Commit Graph
1549 Commits
Author SHA1 Message Date
Oliver 1930db0234 Fix for recursive custom units (#12815) (#12820) 2026-09-08 12:05:04 +10:00
github-actions[bot]andOliver 181d86c651 [bug] Prevent editing of model-type for data import (#12809) (#12811)
(cherry picked from commit 5a7308763e)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-07 22:42:42 +10:00
github-actions[bot]andOliver ad8013dc23 [bug] Plugin fix (#12805) (#12806)
* [bug] Handle null plugin instance

* Add regression test

* Fix secondary instances of same bug

(cherry picked from commit 2566d332a8)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-07 17:12:37 +10:00
github-actions[bot]andOliver 778d44b89c Plugin load fix (#12776) (#12802)
* Robustify plugin file loading

* Lock static file copying

* Improve robustness of static file copying

* Add regression tests

* Handle database not being ready

* Fix identified limitation and refactor code

* Attempt to fix CI job

* instrumentation for CI - will revert

* Another bugfix attempt

(cherry picked from commit b4cb9a9746)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-07 10:49:32 +10:00
github-actions[bot]andOliver 4e0be4a65a Exception handling for data outputs (#12797) (#12800)
(cherry picked from commit 4a0e28510f)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-07 07:46:06 +10:00
github-actions[bot]andOliver b1b060915e Add error message for missing TLD (#12789) (#12796)
* Add error message for missing TLD

* add error code for missing TLD

(cherry picked from commit 321489a41b)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-06 17:03:12 +10:00
github-actions[bot]andOliver 5b97accbf3 Enhanced error message on CSRF failure (#12788) (#12794)
* Enhanced error message on CSRF failure

* Defer to 'detail' field if exists

(cherry picked from commit 9a416df5d4)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-06 13:04:57 +10:00
github-actions[bot]andOliver 1368b7db08 Refactor part pricing updates (#12787) (#12791)
* Refactor part pricing updates

- Handles cases where underlying part has been deleted

* Add regression tests

(cherry picked from commit fa44925b21)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-06 08:52:57 +10:00
Oliver c154bfabc3 BOM Validation Improvements (#12780) (#12786)
* Adjust get_bom_hash function:

- Optionally skip inclusion of part names
- Skip 'piece_count' if default value set

* Fall back to legacy comparison

* Add per-line-item check

* Add regression tests
2026-09-05 10:41:32 +10:00
github-actions[bot]andOliver 4a795ccddc Handle missing record in after_delete_supplier_part (#12772) (#12777)
(cherry picked from commit 8c1c16e59a)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-03 16:15:02 +10:00
github-actions[bot]andOliver 1c4cfd8a47 Metadata fix (#12771) (#12775)
* Fix security hole for metadata API

* Regression test for field injection

(cherry picked from commit 694d890ce5)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-03 11:59:59 +10:00
github-actions[bot]andOliver 2ddc615ca2 Permissions fix for Calendar views (#12764) (#12765)
(cherry picked from commit 1238daa783)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-02 16:00:42 +10:00
github-actions[bot]andOliver ec04fcb31e Tracing fix (#12728) (#12736)
* Bug fix for tracing setup

* Support forking against multiple PIDs

* Updated documentation

(cherry picked from commit fcbcef5aae)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-29 09:11:01 +10:00
github-actions[bot]andOliver 4446c9596f Fix race condition for take_stock method (#12718) (#12719)
(cherry picked from commit 2dca27f78b)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-27 16:06:12 +10:00
Oliver c0469d2530 Bump InvenTree software version to 1.5.3 (#12711) 2026-08-26 09:06:01 +10:00
github-actions[bot]andOliver c77ff7eba0 User permissions check for Attachment API (#12689) (#12691)
(cherry picked from commit 528bb085d7)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-23 23:02:08 +02:00
github-actions[bot]andOliver db404fe0f8 Strip potentially dangerous tags from SVG files (#12687) (#12690)
(cherry picked from commit f16fb36b08)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-23 23:01:51 +02:00
0ed2c2951e fix: trigger pricing recalculation when SupplierPart pack_quantity changes (#12421) (#12674)
* fix: trigger pricing recalculation when SupplierPart is saved or deleted

When a SupplierPart's pack_quantity is updated after price breaks have
already been created, the Part's pricing (and BOM cost rollups for any
assemblies using that part) was not recalculated. This is because there
was no post_save or post_delete signal handler for the SupplierPart model
to trigger schedule_pricing_update on the linked Part.

