NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1350 most downloaded on PyPI
Simple and rapid application development framework, built on top of Flask. includes detailed security, auto CRUD generation for your models, google charts and much more.
Last release 4 days ago
16 Sep 2026
Release timing varies
gaps range from 8 days to 3 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
387 releases · first in 2013
Fix, Possible sql injection vulnerability.
New, #528 support for enum type (SQLA only).
Fix, Possible sql injection vulnerability.
Fix, #489 python3 compatibility fix for unicode api_read.
Fix, #489 python3 compatibility fix for unicode api_read.
Fix, #491 [api/update] only update keys specified in POST data.
Fix, #492 [cosmetics] making row button (show/edit/delete) not primary.
Fix, #493 [cosmetic] left-align the text in dropdowns.
New, #508 Updated bootswatch to version 3.3.7 five new themes included.
New, #512 Docs now use readthedocs theme.
New, #503 FileUploadField: process_on_store() and process_on_delete().
Fix, #511 Added new parameter to fabmanager babel-extract to include aditional keywords, defaults to lazy_gettext, gettext, _, __
New, #483 new parameter for LDAP username formatting AUTH_LDAP_USERNAME_FORMAT.
One column per quarter.
Fix, Decorator oauth_user_info_getter was not according the docs, parameter bug.
Fix, Decorator oauth_user_info_getter was not according the docs, parameter bug.
Fix, #474 Missing menu deviders
Fix, #472 Prevent masquerade attacks through oauth providers.
New, Optional TLS for LDAP Authentication.
Fix, Factory setup was failing when babel get locale was being called.
New, Bootstrap updated to version 3.3.7.
New, flask-sqlalchemy updated to version 2.1.
New, #453 Added support for users to login with their username or email address.
Fix, #467 two instances of urls being generated wrongly when running under a prefix.
Fix, redirect to actual index view rather than '/' on logout for DBAuthView.
Fix, form actions not working under a prefix for CompactCRUDMixin.
Fix, #457 Don't overwrite csrf_token on form fill.
Fix, #453 [rest api] improve error messages, and return item object upon create/update.
New, flask-babel update.
Fix, #409 Google Oauth login and self registration.
New, #402 column_formatters to ModelView.
New, #374 default autosizing to app image (if any).
New, #393 More sensible default page size.
Fix, #397 security: don't crash on oauth errors.
Fix, #395 flask_wtf.Form has been renamed to FlaskForm.
Fix, #354 Improved spanish translation.
Fix, #352 some i18n related bugs.
Fix, #341 for supporting multiple select2 fields.
Fix, #341 for supporting multiple select2 fields.
Fix, #340 Better chinese translations.
New, #338 Support of Mongoengine Document inheritance.
New, Support for python 3.5, now uses flask-babel instead of flask-babelpkg.
New, Support for python 3.5, now uses flask-babel instead of flask-babelpkg.
Fix, #332 Realign deprecated references to flask.ext.
Fix, REST API endpoints for fetching related data columns crashed.
Fix, #332 Realign deprecated references to flask.ext.
New, REST API endpoints for fetching related data columns.
New, REST API endpoints for fetching related data columns.
New, REST endpoint for fetching data with simple output (select2 to consume).
New, AJAX select fields.
New, AJAX select fields that can be setup to be related, when the user chooses on master, the slave show only related data.
Fix, Filters were broken on 1.6.2, impact on searches and Unique validators.
Fix, Filters were broken on 1.6.2, impact on searches and Unique validators.
New, Support for Japanese. Thanks to @giyokun.
New, Support for Japanese. Thanks to @giyokun.
Fix, #312 Solves String encoding causing column labels to be prefixed with 'b' in Python 3x.
Fix, #322 Solves Error on Inline cookie cached, when a record is deleted and it's pk is on the edit cookie.
Fix, Bug with numeric filters, converting to correct python type.
New, Allowing apps to alter title using a jinja block #284
New, Allowing apps to alter title using a jinja block #284
Fix, Prevented user's password being written to debug.
New, Added login failed message to log.
Fix, Fixes #273 by not registering a view that will not exist for LDAP
New, added missing filters for date types for generic models.
New, #316, Adding FilterInFunction to models.sqla.filters.
