# Stop the Django 5.0 press: Move \`URLField.assume\_scheme\` change from deprecation to hard-cut

**URL:** <https://forum.djangoproject.com/t/stop-the-django-5-0-press-move-urlfield-assume-scheme-change-from-deprecation-to-hard-cut/25652>\
**Category:** Django Internals\
**Created:** [November 25, 2023, 11:52pm UTC](https://forum.djangoproject.com/t/stop-the-django-5-0-press-move-urlfield-assume-scheme-change-from-deprecation-to-hard-cut/25652 "2023-11-25T23:52:44Z")\
**Posts on this page:** 4\
**Page:** 2

<div class="post-metadata">

**Author:** ![nessita](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/nessita/32/12194_2.png) [@nessita](https://forum.djangoproject.com/u/nessita)\
**Post date:** [November 28, 2023, 1:40pm UTC](https://forum.djangoproject.com/t/stop-the-django-5-0-press-move-urlfield-assume-scheme-change-from-deprecation-to-hard-cut/25652/21 "2023-11-28T13:40:59Z")

</div>

Amazing, thank you @felixxm! I think this is a very good compromise 👏

---

<div class="post-metadata">

**Author:** ![adamchainz](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/adamchainz/32/26_2.png) [@adamchainz](https://forum.djangoproject.com/u/adamchainz)\
**Post date:** [December 7, 2023, 11:49pm UTC](https://forum.djangoproject.com/t/stop-the-django-5-0-press-move-urlfield-assume-scheme-change-from-deprecation-to-hard-cut/25652/22 "2023-12-07T23:49:18Z")

</div>

I have published my updated blog post now, covering the transitional setting as well:

> **[Django: Fix version 5.0’s URLField.assume\_scheme warnings - Adam Johnson](https://adamj.eu/tech/2023/12/07/django-fix-urlfield-assume-scheme-warnings/)**
>
> Since Django’s inception, the web has gradually moved from HTTP to HTTPS, a welcome move for security. But the history has meant older parts of Django have had a lingering HTTP bias. Many of these have been migrated to default to HTTPS instead in...

---

<div class="post-metadata">

**Author:** ![jsma](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/jsma/32/8071_2.png) [@jsma](https://forum.djangoproject.com/u/jsma)\
**Post date:** [December 9, 2023, 11:27pm UTC](https://forum.djangoproject.com/t/stop-the-django-5-0-press-move-urlfield-assume-scheme-change-from-deprecation-to-hard-cut/25652/23 "2023-12-09T23:27:31Z")

</div>

Firefox, Safari, and Chrome/Edge on my machine all have built-in validation for `<input type="url">` that requires a scheme before allowing users to submit a form.

Why is Django assuming a scheme at all vs doing validation similar to browsers (“Please enter a URL”) to catch incoming data from non-browser sources? When I first saw mention of this change in the release notes, I didn’t realize Django had been assuming “http://” and at first thought all of our forms with URL fields might have been accepting scheme-less URLs this entire time until I actually tested one such form. There isn’t a straightforward way I’m aware of to test `assume_scheme` and the transitional setting in a browser.

---

<div class="post-metadata">

**Author:** ![adamchainz](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/adamchainz/32/26_2.png) [@adamchainz](https://forum.djangoproject.com/u/adamchainz)\
**Post date:** [December 10, 2023, 4:24pm UTC](https://forum.djangoproject.com/t/stop-the-django-5-0-press-move-urlfield-assume-scheme-change-from-deprecation-to-hard-cut/25652/24 "2023-12-10T16:24:08Z")

</div>

The validation isn’t only for “non form” sources. It also applies to fields where the widget or template have been changed.

But thanks for pointing this out. We all missed it. I think it’s more evidence that a hard cut would have not caused much trouble. I will update my blog post with a note here to even more strongly recomend the transitional setting.

[Previous page](https://forum.djangoproject.com/t/stop-the-django-5-0-press-move-urlfield-assume-scheme-change-from-deprecation-to-hard-cut/25652.md?page=1)
