONTEXT_PROCESSORS``
  666. * ``TEMPLATE_DEBUG``
  667. * ``TEMPLATE_DIRS``
  668. * ``TEMPLATE_LOADERS``
  669. * ``TEMPLATE_STRING_IF_INVALID``
  670. * The backwards compatibility alias ``django.template.loader.BaseLoader`` is
  671. removed.
  672. * Django template objects returned by
  673. :func:`~django.template.loader.get_template` and
  674. :func:`~django.template.loader.select_template` no longer accept a
  675. :class:`~django.template.Context` in their
  676. :meth:`~django.template.backends.base.Template.render()` method.
  677. * :doc:`Template response APIs </ref/template-response>` enforce the use of
  678. :class:`dict` and backend-dependent template objects instead of
  679. :class:`~django.template.Context` and :class:`~django.template.Template`
  680. respectively.
  681. * The ``current_app`` parameter for the following function and classes is
  682. removed:
  683. * ``django.shortcuts.render()``
  684. * ``django.template.Context()``
  685. * ``django.template.RequestContext()``
  686. * ``django.template.response.TemplateResponse()``
  687. * The ``dictionary`` and ``context_instance`` parameters for the following
  688. functions are removed:
  689. * ``django.shortcuts.render()``
  690. * ``django.shortcuts.render_to_response()``
  691. * ``django.template.loader.render_to_string()``
  692. * The ``dirs`` parameter for the following functions is removed:
  693. * ``django.template.loader.get_template()``
  694. * ``django.template.loader.select_template()``
  695. * ``django.shortcuts.render()``
  696. * ``django.shortcuts.render_to_response()``
  697. * Session verification is enabled regardless of whether or not
  698. ``'django.contrib.auth.middleware.SessionAuthenticationMiddleware'`` is in
  699. ``MIDDLEWARE_CLASSES``. ``SessionAuthenticationMiddleware`` no longer has
  700. any purpose and can be removed from ``MIDDLEWARE_CLASSES``. It's kept as
  701. a stub until Django 2.0 as a courtesy for users who don't read this note.
  702. * Private attribute ``django.db.models.Field.related`` is removed.
  703. * The ``--list`` option of the ``migrate`` management command is removed.
  704. * The ``ssi`` template tag is removed.
  705. * Support for the ``=`` comparison operator in the ``if`` template tag is
  706. removed.
  707. * The backwards compatibility shims to allow ``Storage.get_available_name()``
  708. and ``Storage.save()`` to be defined without a ``max_length`` argument are
  709. removed.
  710. * Support for the legacy ``%(<foo>)s`` syntax in ``ModelFormMixin.success_url``
  711. is removed.
  712. * ``GeoQuerySet`` aggregate methods ``collect()``, ``extent()``, ``extent3d()``,
  713. ``make_line()``, and ``unionagg()`` are removed.
  714. * The ability to specify ``ContentType.name`` when creating a content type
  715. instance is removed.
  716. * Support for the old signature of ``allow_migrate`` is removed.
  717. * Support for the syntax of ``{% cycle %}`` that uses comma-separated arguments
  718. is removed.
  719. * The warning that :class:`~django.core.signing.Signer` issued when given an
  720. invalid separator is now a ``ValueError``.