Django 1.4 release candidate 2
djangoproject.com
djangoproject.com
- Lots and lots of improvements to the admin app. Also, dropped support for IE6 in the admin ;)
- Better password hashing.
- A cookie-based session backend that uses cryptographic signing to store session data in the browser.
- A new form wizard. This is a big one for me since I needed something like this for one of my side projects.
- Improved WSGI support.
- Custom project and app templates.
- OMG OMG OMG timezone support. "When it's enabled, Django stores date and time information in UTC in the database, uses time-zone-aware datetime objects internally and translates them to the end user's time zone in templates and forms." You could always do this manually, but it's one of those things that should be handled by the framework.
Pretty nice stuff. Best part is, since I'm in very early stages of building a personal website using Django, I can start using this release right now.PS: does anyone else think activity around Django has increased ever since Adrian started spending more time on it? (see http://www.holovaty.com/writing/back-to-django/)
https://code.djangoproject.com/log/django/trunk/docs/interna...
I think that Django went through a rough period of growing pains there but now seems back on track.
https://docs.djangoproject.com/en/dev/ref/models/querysets/#...
PASSWORD_HASHERS = (
'django.contrib.auth.hashers.PBKDF2PasswordHasher',
'django.contrib.auth.hashers.PBKDF2SHA1PasswordHasher',
'django.contrib.auth.hashers.BCryptPasswordHasher',
'django.contrib.auth.hashers.SHA1PasswordHasher',
'django.contrib.auth.hashers.MD5PasswordHasher',
'django.contrib.auth.hashers.CryptPasswordHasher',
)
You get a tuple of password algorithms that are supported. The higher on the list the greater priority it has, so if you have SHA1 passwords in your database, they will get converted to PBKDF2 when the user logs in the first time.If you decided to switch to BCrypt, you would first install py-bcrypt and change the tuple to put BCrypt at the top:
PASSWORD_HASHERS = (
'django.contrib.auth.hashers.BCryptPasswordHasher',
'django.contrib.auth.hashers.PBKDF2PasswordHasher',
'django.contrib.auth.hashers.PBKDF2SHA1PasswordHasher',
'django.contrib.auth.hashers.BCryptPasswordHasher',
'django.contrib.auth.hashers.SHA1PasswordHasher',
'django.contrib.auth.hashers.MD5PasswordHasher',
'django.contrib.auth.hashers.CryptPasswordHasher',
)
and you're done.HOWEVER, if you are sharing the database with an older project that is still using Django 1.3 or less, make sure that 'django.contrib.auth.hashers.SHA1PasswordHasher' is on the top of the list (until all your projects are Django 1.4 or higher) otherwise your other installations won't be able to read the passwords since they won't support any of the newer password hashes.
in settings.py until you get a chance to test things to make sure.