---
title: "Catatan terbitan Django 1.4.8"
version: 1.9
locale: id
source: https://docs.djangoproject.com/id/1.9/releases/1.4.8/
canonical: https://djangodocs.dev/id/1.9/releases/1.4.8/
---
# Catatan terbitan Django 1.4.8

*September 14, 2013*

Django 1.4.8 memperbaiki dua masalah keamanan yang hadir di terbitan Django sebelumnya di seri 1.4.

## Denial-of-service via password hashers

In previous versions of Django, no limit was imposed on the plaintext
length of a password. This allowed a denial-of-service attack through
submission of bogus but extremely large passwords, tying up server
resources performing the (expensive, and increasingly expensive with
the length of the password) calculation of the corresponding hash.

As of 1.4.8, Django's authentication framework imposes a 4096-byte
limit on passwords and will fail authentication with any submitted
password of greater length.

## Corrected usage of [`sensitive_post_parameters()`](/id/1.9/howto/error-reporting/#django.views.decorators.debug.sensitive_post_parameters) in [`django.contrib.auth`](/id/1.9/topics/auth/#module-django.contrib.auth)’s admin

The decoration of the `add_view` and `user_change_password` user admin
views with [`sensitive_post_parameters()`](/id/1.9/howto/error-reporting/#django.views.decorators.debug.sensitive_post_parameters)
did not include [`method_decorator()`](/id/1.9/ref/utils/#django.utils.decorators.method_decorator) (required
since the views are methods) resulting in the decorator not being properly
applied. This usage has been fixed and
[`sensitive_post_parameters()`](/id/1.9/howto/error-reporting/#django.views.decorators.debug.sensitive_post_parameters) will now
throw an exception if it's improperly used.
