Commit Graph
18247 Commits
Author SHA1 Message Date
Oliver ff732d01aa Ignore 'piece_count' if default value (#12781)
* Ignore 'piece_count' if default value

* Add regression testing
2026-09-04 13:16:40 +10:00
Oliver 43bd525240 Tweak search (#12778)
- Prevent single character searches
- Abort previous search requests
2026-09-03 22:11:13 +10:00
Oliver aadd27d217 Prevent delete operation on /api/user/me/ (#12770)
* Prevent delete operation on /api/user/me/

* Bump API version
2026-09-03 15:27:44 +10:00
Oliver 8c1c16e59a Handle missing record in after_delete_supplier_part (#12772) 2026-09-03 13:57:19 +10:00
Matthias MairandOliver fa52affe98 feat: warn about unsafe CORS (#12773)
* feat: warn about unsafe CORS

* extend docs

* fix defaults

* bump api version

---------

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-09-03 13:09:17 +10:00
Matthias Mair 9f8dfda18b chore: add types to templates; add AI agent catch (#12747)
* Update feature_request.yaml

* Update bug_report.yaml

* Update bug_report.yaml

* Update documentation.yaml
2026-09-03 10:32:17 +10:00
Oliver 694d890ce5 Metadata fix (#12771)
* Fix security hole for metadata API

* Regression test for field injection
2026-09-03 09:51:08 +10:00
Bhumin Paladiya 4b1ddcd2d0 Enhance search fields across InvenTree REST API endpoints (#12723)
* Enhance search fields across REST API endpoints

* Revert search_fields on SettingsList to key only for security

* Bump API version to 537 for REST API search fields

* Clean TokenListView search fields and revert common/api.py
2026-09-03 08:49:53 +10:00
Bhumin Paladiya bb151dcb01 Fix order allocation variant validation logic and serializer read_only_fields (#12738)
* Fix order allocation variant validation logic and serializer defects

* Format order models and tests with ruff preview style

* Fix TransferOrder destination field in allocation unit tests
2026-09-03 08:47:21 +10:00
OliverandMatthias Mair 4024075b3b [bug] API permission fixes: (#12766)
- User can only change their own profile
- Users can only access notes against models they are scoped to
- Users can only access parameters against models they are scoped to

Co-authored-by: Matthias Mair <code@mjmair.com>
2026-09-03 08:26:38 +10:00
Oliver f9f9f7499b Fix permissions for SelectionList (#12763)
* Fix permissions for SelectionList

* Bump API version
2026-09-02 15:15:58 +10:00
Oliver 1238daa783 Permissions fix for Calendar views (#12764) 2026-09-02 14:47:34 +10:00
dependabot[bot] b03d3b1ba0 chore(deps): bump python in /contrib/container (#12752)
Bumps python from `ce40764` to `cae66f2`.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.14.7-slim-trixie
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 09:35:52 +10:00
Matthias Mair 913dc7c48a chore(backend): bump all backend deps (#12754)
* bump all backend deps

* fix new detections
2026-09-02 07:59:53 +10:00
Senior Data EngineerandMatthias Mair ffcbbf6292 Clarify SSO setup via Database Admin interface (#12474)
* Clarify SSO setup via Database Admin interface

Fixes #10415 by documenting that Social applications are
configured in Django admin at /admin/, not via config.yaml or API.

* docs: move Database Admin access details to db_admin.md

Per review: drop the access-how-to from SSO.md and link to the Database Admin guide instead.

---------

Co-authored-by: Matthias Mair <code@mjmair.com>
2026-09-01 21:59:08 +10:00
github-actions[bot] e1ff60a64c New Crowdin translations by GitHub Action (#12727)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-01 14:32:12 +10:00
Oliver ed84d06dbe [UI] Fixes for column resizing (#12755)
- Apply CSS fix
- Allow proper dragging
- Ensure table columns fill 100% width
2026-09-01 12:06:09 +10:00
Oliver f8328cd1db [UI] Fix useReceiveLineItems bug (#12756)
- Prevent negative pre-fill values
2026-09-01 12:06:01 +10:00
dependabot[bot] 8ae579124b chore(deps): bump the dependencies group with 4 updates (#12753)
Bumps the dependencies group with 4 updates: [depot/setup-action](https://github.com/depot/setup-action), [CodSpeedHQ/action](https://github.com/codspeedhq/action), [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) and [crowdin/github-action](https://github.com/crowdin/github-action).


Updates `depot/setup-action` from 1.7.1 to 1.7.2
- [Release notes](https://github.com/depot/setup-action/releases)
- [Commits](https://github.com/depot/setup-action/compare/15c09a5f77a0840ad4bce955686522a257853461...91bc8495a33ebfc504ffc89e5674379ccf23c29c)

Updates `CodSpeedHQ/action` from 5.0.3 to 5.2.1
- [Release notes](https://github.com/codspeedhq/action/releases)
- [Changelog](https://github.com/CodSpeedHQ/action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codspeedhq/action/compare/4296e51e7041e24dadb86d1d6e8b9320d223dbe8...373d6868929f444bc08d901fd0eb0ad52a8875ea)

Updates `github/codeql-action/upload-sarif` from 4.37.7 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd...db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28)

Updates `crowdin/github-action` from 2.17.0 to 2.17.1
- [Release notes](https://github.com/crowdin/github-action/releases)
- [Commits](https://github.com/crowdin/github-action/compare/c7af9bc98b01694653031fef2a0dc6c7888ce9bc...8f01d54f70f1713ee3f09d82c2bbb2daeac28689)

---
updated-dependencies:
- dependency-name: depot/setup-action
  dependency-version: 1.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: CodSpeedHQ/action
  dependency-version: 5.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: crowdin/github-action
  dependency-version: 2.17.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-01 10:34:30 +10:00
Senior Data Engineer fe489bd6b6 Document Docker Compose container health checks (#12420)
* Document Docker Compose container health checks

Add user documentation and CHANGELOG entry for the production
docker-compose health checks proposed in #12124.

* docs: match health-check docs to merged docker-compose.yml

Reviewed against inventree/InvenTree#12124: server uses invoke server-health, proxy probes Caddy :9090, worker uses invoke worker-health.
2026-08-31 21:04:14 +10:00
773ed4eb3a (feature): docker health checks (#12124)
* Add Docker container health checks

* Use invoke tasks for Docker container health checks

Updates server and worker healthchecks to use invoke server-health
and invoke worker-health as requested in #12124 review.

Refs #12124

* Added HTTP host check to server health check

* Add health-check endpoint for Caddyfile

* Simplify health check for Caddy

* Remove test file

---------

Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
Co-authored-by: DESKTOP-691E36A\Administrator <br198064@gmail.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-31 16:46:46 +10:00
OliverandMatthias Mair 02da01dfec [Refactor] Notes (#11971)
* Display note info

* Support user locale

* Add unit testing for HTML content

* Observe color mode

* Add link between Note and NotesImage

* Ensure image file is deleted when NotesImage is deleted

* Add support for image upload in editor

* Skeleton for data migration

* Updates

* Update data migration

- Find any NoteImage items which do not link to a model
- Try to associate them with an existing note

* Remove validator

* Updated API endpoints for NotesImage model

* Update server side sanitizing

* Specify max field length

* Remove old fields from NotesImage model

* Refactor clean_string

* Remove obsolete task

* Remove legacy "notes" field from older models

* Adjust search params when switching notes

* Remove NotesFieldMixin

* Change editor

* Resizable image support

* Support tables

* Add table style

* Adjust header actions

* Add data migration for SalesOrderShipment notes

* Adjust back-end sanitizing

* Adjust

* Use subtle editor variant

* Move undo/redo

* Enhance editing logic

* Add report tags for notes

* Add unit test for note image cleanup

* Render note to HTML

- Automatically replace images

* Fix migration order

* Adjust migration text

* Fix "dirty" trigger on notes

* Prevent navigate from dirty notes

* Add documentation

* Prevent image clicking if not in editing mode

* Update API

* Update migration files

* Fix migrations

* remove notes from test fixtures

* remove notes field that does not exsist anymore

* add missing ruleset

* fix assertation

* fix assertation

* Update docs/docs/concepts/notes.md

Co-authored-by: Matthias Mair <code@mjmair.com>

* Remove blocknote deps

* Move old helper functions

- Only used for this migration
- Will potentially be removed at some point in the future?

* Revert change

* Fix note image URL

* Fix migration conflicts

* Fix migrations

* Fix delete call

* Fix content mixin

* Fix note duplication

* Make save method atomic

* Fix double-save

* Add "template" field to Note model

* Adjust migrations

* Frontend updates

* Fix for NotesEditor

* Render Note instance in forms

* Fix button-within-button

* Fix migrations

* Fix missing import

* add docs

* docs for rendering notes in reports

* Restrict queryset based on user view permissions

* APi unit tests for note permissions

* Duplicate embedded images when copying notes

* Add unit test for note duplication

* Add CHANGELOG

* Add 'copy_note' option to duplicate serializer

* Add unit tests for data migrations

* implement note duplication serializers

* frontend UI elements

* Fix migration conflicts

* Use branch for playwrigh testing

* Implement duplicate action for stock item

* Fix import

* Updated playwright tests

* Bug fix for receiving stock items

* Add screenshot

* Fix api_version

* Update unit tests

* Fix docs

* Remove defunct tests

* Fix migration order

* Adjust import/export workflow

* Manual cleaning update

* Fix migrations

* Fix migration files

* Fix for note save

* Adjust save ordering

* Skip constraint checking in NoteSerializer

* Custom validate_constraints on Note model

* Revert "Skip constraint checking in NoteSerializer"

This reverts commit b42bc955c1.

* Fix for note search

* Fix for receive_line_items

* Shim model renderer for NoteTemplate

* Fix playwright tests

* Adjust frontend CI

* Fix import/export CI job

* Fix for data migration test

* Fix migration test

* Adjust unit test

* Fix conflicting migration

* Fix unit test

* Run migration tests in parallel

* Robustify migration test

* Disable parallel options

* Fix conflicting migration

* Remove extraneous unit test

* Fix conflicting migrations

* Additional regression tests

* Check permissions before deleting Note instance

* Updated docs

* Validate note model type

* Prevent discard of unsaved changes in note editor

* Clean up dead code

* Fix migration conflict

* Improved data migration

* Prefetch role groups

* UI refactoring

* Refactor permission checking code

* Further code refactoring

* use DuplicateField helper

* Refactoring

* Add prefetch

* Throw exception rather than assert

* Logic fix for notes editor

* reimplement old background task

* Adjust data migration

* Fix notes field when receiving items

* Fix existing report templates

* Fix save action for notes editor

* Refactoring: Add "instance-info" API endpoint for common model properties

* Fix indicator dots

* Tweak nav alert msg

* Adjust layout of buttons

* Sanitize notes during migration

* Fix for NotesImage delete cascade

* Fix caching

* Fix race condition in notes editor

* Fix distinct issue when searching notse

* Fix race condition when saving new note instance

* Fix improper error

* Refactor StockItem duplication

* Refactoring

* Increase query time

* Fix api_version.py

* Additional migration tests

* Fix CI workflow

---------

Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-31 16:46:33 +10:00
Oliver d39d0262e6 [CI] Adjust query time threshold (#12748)
Allow larger buffer for test variation
2026-08-31 11:07:46 +10:00
Matthias Mair 4066fa6e0a feat(backend): add SCIM for user provisioning (#12713)
* Add SCIM
Closes https://github.com/inventree/InvenTree/issues/6339

* also test scim

* extend testing with conformance suite

* fix test suite results

* coverage completion

* fil test gaps

* add missing schema values

* fix more type issues

* fix error view

* remove route from OpenAPI

* add changelog entry

* add codeowners
2026-08-31 09:24:14 +10:00
Oliver c821fa0f43 Notification fix (#12744)
* Fill out stock location based on part default

* [UI] Bug fix for notifications

- Closes https://github.com/inventree/InvenTree/issues/12706
2026-08-30 15:53:16 +10:00
Oliver 871147d936 Stock location fix (#12742)
* Fill out stock location based on part default

* Add playwright tests
2026-08-30 11:44:07 +10:00
OliverandCopilot Autofix powered by AI a205717171 SSO e2e testing (#12739)
* Extend SSO auth workflows

* SSO e2e testing workflow

* Remove orphaned code

* Add unit tests for SSO

* improved error messaging

* Add test for SSO registration disabled

* Fix gating on LOGIN_ENABLE_SSO

* Adjust UI state management

* Add playwright test for SSO disabled

* Add backend unit tests

* Adjust API version

* Additional playwright tests

* Retain desired page state on login failure

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Adjust test code

* Stricter matcher checking

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-08-30 10:32:54 +10:00
Bhumin Paladiya 69afe7723f Enhance search and autocomplete fields across all InvenTree admin models (#12722)
* Fix PurchaseOrderExtraLine admin search and add search fields across admin classes

* Add search fields and autocomplete fields across common admin models

* Add search and autocomplete fields to importer admin models

* Add search fields to MachineConfigAdmin

* Add search fields to LocationTypeAdmin

* Remove search_fields from DataImportRowAdmin per review feedback
2026-08-29 20:24:49 +10:00
dependabot[bot]andMatthias Mair 02fc34083a chore(deps): bump the dependencies group across 2 directories with 16 updates (#12735)
* chore(deps): bump the dependencies group across 2 directories with 16 updates

Bumps the dependencies group with 1 update in the /docs directory: [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin).
Bumps the dependencies group with 15 updates in the /src/backend directory:

| Package | From | To |
| --- | --- | --- |
| [gunicorn](https://github.com/benoitc/gunicorn) | `26.0.0` | `26.1.0` |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.5.0` | `3.5.1` |
| [idna](https://github.com/kjd/idna) | `3.18` | `3.19` |
| [prek](https://github.com/j178/prek) | `0.4.13` | `0.4.14` |
| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |
| [types-pyyaml](https://github.com/python/typeshed) | `6.0.12.20260724` | `6.0.12.20260815` |
| [boto3](https://github.com/boto/boto3) | `1.43.71` | `1.43.77` |
| [botocore](https://github.com/boto/botocore) | `1.43.71` | `1.43.77` |
| [django-js-asset](https://github.com/feincms/django-js-asset) | `4.0.1` | `4.0.2` |
| [django-oauth-toolkit](https://github.com/django-oauth/django-oauth-toolkit) | `3.4.0` | `3.4.1` |
| [icalendar](https://github.com/collective/icalendar) | `7.2.2` | `7.3.0` |
| [lxml](https://github.com/lxml/lxml) | `6.1.1` | `6.1.2` |
| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.35.1` | `7.36.0` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |
| [webencodings](https://github.com/CourtBouillon/webencodings) | `0.5.1` | `0.6.1` |



Updates `mkdocs-git-revision-date-localized-plugin` from 1.5.3 to 1.5.4
- [Release notes](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin/releases)
- [Commits](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin/compare/v1.5.3...v1.5.4)

Updates `gunicorn` from 26.0.0 to 26.1.0
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](https://github.com/benoitc/gunicorn/compare/26.0.0...26.1.0)

Updates `charset-normalizer` from 3.5.0 to 3.5.1
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](https://github.com/jawah/charset_normalizer/compare/3.5.0...3.5.1)

Updates `idna` from 3.18 to 3.19
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](https://github.com/kjd/idna/compare/v3.18...v3.19)

Updates `prek` from 0.4.13 to 0.4.14
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](https://github.com/j178/prek/compare/v0.4.13...v0.4.14)

Updates `pygments` from 2.20.0 to 2.21.0
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](https://github.com/pygments/pygments/compare/2.20.0...2.21.0)

Updates `types-pyyaml` from 6.0.12.20260724 to 6.0.12.20260815
- [Commits](https://github.com/python/typeshed/commits)

Updates `boto3` from 1.43.71 to 1.43.77
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.71...1.43.77)

Updates `botocore` from 1.43.71 to 1.43.77
- [Commits](https://github.com/boto/botocore/compare/1.43.71...1.43.77)

Updates `django-js-asset` from 4.0.1 to 4.0.2
- [Changelog](https://github.com/feincms/django-js-asset/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/feincms/django-js-asset/compare/4.0.1...4.0.2)

Updates `django-oauth-toolkit` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/django-oauth/django-oauth-toolkit/releases)
- [Changelog](https://github.com/django-oauth/django-oauth-toolkit/blob/master/CHANGELOG.md)
- [Commits](https://github.com/django-oauth/django-oauth-toolkit/compare/3.4.0...3.4.1)

Updates `icalendar` from 7.2.2 to 7.3.0
- [Release notes](https://github.com/collective/icalendar/releases)
- [Changelog](https://github.com/collective/icalendar/blob/main/CHANGES.rst)
- [Commits](https://github.com/collective/icalendar/compare/v7.2.2...v7.3.0)

Updates `lxml` from 6.1.1 to 6.1.2
- [Release notes](https://github.com/lxml/lxml/releases)
- [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt)
- [Commits](https://github.com/lxml/lxml/compare/lxml-6.1.1...lxml-6.1.2)

Updates `protobuf` from 7.35.1 to 7.36.0
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Commits](https://github.com/protocolbuffers/protobuf/commits)

Updates `python-dotenv` from 1.2.2 to 1.2.3
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3)

Updates `webencodings` from 0.5.1 to 0.6.1
- [Release notes](https://github.com/CourtBouillon/webencodings/releases)
- [Changelog](https://github.com/CourtBouillon/webencodings/blob/main/docs/changelog.rst)
- [Commits](https://github.com/CourtBouillon/webencodings/compare/v0.5.1...v0.6.1)

---
updated-dependencies:
- dependency-name: mkdocs-git-revision-date-localized-plugin
  dependency-version: 1.5.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: gunicorn
  dependency-version: 26.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: charset-normalizer
  dependency-version: 3.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: idna
  dependency-version: '3.19'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: prek
  dependency-version: 0.4.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: pygments
  dependency-version: 2.21.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: types-pyyaml
  dependency-version: 6.0.12.20260815
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: boto3
  dependency-version: 1.43.77
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: botocore
  dependency-version: 1.43.77
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: django-js-asset
  dependency-version: 4.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: django-oauth-toolkit
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: icalendar
  dependency-version: 7.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: lxml
  dependency-version: 6.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: protobuf
  dependency-version: 7.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: python-dotenv
  dependency-version: 1.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: webencodings
  dependency-version: 0.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix style

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
2026-08-29 11:17:18 +10:00
Oliver fcbcef5aae Tracing fix (#12728)
* Bug fix for tracing setup

* Support forking against multiple PIDs

* Updated documentation
2026-08-29 08:05:16 +10:00
Matthias Mair 5244b8a4f2 [FR] add well-known mixin to let plugins define well-known urls (#12698)
* [FR] add well-known mixin to let plugins define well-known data entry points
Fixes #11741

* add built-in plugin for apis

* add test

* add decorator

* ignore default

* fix tests

* remove erronius decorator

* all well-known paths to security exception paths

* update test setup

* ignore escape paths

* add docs

* add more on security considerations

* add to nav
2026-08-28 16:43:20 +10:00
Oliver 0ee2ee9ec2 Update sentry.io integration (#12729) 2026-08-28 16:36:28 +10:00
Bhumin Paladiya 494fc58e7c Fix PurchaseOrderExtraLine admin search and add search fields across admin classes (#12721) 2026-08-28 09:01:05 +10:00
Alonso Lopez-ValdezandOliver af4c4220f5 update auto allocation button tooltip and visibility logic (#12720)
Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-28 08:59:23 +10:00
github-actions[bot] ccf34e4b16 New Crowdin translations by GitHub Action (#12701)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-27 16:06:15 +10:00
Oliver 2dca27f78b Fix race condition for take_stock method (#12718) 2026-08-27 15:01:20 +10:00
Oliver 39f2d724aa [UI] PO Receive bug (#12709)
* [UI] Fix for receiving items

* Add playwright regression test
2026-08-25 14:34:33 +10:00
Oliver a6687a6b10 Bug fix for APISearchView (#12707)
The global search endpoint dispatches to viewset-based result types using a bare HttpRequest() with an empty META, so pagination's build_absolute_uri() crashes on the missing SERVER_NAME.
2026-08-25 11:57:00 +10:00
dependabot[bot] 51a01149f8 chore(deps): bump the dependencies group across 1 directory with 3 updates (#12699)
Bumps the dependencies group with 3 updates in the /src/frontend directory: [@codemirror/view](https://github.com/codemirror/view), [dayjs](https://github.com/iamkun/dayjs) and [styled-components](https://github.com/styled-components/styled-components).


Updates `@codemirror/view` from 6.43.8 to 6.43.9
- [Changelog](https://github.com/codemirror/view/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/view/commits)

Updates `dayjs` from 1.11.21 to 1.11.23
- [Release notes](https://github.com/iamkun/dayjs/releases)
- [Changelog](https://github.com/iamkun/dayjs/blob/v1.11.23/CHANGELOG.md)
- [Commits](https://github.com/iamkun/dayjs/compare/v1.11.21...v1.11.23)

Updates `styled-components` from 6.5.1 to 6.5.3
- [Release notes](https://github.com/styled-components/styled-components/releases)
- [Commits](https://github.com/styled-components/styled-components/compare/styled-components@6.5.1...styled-components@6.5.3)

---
updated-dependencies:
- dependency-name: "@codemirror/view"
  dependency-version: 6.43.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: dayjs
  dependency-version: 1.11.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: styled-components
  dependency-version: 6.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 10:40:14 +10:00
dependabot[bot] 67cd3cbda7 chore(deps): bump the dependencies group with 3 updates (#12700)
Bumps the dependencies group with 3 updates: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action), [oasdiff/oasdiff-action/diff](https://github.com/oasdiff/oasdiff-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action).


Updates `docker/setup-buildx-action` from 4.2.0 to 4.3.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/bb05f3f5519dd87d3ba754cc423b652a5edd6d2c...37fe631027851001ddb9b187196cc803df7f5f0e)

Updates `oasdiff/oasdiff-action/diff` from 0.1.12 to 0.1.13
- [Release notes](https://github.com/oasdiff/oasdiff-action/releases)
- [Commits](https://github.com/oasdiff/oasdiff-action/compare/033c15c845bef10f148afb0fa781bf1b2a7fe1bf...2649ebe137aeb72a95707671204e829f86e091fc)

Updates `github/codeql-action/upload-sarif` from 4.37.6 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: oasdiff/oasdiff-action/diff
  dependency-version: 0.1.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 10:40:07 +10:00
James Todd 0ff2f7f3cb PluginDrawer now fetches plugin details itself. (#12703) 2026-08-25 09:00:39 +10:00
Oliver 176ef1af81 Fix table migration (#12697)
- Prevent error on MYSQL migration
2026-08-25 08:57:50 +10:00
github-actions[bot] 08b0bb8088 New Crowdin translations by GitHub Action (#12688)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-24 23:40:25 +10:00
Oliver 33586f6ea9 [bug] Fix broken build complete transition (#12696)
* Add regression test for build complete failure

* Handle offloading of complete_build

* Allow generic offloading of transitions to the background worker

* Refactor cancel_build method

* additional unit test
2026-08-24 23:40:07 +10:00
Oliver e12bdcfb69 [UI] Data import for order lines (#12692)
* [UI] Data import for order lines

* Adjust playwright tests
2026-08-24 22:20:18 +10:00
Oliver 528bb085d7 User permissions check for Attachment API (#12689) 2026-08-23 18:53:33 +10:00
Oliver f16fb36b08 Strip potentially dangerous tags from SVG files (#12687) 2026-08-23 18:50:13 +10:00
Oliver bc98e4bab6 Auto-extract StatusCode values for docs (#12686)
* Auto-extract StatusCode values for docs

* Extract user roles from code

* Fix links

* Remove extraneous source code in docs
2026-08-23 18:48:05 +10:00
github-actions[bot] f063a6c67f New Crowdin translations by GitHub Action (#12679)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-23 11:26:32 +10:00
ebd1b6e936 chore(deps): bump the dependencies group across 1 directory with 16 updates (#12680)
* chore(deps): bump the dependencies group across 1 directory with 16 updates

Bumps the dependencies group with 16 updates in the /src/backend directory:

| Package | From | To |
| --- | --- | --- |
| [setuptools](https://github.com/pypa/setuptools) | `83.0.0` | `84.0.0` |
| [wheel](https://github.com/pypa/wheel) | `0.47.0` | `0.48.0` |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.9` | `3.5.0` |
| [django-silk](https://github.com/jazzband/django-silk) | `5.5.0` | `5.5.2` |
| [django-stubs](https://github.com/typeddjango/django-stubs) | `6.0.9` | `6.1.0` |
| [django-stubs-ext](https://github.com/typeddjango/django-stubs) | `6.0.9` | `6.1.0` |
| [pip-tools](https://github.com/jazzband/pip-tools) | `7.6.0` | `7.6.1` |
| [prek](https://github.com/j178/prek) | `0.4.12` | `0.4.13` |
| [pytest-django](https://github.com/pytest-dev/pytest-django) | `4.13.0` | `4.14.0` |
| [boto3](https://github.com/boto/boto3) | `1.43.66` | `1.43.71` |
| [botocore](https://github.com/boto/botocore) | `1.43.66` | `1.43.71` |
| [django-q2](https://github.com/GDay/django-q2) | `1.10.0` | `1.11.0` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.0` | `4.11.3` |
| [pypdf](https://github.com/py-pdf/pypdf) | `6.15.0` | `6.16.1` |
| [pyphen](https://github.com/Kozea/Pyphen) | `0.17.2` | `0.18.1` |
| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.66.1` | `2.68.0` |



Updates `setuptools` from 83.0.0 to 84.0.0
- [Release notes](https://github.com/pypa/setuptools/releases)
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst)
- [Commits](https://github.com/pypa/setuptools/compare/v83.0.0...v84.0.0)

Updates `wheel` from 0.47.0 to 0.48.0
- [Release notes](https://github.com/pypa/wheel/releases)
- [Changelog](https://github.com/pypa/wheel/blob/main/docs/news.rst)
- [Commits](https://github.com/pypa/wheel/compare/0.47.0...0.48.0)

Updates `charset-normalizer` from 3.4.9 to 3.5.0
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](https://github.com/jawah/charset_normalizer/compare/3.4.9...3.5.0)