New, AUTH_LDAP_APPEND_DOMAIN to always append a certain domain on LDAP user's login.
Fix, GenericInterface.get(pk) bug created on 1.5.0 correction, missing optional extra base_filter parameter
Fix, GenericInterface.get(pk) bug created on 1.5.0 correction, missing optional extra base_filter parameter
New, Simple addon system. Possible modular instalation of views, models and functionality.
New, #261, possible for the user to edit their first name and last name.
New, #261, possible for the user to edit their first name and last name.
Fix, #251, record url from some user can be accessed by any user, show, edit and delete are now constrained by base_filter.
Fix, #265, Fixed double word in views.rst
Fix, #247, bug when ordering view columns where None values are in.
Fix, pinned flask-sqlalchemy to version 2.0.
New, type checks disables on AuditMixin, it allows the use of this mixin when extending the User model.
New, possible to filter fields using dot notation, automatic joins of other models.
Fix, actions on user profile to resetmypasswordview made generic, the view can be safely override.
Fix, actions on user profile to resetpasswordview made generic, the view can be safely override.
New, #228 new property, search_form_query_rel_fields to filter combo lists on search related fields.
New, #228 new property, search_form_query_rel_fields to filter combo lists on search related fields.
Fix, #219 Making the inline crud stateless, CompatCRUDMixin.
Fix, #223 Proxy support.
Fix, #219 Making the inline crud stateless, CompatCRUDMixin.
Fix, #216 English issues found during translation.
New, config key, FILE_ALLOWED_EXTENSIONS, issue #221.
New, #217, Polish translations.
Fix, flask-login version pin on 0.2.11.
Fix, #211, UTF-8 encoding for the json label strings. REST API bug.
Fix, #211, UTF-8 encoding for the json label strings. REST API bug.
Fix, #209, Several improvements to queries on MongoDB.
Fix, #206, registration form fields aren't being validated.
Fix, #205, self.registeruser_model rather than RegisterUser.
Fix, #195, Silent failure of validators_columns on CompactCRUDMixin.
Fix, #197, 'Mixed Content' message when behind an https reverse proxy
Fix, Bug fixed for problem with columns that drilldown model.model.name.
New, Support for Numeric SQLAlchemy type.
Fix, #188 but fix created a display bug on empty queries with related views.
Fix, #188 but fix created a display bug on empty queries with related views.
Fix, #186 LDAP configuration - Invalid DN syntax on OpenLDAP. Introduced AUTH_LDAP_BIND_USER and AUTH_LDAP_BIND_PASSWORD
New, decorator for mapping custom Model property to real db property, supports sorting on custom properties. @renders.
New, various new filters for generic models. #193.
Fix, #188 fix bug, actions return access denied on actions for lists."
Fix, #188 fix bug, actions return access denied on actions for lists."
New, search_form_extra_fields property.
New, search_form_extra_fields property.
New, SimpleFormView and PublicFormView form_post can return a flask response.
New, ListLinkWidget, replaces the show buttom by a link on the first table col.
New, ListWidget, ListItem, ListThumbnail, ListBlock templates inherite from base_list.html.
New, ListWidget, ListItem, ListThumbnail, ListBlock templates inherite from base_list.html.
Fix, MultipleView javascript bug with 2 (or more?) charts #177.
New, baselib.html was replaced by navbar.html, navbar_menu.html, nabar_right.html.
Fix, #168 fixed output when fabmanager is unable to import app.
Fix, #168 fixed output when fabmanager is unable to import app.
Fix, Moved userXXXmodelview properties to BaseSecurityManager.
Fix, Copied XXX_model properties to BaseSecurityManager.
New, SimpleFormView and PublicFormView now subclass BaseFormView.
New, class method for BaseView's get_default_url, returns the default_view url.
New, OAuth authentication method.
New, Search for role with a particular set of permissions on views or menus.
New, Possible to filter MongoEngine ObjectId's.
Fix, MongoEngine (MongoDB) ObjectId's not included in search forms.
Fix, Menu html and icons rework.
New, add_exclude_columns.
New, edit_exclude_columns.
New, show_exclude_columns.
New, exclude_columns on tests.
New, docs for exclude_columns.
New, remove id warning for MongoDB on filters.
Fix, missing translations.
Fix, Changed length of username model field from 32 to 64 characters.
