Commit Graph
1611 Commits
Author SHA1 Message Date
Petr Ledvina b9c7c24f8a Fix validation of dependent serializer fields (#12871) 2026-09-18 07:59:44 +10:00
Petr Ledvina 960c5f18e4 Preserve note image files when transactions roll back (#12867) 2026-09-18 00:13:03 +10:00
github-actions[bot] 3a0ade3265 New Crowdin translations by GitHub Action (#12782)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-16 22:32:45 +10:00
Matthias Mair dca516b318 feat(backend): switch API token storage to hmac digest (#12850)
* [FR] switch API token storage to hmac digest
Fixes #12027

* add pr number

* fix implementation details
allign token prefix and token end (add date issuance)

* fix missing re-issuance

* ensure we raise if not exsistant

* fix test

* add ignore

* extend test

* add information regarding v2 tokens

* add fields for:
- revocation details (reason, revoker)
- issueance
- version
- pepper

* bump apiversion

* make revocation mesagge clearer

* add missing update fields

* ensure this only triggers for v2

* move comment

* re-add v1 coverage

* add missing annotation to api schema
2026-09-16 10:35:12 +10:00
Oliver 225157153e Bug fixes for plugin file check (#12861)
- regex escape package name
- allow package without version indicator
- prevent duplication of entries within the plugins file
- add regression tests
2026-09-15 23:23:12 +10:00
Oliver d0a98f6491 Add more robust plugin installation check (#12858) 2026-09-15 21:24:40 +10:00
Matthias Mair 63a434c652 feat: Add facility to completely hide parts of the interface (#12842)
* fix typing issue for pylance engine

* add flags to mark rough function of setting

* update pr version

* fix settings serialisation

* render security warnings

* move Transfer Orders

* respect return order hiding

* almost all confirm texts will have a warning

* add settings for sales, purchase and buildorder deactivation

* make permission check also ensure gloablsetting for view is available; reduce number of chained gates

* document possible missing check

* ensure we can still show the sales tab

* add additional warning to group cleanup

* hide more ui parts conditionally

* add tests for new code and remove duplication

* fix test

* alternative approach to fix SSO path

* remove patch; now done in serializer

* ignore ldap section
2026-09-15 21:13:59 +10:00
Oliver 0d7c99d405 Prevent editing "part" against existing BuildOrder (#12849) 2026-09-15 08:56:35 +10:00
Matthias Mair 66de7b77d4 add test for migrations (#12838) 2026-09-14 16:18:27 +10:00
dependabot[bot]andMatthias Mair b14a4e7812 chore(deps): bump the dependencies group across 1 directory with 12 updates (#12841)
* chore(deps): bump the dependencies group across 1 directory with 12 updates

Bumps the dependencies group with 12 updates in the /src/backend directory:

| Package | From | To |
| --- | --- | --- |
| [boto3](https://github.com/boto/boto3) | `1.43.84` | `1.43.88` |
| [botocore](https://github.com/boto/botocore) | `1.43.84` | `1.43.88` |
| [cssselect2](https://github.com/Kozea/cssselect2) | `0.10.0` | `0.10.1` |
| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.75.2` | `1.75.3` |
| [jwcrypto](https://github.com/latchset/jwcrypto) | `1.5.9` | `1.6.0` |
| [lxml](https://github.com/lxml/lxml) | `6.1.2` | `6.1.3` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.5` | `4.11.7` |
| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.36.0` | `7.36.1` |
| [pydantic-core](https://github.com/pydantic/pydantic) | `2.46.5` | `2.48.0` |
| [pypdf](https://github.com/py-pdf/pypdf) | `6.16.2` | `6.17.0` |
| [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.0` |
| [prek](https://github.com/j178/prek) | `0.5.0` | `0.5.2` |



Updates `boto3` from 1.43.84 to 1.43.88
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.84...1.43.88)

Updates `botocore` from 1.43.84 to 1.43.88
- [Commits](https://github.com/boto/botocore/compare/1.43.84...1.43.88)

