Kara Engelhardt
5b46124dc8
wallet wip
2026-09-22 10:52:33 +02:00
Kara Engelhardt
85e3a91546
WIP
2026-09-22 10:52:33 +02:00
Kara Engelhardt
4a89d50386
Remove static layout name from editor page
2026-09-22 10:52:33 +02:00
Kara Engelhardt
1ae4f37361
use placeholder name as label default
2026-09-22 10:52:33 +02:00
Kara Engelhardt
eaff44e924
WIP: first successful pass creation
2026-09-22 10:52:33 +02:00
Kara Engelhardt
4837f791db
WalletLayout now contain layouts for all platforms
2026-09-22 10:52:33 +02:00
Kara Engelhardt
9dc083cb88
WIP
2026-09-22 10:52:33 +02:00
Kara Engelhardt
b80c7d68bb
WIP: i18n editor, start apple wallet generation
2026-09-22 10:52:33 +02:00
Kara Engelhardt
326992dd6d
WIP: i18nfields, refactoring, jsonschema-validatoin
2026-09-22 10:52:33 +02:00
Kara Engelhardt
3663754dfb
WIP: use api
2026-09-22 10:52:33 +02:00
Kara Engelhardt
77a4929bdf
WIP
2026-09-22 10:52:33 +02:00
Kara Engelhardt
af15c7cdb7
WIP
2026-09-22 10:52:33 +02:00
Kara Engelhardt
4b76c4e8d7
WIP
2026-09-22 10:52:33 +02:00
Kara Engelhardt
c8ec5d8367
WIP
2026-09-22 10:52:33 +02:00
Kara Engelhardt
ed06acf580
WIP
2026-09-22 10:52:32 +02:00
Kara Engelhardt
3b998f8acc
Add wallet plugins stub
2026-09-22 10:52:32 +02:00
dependabot[bot] and Raphael Michel
efdc83f72a
Update pypdf requirement from ==6.5.* to ==6.11.* ( #6176 )
...
* Update pypdf requirement from ==6.5.* to ==6.11.*
Updates the requirements on [pypdf](https://github.com/py-pdf/pypdf ) to permit the latest version.
- [Release notes](https://github.com/py-pdf/pypdf/releases )
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md )
- [Commits](https://github.com/py-pdf/pypdf/compare/6.5.0...6.11.0 )
---
updated-dependencies:
- dependency-name: pypdf
dependency-version: 6.11.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
* Try to adjust code
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Raphael Michel <michel@rami.io >
2026-09-14 14:09:28 +02:00
Kara Engelhardt
47096f7f1b
sendmail: fix query performance when filtering on checkin (Z#23244045)
2026-09-14 10:24:58 +02:00
Raphael Michel
ce3e59e020
PDF reports: Fix headers for overlong event names (Z#23239566) ( #6521 )
2026-09-14 09:38:44 +02:00
Raphael Michel and Kara Engelhardt
d85e52c83e
ESlint: Ignore vendored and pre-vue code ( #6541 )
...
* ESlint: Ignore vendored and pre-vue code
* Format pre-vue code with eslint where possible
---------
Co-authored-by: Kara Engelhardt <engelhardt@pretix.eu >
2026-09-10 12:35:10 +02:00
Kara Engelhardt
fb948cc7f4
sendmail: small performance winds in checkin query
2026-09-10 11:17:32 +02:00
Kara Engelhardt
c358f412fd
sendmail: code cleanup
2026-09-10 11:17:32 +02:00
Kara Engelhardt
b78de6386b
sendmail: fix quadratic checkin query
2026-09-10 11:17:32 +02:00
Raphael Michel and luelista
42c5de895c
CachedFileField: Bind file access to session (Z#23242301) ( #6447 )
...
* CachedFileField: Bind file access to session (Z#23242301)
* Apply suggestion from @luelista
Co-authored-by: luelista <weller@rami.io >
---------
Co-authored-by: luelista <weller@rami.io >
2026-09-09 09:52:40 +02:00
Lukas Bockstaller
9d53cf840b
PayPal: validate that the sale has any captures before marking paid ( #6498 )
...
* validate that the sale has any captures before marking paid
* code style
2026-09-01 10:16:51 +02:00
Raphael Michel
b74371bef1
Fix typos
2026-08-24 17:26:37 +02:00
Lukas Bockstaller
0b319d201c
handle captures that are declined (PRETIXEU-F8X & PRETIXEU-F93) ( #6482 )
...
* handle captures that are declined
* handle failed captures not stored in sale
* further fixes
* fix tests
2026-08-19 08:41:25 +02:00
Richard Schreiber
f9ea9de078
Fix sendmail/scheduled-mails preview event-based placeholders
...
* Fix sendmail/scheduled-mails placeholders
* Add event_or_subevent to context
* Add placeholders to tests
* fix and improve test
* Revert "fix and improve test"
This reverts commit 874a11e982 .
* undo placeholder-tests
* add test
2026-08-18 14:54:19 +02:00
Martin Gross
7b1558b22e
Revert "Stripe/Wero: Do not send payment_method_data"
...
This reverts commit 488f731396 .
2026-08-14 12:07:34 +02:00
Martin Gross
488f731396
Stripe/Wero: Do not send payment_method_data
2026-08-14 11:24:34 +02:00
Lukas Bockstaller
b8b02de283
paypal change default for allow_retries_during_compliance_hold
2026-08-13 18:10:38 +02:00
Lukas Bockstaller and pajowu
c4a5a9a84d
BasePaymentProvider & PayPal2: allow to cancel pending payments on a per payment basis (Z#23240966) ( #6472 )
...