Fix, Changed length of username model field from 32 to 64 characters.
Fix, Changed LDAP Auth and registration logic.
Fix, Removed LDAP auth indirect bind.
Fix, Redirect update missing on chart views
Fix, Charts with unicode data.
New, add_user on data interfaces accepts new parameter for hashed_password.
SimpleFormView.form_post can return null to redirect back or a Flask response (render or redirect).
SimpleFormView.form_post can return null to redirect back or a Flask response (render or redirect).
Changed the way related views are initialized, no bind to the related_views property.
#144 New MultipleView for rendering multiple BaseViews on the same page.
Can now import all views from flask_appbuilder.
Issue #115, Modal text is now html instead of text.
Issue #115, Modal text is now html instead of text.
Issue #119, confirm HTML is included at the begining of body see baselayout.html.
Issue #119, confirm HTML is included at the begining of body see baselayout.html.
BaseInterface.get_values changed to iterator (does not return list but list iterator).
BaseInterface.get_values changed to iterator (does not return list but list iterator).
REST CRUD API added.
Interface datamodels do not flash messages, they log messages on public property tuple 'message'.
Issue #113, changed html5shiv and respond to import after bootstrap.
Issue #117, added FilterEqualFunction to MongoDB filters.
Issue #118, SQLAlchemy version 0.9.9 does not have as_declarative decorator, temp fix by fixing to 0.9.8.
New, json exposed method was removed from ModelView you must use API now.
- #90 Py3 compact fix for urllib and StringIO.
#90 Py3 compact fix for urllib and StringIO.
Fix, Group by chart with multiple series not displaying data.
Fix, Group by chart with multiple series not displaying data.
New, edit_form_query_rel_fields, add_form_query_rel_fields changed, accepts dict instead of list (BREAKING CHANGE).
New, block template head_js on init.html, affects all templates, better js override or add.
New, base_template parameter on AppBuilder to override the top template, better css and js inclusion.
Fix, fixed menu brand with image (APP_ICON), better display.
New, included boostrap-theme THEME.
Fix, internal API change, BaseIterface/SQLAInterface method get_model_relation new name: get_related_model.
New, internal QuerySelectField QuerySelectMultipleField based on BaseInterface.
New, edit_form_query_rel_fields, add_form_query_rel_fields changed, accepts dict instead of list (BREAKING CHANGE).
Fix, Filter rework datamodel is no longer optional for construct (BREAKING CHANGE).
Fix, Filter methods no longer require datamodel parameter (BREAKING CHANGE).
Fix, All SQLAlchemy Filter's moved to flask_appbuilder.models.sqla.filters.
New, All Filters are accessible from datamodel class, ex: datamodel.FilterEqual
New, Charts will be database ordered (better performance), and can accept dotted cols on relations.
Fix, on menus with dividers if next item has no permission, divider was shown.
New, Bootstrap update to 3.3.1
New, Select2 update to 3.5.1
New, support for many to many relations on ModelView related_view.
New, AppBuilder.add_link supports endpoint names on href parameter, internally will try to use url_for(href).
Fix, Zero division catch on aggregate average function.
New, added form validators for field min and max length.
New, Image size can be configured per column, ImageColumn support size and thumbnail size parameters.
Fix, New auth REMOTE_USER bug, always logged in Admin user, db query filter bug.
Fix, New auth REMOTE_USER bug, always logged in Admin user, db query filter bug.
…to flask.ext.appbuilder.models.filter. (BREAKING CHANGE)
Fix, BaseInterface new property for overriding filter converter class, better interface for new classes.
Fix, search_widget property changed from BaseCRUDView to BaseModelView.
Fix, Openid auth rework, no hacking done.
Fix, exclude possible order by for columns that are functions. #67
Fix, BaseFilter, FilterRelation, BaseFilterRelation changed module from flask.ext.appbuilder.models.base to flask.ext.appbuilder.models.filter. (BREAKING CHANGE)
Fix, sqla filters changed from flask.ext.appbuilder.filters to flask.ext.appbuilder.sql.filters. (BREAKING CHANGE)
New, AUTH_TYPE = 4 Web server auth via REMOTE_USER enviroment var.
Fix, #71 set_index_view removed, doc correction.
Fix, #72 improved german translations.
Fix, #69 added SQLAlchemy Sequence to pk's to support ORACLE.
Fix, #69 improved chinese translations.
Fix, #66 improved spanish translations.
Fix, User role column was not translated, since 1.1.2.
Fix, User role column was not translated, since 1.1.2.
Fix, when only one language setup, menu dropdown was not correct.
Fix, theme default generates 404, issue #60.
Fix, use of reduce as builtin, python3 problem, issue #58.
Fix, changing language was redirecting back.
Fix, changing language was redirecting back.
New, allows order on relationships by implicit declaration of col with dotted notation.
New, allows order on relationships by implicit declaration of col with dotted notation.
New, get_order_columns_list receives optional list_columns to narrow search and auto include dotted cols.
New, dotted columns are also automatically pretty labeled.
Fix, is<Type col> on SQLInterface handles exceptions for none existing cols.
Fix, back special URL included on a new View called UtilView, removes bug: when replacing IndexView the back crashes.
Fix, changed WTForm validator Required to DataRequired.
Fix, changed WTForm validator Required to DataRequired.
Fix, changed WTForm TextField to StringField.
New, AUTH_USER_REGISTRATION for self user registration, on ldap it's used automatic registration based on ldap attrs.
New, AUTH_USER_REGISTRATION for auth db will present registration form, send email with configurable html for activation.
New, AUTH_USER_REGISTRATION for auth oid will present registration form, send email with configurable html for activation.
New, Added property to AppBuilder that returns the frameworks version.
New, User extension mixin (Beta).
New, allows dotted attributes on list_columns, to fetch values from related models.
New, AuthOIDView with oid_ask_for and oid_ask_for_optional, for easy dev override of view.
New, Access Denied log a warning with info.
Fix, OpenID login improvement.
Fix, field icon for date and datetime that selects calendar, changes mouse cursor to hand.
Fix, field icon for date and datetime that selects calendar, changes mouse cursor to hand.
New, render_field changed, could be a breaking feature, if you wrote your own forms. no more <td> on each field.
New, pull request #44, ldap bind options.
Fix, pull request #48, bug with back button url not working when using uwsgi under sub-domain.
New, AppBuilder accepts new parameter security_manager_class, useful to override any security view or auth method.
New, dynamic package version from python file version.py.
New, dynamic package version from python file version.py.
New, extra_args property, for injecting extra arguments to templates.
Fix, Removed footer with link "Powered by F.A.B.".
Fix, Added translation for "Access is denied". ES,GE,RU,ZH
New, Yes and no questions with bootstrap modal.
Fix, Added multiple actions support on other list widgets.
Fix, missing translations for "User info" and "Audit info".
Fix, actions break on MasterDetail or related views.
Fix, actions break on MasterDetail or related views.
New, Support for multiple actions.
New, Support for multiple actions.
Fix, Russian translations from pull request #39
Fix, Russian translations from pull request #39
- Fix, merge problem. issue #38
Fix, merge problem. issue #38
Fix, inserted script in init.html moved to ab.js on static/js.
Fix, inserted script in init.html moved to ab.js on static/js.
Fix, performance improvement on edit, only one form initialization.
New, New back mechanism, with 5 history records. issue #35.
New, json endpoint for model querys, with same parameters has list endpoint.
New, support for boolean columns search, filter with FilterEqual or FilterNotEqual.
Fix, get order columns was including relations.
Fix, get order columns was including relations.
New, possibility to include primary key and foreign key on forms and views.
Fix, python 3 errors on GenericModels, metaclass compatibility.
New, decorator '@permission_name' to override endpoint access permission name.
New, decorator '@permission_name' to override endpoint access permission name.
Fix, edit_form_query_rel_fields error only on 0.10.0, issue #30.
Fix, only add permissions to methods with @has_access decorator.
Fix, prevents duplicate permissions.
New, template block on add.html template, add_form.
New, template block on add.html template, add_form.
New, template block on edit.html template, edit_form.
New, template block on show.html template, show_form.
New, template block on show_cascade.html template, relative_views.
New, template block on edit_cascade.html template, relative_views.
