mirror of
https://github.com/django/django.git
synced 2024-11-24 02:47:35 +01:00
b55699968f
- Validate filename returned by FileField.upload_to() not a filename
passed to the FileField.generate_filename() (upload_to() may
completely ignored passed filename).
- Allow relative paths (without dot segments) in the generated filename.
Thanks to Jakub Kleň for the report and review.
Thanks to all folks for checking this patch on existing projects.
Thanks Florian Apolloner and Markus Holtermann for the discussion and
implementation idea.
Regression in 0b79eb3691
.
16 lines
388 B
Plaintext
16 lines
388 B
Plaintext
===========================
|
|
Django 2.2.23 release notes
|
|
===========================
|
|
|
|
*May 13, 2021*
|
|
|
|
Django 2.2.23 fixes a regression in 2.2.21.
|
|
|
|
Bugfixes
|
|
========
|
|
|
|
* Fixed a regression in Django 2.2.21 where saving ``FileField`` would raise a
|
|
``SuspiciousFileOperation`` even when a custom
|
|
:attr:`~django.db.models.FileField.upload_to` returns a valid file path
|
|
(:ticket:`32718`).
|