#28262: ModelAdmin.lookup_allowed() incorrectly raises 
DisallowedModelAdminLookup
lookup with reverse relation to origin model
--------------------------------------+------------------------------------
     Reporter:  Michal Dabski         |                    Owner:  nobody
         Type:  Bug                   |                   Status:  new
    Component:  contrib.admin         |                  Version:  1.11
     Severity:  Release blocker       |               Resolution:
     Keywords:  admin,lookup_allowed  |             Triage Stage:  Accepted
    Has patch:  0                     |      Needs documentation:  0
  Needs tests:  0                     |  Patch needs improvement:  0
Easy pickings:  0                     |                    UI/UX:  0
--------------------------------------+------------------------------------
Changes (by Tim Graham):

 * severity:  Normal => Release blocker
 * stage:  Unreviewed => Accepted


Old description:

> Consider the following models:
>
> {{{
> class AuditSession(Model):
>     auditor = models.ForeignKey(User)
>
> class Institution(Model):
>     name = models.CharField(max_length=100)
>
> class Auditor(Model):
>     user = models.OneToOneField(User)
>     institution = models.ForeignKey(Institution, null=True, blank=True)
> }}}
>
> And the following filter in audit session admin:
> {{{
> class AuditSessionAdmin(ModelAdmin):
>     list_filter = (
>         ('auditor__auditor__institution'),
>     )
> }}}
>
> As of Django version 1.9 up to the latest release 1.11.1, the above
> lookup will raise server error when used by raising
> `DisallowedModelAdminLookup (Filtering by
> auditor__auditor__institution__id__exact not allowed)`. This is because
> the lookup uses reverse relation between User and Auditor model.
>
> This lookup passes checks and only crashes when user tries to use the
> filter. I could not find the reasoning behind the implementation of
> lookup_allowed and why it would forbid using reverse relations. Nor could
> I find any documentation for this change in 1.9 release notes.
> I have recently upgraded from django 1.8 where this lookup worked
> perfectly fine.

New description:

 Consider the following models:

 {{{
 from django.db import models
 from django.contrib.auth.models import User

 class AuditSession(models.Model):
     auditor = models.ForeignKey(User, on_delete=models.CASCADE)

 class Institution(models.Model):
     name = models.CharField(max_length=100)

     def __str__(self):
         return self.name

 class Auditor(models.Model):
     user = models.OneToOneField(User, on_delete=models.CASCADE)
     institution = models.ForeignKey(Institution, on_delete=models.CASCADE,
 null=True, blank=True)
 }}}

 And the following filter in audit session admin:
 {{{
 from django.contrib import admin

 from .models import AuditSession, Institution, Auditor

 @admin.register(AuditSession)
 class AuditSessionAdmin(admin.ModelAdmin):
     list_filter = (
         ('auditor__auditor__institution'),
     )

 admin.site.register((Institution, Auditor))
 }}}

 As of Django version 1.9 up to the latest release 1.11.1, the above lookup
 will raise server error when used by raising `DisallowedModelAdminLookup
 (Filtering by auditor__auditor__institution__id__exact not allowed)`. This
 is because the lookup uses reverse relation between User and Auditor
 model.

 This lookup passes checks and only crashes when user tries to use the
 filter. I could not find the reasoning behind the implementation of
 lookup_allowed and why it would forbid using reverse relations. Nor could
 I find any documentation for this change in 1.9 release notes.
 I have recently upgraded from django 1.8 where this lookup worked
 perfectly fine.

--

Comment:

 Correction: 8f30556329b64005d63b66859a74752a0b261315 is the commit where
 the regression appeared. I'm updating the description with a copy/paste
 version of the models/admin that I used.

--
Ticket URL: <https://code.djangoproject.com/ticket/28262#comment:3>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-updates/064.4af379be992b85f59dfa226d34389654%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to