Commit Graph

15879 Commits

Author SHA1 Message Date
github-actions 17a15204de Update source translation strings 2026-09-16 05:02:53 +00:00
Jeremy Stretch abccf4e036
Release v4.7.1 (#23179) 2026-09-15 14:35:13 -04:00
Jeremy Stretch a4ade2e7ae
Fixes #23112: Initiate SSO logins via a script-driven navigation (#23177)
Rendering the SSO buttons as POST forms (#23042) made every SSO login a form
submission which NetBox answers with a redirect to the identity provider.
Chromium-based browsers evaluate the CSP form-action directive against every hop
in a form submission's redirect chain, so a deployment which serves NetBox with
`form-action 'self'` blocks that redirect and the button silently does nothing.

Add SocialAuthBeginView, which wraps python-social-auth's begin view and returns
the identity provider's URL as JSON to clients which request it. The login page
now submits the form via fetch() and assigns window.location, which form-action
does not govern. The upstream view is reused as-is, so CSRF protection, the
callback URL, and the session state recorded for the identity provider are
unchanged; clients which do not request JSON (a browser without JavaScript, or a
backend which renders an HTML form rather than redirecting) receive the
unmodified response as before.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-15 13:00:11 -04:00
Jason Novinger e15b3d9080
Fixes #23166: Apply zero-valued numeric bounds to profile attribute form fields 2026-09-15 11:08:58 -04:00
Jeremy Stretch 74fbc90c69 Closes #23110: Upgrade to redis 8.1 2026-09-15 11:01:39 -04:00
bctiemann 1793874dd9
Merge pull request #23174 from netbox-community/23167-module-type-profile-desc-not-sanitized
Fixes #23167: Sanitize JSON schema property descriptions used as form help text
2026-09-15 10:30:35 -04:00
bctiemann 321a2fbf26
Fixes #23154: Correct required=False mismatch on L2VPN.type and RackType.form_factor (#23175) 2026-09-15 09:01:46 -05:00
github-actions 9fcd744c90 Update source translation strings 2026-09-15 05:02:23 +00:00
Jason Novinger f96e6f86b9 Assert the full help text rather than a fragment of it
The sanitization tests used `assertInHTML`, which checks containment. Each
needle happened to span the whole output, so they passed, but a payload
surviving outside the `rendered-markdown` div would not have failed them.
`assertHTMLEqual` is what the docstring already claimed these tests did.
2026-09-14 12:24:02 -05:00
Jason Novinger 8e68d91124 Fixes #23167: Sanitize JSON schema property descriptions used as form help text
`JSONSchemaProperty.to_form_field()` assigned a schema property's description
directly to the form field's `help_text`, which `form_helpers/render_field.html`
renders through the safe filter. Any element a module type profile schema
author put in a property description reached the DOM intact, including ones
outside `HTML_ALLOWED_TAGS`.

Pass the description through `render_markdown()`, which applies the allowlist
via `clean_html()` before `mark_safe()`. This matches how custom field
descriptions are handled in `CustomField.to_form_field()`, so both kinds of
user-defined attribute render their help text the same way.

Descriptions stored since v4.3.0 are now interpreted as Markdown, so one
beginning with "#" renders as a heading and one beginning with "1." renders
as a list item. Custom field descriptions took the same change in #12685.

Sanitizing inside `to_form_field()` rather than at the call site in
`dcim/forms/model_forms.py` means plugins calling this utility are covered too.
2026-09-14 11:52:53 -05:00
Jason Novinger fc5172f170
Closes #22999: Add a default module profile for transceivers (#23165) 2026-09-14 09:00:37 -07:00
Jason Novinger 9d96894f4e
Fixes #23130: Ensure ltree cascade triggers can be restored from a pg_dump (#23137) 2026-09-14 10:35:05 -05:00
Jason Novinger 64ce9e2db4
Closes #23041: Add InfiniBand 2X interface types (#23163)
Add a 2X (two-lane) InfiniBand group for HDR and later generations, covering
the HDR100, NDR200, and XDR400 breakout links formed by splitting a four-lane
port into two independent two-lane links.

SDR through EDR are omitted deliberately: two-lane breakout only became a
shipping configuration once per-lane rates reached 50 Gbps, so there are no
corresponding products at those generations.
2026-09-14 08:20:07 -07:00
bctiemann 07975fda34
Merge pull request #23164 from netbox-community/23012-eszett-in-search
Fixes #23012: Respect column collation when filtering case-insensitively
2026-09-11 05:26:23 -04:00
Jason Novinger 9782be4cd5 Assert the collation reaches the query, and clarify the documented behaviour
The existing tests assert on filter results, which stay correct for ASCII values
even when the collation is never applied. Add a test which asserts on the
lookup's own compiled output, so that the mechanism failing open is caught
rather than passing silently.

Explain why the placeholder is compared literally: a field declaring its own
get_placeholder() compiles to something other than '%s', and splicing a COLLATE
clause into that is not safe, so any other right-hand side is left alone.

The documentation note described the folding as specific to the German
eszett. It is the common example rather than the rule: the collation treats a
character as equivalent to the sequence it expands to in upper case, which also
covers ligatures. Note too that a case-insensitive exact match on a collated
field may now return more than one object.
2026-09-11 03:50:47 -05:00
Jason Novinger 2769e3d9d9 Fixes #23012: Respect column collation when filtering case-insensitively
Django's PostgreSQL backend compiles icontains, iexact, istartswith and
iendswith as UPPER(col::text) LIKE UPPER(%s). UPPER() folds according to the
collation of its argument, and the two sides do not share one: the column folds
under its own collation while the parameter folds under the database default.

For a column using natural_sort, UPPER('ß') is 'SS' on the left and 'ß' on the
right, so searching for 'ß' matched nothing. This affects the name field of most
models and all four case-insensitive lookups, which are also exposed through the
REST API as __ic, __ie, __isw and __iew.

Apply the column's collation to the parameter as well, inside the UPPER() call,
so that both sides fold the same way. Matching on those fields becomes
bidirectional, so 'Strasse' finds 'Straße' and vice versa. Fields without the
collation are unchanged.

The lookups only collate a bare column compared against a simple value. An
expression which already carries an explicit collation, such as Collate() or
CollateAsChar(), would otherwise raise a collation mismatch error.
2026-09-11 03:18:31 -05:00
github-actions 6385c09837 Update source translation strings 2026-09-10 05:02:27 +00:00
bctiemann 5de246563b
Merge pull request #23144 from netbox-community/23096-partial-cable-length-saves-leave-the-normalized-length-out
Fixes #23096: Keep normalized cable length in sync during partial saves
2026-09-09 14:03:29 -04:00
github-actions d2191e0fb3 Update source translation strings 2026-09-09 05:02:18 +00:00
Martin Hauser dfb99e1f69
Fixes #23125: Add missing standard REST API fields for VLAN Translation Policies and Rules (#23127) 2026-09-08 13:40:29 -05:00
Martin Hauser 90675dbbab
fix(dcim): Persist normalized cable length on partial saves
Cable.save() recomputed _abs_length in memory but never added it to
update_fields, so a save naming length or length_unit left the stored
normalized value stale. Derive it from the values the row will hold
after the save and persist it alongside its source fields.

Fixes #23096
2026-09-08 18:53:51 +02:00
Martin Hauser 7b56158d47
Closes #23145: Prevent advisory lock cleanup races in Custom Field tests (#23146) 2026-09-08 11:43:20 -05:00
Martin Hauser 7ae8e4461f
fix(filters): Preserve contains lookup for negated multiselect filters (#23128)
Add FILTER_ARRAY_BASED_LOOKUP_MAP to maintain 'contains' lookup under
negation for MultiValueArrayFilter, preventing fallback to exact match.
Negation now correctly excludes objects whose array contains the value
rather than matching it exactly.

Fixes #23117
2026-09-08 08:43:08 -07:00
Martin Hauser 5685c5218e
Revert "Fixes #23097: Prevent duplicate Cable Paths when Cable Terminations …" (#23149)
This reverts commit 1745a7d9aa.
2026-09-08 17:25:35 +02:00
Martin Hauser 6895fb76c0
Fixes #23120: Fix REST API serialization and assignment of Data Source tags (#23126) 2026-09-08 09:44:47 -05:00
github-actions 46b6a17ae0 Update source translation strings 2026-09-08 05:02:43 +00:00
Arthur Hanson c9a62254d7
Fixes #22750: Validate Custom Script input and resolve object IDs in the REST API (#23119)
Validate REST script input before enqueueing jobs. Resolve ObjectVar
IDs to model instances and MultiObjectVar IDs to querysets, returning
HTTP 400 with errors nested under data when validation fails.

Share form preparation between the API and UI, including multi-value
defaults, while keeping validation out of the job runner to preserve
other execution paths. Exclude only known execution fields from script
data and prevent _notifications from leaking into CLI script input.

Document the REST compatibility changes, including required-field
validation and discarded undeclared keys. Add regression coverage for
object resolution, defaults, validation errors, and execution options.

Co-authored-by: Martin Burggraf <martin.burggraf@netclusive.com>
2026-09-07 13:11:14 +02:00
github-actions eaf30a6fb0 Update source translation strings 2026-09-05 05:02:38 +00:00
Martin Hauser 1745a7d9aa
Fixes #23097: Prevent duplicate Cable Paths when Cable Terminations are unchanged (#23100)
* fix(dcim): Prevent path rebuild when Cable Terminations unchanged

Compare Cable Terminations against stored values instead of the empty
cache when checking for modifications, so a freshly loaded Cable that is
resaved with the same terminations no longer rebuilds its paths. Raise
the flag whenever update_terminations() force-recreates an end, since
the edit form warms the cache that gated it and a profile change then
tore every path down without rebuilding it. Add regression tests for
both.

Fixes #23097

* fix(dcim): Preserve cable end order when terminations unchanged

Compare cable terminations against stored values instead of potentially
stale prefetched relations when checking for modifications. Skip setting
terminations in the form's clean() when a saved cable's members are
unchanged, preserving the connector order assigned by the profile.
2026-09-04 14:02:59 -04:00
Jason Novinger 2d519ece58 Fixes #22569: Ensures that Script Run OpenAPI operation is present
Does two things:
1. Adds a regression test to ensure that the `extras_scripts_run`
   operation is always present in contrib/openapi.json. This has
   regressed at least once since original implementation, so I wanted to
   make sure we catch it quickly in the future.
2. Overrides the Django `CACHES` setting for the OpenAPISchemaTestCase,
   which contains the new test, so that caching of the schema is
   disabled. This caused problems by masking whether or not the
   regression test (and other existing tests) were failing/succeeding in
   response to changes or not.
2026-09-03 08:55:12 -04:00
Jeremy Stretch 5f06007e4c Release v4.7.0 2026-09-02 14:40:04 -04:00
github-actions 8974a98317 Update source translation strings 2026-09-02 16:46:35 +00:00
Jeremy Stretch 8cc4548e1f
Merge pull request #23103 from netbox-community/feature
Merge `feature` into `main`
2026-09-02 12:31:21 -04:00
Martin Hauser 1afaf2de06 fix(templates): Update PostgreSQL version requirement to 15
Updates exception message to reflect PostgreSQL 15 as the minimum
supported version instead of version 14.
2026-09-02 12:15:02 -04:00
Jeremy Stretch a4ff5c7c28
Restore v4.6 migration ordering (#23107) 2026-09-02 17:31:25 +02:00
Jeremy Stretch dcd20089ba
Fix cross-worker cache contamination in parallel test runs (#23106)
RQQueueTestMixin cleared RQ queues with FLUSHALL, which empties every
database on the Redis server — including the caching database, whose
'config'/'config_version' keys are shared by all parallel test workers.
A flush landing mid-test forces an unrelated worker to re-read
core_configrevision, adding two queries to the affected request. Flush
only the queue's own database instead.

