Richard Schreiber
de9bea2f36
Do not add border to disabled btn-link
2026-09-30 09:14:59 +02:00
Richard Schreiber
5ba4655aac
Add border to and increase text-contrast on disabled button
2026-09-30 08:33:16 +02:00
Raphael Michel
d339e1d594
Hotfix: Perform validation on the selected step, not on all steps before
2026-09-29 20:11:51 +02:00
Raphael Michel
cb15559ac6
Scheduled export: Fix copying of email subject and text (Z#23221224) ( #6616 )
2026-09-29 16:44:42 +02:00
pajowu
3c95f1fee7
Add HERMA 9012 90 x 90mm Badge format (Z#23248189) ( #6619 )
2026-09-29 16:44:02 +02:00
Richard Schreiber
6a380c9356
Presale: add js-helper to disable submit for x seconds ( #6592 )
...
* Presale: add js-helper to disable submit for x seconds
* Remove disabled-class from button, if any
* Use Intl.RelativeTimeFormat for time formatting
2026-09-29 16:36:09 +02:00
Kara Engelhardt
eeea01b31a
Fix linter errors
2026-09-29 15:34:26 +02:00
Kara Engelhardt
470621b5cb
Add missing licenseheader
2026-09-29 15:34:23 +02:00
dependabot[bot]
5802153101
Update sentry-sdk requirement from ==2.69.* to ==2.70.* ( #6600 )
...
Updates the requirements on [sentry-sdk](https://github.com/getsentry/sentry-python ) to permit the latest version.
- [Release notes](https://github.com/getsentry/sentry-python/releases )
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md )
- [Commits](https://github.com/getsentry/sentry-python/compare/2.69.0...2.70.0 )
---
updated-dependencies:
- dependency-name: sentry-sdk
dependency-version: 2.70.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-29 15:33:24 +02:00
Nate Horst
e9f89d5d92
Translations: Update Thai
...
Currently translated at 70.0% (4494 of 6419 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/th/
powered by weblate
2026-09-29 15:33:15 +02:00
Nate Horst
695689ed06
Translations: Update Thai
...
Currently translated at 98.8% (257 of 260 strings)
Translation: pretix/pretix (JavaScript parts)
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix-js/th/
powered by weblate
2026-09-29 15:33:15 +02:00
Nate Horst
12d405d861
Translations: Update Thai
...
Currently translated at 69.5% (4463 of 6419 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/th/
powered by weblate
2026-09-29 15:33:15 +02:00
Nate Horst
649eee3025
Translations: Update Thai
...
Currently translated at 65.8% (4230 of 6419 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/th/
powered by weblate
2026-09-29 15:33:15 +02:00
Tim
149b4f23aa
Translations: Update Spanish
...
Currently translated at 100.0% (6419 of 6419 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/es/
powered by weblate
2026-09-29 15:33:15 +02:00
Nate Horst
fa40ccc623
Translations: Update Thai
...
Currently translated at 55.9% (3593 of 6419 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/th/
powered by weblate
2026-09-29 15:33:15 +02:00
Mira Weller
2ba74b1697
Fix various redirects for events on MODE_ORG_ALT_DOMAIN
2026-09-29 14:34:49 +02:00
Mira Weller
e54cd6af44
Fix redirect to customer login page when:
...
- event on custom domain (MODE_EVENT_DOMAIN or MODE_ORG_ALT_DOMAIN)
- organizer on system domain
2026-09-29 14:34:49 +02:00
Mira Weller
d2b58d428e
Fix customer logout when:
...
