Mira Weller
317df5a031
Remove old settings
2026-09-16 16:37:11 +02:00
Mira Weller
0785ca049f
rename some instances of Question -> Datafield
2026-09-16 15:09:51 +02:00
Mira Weller
d8f444d51d
Pass choice field options to JS
2026-09-16 15:07:33 +02:00
Mira Weller
9ace35069c
Remove feature flag from order-level data fields
2026-09-16 15:03:27 +02:00
Mira Weller
54726d6fcd
TODO markings
2026-09-15 16:37:23 +02:00
Mira Weller
53a8a7954d
QuestionnaireChild: system_question und user_question in system_datafield und user_datafield umbenennen
2026-09-15 16:37:22 +02:00
Mira Weller
59cebf3ee8
Rebased --- Squashed commit of the following:
...
commit 2177bebf6a
Merge: ea613bf271 d08216d8c5
Author: Mira Weller <weller@rami.io >
Date: Fri Aug 7 21:22:31 2026 +0200
Merge branch 'master' into questions-vue3
commit ea613bf271
Author: Mira Weller <weller@rami.io >
Date: Fri Aug 7 21:21:35 2026 +0200
wip
commit c8bed5e3b9
Author: Mira Weller <weller@rami.io >
Date: Fri Aug 7 10:15:00 2026 +0200
rename get_cart to get_cart_positions (keep old name alive)
commit 1ec27fff05
Author: Mira Weller <weller@rami.io >
Date: Fri Aug 7 10:01:38 2026 +0200
filter questionnaires by sales channel
commit 0294f205d0
Author: Mira Weller <weller@rami.io >
Date: Thu Aug 6 20:06:05 2026 +0200
refactor: extract build_requested_valid_from_field method
commit 3424aacdc3
Author: Mira Weller <weller@rami.io >
Date: Thu Aug 6 20:05:44 2026 +0200
rename presale question forms and mixins
commit 4012889076
Author: Mira Weller <weller@rami.io >
Date: Thu Aug 6 19:42:29 2026 +0200
rebase migration
commit fe15d71cd2
Merge: 3ea7ea31b6 4d9dfa88fe
Author: Mira Weller <weller@rami.io >
Date: Thu Aug 6 19:25:44 2026 +0200
Merge branch 'master' into questions-vue3
# Conflicts:
# src/pretix/base/forms/questions.py
# src/pretix/base/middleware.py
# src/pretix/base/templates/pretixbase/redirect.html
commit 3ea7ea31b6
Author: Mira Weller <weller@rami.io >
Date: Fri Jul 24 17:37:46 2026 +0200
wip
commit 5b34a25fb5
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 16:21:11 2026 +0200
use questionnaire data for rendering checkout questions step
commit 9467f1d08d
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 15:54:14 2026 +0200
refactor: extract build_system_question_field method
commit 85344a7690
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 15:50:41 2026 +0200
refactor: extract build_user_question_field method
commit 3b47f4aaa7
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 15:49:34 2026 +0200
refactor: cartpos / orderpos
commit 0309b05121
Author: Mira Weller <weller@rami.io >
Date: Thu Mar 19 13:52:18 2026 +0100
vite config: allow cors access from pretix.work subdomains
commit ad092ae0d1
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 12:35:33 2026 +0200
re-add vue-slicksort dep
commit 9f42d679cc
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 12:28:53 2026 +0200
rebase migration
commit 9eae9c6de7
Merge: 84c51e031e 694b915d89
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 12:24:49 2026 +0200
Merge branch 'master' into questions-vue3
