Oliver
43bd525240
Tweak search ( #12778 )
...
- Prevent single character searches
- Abort previous search requests
2026-09-03 22:11:13 +10:00
Oliver
aadd27d217
Prevent delete operation on /api/user/me/ ( #12770 )
...
* Prevent delete operation on /api/user/me/
* Bump API version
2026-09-03 15:27:44 +10:00
Oliver
8c1c16e59a
Handle missing record in after_delete_supplier_part ( #12772 )
2026-09-03 13:57:19 +10:00
Matthias Mair and Oliver
fa52affe98
feat: warn about unsafe CORS ( #12773 )
...
* feat: warn about unsafe CORS
* extend docs
* fix defaults
* bump api version
---------
Co-authored-by: Oliver <oliver.henry.walters@gmail.com >
2026-09-03 13:09:17 +10:00
Matthias Mair
9f8dfda18b
chore: add types to templates; add AI agent catch ( #12747 )
...
* Update feature_request.yaml
* Update bug_report.yaml
* Update bug_report.yaml
* Update documentation.yaml
2026-09-03 10:32:17 +10:00
Oliver
694d890ce5
Metadata fix ( #12771 )
...
* Fix security hole for metadata API
* Regression test for field injection
2026-09-03 09:51:08 +10:00
Bhumin Paladiya
4b1ddcd2d0
Enhance search fields across InvenTree REST API endpoints ( #12723 )
...
* Enhance search fields across REST API endpoints
* Revert search_fields on SettingsList to key only for security
* Bump API version to 537 for REST API search fields
* Clean TokenListView search fields and revert common/api.py
2026-09-03 08:49:53 +10:00
Bhumin Paladiya
bb151dcb01
Fix order allocation variant validation logic and serializer read_only_fields ( #12738 )
...
* Fix order allocation variant validation logic and serializer defects
* Format order models and tests with ruff preview style
* Fix TransferOrder destination field in allocation unit tests
2026-09-03 08:47:21 +10:00
Oliver and Matthias Mair
4024075b3b
[bug] API permission fixes: ( #12766 )
...
- User can only change their own profile
- Users can only access notes against models they are scoped to
- Users can only access parameters against models they are scoped to
Co-authored-by: Matthias Mair <code@mjmair.com >
2026-09-03 08:26:38 +10:00
Oliver
f9f9f7499b
Fix permissions for SelectionList ( #12763 )
...
* Fix permissions for SelectionList
* Bump API version
2026-09-02 15:15:58 +10:00
Oliver
1238daa783
Permissions fix for Calendar views ( #12764 )
2026-09-02 14:47:34 +10:00
dependabot[bot]
b03d3b1ba0
chore(deps): bump python in /contrib/container ( #12752 )
...
Bumps python from `ce40764` to `cae66f2`.
---
updated-dependencies:
- dependency-name: python
dependency-version: 3.14.7-slim-trixie
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 09:35:52 +10:00
Matthias Mair
913dc7c48a
chore(backend): bump all backend deps ( #12754 )
...
* bump all backend deps
* fix new detections
2026-09-02 07:59:53 +10:00
Senior Data Engineer and Matthias Mair
ffcbbf6292
Clarify SSO setup via Database Admin interface ( #12474 )
...
* Clarify SSO setup via Database Admin interface
Fixes #10415 by documenting that Social applications are
configured in Django admin at /admin/, not via config.yaml or API.
* docs: move Database Admin access details to db_admin.md
Per review: drop the access-how-to from SSO.md and link to the Database Admin guide instead.
---------
Co-authored-by: Matthias Mair <code@mjmair.com >
2026-09-01 21:59:08 +10:00
github-actions[bot]
e1ff60a64c
New Crowdin translations by GitHub Action ( #12727 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-01 14:32:12 +10:00
Oliver
ed84d06dbe
[UI] Fixes for column resizing ( #12755 )
...
- Apply CSS fix
- Allow proper dragging
- Ensure table columns fill 100% width
2026-09-01 12:06:09 +10:00
Oliver
f8328cd1db
[UI] Fix useReceiveLineItems bug ( #12756 )
...
- Prevent negative pre-fill values
2026-09-01 12:06:01 +10:00
dependabot[bot]
8ae579124b
chore(deps): bump the dependencies group with 4 updates ( #12753 )
...
