diff --git a/src/pretix/base/models/event.py b/src/pretix/base/models/event.py index f8116bf57..e967e1560 100644 --- a/src/pretix/base/models/event.py +++ b/src/pretix/base/models/event.py @@ -1403,15 +1403,12 @@ class Event(EventMixin, LoggedModel): for mp in self.organizer.meta_properties.all(): if mp.required and not self.meta_data.get(mp.name): - issues.append( - ('' + gettext('You need to fill the meta parameter "{property}".') + '').format( - property=mp.name, - a_attr='href="%s#id_prop-%d-value"' % ( - reverse('control:event.settings', kwargs={'organizer': self.organizer.slug, 'event': self.slug}), - mp.pk - ) - ) - ) + issues.append(format_html( + '{text}', + text=gettext('You need to fill the meta parameter "{property}".').format(property=mp.name), + href=reverse('control:event.settings', kwargs={'organizer': self.organizer.slug, 'event': self.slug}), + href_hash=f'#id_prop-{mp.pk}-value', + )) responses = event_live_issues.send(self) for receiver, response in sorted(responses, key=lambda r: str(r[0])): diff --git a/src/pretix/base/signals.py b/src/pretix/base/signals.py index 108b24b0f..a9d1c3f6e 100644 --- a/src/pretix/base/signals.py +++ b/src/pretix/base/signals.py @@ -535,8 +535,9 @@ EventPluginRegistry = PluginAwareRegistry # for backwards compatibility event_live_issues = EventPluginSignal() """ This signal is sent out to determine whether an event can be taken live. If you want to -prevent the event from going live, return a string that will be displayed to the user -as the error message. If you don't, your receiver should return ``None``. +prevent the event from going live, return an error message to display to the user (either +as a SafeString containing HTML, or a string that will be HTML-escaped). If you don't, +your receiver should return ``None``. As with all event-plugin signals, the ``sender`` keyword argument will contain the event. """ diff --git a/src/pretix/base/templatetags/eventsignal.py b/src/pretix/base/templatetags/eventsignal.py index 54f2da5df..f2e0ec2f4 100644 --- a/src/pretix/base/templatetags/eventsignal.py +++ b/src/pretix/base/templatetags/eventsignal.py @@ -22,6 +22,7 @@ import importlib from django import template +from django.utils.html import conditional_escape from django.utils.safestring import mark_safe from pretix.base.models import Event @@ -44,7 +45,7 @@ def eventsignal(event: Event, signame: str, **kwargs): _html = [] for receiver, response in signal.send(event, **kwargs): if response: - _html.append(response) + _html.append(conditional_escape(response)) return mark_safe("".join(_html)) @@ -63,5 +64,5 @@ def signal(signame: str, request, **kwargs): _html = [] for receiver, response in signal.send(request, **kwargs): if response: - _html.append(response) + _html.append(conditional_escape(response)) return mark_safe("".join(_html)) diff --git a/src/pretix/control/signals.py b/src/pretix/control/signals.py index 2a20f685e..f3b68cc85 100644 --- a/src/pretix/control/signals.py +++ b/src/pretix/control/signals.py @@ -39,7 +39,8 @@ from pretix.base.signals import ( html_page_start = GlobalSignal() """ This signal allows you to put code in the beginning of the main page for every -page in the backend. You are expected to return HTML. +page in the backend. You are expected to return a SafeString containing HTML, or +a string that will be HTML-escaped. The ``sender`` keyword argument will contain the request. """ @@ -129,7 +130,7 @@ event_dashboard_top = EventPluginSignal() Arguments: 'request' This signal is sent out to include custom HTML in the top part of the the event dashboard. -Receivers should return HTML. +Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped. As with all event plugin signals, the ``sender`` keyword argument will contain the event. An additional keyword argument ``subevent`` *can* contain a sub-event. @@ -172,6 +173,7 @@ Arguments: 'form' This signal allows you to add additional HTML to the form that is used for modifying vouchers. You receive the form object in the ``form`` keyword argument. +Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped. As with all event plugin signals, the ``sender`` keyword argument will contain the event. """ @@ -209,6 +211,7 @@ Arguments: 'quota' This signal allows you to append HTML to a Quota's detail view. You receive the quota as argument in the ``quota`` keyword argument. +Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped. As with all event plugin signals, the ``sender`` keyword argument will contain the event. """ @@ -219,6 +222,7 @@ Arguments: 'subevent' This signal allows you to append HTML to a SubEvent's detail view. You receive the subevent as argument in the ``subevent`` keyword argument. +Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped. As with all event plugin signals, the ``sender`` keyword argument will contain the event. """ @@ -265,7 +269,8 @@ order_info = EventPluginSignal() """ Arguments: ``order``, ``request`` -This signal is sent out to display additional information on the order detail page +This signal is sent out to display additional information on the order detail page. +Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped. As with all event plugin signals, the ``sender`` keyword argument will contain the event. Additionally, the argument ``order`` and ``request`` are available. @@ -275,7 +280,8 @@ order_approve_info = EventPluginSignal() """ Arguments: ``order``, ``request`` -This signal is sent out to display additional information on the order approve page +This signal is sent out to display additional information on the order approve page. +Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped. As with all event plugin signals, the ``sender`` keyword argument will contain the event. Additionally, the argument ``order`` and ``request`` are available. @@ -286,6 +292,7 @@ order_position_buttons = EventPluginSignal() Arguments: ``order``, ``position``, ``request`` This signal is sent out to display additional buttons for a single position of an order. +Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped. As with all event plugin signals, the ``sender`` keyword argument will contain the event. Additionally, the argument ``order`` and ``request`` are available. @@ -315,6 +322,7 @@ Arguments: 'request' This signal is sent out to include template snippets on the settings page of an event that allows generating a pretix Widget code. +Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped. As with all event plugin signals, the ``sender`` keyword argument will contain the event. A second keyword argument ``request`` will contain the request object. diff --git a/src/pretix/control/templates/pretixcontrol/event/live.html b/src/pretix/control/templates/pretixcontrol/event/live.html index cd4d0e22e..70b0d3c7b 100644 --- a/src/pretix/control/templates/pretixcontrol/event/live.html +++ b/src/pretix/control/templates/pretixcontrol/event/live.html @@ -19,7 +19,7 @@