Commit Graph
1598 Commits
Author SHA1 Message Date
Mira Weller 14a3056bad add DjangoDialog / notify_parent - allow to load existing views in iframe
...and some more changes
2026-09-30 21:03:27 +02:00
pajowu 7bdb2c1555 Email: always use quoted-printable (#6617) 2026-09-30 09:54:21 +02:00
Mira Weller d78d5b52fa Prevent parsing non-standard-compliant JSON float values (Z#23245937 / PRT-021) 2026-09-29 14:30:54 +02:00
Raphael Michel 4edd3c4654 [SECURITY] OAuth: Disable existing tokens when deactivating Application (CVE-2026-101271, Z#23247296) 2026-09-29 14:30:53 +02:00
Raphael Michel ae9bb68645 [SECURITY] Fix customer session fixation on cross-domain login (CVE-2026-101268, Z#23247268) 2026-09-29 14:30:53 +02:00
Raphael Michel d43032274b [SECURITY] Fix checkout validation bypass (CVE-2026-101266, Z#23245008) 2026-09-29 14:30:53 +02:00
pajowu 43e5b62db3 Banktransfer: Make actionvie atomic (Z#23246414) (#6604) 2026-09-29 11:51:12 +02:00
Richard Schreiber df74cbf5fc Remove Vue2-based widget (#6610)
* Remove Vue2-based widget

* move floatformat.js

* Delete docready.js

* Update widget.py
2026-09-29 10:14:21 +02:00
pajowuandRaphael Michel 558bf910fd Use fragment_product_list in voucher redemption view (Z#23246929) (#6567)
* Use fragment_product_list in voucher redemption view (Z#23246929)

* Formatting

* Fix usage in templates

* Review comments

* handle form prefix in fragment_product_list.html

---------

Co-authored-by: Raphael Michel <michel@pretix.eu>
2026-09-28 13:01:15 +02:00
pajowu 7e1e472691 Monkeypatch stock csrfmiddleware (#6401)
* Monkeypatch stock csrfmiddleware

* Add test for ensure_csrf_cookie
2026-09-28 11:46:23 +02:00
pajowu 2af8d29ca9 Add pdf render tests (#6566)
* Add pdf tests

* pdf tests: Save temporary pdfs for failed test debugging

* Review comments
2026-09-25 16:54:58 +02:00
9aeb4b9731 Organizer API: Add endpoint for event-meta-properties
* Add API-endpoint for event-meta-properties

* Add new doc-file to index, fix spelling and description

* Fix logentry

* Fix logentry again

* validate and add tests

* add meta_properties from organizer only

* fix choices validation

* filter unknown keys from choices due to django-formsets

* Apply batched suggestions from code review

Co-authored-by: Richard Schreiber <wiffbi@gmail.com>

* add safe-guard normalization to None to to_representation

* Apply batched suggestions from code review

Co-authored-by: Raphael Michel <mail@raphaelmichel.de>

* update tests to check for error-messages as well

* fix flake8

* fix permission tests

* Make ObjectListField more flexibel for re-use

* fix validation result

* Improve validation

* Change to I18nField for validation

* update MetaPropertyDictField

* fix docs for i18n strings

* make label_child configurable if MetaPropertyDictField should contain non-localized stuff

* undo test changes in events test

* fix flake8

* Apply batched suggestions from code review

Co-authored-by: Raphael Michel <mail@raphaelmichel.de>

* improve code formatting

---------

Co-authored-by: Richard Schreiber <schreiber@rami.io>
Co-authored-by: Richard Schreiber <schreiber@pretix.eu>
Co-authored-by: Richard Schreiber <wiffbi@gmail.com>
Co-authored-by: Raphael Michel <mail@raphaelmichel.de>
2026-09-24 10:51:23 +02:00
Raphael Michel b8f8e49cce API: Add additional tests for modifying meta data (Z#23247634) 2026-09-23 19:01:52 +02:00
Raphael Michel 806d0a5748 User details: Show list of 2FA devices and allow to reset drift (#6569)
* User details: Show list of 2FA devices