Bumps the dependencies group with 4 updates: [depot/setup-action](https://github.com/depot/setup-action ), [CodSpeedHQ/action](https://github.com/codspeedhq/action ), [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) and [crowdin/github-action](https://github.com/crowdin/github-action ).
Updates `depot/setup-action` from 1.7.1 to 1.7.2
- [Release notes](https://github.com/depot/setup-action/releases )
- [Commits](https://github.com/depot/setup-action/compare/15c09a5f77a0840ad4bce955686522a257853461...91bc8495a33ebfc504ffc89e5674379ccf23c29c )
Updates `CodSpeedHQ/action` from 5.0.3 to 5.2.1
- [Release notes](https://github.com/codspeedhq/action/releases )
- [Changelog](https://github.com/CodSpeedHQ/action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/codspeedhq/action/compare/4296e51e7041e24dadb86d1d6e8b9320d223dbe8...373d6868929f444bc08d901fd0eb0ad52a8875ea )
Updates `github/codeql-action/upload-sarif` from 4.37.7 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd...db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 )
Updates `crowdin/github-action` from 2.17.0 to 2.17.1
- [Release notes](https://github.com/crowdin/github-action/releases )
- [Commits](https://github.com/crowdin/github-action/compare/c7af9bc98b01694653031fef2a0dc6c7888ce9bc...8f01d54f70f1713ee3f09d82c2bbb2daeac28689 )
---
updated-dependencies:
- dependency-name: depot/setup-action
dependency-version: 1.7.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: CodSpeedHQ/action
dependency-version: 5.2.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.8
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: crowdin/github-action
dependency-version: 2.17.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-01 10:34:30 +10:00
Senior Data Engineer
fe489bd6b6
Document Docker Compose container health checks ( #12420 )
...
* Document Docker Compose container health checks
Add user documentation and CHANGELOG entry for the production
docker-compose health checks proposed in #12124 .
* docs: match health-check docs to merged docker-compose.yml
Reviewed against inventree/InvenTree#12124 : server uses invoke server-health, proxy probes Caddy :9090, worker uses invoke worker-health.
2026-08-31 21:04:14 +10:00
773ed4eb3a
(feature): docker health checks ( #12124 )
...
* Add Docker container health checks
* Use invoke tasks for Docker container health checks
Updates server and worker healthchecks to use invoke server-health
and invoke worker-health as requested in #12124 review.
Refs #12124
* Added HTTP host check to server health check
* Add health-check endpoint for Caddyfile
* Simplify health check for Caddy
* Remove test file
---------
Co-authored-by: Oliver <oliver.henry.walters@gmail.com >
Co-authored-by: DESKTOP-691E36A\Administrator <br198064@gmail.com >
Co-authored-by: Matthias Mair <code@mjmair.com >
2026-08-31 16:46:46 +10:00
Oliver and Matthias Mair
02da01dfec
[Refactor] Notes ( #11971 )
...
* Display note info
* Support user locale
* Add unit testing for HTML content
* Observe color mode
* Add link between Note and NotesImage
* Ensure image file is deleted when NotesImage is deleted
* Add support for image upload in editor
* Skeleton for data migration
* Updates
* Update data migration
- Find any NoteImage items which do not link to a model
- Try to associate them with an existing note
* Remove validator
* Updated API endpoints for NotesImage model
* Update server side sanitizing
* Specify max field length
* Remove old fields from NotesImage model
* Refactor clean_string
* Remove obsolete task
* Remove legacy "notes" field from older models
* Adjust search params when switching notes
* Remove NotesFieldMixin
* Change editor
* Resizable image support
* Support tables
* Add table style
* Adjust header actions
* Add data migration for SalesOrderShipment notes
* Adjust back-end sanitizing
* Adjust
* Use subtle editor variant
* Move undo/redo
* Enhance editing logic
* Add report tags for notes
* Add unit test for note image cleanup
* Render note to HTML
- Automatically replace images
* Fix migration order
* Adjust migration text
* Fix "dirty" trigger on notes
* Prevent navigate from dirty notes
* Add documentation
* Prevent image clicking if not in editing mode
* Update API
* Update migration files
* Fix migrations
* remove notes from test fixtures
* remove notes field that does not exsist anymore
* add missing ruleset
* fix assertation
* fix assertation
* Update docs/docs/concepts/notes.md
Co-authored-by: Matthias Mair <code@mjmair.com >
* Remove blocknote deps
* Move old helper functions
- Only used for this migration
- Will potentially be removed at some point in the future?