- event on custom domain (MODE_EVENT_DOMAIN or MODE_ORG_ALT_DOMAIN)
- organizer on system domain
2026-09-29 14:34:49 +02:00
Raphael Michel
74332faa7b
[SECURITY] API: Fix session validation for uploaded files (CVE-2026-101269, Z#23247174)
2026-09-29 14:30:54 +02:00
Mira Weller
bbf391f7d5
Block out of bounds image crop dimensions (Z#23245937 / PRT-009)
2026-09-29 14:30:54 +02:00
Mira Weller
d78d5b52fa
Prevent parsing non-standard-compliant JSON float values (Z#23245937 / PRT-021)
2026-09-29 14:30:54 +02:00
Mira Weller
9c0fef3d72
Fix potential infinite loop in pdf render (Z#23245937 / PRT-021)
2026-09-29 14:30:54 +02:00
Mira Weller
c7d6630979
Fix inefficient loop in compute_validity (Z#23245937 / PRT-013)
2026-09-29 14:30:53 +02:00
Raphael Michel
4edd3c4654
[SECURITY] OAuth: Disable existing tokens when deactivating Application (CVE-2026-101271, Z#23247296)
2026-09-29 14:30:53 +02:00
Mira Weller
b1ae638394
[SECURITY] Escape help texts (CVE-2026-101270)
2026-09-29 14:30:53 +02:00
Raphael Michel
ae9bb68645
[SECURITY] Fix customer session fixation on cross-domain login (CVE-2026-101268, Z#23247268)
2026-09-29 14:30:53 +02:00
Raphael Michel
48f5a7c8cc
[SECURITY] Fix information leak in widgets.json on dashboard (CVE-2026-101267, Z#23247172)
...
Thanks to Wenhao Wu, Southeast University
2026-09-29 14:30:53 +02:00
Raphael Michel
d43032274b
[SECURITY] Fix checkout validation bypass (CVE-2026-101266, Z#23245008)
2026-09-29 14:30:53 +02:00
Raphael Michel
ae9a744fd9
Revert "Always base64-encode email attachments (Z#23242540) ( #6476 )"
...
This reverts commit ff4d3cd403 .
2026-09-29 14:07:57 +02:00
pajowu
ff4d3cd403
Always base64-encode email attachments (Z#23242540) ( #6476 )
...
It might sound unneccesary to base64-encode plaintext attachments, but some smtp providers modify them otherwise
2026-09-29 12:27:43 +02:00
pajowu
3440ee16f2
Plugin List: Apply search filter if prefilled by browser ( #6543 )
...
* Plugin List: Apply searchfilter if prefilled by browser
Browsers often prefill the form fields, e.g. with their old content when reloading or going back from the previous page. However these filters were not applied until you changed one of the form fields
* Fix linting errors in plugins.js
* Apply review suggestions
2026-09-29 11:51:29 +02:00
pajowu
43e5b62db3
Banktransfer: Make actionvie atomic (Z#23246414) ( #6604 )
2026-09-29 11:51:12 +02:00
dependabot[bot]
b249c7b417
Bump markdown from 3.10.3 to 3.11 ( #6608 )
...
Bumps [markdown](https://github.com/Python-Markdown/markdown ) from 3.10.3 to 3.11.
- [Release notes](https://github.com/Python-Markdown/markdown/releases )
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md )
- [Commits](https://github.com/Python-Markdown/markdown/compare/3.10.3...3.11.0 )
---
updated-dependencies:
- dependency-name: markdown
dependency-version: '3.11'
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-29 10:17:48 +02:00
dependabot[bot]
b68c324389
Update flake8 requirement from ==7.3.* to ==7.4.* ( #6609 )
...
Updates the requirements on [flake8](https://github.com/pycqa/flake8 ) to permit the latest version.
- [Commits](https://github.com/pycqa/flake8/compare/7.3.0...7.4.1 )
---
updated-dependencies:
- dependency-name: flake8
dependency-version: 7.4.1
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-29 10:17:29 +02:00
Aodhán Burke
4b320b6dab
Fix typo: then -> than ( #6615 )
2026-09-29 10:16:54 +02:00
Richard Schreiber
df74cbf5fc
Remove Vue2-based widget ( #6610 )
...
* Remove Vue2-based widget
* move floatformat.js
* Delete docready.js
* Update widget.py
2026-09-29 10:14:21 +02:00
pajowu
c875d758f9
Fix crash on too old time machine date (Z#23245824) ( #6599 )
...
