Mira Weller and Raphael Michel
848f7fa0e5
[SECURITY] Fix stored XSS in ticket confirmation page (CVE-2026-13225)
2026-06-25 16:46:13 +02:00
Mira Weller and Raphael Michel
3442a543c8
[SECURITY] Hardening: Don't use |safe on confirm_messages
2026-06-25 16:46:13 +02:00
Mira Weller and Raphael Michel
f88c24863d
[SECURITY] Fix XSS in ticket layout JSON (CVE-2026-57532)
2026-06-25 16:46:13 +02:00
Lukas Bockstaller and GitHub
79c5160b57
Revert "Update django-countries requirement from ==8.2.* to ==9.0.* ( #6269 )" ( #6310 )
...
This reverts commit 1e301da26c .
2026-06-24 10:42:56 +02:00
Richard Schreiber and GitHub
e8492cad3c
Seating: fix handling optional position attribute ( #6303 )
2026-06-24 09:47:08 +02:00
Richard Schreiber and GitHub
7ea5a2b59e
PDF: add placeholder invoice_custom_field ( #6298 )
2026-06-24 09:46:43 +02:00
luelista and GitHub
4c373518d0
Fix event meta property handling when cloning across organizers (Z#23231419) ( #6306 )
2026-06-23 19:01:32 +02:00
luelista and GitHub
1521c0cfcd
Fix URL matching in EventQRCode (Z#23237781) ( #6304 )
2026-06-23 18:34:31 +02:00
3432e62e4f
Update css-inline requirement from ==0.20.* to ==0.21.* ( #6302 )
...
Updates the requirements on [css-inline](https://github.com/Stranger6667/css-inline ) to permit the latest version.
- [Release notes](https://github.com/Stranger6667/css-inline/releases )
- [Changelog](https://github.com/Stranger6667/css-inline/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Stranger6667/css-inline/compare/c-v0.20.0...c-v0.21.0 )
---
updated-dependencies:
- dependency-name: css-inline
dependency-version: 0.21.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-23 13:32:50 +02:00
736fa38ca7
Update sentry-sdk requirement from ==2.62.* to ==2.63.* ( #6301 )
...
Updates the requirements on [sentry-sdk](https://github.com/getsentry/sentry-python ) to permit the latest version.
- [Release notes](https://github.com/getsentry/sentry-python/releases )
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md )
- [Commits](https://github.com/getsentry/sentry-python/compare/2.62.0...2.63.0 )
---
updated-dependencies:
- dependency-name: sentry-sdk
dependency-version: 2.63.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-23 13:32:39 +02:00
d14dc4c5ff
Test order deletion: Improve bulk performance (Z#23237160) ( #6274 )
...
* Test order deletion: Improve bulk performance (Z#23237160)
* Apply suggestion from @pajowu
Co-authored-by: pajowu <engelhardt@pretix.eu >
* Fix style issue
---------
Co-authored-by: pajowu <engelhardt@pretix.eu >
2026-06-22 09:49:27 +02:00
Raphael Michel and GitHub
5db1a5b8af
Rename confusingly named helpers for URL generation ( #6280 )
...
* Rename confusingly named helpers for URL generation
* new name
* fix old call
* Revert "new name"
This reverts commit a6e9a488b6 .
* New name
2026-06-22 09:11:55 +02:00
Nikita Mitasov and Raphael Michel
86a51afe9e
Translations: Update Russian
...
Currently translated at 19.0% (1199 of 6302 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/ru/
powered by weblate
2026-06-22 09:11:47 +02:00
Nikolai and Raphael Michel
ea9c85a1b4
Translations: Update Danish
...
Currently translated at 62.5% (3945 of 6302 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/da/
powered by weblate
2026-06-22 09:11:47 +02:00
Nikita Mitasov and Raphael Michel
226ff9b044
Translations: Update Russian
...
Currently translated at 18.7% (1183 of 6302 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/ru/
powered by weblate
2026-06-22 09:11:47 +02:00
Szurofka Márton and Raphael Michel
d8991d8138
Translations: Update Hungarian
...