* Revert change
* Fix note image URL
* Fix migration conflicts
* Fix migrations
* Fix delete call
* Fix content mixin
* Fix note duplication
* Make save method atomic
* Fix double-save
* Add "template" field to Note model
* Adjust migrations
* Frontend updates
* Fix for NotesEditor
* Render Note instance in forms
* Fix button-within-button
* Fix migrations
* Fix missing import
* add docs
* docs for rendering notes in reports
* Restrict queryset based on user view permissions
* APi unit tests for note permissions
* Duplicate embedded images when copying notes
* Add unit test for note duplication
* Add CHANGELOG
* Add 'copy_note' option to duplicate serializer
* Add unit tests for data migrations
* implement note duplication serializers
* frontend UI elements
* Fix migration conflicts
* Use branch for playwrigh testing
* Implement duplicate action for stock item
* Fix import
* Updated playwright tests
* Bug fix for receiving stock items
* Add screenshot
* Fix api_version
* Update unit tests
* Fix docs
* Remove defunct tests
* Fix migration order
* Adjust import/export workflow
* Manual cleaning update
* Fix migrations
* Fix migration files
* Fix for note save
* Adjust save ordering
* Skip constraint checking in NoteSerializer
* Custom validate_constraints on Note model
* Revert "Skip constraint checking in NoteSerializer"
This reverts commit b42bc955c1 .
* Fix for note search
* Fix for receive_line_items
* Shim model renderer for NoteTemplate
* Fix playwright tests
* Adjust frontend CI
* Fix import/export CI job
* Fix for data migration test
* Fix migration test
* Adjust unit test
* Fix conflicting migration
* Fix unit test
* Run migration tests in parallel
* Robustify migration test
* Disable parallel options
* Fix conflicting migration
* Remove extraneous unit test
* Fix conflicting migrations
* Additional regression tests
* Check permissions before deleting Note instance
* Updated docs
* Validate note model type
* Prevent discard of unsaved changes in note editor
* Clean up dead code
* Fix migration conflict
* Improved data migration
* Prefetch role groups
* UI refactoring
* Refactor permission checking code
* Further code refactoring
* use DuplicateField helper
* Refactoring
* Add prefetch
* Throw exception rather than assert
* Logic fix for notes editor
* reimplement old background task
* Adjust data migration
* Fix notes field when receiving items
* Fix existing report templates
* Fix save action for notes editor
* Refactoring: Add "instance-info" API endpoint for common model properties
* Fix indicator dots
* Tweak nav alert msg
* Adjust layout of buttons
* Sanitize notes during migration
* Fix for NotesImage delete cascade
* Fix caching
* Fix race condition in notes editor
* Fix distinct issue when searching notse
* Fix race condition when saving new note instance
* Fix improper error
* Refactor StockItem duplication
* Refactoring
* Increase query time
* Fix api_version.py
* Additional migration tests
* Fix CI workflow
---------
Co-authored-by: Matthias Mair <code@mjmair.com >
2026-08-31 16:46:33 +10:00
Oliver
d39d0262e6
[CI] Adjust query time threshold ( #12748 )
...
Allow larger buffer for test variation
2026-08-31 11:07:46 +10:00
Matthias Mair
4066fa6e0a
feat(backend): add SCIM for user provisioning ( #12713 )
...
* Add SCIM
Closes https://github.com/inventree/InvenTree/issues/6339
* also test scim
* extend testing with conformance suite
* fix test suite results
* coverage completion
* fil test gaps
* add missing schema values
* fix more type issues
* fix error view
* remove route from OpenAPI
* add changelog entry
* add codeowners
2026-08-31 09:24:14 +10:00
Oliver
c821fa0f43
Notification fix ( #12744 )
...
* Fill out stock location based on part default
* [UI] Bug fix for notifications
- Closes https://github.com/inventree/InvenTree/issues/12706
2026-08-30 15:53:16 +10:00
Oliver
871147d936
Stock location fix ( #12742 )
...
* Fill out stock location based on part default
* Add playwright tests
2026-08-30 11:44:07 +10:00
Oliver and Copilot Autofix powered by AI
a205717171
SSO e2e testing ( #12739 )
...
* Extend SSO auth workflows
* SSO e2e testing workflow
* Remove orphaned code
* Add unit tests for SSO
* improved error messaging
* Add test for SSO registration disabled
* Fix gating on LOGIN_ENABLE_SSO
* Adjust UI state management
* Add playwright test for SSO disabled
* Add backend unit tests
* Adjust API version
* Additional playwright tests
* Retain desired page state on login failure
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
* Adjust test code
* Stricter matcher checking
---------
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
2026-08-30 10:32:54 +10:00
Bhumin Paladiya
69afe7723f
Enhance search and autocomplete fields across all InvenTree admin models ( #12722 )
...
* Fix PurchaseOrderExtraLine admin search and add search fields across admin classes
* Add search fields and autocomplete fields across common admin models
* Add search and autocomplete fields to importer admin models
* Add search fields to MachineConfigAdmin
* Add search fields to LocationTypeAdmin
* Remove search_fields from DataImportRowAdmin per review feedback
2026-08-29 20:24:49 +10:00
dependabot[bot] and Matthias Mair
02fc34083a
chore(deps): bump the dependencies group across 2 directories with 16 updates ( #12735 )
...
* chore(deps): bump the dependencies group across 2 directories with 16 updates
Bumps the dependencies group with 1 update in the /docs directory: [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin ).
Bumps the dependencies group with 15 updates in the /src/backend directory:
| Package | From | To |
| --- | --- | --- |
| [gunicorn](https://github.com/benoitc/gunicorn ) | `26.0.0` | `26.1.0` |
| [charset-normalizer](https://github.com/jawah/charset_normalizer ) | `3.5.0` | `3.5.1` |
| [idna](https://github.com/kjd/idna ) | `3.18` | `3.19` |
| [prek](https://github.com/j178/prek ) | `0.4.13` | `0.4.14` |
| [pygments](https://github.com/pygments/pygments ) | `2.20.0` | `2.21.0` |
| [types-pyyaml](https://github.com/python/typeshed ) | `6.0.12.20260724` | `6.0.12.20260815` |
| [boto3](https://github.com/boto/boto3 ) | `1.43.71` | `1.43.77` |
| [botocore](https://github.com/boto/botocore ) | `1.43.71` | `1.43.77` |
| [django-js-asset](https://github.com/feincms/django-js-asset ) | `4.0.1` | `4.0.2` |
| [django-oauth-toolkit](https://github.com/django-oauth/django-oauth-toolkit ) | `3.4.0` | `3.4.1` |
| [icalendar](https://github.com/collective/icalendar ) | `7.2.2` | `7.3.0` |
| [lxml](https://github.com/lxml/lxml ) | `6.1.1` | `6.1.2` |
| [protobuf](https://github.com/protocolbuffers/protobuf ) | `7.35.1` | `7.36.0` |
| [python-dotenv](https://github.com/theskumar/python-dotenv ) | `1.2.2` | `1.2.3` |
| [webencodings](https://github.com/CourtBouillon/webencodings ) | `0.5.1` | `0.6.1` |
Updates `mkdocs-git-revision-date-localized-plugin` from 1.5.3 to 1.5.4
- [Release notes](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin/releases )
- [Commits](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin/compare/v1.5.3...v1.5.4 )
Updates `gunicorn` from 26.0.0 to 26.1.0
- [Release notes](https://github.com/benoitc/gunicorn/releases )
- [Commits](https://github.com/benoitc/gunicorn/compare/26.0.0...26.1.0 )
Updates `charset-normalizer` from 3.5.0 to 3.5.1
- [Release notes](https://github.com/jawah/charset_normalizer/releases )
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md )
- [Commits](https://github.com/jawah/charset_normalizer/compare/3.5.0...3.5.1 )
Updates `idna` from 3.18 to 3.19
- [Release notes](https://github.com/kjd/idna/releases )
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md )
- [Commits](https://github.com/kjd/idna/compare/v3.18...v3.19 )
Updates `prek` from 0.4.13 to 0.4.14
- [Release notes](https://github.com/j178/prek/releases )
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md )
- [Commits](https://github.com/j178/prek/compare/v0.4.13...v0.4.14 )
Updates `pygments` from 2.20.0 to 2.21.0
- [Release notes](https://github.com/pygments/pygments/releases )
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES )
- [Commits](https://github.com/pygments/pygments/compare/2.20.0...2.21.0 )
Updates `types-pyyaml` from 6.0.12.20260724 to 6.0.12.20260815
- [Commits](https://github.com/python/typeshed/commits )
Updates `boto3` from 1.43.71 to 1.43.77
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.71...1.43.77 )