# Conflicts:
# .github/workflows/tests.yml
# .gitignore
# Dockerfile
# package-lock.json
# package.json
# src/pretix/base/management/commands/runserver.py
# src/pretix/base/middleware.py
# src/pretix/base/templatetags/vite.py
# src/pretix/control/forms/global_settings.py
# src/pretix/control/templates/pretixcontrol/checkin/list_edit.html
# src/pretix/control/views/item.py
# src/pretix/presale/views/widget.py
# src/pretix/settings.py
# src/pretix/static/pretixcontrol/js/ui/checkinrules/App.vue
# src/pretix/static/pretixcontrol/js/ui/checkinrules/constants.ts
# src/pretix/static/pretixcontrol/js/ui/checkinrules/django-interop.ts
# src/pretix/static/pretixcontrol/js/ui/checkinrules/lookup-select2.vue
# src/pretix/static/pretixcontrol/js/ui/checkinrules/timefield.vue
# src/pretix/static/pretixcontrol/js/ui/checkinrules/viz-node.vue
# src/pretix/static/pretixpresale/widget/index.html
# src/pretix/static/pretixpresale/widget/src/api.ts
# src/pretix/static/pretixpresale/widget/src/button.ts
# src/pretix/static/pretixpresale/widget/src/components/PriceBox.vue
# src/pretix/static/pretixpresale/widget/src/main.ts
# src/pretix/static/pretixpresale/widget/src/sharedStore.ts
# src/pretix/static/pretixpresale/widget/src/utils.ts
# src/pretix/static/pretixpresale/widget/src/widget.ts
# src/tests/e2e/conftest.py
# vite.config.ts
commit 84c51e031e
Merge: 902ee9242e 222b453b43
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 12:20:05 2026 +0200
Merge branch 'master' into questions-vue3
commit 902ee9242e
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 12:19:26 2026 +0200
css comment
commit b758efd4a9
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 12:19:19 2026 +0200
question dependencies
commit c68fe00502
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 12:18:00 2026 +0200
add data field edit link
commit b7da9bb6c1
Author: Mira Weller <weller@rami.io >
Date: Wed Jun 17 12:16:20 2026 +0200
handle hidden questions
commit 897120d3da
Author: Mira Weller <weller@rami.io >
Date: Tue May 12 13:04:08 2026 +0200
add ts model definitions
commit 09abc5725e
Author: Mira Weller <weller@rami.io >
Date: Tue May 12 11:30:12 2026 +0200
reorder and save
commit 9a7d5abb1f
Author: Mira Weller <weller@rami.io >
Date: Tue May 12 11:29:37 2026 +0200
fix unhandled exception in taxrules API
commit 3cee5f524b
Author: Mira Weller <weller@rami.io >
Date: Tue May 5 18:12:21 2026 +0200
use slicksort for reordering questionnaires and questions
commit 3a1a6b988e
Author: Mira Weller <weller@rami.io >
Date: Tue Apr 28 19:23:35 2026 +0200
improve i18n, implement "add text block" dialog
commit bdc720f5a2
Author: Mira Weller <weller@rami.io >
Date: Fri Mar 27 18:57:22 2026 +0100
wip
commit 583184af38
Author: Mira Weller <weller@rami.io >
Date: Thu Mar 19 21:45:32 2026 +0100
change existing views
commit 63d9f7cea8
Author: Mira Weller <weller@rami.io >
Date: Thu Mar 19 21:45:32 2026 +0100
adapt vue app to new data model (wip)
commit c3d6fb1bd6
Author: Mira Weller <weller@rami.io >
Date: Thu Mar 19 21:44:47 2026 +0100
add Questionnaire and QuestionnaireChild models and their API; migrate existing data
commit bb43acd257
Author: Mira Weller <weller@rami.io >
Date: Thu Mar 19 13:52:28 2026 +0100
vite config: add questionnaires app
commit e0744951e8
Author: Mira Weller <weller@rami.io >
Date: Thu Mar 19 13:52:18 2026 +0100
vite config: allow cors access from pretix.work subdomains
commit fef1e356f7
Author: Mira Weller <weller@rami.io >
Date: Thu Mar 19 13:33:24 2026 +0100
fix out-of-the-box experience
commit 81775f5d2d
Author: Mira Weller <weller@rami.io >
Date: Thu Mar 19 13:33:24 2026 +0100
setup questionnaires vue app, add code from question editor proof of concept
commit 4bbcc398cc
Merge: a924d0a266 58840a5fd6
Author: Mira Weller <weller@rami.io >
Date: Thu Mar 19 13:13:32 2026 +0100
Merge remote-tracking branch 'refs/remotes/origin/master' into questions-vue3
2026-09-15 16:37:22 +02:00
Raphael Michel
bcacff2ee7
Voucher list: Add budget and budget used to CSV export (Z#23237857) ( #6520 )
...