* move payment into pending on PENDING_REVIEW webhook
* mark approved payment as pending
* extend BasePaymentProvider to gate aborting pending payments on a payment per payment basis
* add timeout to paypal after which a pending payment can be canceled
* formatting
* add missing negation
* cleanup abort_pending_allowed methods
* Apply suggestions from code review
Co-authored-by: pajowu <pajowu@pajowu.de >
* check all capture elements
* rename method and change defaults
* remove left over Constant
* flake8 .
---------
Co-authored-by: pajowu <pajowu@pajowu.de >
2026-08-13 17:28:54 +02:00
Lukas Bockstaller
4a28689690
log paypal payment durations ( #6461 )
...
* log payment processing durations
* remove log noise
* fix attribute access
* remove debugging import
2026-08-07 16:34:36 +02:00
Lukas Bockstaller and Phin Wolkwitz
4d9dfa88fe
Paypal2: handle incomming capture webhooks (Z#23240966) ( #6456 )
...
* store the state of the payment regardless of the state
control.html shows the banner that the payment is in review depending on payment.info
* handle capture ressource
* Update src/pretix/plugins/paypal2/views.py
Co-authored-by: Phin Wolkwitz <wolkwitz@pretix.eu >
* add test
* cleanup logic regarding uninteresting resource_type
* store payment.info during _execute_payment asap
---------
Co-authored-by: Phin Wolkwitz <wolkwitz@pretix.eu >
2026-08-06 15:06:20 +02:00
Raphael Michel
5c448279f0
API: Make all mutating endpoints transactional ( #6430 )
...
All of our API endpoints that do something in the system do at least two
SQL queries, one for the actual change and one for the log entry. Often
many more. We want all of this to happen in a transaction so we know an
API call was executed or not at all, not half-way.
2026-08-05 16:52:28 +02:00
LilaHexe and Raphael Michel
a696c493e2
PayPal: Drop maximum length of client ID ( #6424 )
...
* Update PayPal max_length to 82 characters
* Apply suggestions from code review
Co-authored-by: Raphael Michel <mail@raphaelmichel.de >
---------
Co-authored-by: Raphael Michel <mail@raphaelmichel.de >
2026-07-28 09:13:45 +02:00
Kara Engelhardt
072c17c91a
Banktransfer: Notify incomplete payments after manual assignment (Z#23241009)
2026-07-22 14:15:14 +02:00
Kara Engelhardt
a4d10d9550
Sendmail: clarify order status labels (Z#23230149)
2026-07-22 13:43:07 +02:00
luelista
cc082e2001
Improve CSP handling in vite integration; refactor CSP handling into helper functions (Z#23240534) ( #6387 )
2026-07-21 13:20:31 +02:00
Raphael Michel
32e0e31b15
Redirection plugin: Improve validation to avoid ReDoS ( #6395 )
...
* Redirection plugin: Improve validation to avoid ReDoS
* Stricter regex
2026-07-20 13:39:15 +02:00
Raphael Michel
ea819530f9
Escape HTML arguments to translation strings ( #6399 )
2026-07-20 13:15:09 +02:00
luelista
bf066909a7
Remove more usages of |safe ( #6363 )
...
* Replace |safe with |escapejson where appropriate
* Use JSON encoding for data-replace-with-qr
2026-07-16 13:14:37 +02:00
Raphael Michel and robbi5
eb29101d09
Allow more decimal places for tax rates ( #6092 )
...
* Allow more decimal places for tax rates
* Fix normalization
* More tax rate handling
* Add uncommitted tests
* Rebase migration
* Update src/pretix/base/migrations/0304_tax_rate_decimals.py
Co-authored-by: robbi5 <richt@rami.io >
---------
Co-authored-by: robbi5 <richt@rami.io >
2026-07-15 16:20:45 +02:00
Raphael Michel
4a4cff3c41
Drop all csp_ignore statements from core (except stripe, for now) ( #6337 )
...
* Add proper CSP policy for HTML email preview
* Handle safe types centrally
* Precompile schema validation function to get rid of ajv2020
* Fix tests
* adjust more tests
2026-07-15 09:39:42 +02:00
luelista
78f8830f90
Hotfix: fix order_position_buttons receiver
2026-07-10 15:08:10 +02:00
Raphael Michel
eb594266a7
Hotfix: Add missing mark_safe after strip
2026-07-10 14:56:48 +02:00
Lukas Bockstaller
634754aacb
repair sendmail rules so we don't send emails to all positions in order independent of checkin status (Z#23235255) ( #6340 )
...
* add repro for Z#23235255
* add testcase for fallback to order.email
* only send to orderpositions included in op_qs
* codestyle
2026-07-07 17:46:52 +02:00
Raphael Michel
ea2c81e6dc
Improve handling of logout during asynchronous tasks (Z#23238978) ( #6341 )
...
* Handle logout during async task requests properly
* Handle fragments safely on webcheckin logout
* Remove unnecessary comment
* Revert hash change
2026-07-07 16:14:00 +02:00
pajowu
5fb827c8f5
CheckInListPDF export: remove double html escaping with PlainTextParagraph (Z#23239571) ( #6347 )
2026-07-07 12:00:17 +02:00
Raphael Michel and Mira Weller
c9781f012b
[SECURITY] Centralize framebreaking logic from payment plugins to core (CVE-2026-13602)
...
- Add central framebreaker page via safelink helper
- Update paypal, paypal2 and stripe plugins to use central framebreaker
- Add CSP header to cookies.html
---------
Co-authored-by: Mira Weller <weller@pretix.eu >
2026-07-01 15:15:43 +02:00