mirror of
https://github.com/pretix/pretix.git
synced 2026-08-08 10:27:49 +00:00
Compare commits
3
Commits
stable
...
escapesignals
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3badcfcccb | ||
|
|
a61609a89d | ||
|
|
8ec1b83d25 |
@@ -1403,15 +1403,12 @@ class Event(EventMixin, LoggedModel):
|
|||||||
|
|
||||||
for mp in self.organizer.meta_properties.all():
|
for mp in self.organizer.meta_properties.all():
|
||||||
if mp.required and not self.meta_data.get(mp.name):
|
if mp.required and not self.meta_data.get(mp.name):
|
||||||
issues.append(
|
issues.append(format_html(
|
||||||
('<a {a_attr}>' + gettext('You need to fill the meta parameter "{property}".') + '</a>').format(
|
'<a href="{href}{href_hash}">{text}</a>',
|
||||||
property=mp.name,
|
text=gettext('You need to fill the meta parameter "{property}".').format(property=mp.name),
|
||||||
a_attr='href="%s#id_prop-%d-value"' % (
|
href=reverse('control:event.settings', kwargs={'organizer': self.organizer.slug, 'event': self.slug}),
|
||||||
reverse('control:event.settings', kwargs={'organizer': self.organizer.slug, 'event': self.slug}),
|
href_hash=f'#id_prop-{mp.pk}-value',
|
||||||
mp.pk
|
))
|
||||||
)
|
|
||||||
)
|
|
||||||
)
|
|
||||||
|
|
||||||
responses = event_live_issues.send(self)
|
responses = event_live_issues.send(self)
|
||||||
for receiver, response in sorted(responses, key=lambda r: str(r[0])):
|
for receiver, response in sorted(responses, key=lambda r: str(r[0])):
|
||||||
|
|||||||
@@ -535,8 +535,9 @@ EventPluginRegistry = PluginAwareRegistry # for backwards compatibility
|
|||||||
event_live_issues = EventPluginSignal()
|
event_live_issues = EventPluginSignal()
|
||||||
"""
|
"""
|
||||||
This signal is sent out to determine whether an event can be taken live. If you want to
|
This signal is sent out to determine whether an event can be taken live. If you want to
|
||||||
prevent the event from going live, return a string that will be displayed to the user
|
prevent the event from going live, return an error message to display to the user (either
|
||||||
as the error message. If you don't, your receiver should return ``None``.
|
as a SafeString containing HTML, or a string that will be HTML-escaped). If you don't,
|
||||||
|
your receiver should return ``None``.
|
||||||
|
|
||||||
As with all event-plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event-plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
"""
|
"""
|
||||||
|
|||||||
@@ -22,6 +22,7 @@
|
|||||||
import importlib
|
import importlib
|
||||||
|
|
||||||
from django import template
|
from django import template
|
||||||
|
from django.utils.html import conditional_escape
|
||||||
from django.utils.safestring import mark_safe
|
from django.utils.safestring import mark_safe
|
||||||
|
|
||||||
from pretix.base.models import Event
|
from pretix.base.models import Event
|
||||||
@@ -44,7 +45,7 @@ def eventsignal(event: Event, signame: str, **kwargs):
|
|||||||
_html = []
|
_html = []
|
||||||
for receiver, response in signal.send(event, **kwargs):
|
for receiver, response in signal.send(event, **kwargs):
|
||||||
if response:
|
if response:
|
||||||
_html.append(response)
|
_html.append(conditional_escape(response))
|
||||||
return mark_safe("".join(_html))
|
return mark_safe("".join(_html))
|
||||||
|
|
||||||
|
|
||||||
@@ -63,5 +64,5 @@ def signal(signame: str, request, **kwargs):
|
|||||||
_html = []
|
_html = []
|
||||||
for receiver, response in signal.send(request, **kwargs):
|
for receiver, response in signal.send(request, **kwargs):
|
||||||
if response:
|
if response:
|
||||||
_html.append(response)
|
_html.append(conditional_escape(response))
|
||||||
return mark_safe("".join(_html))
|
return mark_safe("".join(_html))
|
||||||
|
|||||||
@@ -39,7 +39,8 @@ from pretix.base.signals import (
|
|||||||
html_page_start = GlobalSignal()
|
html_page_start = GlobalSignal()
|
||||||
"""
|
"""
|
||||||
This signal allows you to put code in the beginning of the main page for every
|
This signal allows you to put code in the beginning of the main page for every
|
||||||
page in the backend. You are expected to return HTML.
|
page in the backend. You are expected to return a SafeString containing HTML, or
|
||||||
|
a string that will be HTML-escaped.
|
||||||
|
|
||||||
The ``sender`` keyword argument will contain the request.
|
The ``sender`` keyword argument will contain the request.