* Voucher list: Add budget and budget used to CSV export (Z#23237857)
* Fix failing test
2026-09-14 10:31:07 +02:00
Raphael Michel
1aea5633eb
Discounts: Fix ManyToMany fields when cloning ( #6547 )
2026-09-11 18:35:37 +02:00
Richard Schreiber
86cc719651
Widget: serve vite by default, origin-whitelist for vue2 ( #6403 )
2026-09-11 08:53:42 +02:00
Kara Engelhardt
2aadfa2ce4
RRuleForm: allow selecting the fourth occurence of a weekday of a month (Z#23245893)
...
The fourth often is the same as the last, but not always. A weekday can appear five times in a month
2026-09-09 12:21:42 +02:00
Raphael Michel
dd0d78242e
PDF editor: Harden cached file access for background (Z#23242291) ( #6446 )
2026-09-09 11:13:29 +02:00
Raphael Michel and luelista
42c5de895c
CachedFileField: Bind file access to session (Z#23242301) ( #6447 )
...
* CachedFileField: Bind file access to session (Z#23242301)
* Apply suggestion from @luelista
Co-authored-by: luelista <weller@rami.io >
---------
Co-authored-by: luelista <weller@rami.io >
2026-09-09 09:52:40 +02:00
Raphael Michel and luelista
e91718e73b
Password reset: Prevent race condition that uses token twice (Z#23242132) ( #6448 )
...
* Password reset: Prevent race condition that uses token twice
* Apply suggestion from @luelista
Co-authored-by: luelista <weller@rami.io >
---------
Co-authored-by: luelista <weller@rami.io >
2026-09-09 09:52:38 +02:00
Raphael Michel and Lukas Bockstaller
edb4069e18
Payment step: Allow to postpone payment choice on some sales channels ( #6516 )
...
* Payment step: Allow to postpone payment choice on some sales channels
* Add tests
* handle payment provider (de-)selection and partial payments (#6526 )
---------
Co-authored-by: Lukas Bockstaller <bockstaller@pretix.eu >
2026-09-08 09:32:15 +02:00
Raphael Michel
caa6fb187b
VAT ID validation: Alternative API for German shops ( #6507 )
2026-09-02 17:48:38 +02:00
Richard Schreiber
6d4aba6e3d
Questions: add min-length to string/text type questions ( #6488 )
...
* Questions: add min-length to string/text type questions
* fix test
2026-08-25 09:37:37 +02:00
b809d93bdc
Do not hide subevent list if filtered list is empty ( #6460 )
...
* Do not hide subevent list if filtered list is empty
* Event calendar: Allow to show a message if no events are found
* Apply suggestion from @luelista
Co-authored-by: luelista <weller@rami.io >
* Fix failures on org level
* add aria-hidden if no subevents
* Update src/pretix/base/settings.py
* Update src/pretix/base/settings.py
Co-authored-by: Richard Schreiber <schreiber@pretix.eu >
---------
Co-authored-by: luelista <weller@rami.io >
Co-authored-by: Richard Schreiber <schreiber@rami.io >
Co-authored-by: Richard Schreiber <schreiber@pretix.eu >
2026-08-24 14:42:41 +02:00
Raphael Michel and luelista
58f331ba1f
Allow to set payment term per sales channel ( #6459 )
...
* Allow to set payment term per sales channel
* Apply suggestion from @luelista
Co-authored-by: luelista <weller@rami.io >
---------
Co-authored-by: luelista <weller@rami.io >
2026-08-24 09:09:47 +02:00
Martin Gross
91a3993cef
Seating: Set subevents to None if event has no subevents for _seat_allowed annotation (Z#23243880) ( #6487 )
2026-08-19 14:12:05 +02:00
luelista and Richard Schreiber
f8cc31b120
Order-level questions ( #6471 )
...
* New CheckoutSession model, created and deleted throught cart lifetime but only used for order-level question answers so far
* Order-level QuestionAnswers (relations to CheckoutSession / Order)
* New container_type field on Question model to specify whether Question belongs to order or orderposition
* Order-level questions are currently experimental, UI is hidden behind feature flag
---------
Co-authored-by: Richard Schreiber <schreiber@pretix.eu >
2026-08-14 14:56:45 +02:00
7fe31634e6
Allow RelativeDate in relation to a moment of order ( #6160 )
...