* Add reset button

* Reset throttle

* Refactoring

* Fix delete paths in tests
2026-09-23 17:51:10 +02:00
Raphael Michel 69e541e5af Product list: Fix edge case in dependent availabilities (Z#23243701) (#6532) 2026-09-23 17:22:54 +02:00
Raphael Michel b8e1ab8258 Voucher API: Add search parameter (Z#23240589) (#6523) 2026-09-23 15:54:44 +02:00
Raphael MichelandMartin Gross 59026da06b Delete PayPal integration v1 (#6530)
* Delete PayPal integration v1

Leaving only migrations behind

* Try to fix CI

* Fix tests some more

* Rename more plugin name instances in tests and docs

---------

Co-authored-by: Martin Gross <martin@pc-coholic.de>
2026-09-23 11:38:16 +02:00
Raphael Michel 58023381b9 Merge branch 'refund-offset-perm-check' into 'master'
Offset refund: Do not allow to offset to order without access to

See merge request pretix/pretix!52
2026-09-22 12:46:20 +02:00
Raphael Michel e5c44e7aed Offset refund: Do not allow to offset to order without access to 2026-09-22 12:46:20 +02:00
Raphael Michel 29614db1e2 InvoiceShredder: Fix shredding of new fields (#6577)
* InvoiceShredder: Fix shredding of new fields

* Update src/pretix/base/migrations/0311_fix_unshredded_invoices.py
2026-09-22 10:37:58 +02:00
Raphael Michel bc0a6b662b Checkout: Fix VAT ID revalidation after country change (#6575) 2026-09-22 09:51:10 +02:00
Raphael Michelandpajowu aa14505d2c Money representation in templates: Allow more precision (#6454)
* Money representation in templates: Allow more precision

When rendering money in templates, we used to have the following logic:

- When the decimal places fit the currency, render with Babel
- When they don't, e.g. we stored 123.67 JPY, even though there are no
  fractional Yens, render without Babel with a custom format, but render
  the fractional Yens because we'd rather *show* wrong data and make the
  bug obvious than hide it.

However, we only did that up to a prevision of two places, we never
showed more. This is still sufficient for core pretix, but we have
plugins that need to operate in fractional cents. Also, we CAN render
everything through babel for consistent formatting.

There is one **risk**: This might cause weird results on SQLite. Since
SQLite has no concept of precise decimal math, results of in-SQL
computations can sometimes experience floating point errors and show
with A LOT of decimal palces. This used to be invisible since the UI
performed the rounding. With this PR – not any more. We'll need to see
how annoying it is, but it should only affect development mode.

This PR also fixes a bug in tax_rate_format that for some reason did not
do what it was supposed to do, even though I tested it back then, weird.
Might even be a Python version thing?

* Update src/pretix/base/templatetags/money.py

Co-authored-by: pajowu <engelhardt@pretix.eu>

* Apply suggestion from @pajowu

Co-authored-by: pajowu <engelhardt@pretix.eu>

* Fix typing stuff

* Fix precision issue

---------

Co-authored-by: pajowu <engelhardt@pretix.eu>
2026-09-18 11:49:12 +02:00
Raphael Michel bcacff2ee7 Voucher list: Add budget and budget used to CSV export (Z#23237857) (#6520)
* Voucher list: Add budget and budget used to CSV export (Z#23237857)

* Fix failing test
2026-09-14 10:31:07 +02:00
Richard Schreiber 86cc719651 Widget: serve vite by default, origin-whitelist for vue2 (#6403) 2026-09-11 08:53:42 +02:00
Martin GrossandRaphael Michel 2c15d8b074 Event Settings: Make contact_url and imprint_url I18nURLField (Z#23238623) (#6506)
* Event Settings: Make contact_url and imprint_url I18nURLField (Z#23238623)

* isort

* Update doc/api/resources/events.rst

---------

Co-authored-by: Raphael Michel <michel@pretix.eu>
2026-09-09 09:14:37 +02:00
Raphael MichelandLukas Bockstaller edb4069e18 Payment step: Allow to postpone payment choice on some sales channels (#6516)
* Payment step: Allow to postpone payment choice on some sales channels

