mirror of
https://github.com/django/django.git
synced 2024-11-25 07:59:34 +01:00
552f03869e
The errors='replace' parameter to force_text altered the URL before checking it, which wasn't considered sane. Refs24fc935218
andada7a4aef
.
9 lines
254 B
Plaintext
9 lines
254 B
Plaintext
==========================
|
|
Django 1.9.4 release notes
|
|
==========================
|
|
|
|
*March 5, 2016*
|
|
|
|
Django 1.9.4 fixes a regression on Python 2 in the 1.9.3 security release
|
|
where ``utils.http.is_safe_url()`` crashes on bytestring URLs (:ticket:`26308`).
|