Skip to content

Master 4.4.1#3909

Merged
T4rk1n merged 33 commits into
masterfrom
master-4.4.1
Jul 21, 2026
Merged

Master 4.4.1#3909
T4rk1n merged 33 commits into
masterfrom
master-4.4.1

Conversation

@T4rk1n

@T4rk1n T4rk1n commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

No description provided.

T4rk1n and others added 30 commits July 7, 2026 10:33
Since #3785 getLayout() clones the layout, so plotly.js writes user
interactions (pan/zoom ranges, edited annotations, ...) only into its
own copy (gd.layout) and the figure prop goes stale. A subsequent
Patch update is applied to the stale figure and reverts the user's
view. Generalize the shapes-only sync in the plotly_relayout handler
to every layout key touched by the relayout event, excluding
autosize/width/height which come from the resize machinery rather
than user interactions.

Fixes #3810

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
When the app module runs as a script, a server that loads it by import
string (e.g. uvicorn.run("app:server", reload=True)) executes the same
file twice in the worker process: multiprocessing spawn re-runs it as
__mp_main__, then the import string imports it again under its real
name. Both passes run the @callback decorators, duplicating every spec
in _dash-dependencies and triggering "Duplicate callback outputs"
errors in the renderer.

Dash() now pre-registers the running main module in sys.modules under
its canonical import name (only when that name resolves to the same
file and isn't already imported), so the second import reuses the
already-executed module instead of re-executing the file.

Fixes #3818

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The backend refactor moved callback dispatching from Dash.dispatch into
nested closures in the backend modules, changing the view function's
fully-qualified name from dash.dash.dispatch to
dash.backends._flask._dispatch. Flask-WTF's CSRFProtect exempts views by
that name, so csrf._exempt_views.add("dash.dash.dispatch") silently
stopped working, raising "The CSRF token is missing." on every callback.

Restore the dispatch view's identity to dash.dash.dispatch in the Flask
and Quart backends so existing exemptions keep working.

Fixes #3827
Sync all relayout changes back to the figure prop, not only shapes
Co-authored-by: Cameron DeCoster <cameron.decoster@gmail.com>
Fix Flask-WTF/Quart-WTF CSRF exemptions broken by backend refactor
Co-authored-by: Cameron DeCoster <cameron.decoster@gmail.com>
Fix callbacks double-registered when app file is loaded by import string
Add 'comm' to install requirements
@sonarqubecloud

Copy link
Copy Markdown

@T4rk1n
T4rk1n merged commit 39b5c13 into master Jul 21, 2026
107 of 112 checks passed
@T4rk1n
T4rk1n deleted the master-4.4.1 branch July 21, 2026 19:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants