[django/django] a7af6a: [1.6.x] Fixed #23431 -- Allowed inline and hidden ...

2 views
Skip to first unread message

GitHub

unread,
Sep 8, 2014, 2:06:57 PM9/8/14
to django-...@googlegroups.com
Branch: refs/heads/stable/1.6.x
Home: https://github.com/django/django
Commit: a7af6ad96a35634383c2d73fa049127e85a886a6
https://github.com/django/django/commit/a7af6ad96a35634383c2d73fa049127e85a886a6
Author: Simon Charette <chare...@gmail.com>
Date: 2014-09-08 (Mon, 08 Sep 2014)

Changed paths:
M django/contrib/admin/options.py
A docs/releases/1.4.16.txt
A docs/releases/1.5.11.txt
A docs/releases/1.6.8.txt
M docs/releases/index.txt
M tests/admin_views/admin.py
M tests/admin_views/models.py
M tests/admin_views/tests.py

Log Message:
-----------
[1.6.x] Fixed #23431 -- Allowed inline and hidden references to admin fields.

This fixes a regression introduced by the 53ff096982 security fix.

Thanks to @a1tus for the report and Tim for the review.

refs #23329.

Backport of 342ccbd from master


Reply all
Reply to author
Forward
0 new messages