* Fix crash on too old time machine date (Z#23245824)
dateutil.parser seems to reject dates with second-precision timezone-offsets, which datetime produces for some dates aroung the year 200. datetime.fromisoformat has no problem parsing them
* Review comments
* Add min date
2026-09-28 17:28:26 +02:00
Martin Gross
2ebdd048c2
PayPal2: Drop maximum length of client ID (Rel: #6424 )
2026-09-28 16:12:55 +02:00
Raphael Michel
ca40b09080
Fix API documentation bug
2026-09-28 15:46:41 +02:00
pajowu and Raphael Michel
558bf910fd
Use fragment_product_list in voucher redemption view (Z#23246929) ( #6567 )
...
* Use fragment_product_list in voucher redemption view (Z#23246929)
* Formatting
* Fix usage in templates
* Review comments
* handle form prefix in fragment_product_list.html
---------
Co-authored-by: Raphael Michel <michel@pretix.eu >
2026-09-28 13:01:15 +02:00
pajowu
7e1e472691
Monkeypatch stock csrfmiddleware ( #6401 )
...
* Monkeypatch stock csrfmiddleware
* Add test for ensure_csrf_cookie
2026-09-28 11:46:23 +02:00
Richard Schreiber
b06c9ef463
Control: do not fail on missing reason when user confirm ( #6602 )
2026-09-28 11:43:52 +02:00
pajowu
2af8d29ca9
Add pdf render tests ( #6566 )
...
* Add pdf tests
* pdf tests: Save temporary pdfs for failed test debugging
* Review comments
2026-09-25 16:54:58 +02:00
Raphael Michel
2791d5e49e
Celery: Fix missing log if workers are recycled due to RAM usage ( #6588 )
2026-09-25 08:56:49 +02:00
Richard Schreiber
ed68719731
Widget: fix calendar view showing old events due to non-unique key (Z#23247433) ( #6585 )
...
* Widget: fix calendar view showing old events due to cache-key (Z#23247433)
* Update EventCalendarCell.vue
2026-09-24 12:00:57 +02:00
9aeb4b9731
Organizer API: Add endpoint for event-meta-properties
...
* Add API-endpoint for event-meta-properties
* Add new doc-file to index, fix spelling and description
* Fix logentry
* Fix logentry again
* validate and add tests
* add meta_properties from organizer only
* fix choices validation
* filter unknown keys from choices due to django-formsets
* Apply batched suggestions from code review
Co-authored-by: Richard Schreiber <wiffbi@gmail.com >
* add safe-guard normalization to None to to_representation
* Apply batched suggestions from code review
Co-authored-by: Raphael Michel <mail@raphaelmichel.de >
* update tests to check for error-messages as well
* fix flake8
* fix permission tests
* Make ObjectListField more flexibel for re-use
* fix validation result
* Improve validation
* Change to I18nField for validation
* update MetaPropertyDictField
* fix docs for i18n strings
* make label_child configurable if MetaPropertyDictField should contain non-localized stuff
* undo test changes in events test
* fix flake8
* Apply batched suggestions from code review
Co-authored-by: Raphael Michel <mail@raphaelmichel.de >
* improve code formatting
---------
Co-authored-by: Richard Schreiber <schreiber@rami.io >
Co-authored-by: Richard Schreiber <schreiber@pretix.eu >
Co-authored-by: Richard Schreiber <wiffbi@gmail.com >
Co-authored-by: Raphael Michel <mail@raphaelmichel.de >
2026-09-24 10:51:23 +02:00
Minding
9324887790
Translate OAuth buttons ( #6590 )
...
* Translate OAuth buttons
* Revert .po changes
2026-09-24 09:52:47 +02:00
Nate Horst
d353384555
Translations: Update Thai
...
Currently translated at 53.0% (3407 of 6419 strings)
Translation: pretix/pretix
Translate-URL: https://translate.pretix.eu/projects/pretix/pretix/th/
powered by weblate
2026-09-24 09:16:49 +02:00
Raphael Michel
b8f8e49cce
API: Add additional tests for modifying meta data (Z#23247634)
2026-09-23 19:01:52 +02:00
Raphael Michel
806d0a5748
User details: Show list of 2FA devices and allow to reset drift ( #6569 )
...
* User details: Show list of 2FA devices
* Add reset button
* Reset throttle
* Refactoring
* Fix delete paths in tests
2026-09-23 17:51:10 +02:00