Currently translated at 64.6% (119 of 184 strings)
Translation: pretix/pretix (JavaScript parts)
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix-js/hu/
powered by weblate
2026-06-22 09:11:47 +02:00
Nikita Mitasov and Raphael Michel
83642ec9f3
Translations: Update Russian
...
Currently translated at 18.6% (1174 of 6302 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/ru/
powered by weblate
2026-06-22 09:11:47 +02:00
9f0ce28ce4
Bump vite from 8.0.12 to 8.0.16 ( #6294 )
...
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite ) from 8.0.12 to 8.0.16.
- [Release notes](https://github.com/vitejs/vite/releases )
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md )
- [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite )
---
updated-dependencies:
- dependency-name: vite
dependency-version: 8.0.16
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 08:57:41 +02:00
28722fecbd
Update cryptography requirement from >=48.0.1 to >=49.0.0 ( #6289 )
...
Updates the requirements on [cryptography](https://github.com/pyca/cryptography ) to permit the latest version.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/48.0.1...49.0.0 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 49.0.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 08:57:33 +02:00
10a5d4ac68
Update pytest requirement from ==9.0.* to ==9.1.* ( #6290 )
...
Updates the requirements on [pytest](https://github.com/pytest-dev/pytest ) to permit the latest version.
- [Release notes](https://github.com/pytest-dev/pytest/releases )
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pytest-dev/pytest/compare/9.0.0...9.1.0 )
---
updated-dependencies:
- dependency-name: pytest
dependency-version: 9.1.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 08:57:10 +02:00
ba36f6d2ce
Update webauthn requirement from ==2.7.* to ==2.8.* ( #6293 )
...
Updates the requirements on [webauthn](https://github.com/duo-labs/py_webauthn ) to permit the latest version.
- [Release notes](https://github.com/duo-labs/py_webauthn/releases )
- [Changelog](https://github.com/duo-labs/py_webauthn/blob/master/CHANGELOG.md )
- [Commits](https://github.com/duo-labs/py_webauthn/compare/v2.7.0...v2.8.0 )
---
updated-dependencies:
- dependency-name: webauthn
dependency-version: 2.8.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 08:56:57 +02:00
1e301da26c
Update django-countries requirement from ==8.2.* to ==9.0.* ( #6269 )
...
Updates the requirements on [django-countries](https://github.com/SmileyChris/django-countries ) to permit the latest version.
- [Changelog](https://github.com/SmileyChris/django-countries/blob/main/CHANGES.md )
- [Commits](https://github.com/SmileyChris/django-countries/compare/v8.2.0...v9.0.0 )
---
updated-dependencies:
- dependency-name: django-countries
dependency-version: 9.0.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 08:56:41 +02:00
luelista and GitHub
d0307b9936
Use OrderPosition.all instead of .objects in metrics ( #6285 )
2026-06-21 12:46:07 +02:00
Martin Gross
c083ce904a
Checkin API: Provide 'reason' for RequiredMediaExchangeError (PRETIXEU-DHW)
2026-06-19 12:41:32 +02:00
694b915d89
include errors.js by default and make it coop with async_task_replace_page (Z#23236752) ( #6284 )
...
* load errors.js as standard and make it coop with async_task_replace_page
* scope down event
* Update src/pretix/static/pretixbase/js/asynctask.js
Co-authored-by: pajowu <engelhardt@pretix.eu >
* drop the jquery dependency for error.js
Co-authored-by: pajowu <pajowu@pajowu.de >
* include errors.js in error.html
* include errors.js in control base.html
* Update src/pretix/static/pretixbase/js/asynctask.js
Co-authored-by: Richard Schreiber <schreiber@pretix.eu >
* put errors.js in an IIFE call
---------
Co-authored-by: pajowu <engelhardt@pretix.eu >
Co-authored-by: pajowu <pajowu@pajowu.de >
Co-authored-by: Richard Schreiber <schreiber@pretix.eu >
2026-06-16 15:18:19 +02:00
Raphael Michel and GitHub
ea928ea7d4
Widget: Fix handling of HTTP-429 errors
2026-06-16 09:11:33 +02:00
Richard Schreiber and GitHub
36d49fbd77
Question detail: Fix crash in filter
2026-06-15 08:00:55 +02:00
Raphael Michel and pajowu
f0cb451c34
LocaleMiddleware: Correctly reset region for backend views
2026-06-12 15:30:06 +02:00
2c7fcd0599
Accounting report: Correctly split subevents with same label (Z#23237301) ( #6275 )
...
