djangodocs.org

689 sections across all versions Narrow to Django 6.0 (current) →

Reference Settings Core Settings

You can set this to None to disable the check. Applications that are expected to receive unusually large form posts should tune this setting. Under ASGI, the entire request may be spooled to disk before this limit is enforced.

Reference Settings Core Settings

You can set this to None to disable the check. Applications that are expected to receive an unusually large number of form fields should tune this setting.

csp_nonce_attr

Reference Built-in template tags and filters Built-in tag reference

… object as the argument, renders its assets with the CSP nonce applied to each <script> and <link> element: In both forms, if the context processor is not configured, assets are rendered without a nonce attribute. See Nonce usage for full …

dev

get_static_prefix

Reference Built-in template tags and filters Other tags and filters librariesstatic

… need more control over exactly where and how STATIC_URL is injected into the template, you can use the get_static_prefix template tag: There’s also a second form you can use to avoid extra processing if you need the value multiple times:

Conversion functions

Reference Unicode data General string handlingUseful utility functions

… its input to a string. The encoding parameter specifies the input encoding. (For example, Django uses this internally when processing form input data, which might not be UTF-8 encoded.) The strings_only parameter, if set to True, will result in Python …

Topic guide Using the Django authentication system Authentication in web requestsLimiting access to logged-in users

permission_required(perm,login_url=None,raise_exception=False)[source] : It’s a relatively common task to check whether a user has a particular permission. For that reason, Django provides a shortcut for that case: the permission_required() decorator:

Class-based views

Topic guide

For full details, see the class-based views reference documentation. Introduction to class-based views Built-in class-based generic views Form handling with class-based views Using mixins with class-based views

A better solution

Topic guide Using mixins with class-based views Avoid anything more complex

The number of subtle interactions between FormMixin and DetailView is already testing our ability to manage things. It’s unlikely you’d want to write this kind of class yourself.

Topic guide Using mixins with class-based views Avoid anything more complex

So why not do just that? We have a very clear division here: GET requests should get the DetailView (with the Form added to the context data), and POST requests should get the FormView. Let’s set up those views first.

Field lookups

Topic guide Making queries Retrieving objects

Field lookups are how you specify the meat of an SQL WHERE clause. They’re specified as keyword arguments to the QuerySet methods filter(), exclude() and get(). Basic lookups keyword arguments take the form field__lookuptype=value. (That’s a double-underscore).

The pk lookup shortcut

Topic guide Making queries Retrieving objects

… equivalent: The use of pk isn’t limited to __exact queries – any query term can be combined with pk to perform a query on the primary key of a model: pk lookups also work across joins. For example, these three …

Topic guide Making queries Querying JSONField

… To query a key for JSON null, None or JSONNull() can be used. Multiple keys can be chained together to form a path lookup: If the key is an integer, it will be interpreted as an index transform in an …

dev

Topic guide Formsets

The absolute_max parameter to formset_factory() allows limiting the number of forms that can be instantiated when supplying POST data. This protects against memory exhaustion attacks using forged POST requests: When absolute_max is None, it defaults to max_num + 1000.

can_order

Topic guide Formsets Dealing with ordering and deletion of forms

BaseFormSet.can_order Default: False Lets you create a formset with the ability to order: This adds an additional field to each form. This new field is named ORDER and is an forms.IntegerField.

can_delete

Topic guide Formsets Dealing with ordering and deletion of forms

BaseFormSet.can_delete Default: False Lets you create a formset with the ability to select forms for deletion: Similar to can_order this adds a new field to each form named DELETE and is a forms.BooleanField.