Updates `botocore` from 1.43.71 to 1.43.77
- [Commits](https://github.com/boto/botocore/compare/1.43.71...1.43.77 )
Updates `django-js-asset` from 4.0.1 to 4.0.2
- [Changelog](https://github.com/feincms/django-js-asset/blob/main/CHANGELOG.rst )
- [Commits](https://github.com/feincms/django-js-asset/compare/4.0.1...4.0.2 )
Updates `django-oauth-toolkit` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/django-oauth/django-oauth-toolkit/releases )
- [Changelog](https://github.com/django-oauth/django-oauth-toolkit/blob/master/CHANGELOG.md )
- [Commits](https://github.com/django-oauth/django-oauth-toolkit/compare/3.4.0...3.4.1 )
Updates `icalendar` from 7.2.2 to 7.3.0
- [Release notes](https://github.com/collective/icalendar/releases )
- [Changelog](https://github.com/collective/icalendar/blob/main/CHANGES.rst )
- [Commits](https://github.com/collective/icalendar/compare/v7.2.2...v7.3.0 )
Updates `lxml` from 6.1.1 to 6.1.2
- [Release notes](https://github.com/lxml/lxml/releases )
- [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt )
- [Commits](https://github.com/lxml/lxml/compare/lxml-6.1.1...lxml-6.1.2 )
Updates `protobuf` from 7.35.1 to 7.36.0
- [Release notes](https://github.com/protocolbuffers/protobuf/releases )
- [Commits](https://github.com/protocolbuffers/protobuf/commits )
Updates `python-dotenv` from 1.2.2 to 1.2.3
- [Release notes](https://github.com/theskumar/python-dotenv/releases )
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md )
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3 )
Updates `webencodings` from 0.5.1 to 0.6.1
- [Release notes](https://github.com/CourtBouillon/webencodings/releases )
- [Changelog](https://github.com/CourtBouillon/webencodings/blob/main/docs/changelog.rst )
- [Commits](https://github.com/CourtBouillon/webencodings/compare/v0.5.1...v0.6.1 )
---
updated-dependencies:
- dependency-name: mkdocs-git-revision-date-localized-plugin
dependency-version: 1.5.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: gunicorn
dependency-version: 26.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: charset-normalizer
dependency-version: 3.5.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: idna
dependency-version: '3.19'
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: prek
dependency-version: 0.4.14
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: pygments
dependency-version: 2.21.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: types-pyyaml
dependency-version: 6.0.12.20260815
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: boto3
dependency-version: 1.43.77
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: botocore
dependency-version: 1.43.77
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: django-js-asset
dependency-version: 4.0.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: django-oauth-toolkit
dependency-version: 3.4.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: icalendar
dependency-version: 7.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: lxml
dependency-version: 6.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: protobuf
dependency-version: 7.36.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: python-dotenv
dependency-version: 1.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: webencodings
dependency-version: 0.6.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
* fix style
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com >
2026-08-29 11:17:18 +10:00
Oliver
fcbcef5aae
Tracing fix ( #12728 )
...
* Bug fix for tracing setup
* Support forking against multiple PIDs
* Updated documentation
2026-08-29 08:05:16 +10:00
Matthias Mair
5244b8a4f2
[FR] add well-known mixin to let plugins define well-known urls ( #12698 )
...
* [FR] add well-known mixin to let plugins define well-known data entry points
Fixes #11741
* add built-in plugin for apis
* add test
* add decorator
* ignore default
* fix tests
* remove erronius decorator
* all well-known paths to security exception paths
* update test setup
* ignore escape paths
* add docs
* add more on security considerations
* add to nav
2026-08-28 16:43:20 +10:00
Oliver
0ee2ee9ec2
Update sentry.io integration ( #12729 )
2026-08-28 16:36:28 +10:00
Bhumin Paladiya
494fc58e7c
Fix PurchaseOrderExtraLine admin search and add search fields across admin classes ( #12721 )
2026-08-28 09:01:05 +10:00
Alonso Lopez-Valdez and Oliver
af4c4220f5
update auto allocation button tooltip and visibility logic ( #12720 )
...