* Add tests

* handle payment provider (de-)selection and partial payments (#6526)

---------

Co-authored-by: Lukas Bockstaller <bockstaller@pretix.eu>
2026-09-08 09:32:15 +02:00
Lukas Bockstaller 9d53cf840b PayPal: validate that the sale has any captures before marking paid (#6498)
* validate that the sale has any captures before marking paid

* code style
2026-09-01 10:16:51 +02:00
Richard Schreiber d7aae65777 API: fix tax rules create default handling (#6490)
* API: fix tax rules create default handling

* fix flake8
2026-08-25 09:39:21 +02:00
Richard Schreiber dbd971cc22 API: fix writing old permissions on teams (#6489) 2026-08-25 09:38:11 +02:00
Richard Schreiber 6d4aba6e3d Questions: add min-length to string/text type questions (#6488)
* Questions: add min-length to string/text type questions

* fix test
2026-08-25 09:37:37 +02:00
Kara Engelhardt 0593172146 Transmit invoices generated due to paymentprovider changes (Z#23242806) 2026-08-24 13:45:54 +02:00
Raphael Michelandluelista 58f331ba1f Allow to set payment term per sales channel (#6459)
* Allow to set payment term per sales channel

* Apply suggestion from @luelista

Co-authored-by: luelista <weller@rami.io>

---------

Co-authored-by: luelista <weller@rami.io>
2026-08-24 09:09:47 +02:00
Lukas Bockstaller 0b319d201c handle captures that are declined (PRETIXEU-F8X & PRETIXEU-F93) (#6482)
* handle captures that are declined

* handle failed captures not stored in sale

* further fixes

* fix tests
2026-08-19 08:41:25 +02:00
Richard Schreiber f9ea9de078 Fix sendmail/scheduled-mails preview event-based placeholders
* Fix sendmail/scheduled-mails placeholders

* Add event_or_subevent to context

* Add placeholders to tests

* fix and improve test

* Revert "fix and improve test"

This reverts commit 874a11e982.

* undo placeholder-tests

* add test
2026-08-18 14:54:19 +02:00
Lukas Bockstallerandpajowu c4a5a9a84d BasePaymentProvider & PayPal2: allow to cancel pending payments on a per payment basis (Z#23240966) (#6472)
* move payment into pending on PENDING_REVIEW webhook

* mark approved payment as pending

* extend BasePaymentProvider to gate aborting pending payments on a payment per payment basis

* add timeout to paypal after which a pending payment can be canceled

* formatting

* add missing negation

* cleanup abort_pending_allowed methods

* Apply suggestions from code review

Co-authored-by: pajowu <pajowu@pajowu.de>

* check all capture elements

* rename method and change defaults

* remove left over Constant

* flake8 .

---------

Co-authored-by: pajowu <pajowu@pajowu.de>
2026-08-13 17:28:54 +02:00
7fe31634e6 Allow RelativeDate in relation to a moment of order (#6160)
* initial implementation

* factor out _resolve_base_date

* add js to prevent illegal inputs

* fix tests

* Update src/pretix/base/reldate.py

Co-authored-by: Raphael Michel <michel@pretix.eu>

* Apply suggestions from code review

Co-authored-by: Raphael Michel <mail@raphaelmichel.de>

* move js includes of to fragment_js.html

* add type annotations

* moves logic from RelativeDateWrapper into RelativeDate and adds BaseChoice for configuring which models attributes support which relationship

* fix tests

* test upgrade behaviour

* Apply suggestions from code review

Co-authored-by: Raphael Michel <mail@raphaelmichel.de>

* move reldate.js include in correct file

* add OptionAttrsSelect to allow select options with their own attributes per value