Updates `django-silk` from 5.5.0 to 5.5.2
- [Release notes](https://github.com/jazzband/django-silk/releases)
- [Changelog](https://github.com/jazzband/django-silk/blob/master/CHANGELOG.md)
- [Commits](https://github.com/jazzband/django-silk/compare/5.5.0...5.5.2)

Updates `django-stubs` from 6.0.9 to 6.1.0
- [Release notes](https://github.com/typeddjango/django-stubs/releases)
- [Commits](https://github.com/typeddjango/django-stubs/compare/6.0.9...6.1.0)

Updates `django-stubs-ext` from 6.0.9 to 6.1.0
- [Release notes](https://github.com/typeddjango/django-stubs/releases)
- [Commits](https://github.com/typeddjango/django-stubs/compare/6.0.9...6.1.0)

Updates `pip-tools` from 7.6.0 to 7.6.1
- [Release notes](https://github.com/jazzband/pip-tools/releases)
- [Changelog](https://github.com/jazzband/pip-tools/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jazzband/pip-tools/compare/v7.6.0...v7.6.1)

Updates `prek` from 0.4.12 to 0.4.13
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](https://github.com/j178/prek/compare/v0.4.12...v0.4.13)

Updates `pytest-django` from 4.13.0 to 4.14.0
- [Release notes](https://github.com/pytest-dev/pytest-django/releases)
- [Changelog](https://github.com/pytest-dev/pytest-django/blob/main/docs/changelog.rst)
- [Commits](https://github.com/pytest-dev/pytest-django/compare/v4.13.0...v4.14.0)

Updates `boto3` from 1.43.66 to 1.43.71
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.66...1.43.71)

Updates `botocore` from 1.43.66 to 1.43.71
- [Commits](https://github.com/boto/botocore/compare/1.43.66...1.43.71)

Updates `django-q2` from 1.10.0 to 1.11.0
- [Release notes](https://github.com/GDay/django-q2/releases)
- [Changelog](https://github.com/django-q2/django-q2/blob/master/CHANGELOG.md)
- [Commits](https://github.com/GDay/django-q2/compare/v1.10.0...v1.11.0)

Updates `platformdirs` from 4.11.0 to 4.11.3
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](https://github.com/tox-dev/platformdirs/compare/4.11.0...4.11.3)

Updates `pypdf` from 6.15.0 to 6.16.1
- [Release notes](https://github.com/py-pdf/pypdf/releases)
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md)
- [Commits](https://github.com/py-pdf/pypdf/compare/6.15.0...6.16.1)

Updates `pyphen` from 0.17.2 to 0.18.1
- [Release notes](https://github.com/Kozea/Pyphen/releases)
- [Changelog](https://github.com/Kozea/Pyphen/blob/main/docs/changelog.rst)
- [Commits](https://github.com/Kozea/Pyphen/compare/0.17.2...0.18.1)

Updates `sentry-sdk` from 2.66.1 to 2.68.0
- [Release notes](https://github.com/getsentry/sentry-python/releases)
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md)
- [Commits](https://github.com/getsentry/sentry-python/compare/2.66.1...2.68.0)

---
updated-dependencies:
- dependency-name: setuptools
  dependency-version: 84.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
- dependency-name: wheel
  dependency-version: 0.48.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: charset-normalizer
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: django-silk
  dependency-version: 5.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: django-stubs
  dependency-version: 6.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: django-stubs-ext
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: pip-tools
  dependency-version: 7.6.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: prek
  dependency-version: 0.4.13
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: pytest-django
  dependency-version: 4.14.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: boto3
  dependency-version: 1.43.71
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: botocore
  dependency-version: 1.43.71
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: django-q2
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: platformdirs
  dependency-version: 4.11.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: pypdf
  dependency-version: 6.16.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: pyphen
  dependency-version: 0.18.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: sentry-sdk
  dependency-version: 2.68.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix style

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Matthias Mair <code@mjmair.com>
Co-authored-by: Oliver <oliver.henry.walters@gmail.com>
2026-08-23 00:47:30 +10:00