* initial implementation
* factor out _resolve_base_date
* add js to prevent illegal inputs
* fix tests
* Update src/pretix/base/reldate.py
Co-authored-by: Raphael Michel <michel@pretix.eu >
* Apply suggestions from code review
Co-authored-by: Raphael Michel <mail@raphaelmichel.de >
* move js includes of to fragment_js.html
* add type annotations
* moves logic from RelativeDateWrapper into RelativeDate and adds BaseChoice for configuring which models attributes support which relationship
* fix tests
* test upgrade behaviour
* Apply suggestions from code review
Co-authored-by: Raphael Michel <mail@raphaelmichel.de >
* move reldate.js include in correct file
* add OptionAttrsSelect to allow select options with their own attributes per value
* add a little bit of information to the tests for future reference
* rewrite reldate.js use data-attributes
* general cleanup
* add test for order.subevents cases
* use correct choice format
* remove order.subevent variants
* various cleanup
* Apply suggestions from code review
Co-authored-by: Raphael Michel <mail@raphaelmichel.de >
* remove empty docstrings
* add depreciation warning
* change event listener to pretix:bind-forms
---------
Co-authored-by: Raphael Michel <michel@pretix.eu >
Co-authored-by: Raphael Michel <mail@raphaelmichel.de >
2026-08-12 15:37:29 +02:00
Raphael Michel
ea792e76b2
Device list: Show online status ( #6455 )
...
* Device list: Show online status
* Fixes post-review
2026-08-06 09:07:20 +02:00
Raphael Michel
407728cc55
Bulk refund: Fix only first refund being made (Z#23239965) ( #6376 )
2026-08-05 11:46:52 +02:00
Raphael Michel
9fe25544c1
Email settings: Fix DMARC warning ( #6452 )
2026-08-05 11:04:56 +02:00
Raphael Michel
e7657a3dd3
Prevent HTML injection in email preview (Z#23241741)
2026-08-05 10:56:46 +02:00
Raphael Michel
16040f70bb
[SECURITY] Add missing permission check for view (CVE-2026-57532)
2026-07-28 12:24:59 +02:00
Raphael Michel
9b5ed06b2e
Improve handling of reauth during async tasks (Z#23238978) ( #6381 )
2026-07-28 10:59:42 +02:00
Raphael Michel
163cf85c86
Orders: Fix N+1 query issues on order detail and change page ( #6390 )
...
* rders: Fix N+1 query issues on order detail and change page
There is one I couldn't fix: Loading the list of tax rules for every
select box on the OrderChange page. Unfortunately, Django has a
cache-breaking .all() in ModelChoiceField and that would need nasty
patching that didn't feel worth it
* Fix isort
* Fix N+1 query in gate call
* Fix leftovers
* Add local cache for objects referenced in log entries
* Update src/pretix/control/views/orders.py
2026-07-28 09:08:14 +02:00
Raphael Michel
d9f8679647
Waiting list: Redirect back after voucher edit (Z#23230178) ( #6252 )
2026-07-27 23:19:10 +02:00
Raphael Michel and pajowu
1a7e36a144
Event-dashboard: Lazy-load warnings ( #6421 )
...
* Event-dashboard: Lazy-load warnings
I don't like this, it's not pretty, but we have no quick way of fixing
the overpaid orders check otherwise and a slow query on the event
dashboard feels really bad, because even if you don't wanna see the
dashboard ou are always going through it in navigation and that can get
very annoying very quickly.
* Update src/pretix/control/templates/pretixcontrol/event/dashboard_partial_warnings.html
Co-authored-by: pajowu <engelhardt@pretix.eu >
---------
Co-authored-by: pajowu <engelhardt@pretix.eu >
2026-07-27 14:40:34 +02:00
Raphael Michel and pajowu
9afc71c245
Update src/pretix/control/views/checkin.py
...
Co-authored-by: pajowu <engelhardt@pretix.eu >
2026-07-27 13:54:06 +02:00
Raphael Michel
1087db9529
Check-in history: Avoid JOINs
...
On a test dataset, this was a speedup from 18s to 900ms
2026-07-27 13:54:06 +02:00
Raphael Michel
351d2055f8
Log view: Disable counting the number of pages (Z#23241035) ( #6414 )
2026-07-24 12:17:48 +02:00
Raphael Michel and luelista
ca03a2556d
Log view: New filter form ( #6412 )
...
* Rework filter form for event log view
* Log view: New filter form
* isort
* Update src/pretix/control/forms/filter.py
Co-authored-by: luelista <weller@rami.io >
---------
Co-authored-by: luelista <weller@rami.io >
2026-07-23 17:35:18 +02:00
luelista
cc082e2001
Improve CSP handling in vite integration; refactor CSP handling into helper functions (Z#23240534) ( #6387 )
2026-07-21 13:20:31 +02:00
5f2264daeb
User email verifications: Add rate limiting (Z#23232834) ( #6219 )
...