Updates `cssselect2` from 0.10.0 to 0.10.1
- [Release notes](https://github.com/Kozea/cssselect2/releases)
- [Changelog](https://github.com/Kozea/cssselect2/blob/main/docs/changelog.rst)
- [Commits](https://github.com/Kozea/cssselect2/compare/0.10.0...0.10.1)

Updates `googleapis-common-protos` from 1.75.2 to 1.75.3
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-python/compare/googleapis-common-protos-v1.75.2...googleapis-common-protos-v1.75.3)

Updates `jwcrypto` from 1.5.9 to 1.6.0
- [Release notes](https://github.com/latchset/jwcrypto/releases)
- [Commits](https://github.com/latchset/jwcrypto/compare/v1.5.9...v1.6.0)

Updates `lxml` from 6.1.2 to 6.1.3
- [Release notes](https://github.com/lxml/lxml/releases)
- [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt)
- [Commits](https://github.com/lxml/lxml/compare/lxml-6.1.2...lxml-6.1.3)

Updates `platformdirs` from 4.11.5 to 4.11.7
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](https://github.com/tox-dev/platformdirs/compare/4.11.5...4.11.7)

Updates `protobuf` from 7.36.0 to 7.36.1
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Commits](https://github.com/protocolbuffers/protobuf/commits)

Updates `pydantic-core` from 2.46.5 to 2.48.0
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/main/HISTORY.md)
- [Commits](https://github.com/pydantic/pydantic/compare/core-v2.46.5...core-v2.48.0)

Updates `pypdf` from 6.16.2 to 6.17.0
- [Release notes](https://github.com/py-pdf/pypdf/releases)
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md)
- [Commits](https://github.com/py-pdf/pypdf/compare/6.16.2...6.17.0)

Updates `anyio` from 4.14.2 to 4.15.0
- [Release notes](https://github.com/agronholm/anyio/releases)
- [Commits](https://github.com/agronholm/anyio/compare/4.14.2...4.15.0)

Updates `prek` from 0.5.0 to 0.5.2
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](https://github.com/j178/prek/compare/v0.5.0...v0.5.2)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.88
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: botocore
  dependency-version: 1.43.88
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: cssselect2
  dependency-version: 0.10.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: googleapis-common-protos
  dependency-version: 1.75.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: jwcrypto
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: lxml
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: platformdirs
  dependency-version: 4.11.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: protobuf
  dependency-version: 7.36.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: pydantic-core
  dependency-version: 2.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: pypdf
  dependency-version: 6.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: anyio
  dependency-version: 4.15.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: prek
  dependency-version: 0.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix style

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-09-13 13:51:31 +10:00
Matthias Mair 6b1a3b899e fix: users created via Admin Center never receive password reset emails (#12839)
* Users created via Admin Center never receive password reset emails
Fixes #12733

* fix issue when using registration endpoint

* remove duplicate code path; we now always do that

* remove old test backfill that is not required anymore
2026-09-13 13:50:52 +10:00
wyyd-yxcandMatthias Mair 9181097194 Add user option to rotate table column headers (#12837)
* Add user option to rotate table column headers (#12558)

Wide column titles (e.g. "Temperature coefficient [±ppm/°C]") take a
lot of horizontal space for narrow data. Add a ROTATE_TABLE_HEADERS
user setting (Display Options) which renders table header titles
vertically via a scoped CSS class, following the implementation
sketch from the issue discussion.

* Format ROTATE_TABLE_HEADERS description per ruff-format

* add missing doc place

* Document ROTATE_TABLE_HEADERS setting in user settings docs

* docs: add changelog entry for rotated table headers option

---------

Co-authored-by: Matthias Mair <code@mjmair.com>
2026-09-12 14:12:39 +10:00
dependabot[bot]andMatthias Mair 0bf4fffb39 chore(deps): bump weasyprint from 69.0 to 70.0 in /src/backend (#12833)
* chore(deps): bump weasyprint from 69.0 to 70.0 in /src/backend

