mirror of
https://github.com/pretix/pretix.git
synced 2025-12-05 21:32:28 +00:00
[SECURITY] Use defusedcsv for exports
This commit is contained in:
@@ -1,9 +1,9 @@
|
||||
import csv
|
||||
import io
|
||||
from collections import OrderedDict
|
||||
from decimal import Decimal
|
||||
|
||||
import pytz
|
||||
from defusedcsv import csv
|
||||
from django import forms
|
||||
from django.db.models import Sum
|
||||
from django.dispatch import receiver
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
import csv
|
||||
import io
|
||||
|
||||
from defusedcsv import csv
|
||||
from django.conf import settings
|
||||
from django.contrib import messages
|
||||
from django.core.urlresolvers import resolve, reverse
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
import csv
|
||||
import io
|
||||
from collections import OrderedDict
|
||||
|
||||
from defusedcsv import csv
|
||||
from django import forms
|
||||
from django.db.models.functions import Coalesce
|
||||
from django.utils.translation import (
|
||||
|
||||
@@ -43,3 +43,4 @@ vobject==0.9.*
|
||||
pycountry
|
||||
django-countries
|
||||
pyuca # for better sorting of country names in django-countries
|
||||
defusedcsv>=1.0.1
|
||||
|
||||
@@ -104,7 +104,8 @@ setup(
|
||||
'vobject==0.9.*',
|
||||
'pycountry',
|
||||
'django-countries',
|
||||
'pyuca'
|
||||
'pyuca',
|
||||
'defusedcsv'
|
||||
],
|
||||
extras_require={
|
||||
'dev': [
|
||||
|
||||
Reference in New Issue
Block a user