* Accounting report: Correctly split subevents with same label (Z#23237301)
* Accountingreport: Fix crash for single events
---------
Co-authored-by: Kara Engelhardt <engelhardt@pretix.eu >
2026-06-12 14:36:10 +02:00
Raphael Michel
034722fa39
Skip e2e tests on gitlab for now
2026-06-12 14:07:42 +02:00
dependabot[bot] and Raphael Michel
5a6870fce1
Update cryptography requirement from >=48.0.0 to >=48.0.1
...
Updates the requirements on [cryptography](https://github.com/pyca/cryptography ) to permit the latest version.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/pyca/cryptography/compare/48.0.0...48.0.1 )
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 48.0.1
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-12 08:23:03 +02:00
Mira and Raphael Michel
de28425993
Translations: Update German (informal) (de_Informal)
...
Currently translated at 100.0% (6302 of 6302 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/de_Informal/
powered by weblate
2026-06-11 18:59:48 +02:00
Mira and Raphael Michel
f3eb0d2dba
Translations: Update German
...
Currently translated at 100.0% (6302 of 6302 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/de/
powered by weblate
2026-06-11 18:59:48 +02:00
Sébastien BRUNEAU and Raphael Michel
0630e05d50
Translations: Update French
...
Currently translated at 100.0% (6302 of 6302 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/fr/
powered by weblate
2026-06-11 18:59:48 +02:00
f868507670
Update beautifulsoup4 requirement from ==4.14.* to ==4.15.* ( #6257 )
...
Updates the requirements on [beautifulsoup4](https://www.crummy.com/software/BeautifulSoup/bs4/ ) to permit the latest version.
---
updated-dependencies:
- dependency-name: beautifulsoup4
dependency-version: 4.15.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 16:29:49 +02:00
04032078c1
Update sentry-sdk requirement from ==2.61.* to ==2.62.* ( #6256 )
...
Updates the requirements on [sentry-sdk](https://github.com/getsentry/sentry-python ) to permit the latest version.
- [Release notes](https://github.com/getsentry/sentry-python/releases )
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md )
- [Commits](https://github.com/getsentry/sentry-python/compare/2.61.0...2.62.0 )
---
updated-dependencies:
- dependency-name: sentry-sdk
dependency-version: 2.62.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 16:29:40 +02:00
Martin Weinelt and GitHub
8af2714a04
Prune wheel and setuptools-rust from build-system ( #6268 )
...
For wheel the setuptools documentation notes:
> Historically this documentation has unnecessarily listed wheel in
> the requires list, and many projects still do that. This is not
> recommended, as the backend no longer requires the wheel package,
> and listing it explicitly causes it to be unnecessarily required for
> source distribution builds.
https://setuptools.pypa.io/en/latest/userguide/quickstart.html#basic-use
For setuptools-rust I could not find any Rust extension that need to be
built. The introduction goes back to c132ccd14 , where css-inline, a rust
component, was added as a dependency.
2026-06-11 16:29:32 +02:00
luelista and GitHub
c4b9cc4143
Allow search by partial giftcard secret with organizer.giftcards:read ( #6263 )
2026-06-11 16:26:05 +02:00
8c132d8342
Teams: Add a note to the degree of isolation between permissions ( #6258 )
...