Bumps [weasyprint](https://github.com/Kozea/WeasyPrint) from 69.0 to 70.0.
- [Release notes](https://github.com/Kozea/WeasyPrint/releases)
- [Changelog](https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst)
- [Commits](https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0)

---
updated-dependencies:
- dependency-name: weasyprint
  dependency-version: '70.0'
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix style

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-09-12 08:12:50 +10:00
Oliver c26db6a790 Squash migrations (#12830)
* Squash migrations for "users" app

* Squash migrations for "common" app

Note: we will come back again later to squash some more

* Significant squashing

* Update legacy migrations

* Further squashing of migrations

* Even more cleanup

* Adjust CI workflow

* Update CI Job

* Update docs

* Update CHANGELOG.md

* Cleanup old comments

* Throw error if pre 1.0.0 DB detected

* Refactor incomplete migration check
2026-09-11 16:03:41 +10:00
Oliver e8af71ae5a Bug fixes for Note model (#12835)
* Bug fixes for Note model

- Allow note to be created as "primary"
- Reset note creation fields in editor

* Tweak to ensure that the API spec does not change
2026-09-10 14:22:55 +10:00
Matthias Mair 97f7c039c9 fix lease issue (#12828) 2026-09-09 07:15:05 +10:00
Oliver 7cd74eecd4 Migration fix (#12808)
* Fix for Note migration

- Handles case where data migration is running on a DB which does not support RETURNING

* Run migration tests against all supported backends

* Fix typo

* Adjust CI workflows

* TZ migration fix

* Tweak migration test

* Adjust migration tests

* Ensure consistent ordering

* Bump API version

* Fix tests to allow non psql database support
2026-09-08 18:50:13 +10:00
Oliver ef42a7b309 Attachment filtering by filename (#12807)
* Attachment filtering by filename

* Update API version
2026-09-08 09:25:20 +10:00
Oliver 5ffd777f5d Fix for recursive custom units (#12815) 2026-09-08 08:24:44 +10:00
Oliver 5a7308763e [bug] Prevent editing of model-type for data import (#12809) 2026-09-07 21:08:02 +10:00
Matthias Mair c959ca4574 feat(frontend): add SAML helper (#12799)
* squash #12762

* implement https://github.com/inventree/InvenTree/issues/3509

* add changelog

* add option to use the full width
2026-09-07 16:52:24 +10:00
Oliver 2566d332a8 [bug] Plugin fix (#12805)
* [bug] Handle null plugin instance

* Add regression test

* Fix secondary instances of same bug
2026-09-07 14:45:48 +10:00
Oliver b4cb9a9746 Plugin load fix (#12776)
* Robustify plugin file loading

* Lock static file copying

* Improve robustness of static file copying

* Add regression tests

* Handle database not being ready

* Fix identified limitation and refactor code

* Attempt to fix CI job

* instrumentation for CI - will revert

* Another bugfix attempt
2026-09-07 07:45:53 +10:00
Oliver 4a0e28510f Exception handling for data outputs (#12797) 2026-09-06 21:36:01 +10:00
Oliver 1218af7366 Adds bulk-import option for "import-records" task (#12792)
* skip plugin events if importing or migrating data

* Add bulkloaddata option

* Skip signals if importing

* Improve bulkloaddata command

* Optionally rebuild thumbnails

* enhancements for import_records task

* cache natural key references in bulkloaddata

* wrap export_records in @state_logger

* Reduce file size of exported data

* Added docs

* Test bulk workflow as part of CI

* Add progress bar for data import

* fix for import workflow bug

* Separately test bulk import workflow

* Exercise --prettify option

* Additional CI checks for content excludes

* Allow plugin loading for list_apps

* Additional CI unit tests

* Test for importing with conflicting records

* path fixes

* Adjust test conditions
2026-09-06 19:58:52 +10:00
Oliver 321489a41b Add error message for missing TLD (#12789)
* Add error message for missing TLD

* add error code for missing TLD
2026-09-06 15:00:22 +10:00
Oliver 5b4c8135dc [CI] Allow more query time (#12790) 2026-09-05 19:55:57 +10:00
Oliver 9a416df5d4 Enhanced error message on CSRF failure (#12788)
* Enhanced error message on CSRF failure