* add a little bit of information to the tests for future reference

* rewrite reldate.js use data-attributes

* general cleanup

* add test for order.subevents cases

* use correct choice format

* remove order.subevent variants

* various cleanup

* Apply suggestions from code review

Co-authored-by: Raphael Michel <mail@raphaelmichel.de>

* remove empty docstrings

* add depreciation warning

* change event listener to pretix:bind-forms

---------

Co-authored-by: Raphael Michel <michel@pretix.eu>
Co-authored-by: Raphael Michel <mail@raphaelmichel.de>
2026-08-12 15:37:29 +02:00
Raphael Michel d08216d8c5 API: Allow to simulate check-ins (#6360)
* API: Allow to simulate check-ins

* Add missing file
2026-08-07 18:59:01 +02:00
luelista 958f75b109 Add tests to prevent reintroducing CSP nonces (Z#23240534) (#6409)
As discussed in PR #6387
2026-08-07 14:36:46 +02:00
Lukas BockstallerandPhin Wolkwitz 4d9dfa88fe Paypal2: handle incomming capture webhooks (Z#23240966) (#6456)
* store the state of the payment regardless of the state

control.html shows the banner that the payment is in review depending on payment.info

* handle capture ressource

* Update src/pretix/plugins/paypal2/views.py

Co-authored-by: Phin Wolkwitz <wolkwitz@pretix.eu>

* add test

* cleanup logic regarding uninteresting resource_type

* store payment.info during _execute_payment asap

---------

Co-authored-by: Phin Wolkwitz <wolkwitz@pretix.eu>
2026-08-06 15:06:20 +02:00
Raphael Michel 8133061fe1 Devices: Store timestamp of last contact (#6453) 2026-08-05 10:57:13 +02:00
pajowu b20557a996 Show correct number of currency placed in widget (Z#23241522) (#6425) 2026-08-04 11:19:43 +02:00
pajowu 01d736361d Cart Manager: Round custom price to currency when adding (#6426) 2026-08-03 14:26:57 +02:00
Raphael Michel 85de097497 API: Disable endpoints that should have never existed (#6431) 2026-07-29 13:04:45 +02:00
Raphael Michel 16040f70bb [SECURITY] Add missing permission check for view (CVE-2026-57532) 2026-07-28 12:24:59 +02:00
Kara Engelhardt 072c17c91a Banktransfer: Notify incomplete payments after manual assignment (Z#23241009) 2026-07-22 14:15:14 +02:00
Kara Engelhardt 39fbd25fbb Ignore expiry date for payments created via api (Z#23232671) 2026-07-20 12:46:50 +02:00
Raphael Michel 2de032c2be Fix test failure on PostgreSQL 2026-07-17 19:22:50 +02:00
5f2264daeb User email verifications: Add rate limiting (Z#23232834) (#6219)
* User email verifications: Add rate limiting (Z#23232834)

Also, refactor rate limiting into a central utility

* Make ip block work in dev

* Review notes

* Update src/pretix/base/forms/user.py

Co-authored-by: luelista <weller@rami.io>

* Apply suggestions from code review

Co-authored-by: luelista <mira@teamwiki.de>

* Add rate limit reset

---------

Co-authored-by: luelista <weller@rami.io>
Co-authored-by: luelista <mira@teamwiki.de>
2026-07-17 18:35:03 +02:00
Raphael Michel 4295b02406 Fix tests after hierarkey update 2026-07-17 18:33:20 +02:00
luelistaandKara Engelhardt 7cff4321e0 Order change: Fix crash if addon has hidden_if_item_available (Z#23236380) (#6357)
* Fix crash in rebooking if addon has hidden_if_item_available
* Move get_grouped_items into its own file and rename to prepare_item_list_for_shop
  (but keep a reference under original name for plugin compatibility)
* Make Item[Variation].unavailability_reason helper functions next to get_grouped_items
* Use current_unavailability_reason attribute instead of unavailability_reason()
* Add test case for:
  Order has product with addon 1; Addon 1 is hidden if Addon 2 is available; When order is changed, Addon 1 should not be removable
* Fix special case if addon product is now set to require a voucher (vouchers for addons are not supported)

---------

Co-authored-by: Kara Engelhardt <engelhardt@pretix.eu>
2026-07-16 12:52:08 +02:00