Commit Graph
1287 Commits
Author SHA1 Message Date
Kara Engelhardt 5b46124dc8 wallet wip 2026-09-22 10:52:33 +02:00
Kara Engelhardt 85e3a91546 WIP 2026-09-22 10:52:33 +02:00
Kara Engelhardt 4a89d50386 Remove static layout name from editor page 2026-09-22 10:52:33 +02:00
Kara Engelhardt 1ae4f37361 use placeholder name as label default 2026-09-22 10:52:33 +02:00
Kara Engelhardt eaff44e924 WIP: first successful pass creation 2026-09-22 10:52:33 +02:00
Kara Engelhardt 4837f791db WalletLayout now contain layouts for all platforms 2026-09-22 10:52:33 +02:00
Kara Engelhardt 9dc083cb88 WIP 2026-09-22 10:52:33 +02:00
Kara Engelhardt b80c7d68bb WIP: i18n editor, start apple wallet generation 2026-09-22 10:52:33 +02:00
Kara Engelhardt 326992dd6d WIP: i18nfields, refactoring, jsonschema-validatoin 2026-09-22 10:52:33 +02:00
Kara Engelhardt 3663754dfb WIP: use api 2026-09-22 10:52:33 +02:00
Kara Engelhardt 77a4929bdf WIP 2026-09-22 10:52:33 +02:00
Kara Engelhardt af15c7cdb7 WIP 2026-09-22 10:52:33 +02:00
Kara Engelhardt 4b76c4e8d7 WIP 2026-09-22 10:52:33 +02:00
Kara Engelhardt c8ec5d8367 WIP 2026-09-22 10:52:33 +02:00
Kara Engelhardt ed06acf580 WIP 2026-09-22 10:52:32 +02:00
Kara Engelhardt 3b998f8acc Add wallet plugins stub 2026-09-22 10:52:32 +02:00
dependabot[bot]andRaphael Michel efdc83f72a Update pypdf requirement from ==6.5.* to ==6.11.* (#6176)
* Update pypdf requirement from ==6.5.* to ==6.11.*

Updates the requirements on [pypdf](https://github.com/py-pdf/pypdf) to permit the latest version.
- [Release notes](https://github.com/py-pdf/pypdf/releases)
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md)
- [Commits](https://github.com/py-pdf/pypdf/compare/6.5.0...6.11.0)

---
updated-dependencies:
- dependency-name: pypdf
  dependency-version: 6.11.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Try to adjust code

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Raphael Michel <michel@rami.io>
2026-09-14 14:09:28 +02:00
Kara Engelhardt 47096f7f1b sendmail: fix query performance when filtering on checkin (Z#23244045) 2026-09-14 10:24:58 +02:00
Raphael Michel ce3e59e020 PDF reports: Fix headers for overlong event names (Z#23239566) (#6521) 2026-09-14 09:38:44 +02:00
Raphael MichelandKara Engelhardt d85e52c83e ESlint: Ignore vendored and pre-vue code (#6541)
* ESlint: Ignore vendored and pre-vue code

* Format pre-vue code with eslint where possible

---------

Co-authored-by: Kara Engelhardt <engelhardt@pretix.eu>
2026-09-10 12:35:10 +02:00
Kara Engelhardt fb948cc7f4 sendmail: small performance winds in checkin query 2026-09-10 11:17:32 +02:00
Kara Engelhardt c358f412fd sendmail: code cleanup 2026-09-10 11:17:32 +02:00
Kara Engelhardt b78de6386b sendmail: fix quadratic checkin query 2026-09-10 11:17:32 +02:00
Raphael Michelandluelista 42c5de895c CachedFileField: Bind file access to session (Z#23242301) (#6447)
* CachedFileField: Bind file access to session (Z#23242301)

* Apply suggestion from @luelista

Co-authored-by: luelista <weller@rami.io>

---------

Co-authored-by: luelista <weller@rami.io>
2026-09-09 09:52:40 +02:00
Lukas Bockstaller 9d53cf840b PayPal: validate that the sale has any captures before marking paid (#6498)
* validate that the sale has any captures before marking paid

* code style
2026-09-01 10:16:51 +02:00
Raphael Michel b74371bef1 Fix typos 2026-08-24 17:26:37 +02:00
Lukas Bockstaller 0b319d201c handle captures that are declined (PRETIXEU-F8X & PRETIXEU-F93) (#6482)
* handle captures that are declined

* handle failed captures not stored in sale

* further fixes

* fix tests
2026-08-19 08:41:25 +02:00
Richard Schreiber f9ea9de078 Fix sendmail/scheduled-mails preview event-based placeholders
* Fix sendmail/scheduled-mails placeholders

* Add event_or_subevent to context

* Add placeholders to tests

* fix and improve test

* Revert "fix and improve test"

This reverts commit 874a11e982.

* undo placeholder-tests

* add test
2026-08-18 14:54:19 +02:00
Martin Gross 7b1558b22e Revert "Stripe/Wero: Do not send payment_method_data"
This reverts commit 488f731396.
2026-08-14 12:07:34 +02:00
Martin Gross 488f731396 Stripe/Wero: Do not send payment_method_data 2026-08-14 11:24:34 +02:00
Lukas Bockstaller b8b02de283 paypal change default for allow_retries_during_compliance_hold 2026-08-13 18:10:38 +02:00
Lukas Bockstallerandpajowu c4a5a9a84d BasePaymentProvider & PayPal2: allow to cancel pending payments on a per payment basis (Z#23240966) (#6472)
* move payment into pending on PENDING_REVIEW webhook

* mark approved payment as pending

* extend BasePaymentProvider to gate aborting pending payments on a payment per payment basis

* add timeout to paypal after which a pending payment can be canceled

* formatting

* add missing negation

* cleanup abort_pending_allowed methods

* Apply suggestions from code review

Co-authored-by: pajowu <pajowu@pajowu.de>

* check all capture elements

* rename method and change defaults

* remove left over Constant

* flake8 .