* Defer to 'detail' field if exists
2026-09-05 19:55:37 +10:00
Matthias Mair 0a4f095397 feat(backend): enable OIDC/oAuth2 provider by default (#12731)
* Add SCIM
Closes https://github.com/inventree/InvenTree/issues/6339

* also test scim

* extend testing with conformance suite

* fix test suite results

* coverage completion

* fil test gaps

* add missing schema values

* fix more type issues

* fix error view

* remove route from OpenAPI

* User permissions check for Attachment API (#12689)

* enable oidc proivder by default

* add .well-known entry for OIDC server

* add default client registration

* add changelog entry

* add codeowners

* remove redundant info

* re-name and restructure panel

* add a smal explainer section on top

* flesh out section a bit more

* change name

* basic sso panel

* refactor rendering

* add api and mgmt functions

* add create/delete options

* simplify test

* handle secret generation

* fix merge

* update coverage

* add test

* reduce user friction

* add better labels

* make it more clear that this is only shown once

* add regenerate function

* update tests

* simplify test calls

* fix test
2026-09-05 12:10:13 +10:00
Oliver fa44925b21 Refactor part pricing updates (#12787)
* Refactor part pricing updates

- Handles cases where underlying part has been deleted

* Add regression tests
2026-09-05 11:57:39 +10:00
Oliver b51f710ee5 BOM Validation Improvements (#12780)
* Adjust get_bom_hash function:

- Optionally skip inclusion of part names
- Skip 'piece_count' if default value set

* Fall back to legacy comparison

* Add per-line-item check

* Add regression tests
2026-09-05 08:30:02 +10:00
github-actions[bot] e4e4d87476 New Crowdin translations by GitHub Action (#12759)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-04 16:00:50 +10:00
Oliver ff732d01aa Ignore 'piece_count' if default value (#12781)
* Ignore 'piece_count' if default value

* Add regression testing
2026-09-04 13:16:40 +10:00
Oliver aadd27d217 Prevent delete operation on /api/user/me/ (#12770)
* Prevent delete operation on /api/user/me/

* Bump API version
2026-09-03 15:27:44 +10:00
Oliver 8c1c16e59a Handle missing record in after_delete_supplier_part (#12772) 2026-09-03 13:57:19 +10:00
Matthias MairandOliver fa52affe98 feat: warn about unsafe CORS (#12773)
* feat: warn about unsafe CORS

* extend docs

* fix defaults

* bump api version

---------

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-03 13:09:17 +10:00
Oliver 694d890ce5 Metadata fix (#12771)
* Fix security hole for metadata API

* Regression test for field injection
2026-09-03 09:51:08 +10:00
Bhumin Paladiya 4b1ddcd2d0 Enhance search fields across InvenTree REST API endpoints (#12723)
* Enhance search fields across REST API endpoints

* Revert search_fields on SettingsList to key only for security

* Bump API version to 537 for REST API search fields

* Clean TokenListView search fields and revert common/api.py
2026-09-03 08:49:53 +10:00
Bhumin Paladiya bb151dcb01 Fix order allocation variant validation logic and serializer read_only_fields (#12738)
* Fix order allocation variant validation logic and serializer defects

* Format order models and tests with ruff preview style

* Fix TransferOrder destination field in allocation unit tests
2026-09-03 08:47:21 +10:00
OliverandMatthias Mair 4024075b3b [bug] API permission fixes: (#12766)
- User can only change their own profile
- Users can only access notes against models they are scoped to
- Users can only access parameters against models they are scoped to

Co-authored-by: Matthias Mair <code@mjmair.com>
2026-09-03 08:26:38 +10:00
Oliver f9f9f7499b Fix permissions for SelectionList (#12763)
* Fix permissions for SelectionList

* Bump API version
2026-09-02 15:15:58 +10:00
Oliver 1238daa783 Permissions fix for Calendar views (#12764) 2026-09-02 14:47:34 +10:00
Matthias Mair 913dc7c48a chore(backend): bump all backend deps (#12754)
* bump all backend deps