Also stop GraphQLDeferredColumnTestCase from comparing total query counts
between two requests, which is what surfaced the race as intermittent
"Query count grew from 7 to 9" failures in CI. Assert that the target
table is read exactly once per request instead, as #23034 did for the
equivalent custom fields test.
2026-09-02 15:47:34 +02:00
github-actions 1fae2d0111 Update source translation strings 2026-09-02 05:02:56 +00:00
Jeremy Stretch 56693d62ae Merge branch 'main' into feature
# Conflicts:
#	contrib/openapi.json
#	netbox/core/forms/filtersets.py
#	netbox/core/tests/test_openapi_schema.py
#	netbox/dcim/forms/mixins.py
#	netbox/extras/events.py
#	netbox/ipam/forms/bulk_edit.py
#	netbox/ipam/forms/model_forms.py
#	netbox/ipam/models/services.py
#	netbox/ipam/tests/test_forms.py
#	netbox/ipam/tests/test_models.py
#	netbox/ipam/tests/test_views.py
#	netbox/netbox/jobs.py
#	netbox/project-static/dist/netbox.js
#	netbox/project-static/dist/netbox.js.map
#	netbox/release.yaml
#	requirements.txt
2026-09-01 16:46:44 -04:00
Jeremy Stretch 560da79ea1 Release v4.6.10 2026-09-01 15:07:36 -04:00
Martin Hauser 9aa0c5c605
Fixes #23072: Rebuild cable paths when applying or changing a cable profile (#23091)
Set `_terminations_modified` flag when recreating terminations to ensure
paths are rebuilt even when endpoints remain unchanged.
Reset `_orig_status`, `_orig_profile`, and `_terminations_modified`
after saving a cable to prevent repeated saves from recreating
terminations and paths.
Add comprehensive test coverage for profile changes, trunk regrouping,
and mid-span cables.
2026-09-01 17:46:17 +02:00
Jeremy Stretch 6345ed1de2
Misc. cleanup ahead of the v4.7.0 release (#23084) 2026-09-01 08:32:44 -07:00
Jeremy Stretch 4d8c0bf80c
Fix omission of Service protocol field from the OpenAPI request schema (#23085) 2026-09-01 08:32:00 -07:00
Jason Novinger a39d5626fe
Closes #22872: Validate custom script Meta values before enqueueing (#23068)
Validate the effective timeout and notification settings at the
ScriptJob enqueue boundary so invalid script configuration is reported
consistently across all execution paths instead of raising an unhandled
exception.

Preserve the inherited positional enqueue contract and prevent tests
from interfering through shared RQ queue state during parallel runs.
2026-09-01 16:35:09 +02:00
Jeremy Stretch f535a47db2
Fixes #23090: Fix filtering of jobs by user in UI (#23092) 2026-09-01 15:41:21 +02:00
bctiemann f66ce9818a
Merge pull request #23071 from netbox-community/22989-nested-schema-components
Closes #22989: Reference brief components for nested SerializedPKRelatedField
2026-09-01 08:24:26 -04:00
github-actions cc112619ae Update source translation strings 2026-09-01 05:02:13 +00:00
Martin Hauser f64bf0b217 fix(models): Normalize update_fields to prevent iterable consumption
Introduces normalize_update_fields() utility to materialize one-shot
iterables like generators into frozensets, preventing bugs in save()
overrides that perform membership tests. Fixes channelization cascades,
module moves, and ltree parent tracking when using generator
expressions.

Fixes #23074
2026-08-31 13:50:59 -04:00
Martin Hauser 2b3b9e62e7
perf(api): Prefetch reverse many-to-many serializer fields (#23064)
Recognize Django's ManyToManyRel in get_prefetches_for_serializer().
Because it is a sibling of ManyToOneRel rather than a subclass, reverse
many-to-many accessors were omitted from the generated prefetch paths and
fetched once per serialized object.

Add regression coverage for both automatically generated fields and
SerializedPKRelatedField(many=True), and regenerate the affected ASN and
ObjectPermission API query-count baselines.

Fixes #23060
2026-08-31 10:15:21 -07:00
Martin Hauser 0f22d67617 fix(models): Normalize update_fields to prevent generator consumption
Introduce `normalize_update_fields()` utility to convert update_fields
to frozenset, preventing one-shot iterables from being consumed during
membership tests. Update Service, VLANGroup, and CircuitTermination
save methods to use normalized fields. Add comprehensive test coverage.

Fixes generator exhaustion when save() overrides check field membership
before persisting denormalized caches alongside their source fields.

Fixes #23078
2026-08-31 12:48:51 -04:00
Martin Hauser 60f80c8ad2 fix(forms): Assign scope before validation in ScopedForm mixin
Move scope assignment before validation to prevent stale scope values
on instances when validation fails. Refactor VLANGroupForm to inherit
from ScopedForm, removing duplicate scope handling code. Add test
coverage for scope type changes and validation errors.

Fixes #23040
2026-08-31 12:36:11 -04:00