* User email verifications: Add rate limiting (Z#23232834)
Also, refactor rate limiting into a central utility
* Make ip block work in dev
* Review notes
* Update src/pretix/base/forms/user.py
Co-authored-by: luelista <weller@rami.io >
* Apply suggestions from code review
Co-authored-by: luelista <mira@teamwiki.de >
* Add rate limit reset
---------
Co-authored-by: luelista <weller@rami.io >
Co-authored-by: luelista <mira@teamwiki.de >
2026-07-17 18:35:03 +02:00
Raphael Michel
49247062bc
Drop second component from many time picker fields ( #6150 )
2026-07-17 17:42:51 +02:00
luelista
83e607b88d
Fix double escaping in dashboard widgets (Z#23240769) ( #6394 )
2026-07-17 17:03:09 +02:00
Raphael Michel
4372aa6725
Devices: Allow admins to inspect raw info data ( #6389 )
2026-07-16 19:22:31 +02:00
luelista
bf066909a7
Remove more usages of |safe ( #6363 )
...
* Replace |safe with |escapejson where appropriate
* Use JSON encoding for data-replace-with-qr
2026-07-16 13:14:37 +02:00
luelista
1399d37827
UX improvement for enabling payment provider plugins ( #6364 )
...
Make flow of enabling new payment plugin smoother by redirecting back to
payment settings, and highlighting the newly enabled provider.
2026-07-16 12:59:29 +02:00
luelista
6e647b41e4
Use format_html in dashboard widgets ( #6369 )
...
This changes the API of pretix.control.signals.event_dashboard_widgets and
pretix.control.signals.user_dashboard_widgets, such that the "content" key of
returned dictionaries must contain a SafeString if HTML therein is to be
rendered.
2026-07-16 12:56:39 +02:00
luelista
fe5d095ae7
Prevent changing ticket secret of gift-card-issuing order positions ( #6281 )
2026-07-16 12:41:27 +02:00
luelista
ebc31c901a
Fix sorting in voucher list (Z#23240539) ( #6383 )
2026-07-16 12:11:30 +02:00
Raphael Michel and robbi5
eb29101d09
Allow more decimal places for tax rates ( #6092 )
...
* Allow more decimal places for tax rates
* Fix normalization
* More tax rate handling
* Add uncommitted tests
* Rebase migration
* Update src/pretix/base/migrations/0304_tax_rate_decimals.py
Co-authored-by: robbi5 <richt@rami.io >
---------
Co-authored-by: robbi5 <richt@rami.io >
2026-07-15 16:20:45 +02:00
Raphael Michel
52ed8eeb50
Mail setup: Add DKIM + DMARC validation ( #6339 )
...
* Mail setup: Add DKIM + DMARC validation
* Tests
* Test fixes
2026-07-15 11:36:35 +02:00
Raphael Michel
4a4cff3c41
Drop all csp_ignore statements from core (except stripe, for now) ( #6337 )
...
* Add proper CSP policy for HTML email preview
* Handle safe types centrally
* Precompile schema validation function to get rid of ajv2020
* Fix tests
* adjust more tests
2026-07-15 09:39:42 +02:00
Raphael Michel
723c63008d
Team invite: Improve error message (Z#23239860) ( #6368 )
2026-07-10 12:13:44 +02:00
luelista
430c6dd269
Use SafeStrings for plugin signals returning HTML that should be rendered ( #6343 )
...
As a security precaution, we change the contract of some signals such that a
SafeString needs to be returned if HTML should be rendered without further
escaping.
Before, the `{% signal ... %}` and `{% eventsignal ... %}` template tags
called mark_safe themselves on all strings returned from signals. That could
lead to unsafe coding practices, where untrusted values are interpolated into
HTML format strings. However, such interpolations should usually be performed
using helpers such Django's format_html, which automatically escapes inputs
and returns a SafeString.
Now, we call conditional_escape on signal results, so that any HTML not explicitly
marked as safe gets escaped.
Most plugins are not affected by this change as they return a SafeString as a
result of Template.render already.
2026-07-09 17:50:26 +02:00