---------

Co-authored-by: pajowu <pajowu@pajowu.de>
2026-08-13 17:28:54 +02:00
Lukas Bockstaller 4a28689690 log paypal payment durations (#6461)
* log payment processing durations

* remove log noise

* fix attribute access

* remove debugging import
2026-08-07 16:34:36 +02:00
Lukas BockstallerandPhin Wolkwitz 4d9dfa88fe Paypal2: handle incomming capture webhooks (Z#23240966) (#6456)
* store the state of the payment regardless of the state

control.html shows the banner that the payment is in review depending on payment.info

* handle capture ressource

* Update src/pretix/plugins/paypal2/views.py

Co-authored-by: Phin Wolkwitz <wolkwitz@pretix.eu>

* add test

* cleanup logic regarding uninteresting resource_type

* store payment.info during _execute_payment asap

---------

Co-authored-by: Phin Wolkwitz <wolkwitz@pretix.eu>
2026-08-06 15:06:20 +02:00
Raphael Michel 5c448279f0 API: Make all mutating endpoints transactional (#6430)
All of our API endpoints that do something in the system do at least two
SQL queries, one for the actual change and one for the log entry. Often
many more. We want all of this to happen in a transaction so we know an
API call was executed or not at all, not half-way.
2026-08-05 16:52:28 +02:00
LilaHexeandRaphael Michel a696c493e2 PayPal: Drop maximum length of client ID (#6424)
* Update PayPal max_length to 82 characters

* Apply suggestions from code review

Co-authored-by: Raphael Michel <mail@raphaelmichel.de>

---------

Co-authored-by: Raphael Michel <mail@raphaelmichel.de>
2026-07-28 09:13:45 +02:00
Kara Engelhardt 072c17c91a Banktransfer: Notify incomplete payments after manual assignment (Z#23241009) 2026-07-22 14:15:14 +02:00
Kara Engelhardt a4d10d9550 Sendmail: clarify order status labels (Z#23230149) 2026-07-22 13:43:07 +02:00
luelista cc082e2001 Improve CSP handling in vite integration; refactor CSP handling into helper functions (Z#23240534) (#6387) 2026-07-21 13:20:31 +02:00
Raphael Michel 32e0e31b15 Redirection plugin: Improve validation to avoid ReDoS (#6395)
* Redirection plugin: Improve validation to avoid ReDoS

* Stricter regex
2026-07-20 13:39:15 +02:00
Raphael Michel ea819530f9 Escape HTML arguments to translation strings (#6399) 2026-07-20 13:15:09 +02:00
luelista bf066909a7 Remove more usages of |safe (#6363)
* Replace |safe with |escapejson where appropriate
* Use JSON encoding for data-replace-with-qr
2026-07-16 13:14:37 +02:00
Raphael Michelandrobbi5 eb29101d09 Allow more decimal places for tax rates (#6092)
* Allow more decimal places for tax rates

* Fix normalization

* More tax rate handling

* Add uncommitted tests

* Rebase migration

* Update src/pretix/base/migrations/0304_tax_rate_decimals.py

Co-authored-by: robbi5 <richt@rami.io>

---------

Co-authored-by: robbi5 <richt@rami.io>
2026-07-15 16:20:45 +02:00
Raphael Michel 4a4cff3c41 Drop all csp_ignore statements from core (except stripe, for now) (#6337)
* Add proper CSP policy for HTML email preview

* Handle safe types centrally

* Precompile schema validation function to get rid of ajv2020

* Fix tests

* adjust more tests
2026-07-15 09:39:42 +02:00
luelista 78f8830f90 Hotfix: fix order_position_buttons receiver 2026-07-10 15:08:10 +02:00
Raphael Michel eb594266a7 Hotfix: Add missing mark_safe after strip 2026-07-10 14:56:48 +02:00
Lukas Bockstaller 634754aacb repair sendmail rules so we don't send emails to all positions in order independent of checkin status (Z#23235255) (#6340)
* add repro for Z#23235255

* add testcase for fallback to order.email

* only send to orderpositions included in op_qs

* codestyle
2026-07-07 17:46:52 +02:00
Raphael Michel ea2c81e6dc Improve handling of logout during asynchronous tasks (Z#23238978) (#6341)
* Handle logout during async task requests properly

* Handle fragments safely on webcheckin logout

* Remove unnecessary comment

* Revert hash change
2026-07-07 16:14:00 +02:00
pajowu 5fb827c8f5 CheckInListPDF export: remove double html escaping with PlainTextParagraph (Z#23239571) (#6347) 2026-07-07 12:00:17 +02:00
Raphael MichelandMira Weller c9781f012b [SECURITY] Centralize framebreaking logic from payment plugins to core (CVE-2026-13602)
- Add central framebreaker page via safelink helper
- Update paypal, paypal2 and stripe plugins to use central framebreaker
- Add CSP header to cookies.html

---------

Co-authored-by: Mira Weller <weller@pretix.eu>
2026-07-01 15:15:43 +02:00