* fix new detections
2026-09-02 07:59:53 +10:00
github-actions[bot] e1ff60a64c New Crowdin translations by GitHub Action (#12727)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-01 14:32:12 +10:00
OliverandMatthias Mair 02da01dfec [Refactor] Notes (#11971)
* Display note info

* Support user locale

* Add unit testing for HTML content

* Observe color mode

* Add link between Note and NotesImage

* Ensure image file is deleted when NotesImage is deleted

* Add support for image upload in editor

* Skeleton for data migration

* Updates

* Update data migration

- Find any NoteImage items which do not link to a model
- Try to associate them with an existing note

* Remove validator

* Updated API endpoints for NotesImage model

* Update server side sanitizing

* Specify max field length

* Remove old fields from NotesImage model

* Refactor clean_string

* Remove obsolete task

* Remove legacy "notes" field from older models

* Adjust search params when switching notes

* Remove NotesFieldMixin

* Change editor

* Resizable image support

* Support tables

* Add table style

* Adjust header actions

* Add data migration for SalesOrderShipment notes

* Adjust back-end sanitizing

* Adjust

* Use subtle editor variant

* Move undo/redo

* Enhance editing logic

* Add report tags for notes

* Add unit test for note image cleanup

* Render note to HTML

- Automatically replace images

* Fix migration order

* Adjust migration text

* Fix "dirty" trigger on notes

* Prevent navigate from dirty notes

* Add documentation

* Prevent image clicking if not in editing mode

* Update API

* Update migration files

* Fix migrations

* remove notes from test fixtures

* remove notes field that does not exsist anymore

* add missing ruleset

* fix assertation

* fix assertation

* Update docs/docs/concepts/notes.md

Co-authored-by: Matthias Mair <code@mjmair.com>

* Remove blocknote deps

* Move old helper functions

- Only used for this migration
- Will potentially be removed at some point in the future?

* Revert change

* Fix note image URL

* Fix migration conflicts

* Fix migrations

* Fix delete call

* Fix content mixin

* Fix note duplication

* Make save method atomic

* Fix double-save

* Add "template" field to Note model

* Adjust migrations

* Frontend updates

* Fix for NotesEditor

* Render Note instance in forms

* Fix button-within-button

* Fix migrations

* Fix missing import

* add docs

* docs for rendering notes in reports

* Restrict queryset based on user view permissions

* APi unit tests for note permissions

* Duplicate embedded images when copying notes

* Add unit test for note duplication

* Add CHANGELOG

* Add 'copy_note' option to duplicate serializer

* Add unit tests for data migrations

* implement note duplication serializers

* frontend UI elements

* Fix migration conflicts

* Use branch for playwrigh testing

* Implement duplicate action for stock item

* Fix import

* Updated playwright tests

* Bug fix for receiving stock items

* Add screenshot

* Fix api_version

* Update unit tests

* Fix docs

* Remove defunct tests

* Fix migration order

* Adjust import/export workflow

* Manual cleaning update

* Fix migrations

* Fix migration files

* Fix for note save

* Adjust save ordering

* Skip constraint checking in NoteSerializer

* Custom validate_constraints on Note model

* Revert "Skip constraint checking in NoteSerializer"

This reverts commit b42bc955c1.