Co-authored-by: Oliver <oliver.henry.walters@gmail.com >
2026-08-28 08:59:23 +10:00
github-actions[bot]
ccf34e4b16
New Crowdin translations by GitHub Action ( #12701 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-27 16:06:15 +10:00
Oliver
2dca27f78b
Fix race condition for take_stock method ( #12718 )
2026-08-27 15:01:20 +10:00
Oliver
39f2d724aa
[UI] PO Receive bug ( #12709 )
...
* [UI] Fix for receiving items
* Add playwright regression test
2026-08-25 14:34:33 +10:00
Oliver
a6687a6b10
Bug fix for APISearchView ( #12707 )
...
The global search endpoint dispatches to viewset-based result types using a bare HttpRequest() with an empty META, so pagination's build_absolute_uri() crashes on the missing SERVER_NAME.
2026-08-25 11:57:00 +10:00
dependabot[bot]
51a01149f8
chore(deps): bump the dependencies group across 1 directory with 3 updates ( #12699 )
...
Bumps the dependencies group with 3 updates in the /src/frontend directory: [@codemirror/view](https://github.com/codemirror/view ), [dayjs](https://github.com/iamkun/dayjs ) and [styled-components](https://github.com/styled-components/styled-components ).
Updates `@codemirror/view` from 6.43.8 to 6.43.9
- [Changelog](https://github.com/codemirror/view/blob/main/CHANGELOG.md )
- [Commits](https://github.com/codemirror/view/commits )
Updates `dayjs` from 1.11.21 to 1.11.23
- [Release notes](https://github.com/iamkun/dayjs/releases )
- [Changelog](https://github.com/iamkun/dayjs/blob/v1.11.23/CHANGELOG.md )
- [Commits](https://github.com/iamkun/dayjs/compare/v1.11.21...v1.11.23 )
Updates `styled-components` from 6.5.1 to 6.5.3
- [Release notes](https://github.com/styled-components/styled-components/releases )
- [Commits](https://github.com/styled-components/styled-components/compare/styled-components@6.5.1...styled-components@6.5.3 )
---
updated-dependencies:
- dependency-name: "@codemirror/view"
dependency-version: 6.43.9
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: dayjs
dependency-version: 1.11.23
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: styled-components
dependency-version: 6.5.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 10:40:14 +10:00
dependabot[bot]
67cd3cbda7
chore(deps): bump the dependencies group with 3 updates ( #12700 )
...
Bumps the dependencies group with 3 updates: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ), [oasdiff/oasdiff-action/diff](https://github.com/oasdiff/oasdiff-action ) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ).
Updates `docker/setup-buildx-action` from 4.2.0 to 4.3.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](https://github.com/docker/setup-buildx-action/compare/bb05f3f5519dd87d3ba754cc423b652a5edd6d2c...37fe631027851001ddb9b187196cc803df7f5f0e )
Updates `oasdiff/oasdiff-action/diff` from 0.1.12 to 0.1.13
- [Release notes](https://github.com/oasdiff/oasdiff-action/releases )
- [Commits](https://github.com/oasdiff/oasdiff-action/compare/033c15c845bef10f148afb0fa781bf1b2a7fe1bf...2649ebe137aeb72a95707671204e829f86e091fc )
Updates `github/codeql-action/upload-sarif` from 4.37.6 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-version: 4.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: oasdiff/oasdiff-action/diff
dependency-version: 0.1.13
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 10:40:07 +10:00
James Todd
0ff2f7f3cb
PluginDrawer now fetches plugin details itself. ( #12703 )
2026-08-25 09:00:39 +10:00
Oliver
176ef1af81
Fix table migration ( #12697 )
...
- Prevent error on MYSQL migration
2026-08-25 08:57:50 +10:00
github-actions[bot]
08b0bb8088
New Crowdin translations by GitHub Action ( #12688 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-24 23:40:25 +10:00
Oliver
33586f6ea9
[bug] Fix broken build complete transition ( #12696 )
...