Added post_save and post_delete signal handlers for SupplierPart that
mirror the existing SupplierPriceBreak signal handlers. The pricing
cascade (via update_assemblies) ensures BOM line costs in parent
assemblies are also updated.

Fixes #12285

* style: fix ruff format issues

* style: apply ruff format with --preview flag (matching project config)

* fix: resolve PartPricing.DoesNotExist in pack_quantity test

The test captured self.part.pricing before any PartPricing row existed,
yielding an unsaved instance; the later refresh_from_db() then raised
DoesNotExist. Re-fetch self.part.pricing after the price break creates
the row, matching the pattern in test_supplier_part_pricing.

---------



(cherry picked from commit be9faff766)

Co-authored-by: amanjain57-gif <aman.jain57@gmail.com>
Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
Co-authored-by: Aman Jain <jainamn@amazon.com>
2026-08-21 15:25:01 +10:00
Oliver 4a490854c8 Bump InvenTree software version to 1.5.2 (#12660) 2026-08-20 00:23:35 +02:00
84052e1ac8 chore(deps): bump sqlparse from 0.5.5 to 0.6.0 in /src/backend (#12653) (#12659)
* chore(deps): bump sqlparse from 0.5.5 to 0.6.0 in /src/backend

Bumps [sqlparse](https://github.com/andialbrecht/sqlparse) from 0.5.5 to 0.6.0.
- [Changelog](https://github.com/andialbrecht/sqlparse/blob/master/CHANGELOG)
- [Commits](https://github.com/andialbrecht/sqlparse/compare/0.5.5...0.6.0)

---
updated-dependencies:
- dependency-name: sqlparse
  dependency-version: 0.6.0
  dependency-type: direct:production
...



* fix style

---------




(cherry picked from commit dc9a277478)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-19 13:18:52 +10:00
github-actions[bot]andOliver 0acfec3ef0 Improve error handling for unit registry (#12643) (#12645)
(cherry picked from commit af74f1abf6)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-16 12:41:38 +10:00
github-actions[bot]andOliver 6362f59fd5 [bug] Fix ReturnOrder event registration (#12633) (#12636)
(cherry picked from commit 695b9c1dc2)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-13 20:09:56 +10:00
github-actions[bot]andOliver 9af445268f [bug] OptionalField race condition (#12627) (#12629)
* [bug] OptionalField race condition

Fixes subtle bug where OptionalField entries can be  silenty dropped from an API request due to concurrent requests / race conditions

* Additional unit tests

* Additional guard in metadata.py

* include extra kwargs

* Adjust import/exporting options

* Fix attribute sharing across class instances

(cherry picked from commit 2b3283d5d2)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-12 19:46:36 +10:00
efb0b94c07 reset errors on update (#12550) (#12630)
* reset errors on update

* add empty line

---------


(cherry picked from commit f5c4bbc6a8)

Co-authored-by: ribsey <lukas.ribi@gmail.com>
Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-12 17:45:15 +10:00
github-actions[bot]andOliver be566f4e0f [bug] Handle duplicate email addresses for magic links (#12621) (#12622)
(cherry picked from commit 77d8470141)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-12 10:27:03 +10:00
ea146937c1 fix: support UUID notification references (#12616) (#12626)
* fix: support UUID notification references

* test: update notification uid expectation

---------


(cherry picked from commit 55a193e5d7)

Co-authored-by: FurinaDog <feixiang130214@outlook.com>
Co-authored-by: FurinaDog <FurinaDog@users.noreply.github.com>
2026-08-12 08:55:11 +10:00
Oliver 0a22512ae6 Bump InvenTree software version to 1.5.1 (#12620) 2026-08-11 22:58:17 +10:00
github-actions[bot] e09b4c65c5 New Crowdin translations by GitHub Action (#12535) (#12618)
(cherry picked from commit f054a487ef)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-11 21:08:11 +10:00
github-actions[bot]andOliver 7e206547a2 Fix for API exception_handler (#12604) (#12605)
- Only log unhandled exceptions to sentry.io
- Check for valid handling first
- Report second

(cherry picked from commit 1020ed3009)

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-11 08:54:48 +10:00
Oliver d9a5d96d8d Bump version number to 1.5.0 (#12602)
* Bump version number to 1.5.0

* Add release date
2026-08-10 21:57:43 +10:00
Matthias Mair 324b0ca012 feat(backend): add throtteling by default (#11951)
* feat(backend): add throtteling by default

