mirror of
https://github.com/pretix/pretix.git
synced 2026-05-17 17:14:04 +00:00
[SECURITY] Use defusedcsv for exports
This commit is contained in:
@@ -1,9 +1,9 @@
|
|||||||
import csv
|
|
||||||
import io
|
import io
|
||||||
from collections import OrderedDict
|
from collections import OrderedDict
|
||||||
from decimal import Decimal
|
from decimal import Decimal
|
||||||
|
|
||||||
import pytz
|
import pytz
|
||||||
|
from defusedcsv import csv
|
||||||
from django import forms
|
from django import forms
|
||||||
from django.db.models import Sum
|
from django.db.models import Sum
|
||||||
from django.dispatch import receiver
|
from django.dispatch import receiver
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
import csv
|
|
||||||
import io
|
import io
|
||||||
|
|
||||||
|
from defusedcsv import csv
|
||||||
from django.conf import settings
|
from django.conf import settings
|
||||||
from django.contrib import messages
|
from django.contrib import messages
|
||||||
from django.core.urlresolvers import resolve, reverse
|
from django.core.urlresolvers import resolve, reverse
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import csv
|
|
||||||
import io
|
import io
|
||||||
from collections import OrderedDict
|
from collections import OrderedDict
|
||||||
|
|
||||||
|
from defusedcsv import csv
|
||||||
from django import forms
|
from django import forms
|
||||||
from django.db.models.functions import Coalesce
|
from django.db.models.functions import Coalesce
|
||||||
from django.utils.translation import ugettext as _, ugettext_lazy
|
from django.utils.translation import ugettext as _, ugettext_lazy
|
||||||
|
|||||||
@@ -39,3 +39,4 @@ chardet<3.1.0,>=3.0.2
|
|||||||
mt-940==3.2
|
mt-940==3.2
|
||||||
vobject==0.9.*
|
vobject==0.9.*
|
||||||
pycountry
|
pycountry
|
||||||
|
defusedcsv>=1.0.1
|
||||||
|
|||||||
@@ -100,7 +100,8 @@ setup(
|
|||||||
'mt-940==4.7',
|
'mt-940==4.7',
|
||||||
'django-i18nfield>=1.0.1',
|
'django-i18nfield>=1.0.1',
|
||||||
'vobject==0.9.*',
|
'vobject==0.9.*',
|
||||||
'pycountry'
|
'pycountry',
|
||||||
|
'defusedcsv'
|
||||||
],
|
],
|
||||||
extras_require={
|
extras_require={
|
||||||
'dev': [
|
'dev': [
|
||||||
|
|||||||
Reference in New Issue
Block a user