#28262: ModelAdmin.lookup_allowed() incorrectly raises
DisallowedModelAdminLookup
lookup with reverse relation to origin model
--------------------------------------+------------------------------------
Reporter: Michal Dabski | Owner: nobody
Type: Bug | Status: new
Component: contrib.admin | Version: 1.11
Severity: Release blocker | Resolution:
Keywords: admin,lookup_allowed | Triage Stage: Accepted
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
--------------------------------------+------------------------------------
Changes (by Tim Graham):
* severity: Normal => Release blocker
* stage: Unreviewed => Accepted
Old description:
> Consider the following models:
>
> {{{
> class AuditSession(Model):
> auditor = models.ForeignKey(User)
>
> class Institution(Model):
> name = models.CharField(max_length=100)
>
> class Auditor(Model):
> user = models.OneToOneField(User)
> institution = models.ForeignKey(Institution, null=True, blank=True)
> }}}
>
> And the following filter in audit session admin:
> {{{
> class AuditSessionAdmin(ModelAdmin):
> list_filter = (
> ('auditor__auditor__institution'),
> )
> }}}
>
> As of Django version 1.9 up to the latest release 1.11.1, the above
> lookup will raise server error when used by raising
> `DisallowedModelAdminLookup (Filtering by
> auditor__auditor__institution__id__exact not allowed)`. This is because
> the lookup uses reverse relation between User and Auditor model.
>
> This lookup passes checks and only crashes when user tries to use the
> filter. I could not find the reasoning behind the implementation of
> lookup_allowed and why it would forbid using reverse relations. Nor could
> I find any documentation for this change in 1.9 release notes.
> I have recently upgraded from django 1.8 where this lookup worked
> perfectly fine.
New description:
Consider the following models:
{{{
from django.db import models
from django.contrib.auth.models import User
class AuditSession(models.Model):
auditor = models.ForeignKey(User, on_delete=models.CASCADE)
class Institution(models.Model):
name = models.CharField(max_length=100)
def __str__(self):
return self.name
class Auditor(models.Model):
user = models.OneToOneField(User, on_delete=models.CASCADE)
institution = models.ForeignKey(Institution, on_delete=models.CASCADE,
null=True, blank=True)
}}}
And the following filter in audit session admin:
{{{
from django.contrib import admin
from .models import AuditSession, Institution, Auditor
@admin.register(AuditSession)
class AuditSessionAdmin(admin.ModelAdmin):
list_filter = (
('auditor__auditor__institution'),
)
admin.site.register((Institution, Auditor))
}}}
As of Django version 1.9 up to the latest release 1.11.1, the above lookup
will raise server error when used by raising `DisallowedModelAdminLookup
(Filtering by auditor__auditor__institution__id__exact not allowed)`. This
is because the lookup uses reverse relation between User and Auditor
model.
This lookup passes checks and only crashes when user tries to use the
filter. I could not find the reasoning behind the implementation of
lookup_allowed and why it would forbid using reverse relations. Nor could
I find any documentation for this change in 1.9 release notes.
I have recently upgraded from django 1.8 where this lookup worked
perfectly fine.
--
Comment:
Correction: 8f30556329b64005d63b66859a74752a0b261315 is the commit where
the regression appeared. I'm updating the description with a copy/paste
version of the models/admin that I used.
--
Ticket URL: <https://code.djangoproject.com/ticket/28262#comment:3>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/064.4af379be992b85f59dfa226d34389654%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.