* add changelog entry

* ignore throtetling in debug mode

* increase threshold
2026-08-10 18:41:15 +10:00
Oliver 1b20920e4a [security] Additional SSRF protections (#12595)
Tighten SSRF protections when fetching from external URLs
2026-08-10 18:32:49 +10:00
dependabot[bot]andMatthias Mair edae156439 chore(deps): bump pypdf from 6.14.2 to 6.15.0 in /src/backend (#12594)
* chore(deps): bump pypdf from 6.14.2 to 6.15.0 in /src/backend

Bumps [pypdf](https://github.com/py-pdf/pypdf) from 6.14.2 to 6.15.0.
- [Release notes](https://github.com/py-pdf/pypdf/releases)
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md)
- [Commits](https://github.com/py-pdf/pypdf/compare/6.14.2...6.15.0)

---
updated-dependencies:
- dependency-name: pypdf
  dependency-version: 6.15.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix style

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-10 16:13:05 +10:00
siddhartha28andSiddhartha Ravilla 76bce6a7b1 Fix Install Stock Items shows only selected parts (#12596)
* Bug Fix Install Stock Item showing variant stock when BOM disallows variants

* Add regression test for include_variants stock filter

---------

Co-authored-by: Siddhartha Ravilla <ravilla.si@northeastern.edu>
2026-08-09 17:57:18 +10:00
214f472ec9 Fix test result ordering by test timestamps (#12533)
* Fix test result ordering by test timestamps

* Refractor test result comparison helper

* Apply formatting fixes

* Fix frontend formatting

* Avoid mutating test result records

* Add migration for test result ordering

* Retry documentation build

---------

Co-authored-by: jayasree723 <confidentlehmann@tomorjerry.com>
Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-09 09:56:48 +10:00
Oliver afcc89ecfb Data import fix (#12568)
* Specify JSON encoder for data import fields

- Fixes encoding issues when importing from XLSX file

* Add regression test

* Fix faulty error handler

* Fix for unit test
2026-08-09 08:19:19 +10:00
Oliver 901dc024c0 [bug] Fix for plugin fetching (#12590)
- Prevent operation on stale plugin
2026-08-09 08:19:01 +10:00
Oliver 61fe3c9ce5 [bug] Fix PartStocktakeSerializer (#12587)
Closes https://github.com/inventree/InvenTree/issues/12555
2026-08-09 07:26:37 +10:00
OliverandMatthias Mair 94024ad23e [bug] Validate location when completing build outputs (#12570)
* [bug] Validate location when completing build outputs

- Cannot be structural

* Fix unit test

---------

Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-08 23:27:53 +10:00
Oliver c0ed42549f [API] Restrict barcode scan history (#12569)
- A non-staff user can only view their own results
2026-08-08 21:56:47 +10:00
Oliver 28fea388f6 [bug] Handle deleted Part (#12578) 2026-08-08 21:56:25 +10:00
Oliver 6cdc21c308 [sentry] Do not report MethodNotAllowed (#12584) 2026-08-08 20:51:21 +10:00
Oliver 21819ebc78 Fix flaky test on sqlite (#12582) 2026-08-08 20:27:50 +10:00
Oliver 5c798f4237 [bug] Fix part duplicate checks (#12574)
* [bug] Fix part duplicate checks

* Additional unit tests
2026-08-08 19:11:46 +10:00
Oliver cf2f64c83a [bug] Fix getLogoImage helper (#12577)
* [bug] Fix getLogoImage helper

- Do not return a file:// URI

* cleanup code
2026-08-08 19:11:32 +10:00
Oliver f1e6ec249d [bug] Fix post-delete actions (#12575)
- Check that underlying part is still available
2026-08-08 17:58:21 +10:00
Oliver 9b5c69da26 [bug] excel encoding for data import (#12576)
- Handle different encoding types for excel import
- Fail cleanly if cannot read file
2026-08-08 17:58:01 +10:00
Oliver fe82ff1f9e [refactor] Improve efficiency of check_missing_pricing (#12572) 2026-08-08 17:17:20 +10:00
Oliver 66b95cde5b [API] Handle AppRegistryNotReady (#12571)
Explicit handling for AppRegistryNotReady error
2026-08-08 16:11:30 +10:00
Oliver 358c464349 Barcode API bugs (#12565)
* Add explicit permission checks for barcode scanning

- Previous role_required attribute did not do anything

* Additional unit tests
2026-08-08 14:17:50 +10:00