#28589: When saving in admin, readonly fields are potentially overwritten
-------------------------------------+-------------------------------------
Reporter: FingalP | Owner: FingalP
Type: Bug | Status: assigned
Component: contrib.admin | Version: master
Severity: Normal | Resolution:
Keywords: Admin SQL Overwrite | Triage Stage:
| Unreviewed
Has patch: 1 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 1 | UI/UX: 0
-------------------------------------+-------------------------------------
Description changed by FingalP:
Old description:
> On the admin page for a model, if a field is in readonly_fields or has
> editable=False, then saving that model from the admin will create an SQL
> query that sets the readonly field to it's value at the time the save
> button was clicked. This field might have been changed (e.g. by a command
> or some other process) during the time that the model is being saved, and
> with current behaviour it would then be overwritten to it's old value.
>
> Correct behaviour would be to not set the readonly field at all in the
> SQL query.
New description:
On the admin page for a model, if a field is in readonly_fields or has
editable=False, then saving that model from the admin will create an SQL
query that sets the readonly field to it's value at the time the save
button was clicked. This field might have been changed (e.g. by a command
or some other process) during the time that the model is being saved, and
with current behaviour it would then be overwritten to it's old value.
Correct behaviour would be to not set the readonly/uneditable field at all
in the SQL query.
The exception to this is a DateTimeField with auto_now or auto_now_add,
which have editable=False but should be updated when the SQL query is
made.
--
--
Ticket URL: <https://code.djangoproject.com/ticket/28589#comment:4>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/065.fe3d05f2a55af129339f598d8974fbb7%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.