* Fix for note search

* Fix for receive_line_items

* Shim model renderer for NoteTemplate

* Fix playwright tests

* Adjust frontend CI

* Fix import/export CI job

* Fix for data migration test

* Fix migration test

* Adjust unit test

* Fix conflicting migration

* Fix unit test

* Run migration tests in parallel

* Robustify migration test

* Disable parallel options

* Fix conflicting migration

* Remove extraneous unit test

* Fix conflicting migrations

* Additional regression tests

* Check permissions before deleting Note instance

* Updated docs

* Validate note model type

* Prevent discard of unsaved changes in note editor

* Clean up dead code

* Fix migration conflict

* Improved data migration

* Prefetch role groups

* UI refactoring

* Refactor permission checking code

* Further code refactoring

* use DuplicateField helper

* Refactoring

* Add prefetch

* Throw exception rather than assert

* Logic fix for notes editor

* reimplement old background task

* Adjust data migration

* Fix notes field when receiving items

* Fix existing report templates

* Fix save action for notes editor

* Refactoring: Add "instance-info" API endpoint for common model properties

* Fix indicator dots

* Tweak nav alert msg

* Adjust layout of buttons

* Sanitize notes during migration

* Fix for NotesImage delete cascade

* Fix caching

* Fix race condition in notes editor

* Fix distinct issue when searching notse

* Fix race condition when saving new note instance

* Fix improper error

* Refactor StockItem duplication

* Refactoring

* Increase query time

* Fix api_version.py

* Additional migration tests

* Fix CI workflow

---------

Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-31 16:46:33 +10:00
Oliver d39d0262e6 [CI] Adjust query time threshold (#12748)
Allow larger buffer for test variation
2026-08-31 11:07:46 +10:00
Matthias Mair 4066fa6e0a feat(backend): add SCIM for user provisioning (#12713)
* Add SCIM
Closes https://github.com/inventree/InvenTree/issues/6339

* also test scim

* extend testing with conformance suite

* fix test suite results

* coverage completion

* fil test gaps

* add missing schema values

* fix more type issues

* fix error view

* remove route from OpenAPI

* add changelog entry

* add codeowners
2026-08-31 09:24:14 +10:00
OliverandCopilot Autofix powered by AI a205717171 SSO e2e testing (#12739)
* Extend SSO auth workflows

* SSO e2e testing workflow

* Remove orphaned code

* Add unit tests for SSO

* improved error messaging

* Add test for SSO registration disabled

* Fix gating on LOGIN_ENABLE_SSO

* Adjust UI state management

* Add playwright test for SSO disabled

* Add backend unit tests

* Adjust API version

* Additional playwright tests

* Retain desired page state on login failure

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Adjust test code

* Stricter matcher checking

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-08-30 10:32:54 +10:00
Bhumin Paladiya 69afe7723f Enhance search and autocomplete fields across all InvenTree admin models (#12722)
* Fix PurchaseOrderExtraLine admin search and add search fields across admin classes

* Add search fields and autocomplete fields across common admin models

* Add search and autocomplete fields to importer admin models

* Add search fields to MachineConfigAdmin

* Add search fields to LocationTypeAdmin

* Remove search_fields from DataImportRowAdmin per review feedback
2026-08-29 20:24:49 +10:00
dependabot[bot]andMatthias Mair 02fc34083a chore(deps): bump the dependencies group across 2 directories with 16 updates (#12735)
* chore(deps): bump the dependencies group across 2 directories with 16 updates

Bumps the dependencies group with 1 update in the /docs directory: [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin).
Bumps the dependencies group with 15 updates in the /src/backend directory:

| Package | From | To |
| --- | --- | --- |
| [gunicorn](https://github.com/benoitc/gunicorn) | `26.0.0` | `26.1.0` |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.5.0` | `3.5.1` |
| [idna](https://github.com/kjd/idna) | `3.18` | `3.19` |
| [prek](https://github.com/j178/prek) | `0.4.13` | `0.4.14` |
| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |
| [types-pyyaml](https://github.com/python/typeshed) | `6.0.12.20260724` | `6.0.12.20260815` |
| [boto3](https://github.com/boto/boto3) | `1.43.71` | `1.43.77` |
| [botocore](https://github.com/boto/botocore) | `1.43.71` | `1.43.77` |
| [django-js-asset](https://github.com/feincms/django-js-asset) | `4.0.1` | `4.0.2` |
| [django-oauth-toolkit](https://github.com/django-oauth/django-oauth-toolkit) | `3.4.0` | `3.4.1` |
| [icalendar](https://github.com/collective/icalendar) | `7.2.2` | `7.3.0` |
| [lxml](https://github.com/lxml/lxml) | `6.1.1` | `6.1.2` |
| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.35.1` | `7.36.0` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |
| [webencodings](https://github.com/CourtBouillon/webencodings) | `0.5.1` | `0.6.1` |