|
||||||
"""
|
"""
|
||||||
@@ -129,7 +130,7 @@ event_dashboard_top = EventPluginSignal()
|
|||||||
Arguments: 'request'
|
Arguments: 'request'
|
||||||
|
|
||||||
This signal is sent out to include custom HTML in the top part of the the event dashboard.
|
This signal is sent out to include custom HTML in the top part of the the event dashboard.
|
||||||
Receivers should return HTML.
|
Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
An additional keyword argument ``subevent`` *can* contain a sub-event.
|
An additional keyword argument ``subevent`` *can* contain a sub-event.
|
||||||
@@ -172,6 +173,7 @@ Arguments: 'form'
|
|||||||
|
|
||||||
This signal allows you to add additional HTML to the form that is used for modifying vouchers.
|
This signal allows you to add additional HTML to the form that is used for modifying vouchers.
|
||||||
You receive the form object in the ``form`` keyword argument.
|
You receive the form object in the ``form`` keyword argument.
|
||||||
|
Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
"""
|
"""
|
||||||
@@ -209,6 +211,7 @@ Arguments: 'quota'
|
|||||||
|
|
||||||
This signal allows you to append HTML to a Quota's detail view. You receive the
|
This signal allows you to append HTML to a Quota's detail view. You receive the
|
||||||
quota as argument in the ``quota`` keyword argument.
|
quota as argument in the ``quota`` keyword argument.
|
||||||
|
Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
"""
|
"""
|
||||||
@@ -219,6 +222,7 @@ Arguments: 'subevent'
|
|||||||
|
|
||||||
This signal allows you to append HTML to a SubEvent's detail view. You receive the
|
This signal allows you to append HTML to a SubEvent's detail view. You receive the
|
||||||
subevent as argument in the ``subevent`` keyword argument.
|
subevent as argument in the ``subevent`` keyword argument.
|
||||||
|
Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
"""
|
"""
|
||||||
@@ -265,7 +269,8 @@ order_info = EventPluginSignal()
|
|||||||
"""
|
"""
|
||||||
Arguments: ``order``, ``request``
|
Arguments: ``order``, ``request``
|
||||||
|
|
||||||
This signal is sent out to display additional information on the order detail page
|
This signal is sent out to display additional information on the order detail page.
|
||||||
|
Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
Additionally, the argument ``order`` and ``request`` are available.
|
Additionally, the argument ``order`` and ``request`` are available.
|
||||||
@@ -275,7 +280,8 @@ order_approve_info = EventPluginSignal()
|
|||||||
"""
|
"""
|
||||||
Arguments: ``order``, ``request``
|
Arguments: ``order``, ``request``
|
||||||
|
|
||||||
This signal is sent out to display additional information on the order approve page
|
This signal is sent out to display additional information on the order approve page.
|
||||||
|
Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
Additionally, the argument ``order`` and ``request`` are available.
|
Additionally, the argument ``order`` and ``request`` are available.
|
||||||
@@ -286,6 +292,7 @@ order_position_buttons = EventPluginSignal()
|
|||||||
Arguments: ``order``, ``position``, ``request``
|
Arguments: ``order``, ``position``, ``request``
|
||||||
|
|
||||||
This signal is sent out to display additional buttons for a single position of an order.
|
This signal is sent out to display additional buttons for a single position of an order.
|
||||||
|
Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
Additionally, the argument ``order`` and ``request`` are available.
|
Additionally, the argument ``order`` and ``request`` are available.
|
||||||
@@ -315,6 +322,7 @@ Arguments: 'request'
|
|||||||
|
|
||||||
This signal is sent out to include template snippets on the settings page of an event
|
This signal is sent out to include template snippets on the settings page of an event
|
||||||
that allows generating a pretix Widget code.
|
that allows generating a pretix Widget code.
|
||||||
|
Receivers should return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
A second keyword argument ``request`` will contain the request object.
|
A second keyword argument ``request`` will contain the request object.
|
||||||
|
|||||||
@@ -19,7 +19,7 @@
|
|||||||
</p>
|
</p>
|
||||||
<ul>
|
<ul>
|
||||||
{% for issue in issues %}
|
{% for issue in issues %}
|
||||||
<li>{{ issue|safe }}</li>
|
<li>{{ issue }}</li>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
</ul>
|
</ul>
|
||||||
</div>
|
</div>
|
||||||
@@ -42,7 +42,7 @@
|
|||||||
</p>
|
</p>
|
||||||
<ul>
|
<ul>
|
||||||
{% for issue in issues %}
|
{% for issue in issues %}
|
||||||
<li>{{ issue|safe }}</li>
|
<li>{{ issue }}</li>
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
</ul>
|
</ul>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -161,7 +161,8 @@ voucher_redeem_info = EventPluginSignal()
|
|||||||
"""
|
"""
|
||||||
Arguments: ``voucher``
|
Arguments: ``voucher``
|
||||||
|
|
||||||
This signal is sent out to display additional information on the "redeem a voucher" page
|
This signal is sent out to display additional information on the "redeem a voucher" page.
