Reference
Model instance reference
… as a whole - Model.clean() Validate the field uniqueness - Model.validate_unique() Validate the constraints - Model.validate_constraints() All four steps are performed when you call a model’s full_clean() method. When you use a ModelForm, the call to is_valid() will perform these …
Reference
Model instance reference
class Article(models.Model): ... To assign exceptions to a specific field, instantiate the ValidationError with a dictionary, where the keys are the field names.
Topic guide
Models
Fields
INTEGER, VARCHAR, TEXT). The default HTML widget to use when rendering a form field (e.g. <input type="text">, <select>). The minimal validation requirements, used in Django’s admin and in automatically-generated forms.
Topic guide
Creating forms from models
Model formsets
Just like with a ModelForm, by default the clean() method of a ModelFormSet will validate that none of the items in the formset violate the unique constraints on your model (either unique, unique_together or unique_for_date|month|year).
Reference
The Django admin site
ModelAdmin objects
ModelAdmin.formfield_for_manytomany(db_field,request,**kwargs) : Like the formfield_for_foreignkey method, the formfield_for_manytomany method can be overridden to change the default formfield for a many to many field.
Topic guide
Translation
Internationalization: in Python codeWorking with lazy translation objects
When using lazy translation for a plural string (n[p]gettext_lazy), you generally don’t know the number argument at the time of the string definition. Therefore, you are authorized to pass a key name instead of an integer as the number argument.
Reference
The Django admin site
ModelAdmin objects
That is, fields listed in list_editable will be displayed as form widgets on the change list page, allowing users to edit and save multiple rows at once.
Reference
Cross Site Request Forgery protection
2. A hidden form field with the name ‘csrfmiddlewaretoken’, present in all outgoing POST forms. In order to protect against BREACH attacks, the value of this field is not simply the secret.
Topic guide
Using the Django authentication system
Authentication in web requests
If you don’t want to use the built-in views, but want the convenience of not having to write forms for this functionality, the authentication system provides several built-in forms located in django.contrib.auth.forms: NOTE: The built-in authentication forms make certain assumptions …
Topic guide
Formsets
The max_num parameter to formset_factory() gives you the ability to limit the number of forms the formset will display: If the value of max_num is greater than the number of existing items in the initial data, up to extra additional …
Topic guide
Creating forms from models
ModelForm
… you can do so by defining the field declaratively and setting its validators parameter: NOTE: When you explicitly instantiate a form field like this, it is important to > understand how ModelForm and regular Form are related. ModelForm is a …
Topic guide
… Apache and mod_wsgi Get your database running Install the Django code Models and databases Models Making queries Aggregation Search Managers Performing raw SQL queries Database transactions Multiple databases Tablespaces Database access optimization Database instrumentation Fixtures Examples of model relationship API …
Index
… - naturaltime - template filter - NEVER (ModelAdmin.ShowFacets attribute) - never_cache() (in module django.views.decorators.cache) - new_file() (FileUploadHandler method) - new_objects (models.BaseModelFormSet attribute) - next_page (LoginView attribute) - (LogoutView attribute) - next_page_number() (Page method) - ngettext() (in module django.utils.translation) - ngettext_lazy() …
Reference
The Django admin site
ModelAdmin objects
ModelAdmin.form : By default a ModelForm is dynamically created for your model. It is used to create the form presented on both the add/change pages.
Reference
GDAL API
Raster Data ObjectsUsing GDAL’s Virtual Filesystem
When validating geometry inputs, the GeometryField form field will reject raster values. When validating raster inputs, you should write custom validation. For defense-in-depth strategies for limiting the available raster drivers, see GDAL security considerations.
Topic guide
Sending email
Header injection is a security exploit in which an attacker inserts extra email headers to control the “To:” and “From:” in email messages that your scripts generate.
Topic guide
Customizing authentication in Django
Substituting a custom User model
This model would be compatible with all the built-in auth forms and views, except for the user creation forms.
Index
… setting - CACHES-TIMEOUT - setting - CACHES-VERSION - setting - CallbackFilter (class in django.utils.log) - callproc() (CursorWrapper method) - can_delete (BaseFormSet attribute) - (InlineModelAdmin attribute) - can_delete_extra (BaseFormSet attribute) - can_order (BaseFormSet attribute) - capfirst - template filter - captured_kwargs …
Index
… - PASSWORD - setting - password (models.User attribute) - password_change_done_template (AdminSite attribute) - password_change_template (AdminSite attribute) - password_changed() (in module django.contrib.auth.password_validation) - PASSWORD_HASHERS - setting - PASSWORD_RESET_TIMEOUT - setting - password_validators_help_text_html() (in module django.contrib.auth.password_validation) - password_validators_help_texts() (in module django.contrib.auth.password_validation) - …
Index
… urlencode - template filter - urlencode() (in module django.utils.http) - (QueryDict method) - URLField (class in django.db.models) - (class in django.forms) - URLInput (class in django.forms) - urlize - template filter - urlizetrunc - template filter - urls - definitive …