* Add regression test for build complete failure
* Handle offloading of complete_build
* Allow generic offloading of transitions to the background worker
* Refactor cancel_build method
* additional unit test
2026-08-24 23:40:07 +10:00
Oliver
e12bdcfb69
[UI] Data import for order lines ( #12692 )
...
* [UI] Data import for order lines
* Adjust playwright tests
2026-08-24 22:20:18 +10:00
Oliver
528bb085d7
User permissions check for Attachment API ( #12689 )
2026-08-23 18:53:33 +10:00
Oliver
f16fb36b08
Strip potentially dangerous tags from SVG files ( #12687 )
2026-08-23 18:50:13 +10:00
Oliver
bc98e4bab6
Auto-extract StatusCode values for docs ( #12686 )
...
* Auto-extract StatusCode values for docs
* Extract user roles from code
* Fix links
* Remove extraneous source code in docs
2026-08-23 18:48:05 +10:00
github-actions[bot]
f063a6c67f
New Crowdin translations by GitHub Action ( #12679 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-23 11:26:32 +10:00
ebd1b6e936
chore(deps): bump the dependencies group across 1 directory with 16 updates ( #12680 )
...
* chore(deps): bump the dependencies group across 1 directory with 16 updates
Bumps the dependencies group with 16 updates in the /src/backend directory:
| Package | From | To |
| --- | --- | --- |
| [setuptools](https://github.com/pypa/setuptools ) | `83.0.0` | `84.0.0` |
| [wheel](https://github.com/pypa/wheel ) | `0.47.0` | `0.48.0` |
| [charset-normalizer](https://github.com/jawah/charset_normalizer ) | `3.4.9` | `3.5.0` |
| [django-silk](https://github.com/jazzband/django-silk ) | `5.5.0` | `5.5.2` |
| [django-stubs](https://github.com/typeddjango/django-stubs ) | `6.0.9` | `6.1.0` |
| [django-stubs-ext](https://github.com/typeddjango/django-stubs ) | `6.0.9` | `6.1.0` |
| [pip-tools](https://github.com/jazzband/pip-tools ) | `7.6.0` | `7.6.1` |
| [prek](https://github.com/j178/prek ) | `0.4.12` | `0.4.13` |
| [pytest-django](https://github.com/pytest-dev/pytest-django ) | `4.13.0` | `4.14.0` |
| [boto3](https://github.com/boto/boto3 ) | `1.43.66` | `1.43.71` |
| [botocore](https://github.com/boto/botocore ) | `1.43.66` | `1.43.71` |
| [django-q2](https://github.com/GDay/django-q2 ) | `1.10.0` | `1.11.0` |
| [platformdirs](https://github.com/tox-dev/platformdirs ) | `4.11.0` | `4.11.3` |
| [pypdf](https://github.com/py-pdf/pypdf ) | `6.15.0` | `6.16.1` |
| [pyphen](https://github.com/Kozea/Pyphen ) | `0.17.2` | `0.18.1` |
| [sentry-sdk](https://github.com/getsentry/sentry-python ) | `2.66.1` | `2.68.0` |
Updates `setuptools` from 83.0.0 to 84.0.0
- [Release notes](https://github.com/pypa/setuptools/releases )
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst )
- [Commits](https://github.com/pypa/setuptools/compare/v83.0.0...v84.0.0 )
Updates `wheel` from 0.47.0 to 0.48.0
- [Release notes](https://github.com/pypa/wheel/releases )
- [Changelog](https://github.com/pypa/wheel/blob/main/docs/news.rst )
- [Commits](https://github.com/pypa/wheel/compare/0.47.0...0.48.0 )
Updates `charset-normalizer` from 3.4.9 to 3.5.0
- [Release notes](https://github.com/jawah/charset_normalizer/releases )
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md )
- [Commits](https://github.com/jawah/charset_normalizer/compare/3.4.9...3.5.0 )
Updates `django-silk` from 5.5.0 to 5.5.2
- [Release notes](https://github.com/jazzband/django-silk/releases )
- [Changelog](https://github.com/jazzband/django-silk/blob/master/CHANGELOG.md )
- [Commits](https://github.com/jazzband/django-silk/compare/5.5.0...5.5.2 )
Updates `django-stubs` from 6.0.9 to 6.1.0
- [Release notes](https://github.com/typeddjango/django-stubs/releases )
- [Commits](https://github.com/typeddjango/django-stubs/compare/6.0.9...6.1.0 )
Updates `django-stubs-ext` from 6.0.9 to 6.1.0
- [Release notes](https://github.com/typeddjango/django-stubs/releases )
- [Commits](https://github.com/typeddjango/django-stubs/compare/6.0.9...6.1.0 )
Updates `pip-tools` from 7.6.0 to 7.6.1
- [Release notes](https://github.com/jazzband/pip-tools/releases )