Updates `mkdocs-git-revision-date-localized-plugin` from 1.5.3 to 1.5.4
- [Release notes](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin/releases)
- [Commits](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin/compare/v1.5.3...v1.5.4)

Updates `gunicorn` from 26.0.0 to 26.1.0
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](https://github.com/benoitc/gunicorn/compare/26.0.0...26.1.0)

Updates `charset-normalizer` from 3.5.0 to 3.5.1
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](https://github.com/jawah/charset_normalizer/compare/3.5.0...3.5.1)

Updates `idna` from 3.18 to 3.19
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](https://github.com/kjd/idna/compare/v3.18...v3.19)

Updates `prek` from 0.4.13 to 0.4.14
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](https://github.com/j178/prek/compare/v0.4.13...v0.4.14)

Updates `pygments` from 2.20.0 to 2.21.0
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](https://github.com/pygments/pygments/compare/2.20.0...2.21.0)

Updates `types-pyyaml` from 6.0.12.20260724 to 6.0.12.20260815
- [Commits](https://github.com/python/typeshed/commits)

Updates `boto3` from 1.43.71 to 1.43.77
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.71...1.43.77)

Updates `botocore` from 1.43.71 to 1.43.77
- [Commits](https://github.com/boto/botocore/compare/1.43.71...1.43.77)

Updates `django-js-asset` from 4.0.1 to 4.0.2
- [Changelog](https://github.com/feincms/django-js-asset/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/feincms/django-js-asset/compare/4.0.1...4.0.2)

Updates `django-oauth-toolkit` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/django-oauth/django-oauth-toolkit/releases)
- [Changelog](https://github.com/django-oauth/django-oauth-toolkit/blob/master/CHANGELOG.md)
- [Commits](https://github.com/django-oauth/django-oauth-toolkit/compare/3.4.0...3.4.1)

Updates `icalendar` from 7.2.2 to 7.3.0
- [Release notes](https://github.com/collective/icalendar/releases)
- [Changelog](https://github.com/collective/icalendar/blob/main/CHANGES.rst)
- [Commits](https://github.com/collective/icalendar/compare/v7.2.2...v7.3.0)

Updates `lxml` from 6.1.1 to 6.1.2
- [Release notes](https://github.com/lxml/lxml/releases)
- [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt)
- [Commits](https://github.com/lxml/lxml/compare/lxml-6.1.1...lxml-6.1.2)

Updates `protobuf` from 7.35.1 to 7.36.0
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Commits](https://github.com/protocolbuffers/protobuf/commits)

Updates `python-dotenv` from 1.2.2 to 1.2.3
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3)

Updates `webencodings` from 0.5.1 to 0.6.1
- [Release notes](https://github.com/CourtBouillon/webencodings/releases)
- [Changelog](https://github.com/CourtBouillon/webencodings/blob/main/docs/changelog.rst)
- [Commits](https://github.com/CourtBouillon/webencodings/compare/v0.5.1...v0.6.1)

---
updated-dependencies:
- dependency-name: mkdocs-git-revision-date-localized-plugin
  dependency-version: 1.5.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: gunicorn
  dependency-version: 26.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: charset-normalizer
  dependency-version: 3.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: idna
  dependency-version: '3.19'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: prek
  dependency-version: 0.4.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: pygments
  dependency-version: 2.21.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: types-pyyaml
  dependency-version: 6.0.12.20260815
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: boto3
  dependency-version: 1.43.77
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: botocore
  dependency-version: 1.43.77
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: django-js-asset
  dependency-version: 4.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: django-oauth-toolkit
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: icalendar
  dependency-version: 7.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: lxml
  dependency-version: 6.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: protobuf
  dependency-version: 7.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: python-dotenv
  dependency-version: 1.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: webencodings
  dependency-version: 0.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix style

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-29 11:17:18 +10:00