* Teams: Add a note to the degree of isolation between permissions
* Update src/pretix/control/templates/pretixcontrol/organizers/team_edit.html
Co-authored-by: pajowu <engelhardt@pretix.eu >
---------
Co-authored-by: pajowu <engelhardt@pretix.eu >
2026-06-11 16:25:58 +02:00
pajowu and GitHub
8e63fafc62
Devex: Fix vite devserver capturing stdin ( #6267 )
...
Pass DEVNULL as stdin to vite, otherwise the vite devserver captures parts of stdin, making things like pasting during debugging impossible
2026-06-11 16:25:48 +02:00
luelista and GitHub
63ebe16fd3
Fix count in order bulk delete success message ( #6270 )
2026-06-11 16:25:38 +02:00
775fdd1ccb
Check-in API: Add reusable media exchange ( #6115 )
...
* Add Reusable Media Exchange to Checkin API
* isort
* Remove debugging leftover
* Apply suggestions from code review
Co-authored-by: robbi5 <maxi@richt.name >
* Add media_exchange_supported to CheckinRPCRedeemInputSerializer
* SecurityProfiles: Add api-v1:reusablemedia-lookup and -detail for SCAN
* Simplify media exchange checks
* Apply suggestions from code review
Co-authored-by: Raphael Michel <mail@raphaelmichel.de >
* Wording: re-usable --> reusable
* Deny checkins if media-exchange is required but device does not support it.
* Remove media_exchange_supported-Flag: Checkin will always be denied if media needs to be exchanged; apps will fall back to explanation text
* CheckinRPC: Also perform media exchange
* Use media_policy from item, not as a checkinrpc parameter
* my own review notes
* Fixes, cleanup, rebase
* block expired media
* Fix query
* add logging
* Refactor link_action into media policy, gift card support
* Block illegal policy-type combination
* Drop add_to_reusable_medium, decide all by policy
* Fix test failure
* fix test on postgres
* Expose reusable_media_usage_enforced to devies
* Explicitly set update view
---------
Co-authored-by: robbi5 <maxi@richt.name >
Co-authored-by: Maximilian Richt <richt@pretix.eu >
Co-authored-by: Raphael Michel <mail@raphaelmichel.de >
Co-authored-by: Raphael Michel <michel@rami.io >
Co-authored-by: Raphael Michel <michel@pretix.eu >
2026-06-11 16:25:13 +02:00
luelista and GitHub
784577d86f
Fix markup of error template ( #6265 )
2026-06-10 14:16:46 +02:00
Richard Schreiber and GitHub
07d27e66d1
Use HTTP-REFERER as fallback for vite_origins ( #6246 )
2026-06-09 13:24:46 +02:00
Richard Schreiber and GitHub
b404316dfd
[SECURITY] Reusable media export: Respect giftcard permissions (CVE-2026-11764) ( #6261 )
2026-06-09 13:20:48 +02:00
luelista and GitHub
edf97a13cd
Don't show warning if inactive products are used in checkin-rules (Z#23236197) ( #6242 )
2026-06-09 12:48:03 +02:00
c384bc2e7a
Update bleach requirement from ==6.3.* to ==6.4.* ( #6249 )
...
Updates the requirements on [bleach](https://github.com/mozilla/bleach ) to permit the latest version.
- [Changelog](https://github.com/mozilla/bleach/blob/main/CHANGES )
- [Commits](https://github.com/mozilla/bleach/compare/v6.3.0...v6.4.0 )
---
updated-dependencies:
- dependency-name: bleach
dependency-version: 6.4.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-08 17:33:50 +02:00
Raphael Michel and GitHub
f16034d0cc
Check-in: Fix handling of optional file questions (Z#23236493) ( #6251 )
2026-06-08 14:25:50 +02:00
Raphael Michel
93469d33e5
SubEvent details: Fix incorrect signal usage
2026-06-05 11:42:45 +02:00
329b118810
Update aiohttp requirement from ==3.13.* to ==3.14.* ( #6245 )
...
---
updated-dependencies:
- dependency-name: aiohttp
dependency-version: 3.14.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-04 15:19:47 +02:00