- [Changelog](https://github.com/jazzband/pip-tools/blob/main/CHANGELOG.md )
- [Commits](https://github.com/jazzband/pip-tools/compare/v7.6.0...v7.6.1 )
Updates `prek` from 0.4.12 to 0.4.13
- [Release notes](https://github.com/j178/prek/releases )
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md )
- [Commits](https://github.com/j178/prek/compare/v0.4.12...v0.4.13 )
Updates `pytest-django` from 4.13.0 to 4.14.0
- [Release notes](https://github.com/pytest-dev/pytest-django/releases )
- [Changelog](https://github.com/pytest-dev/pytest-django/blob/main/docs/changelog.rst )
- [Commits](https://github.com/pytest-dev/pytest-django/compare/v4.13.0...v4.14.0 )
Updates `boto3` from 1.43.66 to 1.43.71
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.66...1.43.71 )
Updates `botocore` from 1.43.66 to 1.43.71
- [Commits](https://github.com/boto/botocore/compare/1.43.66...1.43.71 )
Updates `django-q2` from 1.10.0 to 1.11.0
- [Release notes](https://github.com/GDay/django-q2/releases )
- [Changelog](https://github.com/django-q2/django-q2/blob/master/CHANGELOG.md )
- [Commits](https://github.com/GDay/django-q2/compare/v1.10.0...v1.11.0 )
Updates `platformdirs` from 4.11.0 to 4.11.3
- [Release notes](https://github.com/tox-dev/platformdirs/releases )
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst )
- [Commits](https://github.com/tox-dev/platformdirs/compare/4.11.0...4.11.3 )
Updates `pypdf` from 6.15.0 to 6.16.1
- [Release notes](https://github.com/py-pdf/pypdf/releases )
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md )
- [Commits](https://github.com/py-pdf/pypdf/compare/6.15.0...6.16.1 )
Updates `pyphen` from 0.17.2 to 0.18.1
- [Release notes](https://github.com/Kozea/Pyphen/releases )
- [Changelog](https://github.com/Kozea/Pyphen/blob/main/docs/changelog.rst )
- [Commits](https://github.com/Kozea/Pyphen/compare/0.17.2...0.18.1 )
Updates `sentry-sdk` from 2.66.1 to 2.68.0
- [Release notes](https://github.com/getsentry/sentry-python/releases )
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md )
- [Commits](https://github.com/getsentry/sentry-python/compare/2.66.1...2.68.0 )
---
updated-dependencies:
- dependency-name: setuptools
dependency-version: 84.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: dependencies
- dependency-name: wheel
dependency-version: 0.48.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: charset-normalizer
dependency-version: 3.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: django-silk
dependency-version: 5.5.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: django-stubs
dependency-version: 6.1.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: django-stubs-ext
dependency-version: 6.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: pip-tools
dependency-version: 7.6.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: prek
dependency-version: 0.4.13
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: pytest-django
dependency-version: 4.14.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: boto3
dependency-version: 1.43.71
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: botocore
dependency-version: 1.43.71
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: django-q2
dependency-version: 1.11.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: platformdirs
dependency-version: 4.11.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: dependencies
- dependency-name: pypdf
dependency-version: 6.16.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: pyphen
dependency-version: 0.18.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
- dependency-name: sentry-sdk
dependency-version: 2.68.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: dependencies
...
Signed-off-by: dependabot[bot] <support@github.com >
* fix style
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com >
Co-authored-by: Oliver <oliver.henry.walters@gmail.com >
2026-08-23 00:47:30 +10:00
Oliver
669c2c0511
Add --traceback to invoke commands ( #12681 )
...
Provides better feedback in the case of failure
2026-08-22 15:00:39 +10:00