|
||||||
|
You are expected to return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
"""
|
"""
|
||||||
@@ -194,6 +195,7 @@ Arguments: ``request``
|
|||||||
|
|
||||||
This signals allows you to add HTML content to the confirmation page that is presented at the
|
This signals allows you to add HTML content to the confirmation page that is presented at the
|
||||||
end of the checkout process, just before the order is being created.
|
end of the checkout process, just before the order is being created.
|
||||||
|
You are expected to return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event. A ``request``
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event. A ``request``
|
||||||
argument will contain the request object.
|
argument will contain the request object.
|
||||||
@@ -276,7 +278,8 @@ order_info = EventPluginSignal()
|
|||||||
"""
|
"""
|
||||||
Arguments: ``order``, ``request``
|
Arguments: ``order``, ``request``
|
||||||
|
|
||||||
This signal is sent out to display additional information on the order detail page
|
This signal is sent out to display additional information on the order detail page.
|
||||||
|
Return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
"""
|
"""
|
||||||
@@ -285,7 +288,8 @@ position_info = EventPluginSignal()
|
|||||||
"""
|
"""
|
||||||
Arguments: ``order``, ``position``, ``request``
|
Arguments: ``order``, ``position``, ``request``
|
||||||
|
|
||||||
This signal is sent out to display additional information on the position detail page
|
This signal is sent out to display additional information on the position detail page.
|
||||||
|
Return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
"""
|
"""
|
||||||
@@ -294,7 +298,8 @@ order_info_top = EventPluginSignal()
|
|||||||
"""
|
"""
|
||||||
Arguments: ``order``, ``request``
|
Arguments: ``order``, ``request``
|
||||||
|
|
||||||
This signal is sent out to display additional information on top of the order detail page
|
This signal is sent out to display additional information on top of the order detail page.
|
||||||
|
Return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
"""
|
"""
|
||||||
@@ -303,7 +308,8 @@ position_info_top = EventPluginSignal()
|
|||||||
"""
|
"""
|
||||||
Arguments: ``order``, ``position``, ``request``
|
Arguments: ``order``, ``position``, ``request``
|
||||||
|
|
||||||
This signal is sent out to display additional information on top of the position detail page
|
This signal is sent out to display additional information on top of the position detail page.
|
||||||
|
Return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event.
|
||||||
"""
|
"""
|
||||||
@@ -349,7 +355,7 @@ This signal is sent out to display additional information on the frontpage above
|
|||||||
of products and but below a custom frontpage text.
|
of products and but below a custom frontpage text.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event. The
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event. The
|
||||||
receivers are expected to return HTML.
|
receivers are expected to return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
render_seating_plan = EventPluginSignal()
|
render_seating_plan = EventPluginSignal()
|
||||||
@@ -361,7 +367,7 @@ You will be passed the ``request`` as a keyword argument. If applicable, a ``sub
|
|||||||
``voucher`` argument might be given.
|
``voucher`` argument might be given.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event. The
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event. The
|
||||||
receivers are expected to return HTML.
|
receivers are expected to return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
front_page_bottom = EventPluginSignal()
|
front_page_bottom = EventPluginSignal()
|
||||||
@@ -372,7 +378,7 @@ This signal is sent out to display additional information on the frontpage below
|
|||||||
of products.
|
of products.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event. The
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event. The
|
||||||
receivers are expected to return HTML.
|
receivers are expected to return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
front_page_bottom_widget = EventPluginSignal()
|
front_page_bottom_widget = EventPluginSignal()
|
||||||
@@ -383,7 +389,7 @@ This signal is sent out to display additional information on the frontpage below
|
|||||||
of products if the front page is shown in the widget.
|
of products if the front page is shown in the widget.
|
||||||
|
|
||||||
As with all event plugin signals, the ``sender`` keyword argument will contain the event. The
|
As with all event plugin signals, the ``sender`` keyword argument will contain the event. The
|
||||||
receivers are expected to return HTML.
|
receivers are expected to return a SafeString containing HTML, or a string that will be HTML-escaped.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
checkout_all_optional = EventPluginSignal()
|
checkout_all_optional = EventPluginSignal()
|
||||||
@@ -403,7 +409,7 @@ Arguments: ``item``, ``variation``, ``subevent``
|
|||||||
|
|
||||||
This signal is sent out when the description of an item or variation is rendered and allows you to append
|
This signal is sent out when the description of an item or variation is rendered and allows you to append
|
||||||
additional text to the description. You are passed the ``item``, ``variation`` and ``subevent``. You are
|
additional text to the description. You are passed the ``item``, ``variation`` and ``subevent``. You are
|
||||||
expected to return HTML.
|
expected to return markdown.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
register_cookie_providers = EventPluginSignal()
|
register_cookie_providers = EventPluginSignal()
|
||||||
|
|||||||
Reference in New Issue
Block a user