Re: ModelForms and the Rails input handling vulnerability

2012-06-17 Thread Anssi Kääriäinen
On 17 kesä, 23:14, Erik Romijn wrote: > Especially after seeing Jessica McKellar's keynote at Djangocon EU, on > the experience of novice developers when using Django, I strongly feel > we should not leave the situation as it is. Although this risk and it's > mitigations may be obvious to people o

Re: ModelForms and the Rails input handling vulnerability

2012-06-17 Thread Erik Romijn
Hello Luke and others, On Jun 13, 2012, at 1:16 AM, Luke Plant wrote: > On django-core we've been discussing an issue that was security related. > However, we decided it wasn't urgent enough to warrant a security > release, and so we're moving the discussion here (especially because we > couldn't

Re: GeoDjango and requirement's versions

2012-06-17 Thread Volker Froehlich
On Wed, 2012-05-30 at 05:05 -0700, Václav Řehák wrote: > > Has anybody tested GDAL 1.9 or Proj 4.8? I've seen, ubuntu uses GDAL 1.7 > > (and gdal 1.9 for the next release). Is there any known test case to > > check, if geodjango works with proj 4.8 and/or GDAL 1.9? > > I haven't tested myself but