New, API Change, DataModel is now BaseInterface and on flask.ext.appbuilder.models.base
New, API Change, SQLAModel is now SQLAInterface
New, API Change, SQLAInterface inherits from BaseInterface (not DataModel)
New, API Change, SQLAInterface is on flask.ext.appbuilder.models.sqla.interface
New, API Change, Filters for sqla are on flask.ext.appbuilder.models.sqla.filters
New, API Change, BaseFilter is on flask.ext.appbuilder.model.base
Fix, nullable Float and Integer bug issue #26
New, default model sqlalchemy support on forms (issue #26). static and callable value
Fix, DateTimeField Fix issue #22.
Fix, DateTimeField Fix issue #22.
New, bootstrap updated to version 3.1.1.
New, fontawesome updated to version 4.1.0.
Fix, label for 'username' was displaying 'Failed Login Count', Chart definition override.
Fix, label for 'username' was displaying 'Failed Login Count', Chart definition override.
New, Support for application factory *init_app* (Flask ext approved guide line).
New, Support for application factory init_app (Flask ext approved guide line).
New, Flexible group by charts with multiple series and formatters, no need for ChartView or TimeChartView.
New, internal AppBuilder rebuild.
New, class name change 'BaseApp' to 'AppBuilder', import like: from flask.ext.appbuilder import AppBuilder
New, class name change 'BaseApp' to 'AppBuilder', import like: from flask.ext.appbuilder import AppBuilder
New, can import expose decorator like: flask.ext.appbuilder import expose
New, Changed 'Base' declarative name to 'Model' no need to add BaseMixin.
New, No automatic dev's model creation, must invoke appbuilder.create_db()
New, Change GeneralView to ModelView.
Fix, Multiple database support correction.
New, security cleanup method, useful if you have changed a menu's name or view class name.
New, security cleanup method, useful if you have changed a menu's name or view class name.
Fix, internal security management optimization.
New, security management method security_cleanup, will remove unused permissions, views and menus.
Fix, removed automatic migration from version 0.3.
be the same has the security tables.
Fix, Security menu with wrong label and view association on 'Permission Views/Menu'.
Fix, js for remembering latest accordion was working like toggle (bs bug?).
Fix, js for remembering latest accordion was working like toggle (bs bug?).
- Portuguese Brazil translations
Portuguese Brazil translations
Fix, possible to register on the menu different links to the same view class.
Fix, possible to register on the menu different links to the same view class.
Fix, init of baseapp missing init of baseviews list.
New, Python 3 partial support (babel will not work, caused by the babel package itself).
New, Python 3 partial support (babel will not work, caused by the babel package itself).
Fix, Removed Flask-wtf requirement version limitation.
New, test suite with nose.
New, Language, Simplified Chinese support.
New, Language, Simplified Chinese support.
New, Language, Russian support.
New, Language, German support.
Fix, various translations.
Fix,New support for virtual directory no need to install on root url, relative urls fixes.
Fix, Auto creation of user's models from Base.
New, login form style.
Fix, Auto creation of user's models from Base.
Fix, Removed double flash message on reset password form.
New, support for icons on menu categories.
New, remove "-" bettwen icons and menu labels.
New, added optional parameter "label" and "category_label" for menu items. better security and i18n.
Fix, removed unnecessary log output.
Fix, removed unnecessary log output.
Fix, TimeChartView not ordering dates correctly.
Fix, TimeChartView not ordering dates correctly.
New, charts can be included has related views, can use it has tab, collapse and master-detail templates.
New, charts can be included has related views, can use it has tab, collapse and master-detail templates.
Fix, login ldap, double message login failed correction.
Fix, search responsive correction.
New, accordion related view will record last choice on cookie.
New, footer page, this can be overridden.
New, internal change, list functional header on lib.
New, internal change, list functional header on lib.
Fix, removed audit columns from user info view. Only shown on security admin.
Fix, removed forced cast to int on json conversion for DirectChartView. Better support for float.
Fix, removed forced cast to int on json conversion for DirectChartView. Better support for float.
New, List for simple master detail, master works like a menu on the left side.
Fix, fixed buttons size for show, edit, delete on lists. Buttons will not adapt to vertical.
Fix, if no permissions for show, edit, delete, no empty cell is shown <th> or <td>.
New, internal change, crud buttons on lib.
Your coding agent can read these notes before it upgrades. Set up the MCP server →