Commit Graph

15857 Commits

Author SHA1 Message Date
github-actions 158f6846c3 Update source translation strings 2026-07-19 05:58:36 +00:00
bctiemann 0eb1fcc09c
Closes #22682: Fix CachedScopeMixin cache fields cascading on ancestor deletion (#22693)
CachedScopeMixin._region and ._site_group may cache ancestors of a
Site or Location scope. Change these relationships to SET_NULL so
deleting a Region or SiteGroup clears the cached value instead of
deleting the scoped Prefix, Cluster, or WirelessLAN.

Add reverse GenericRelation fields for Cluster and WirelessLAN on
Region and SiteGroup. This preserves the expected cascade when a
Region or SiteGroup is itself the direct scope, matching the existing
Prefix behavior.

Add migrations recording the ORM-level on_delete changes and regression
coverage for Site, Location, and direct Region/SiteGroup scopes.
2026-07-18 10:35:08 +02:00
github-actions 100589bf06 Update source translation strings 2026-07-18 05:44:18 +00:00
bctiemann 5d05fcc983
Merge pull request #22696 from netbox-community/21988-restrict-filtered-object-references
Fixes #21988: Enforce view permissions when referencing related object by attributes in REST API
2026-07-17 14:40:05 -04:00
Arthur Hanson 8aa39cf24b
Closes #22678: Add security note for Redis broker trust / RQ task deserialization (#22679) 2026-07-17 13:59:47 +02:00
bctiemann f0a58362f4
Closes #22687: Fix queryset truthiness check in RenderTemplateMixin.render_to_response() (#22689) 2026-07-16 15:17:21 -04:00
Jeremy Stretch e713b4fd07 Fixes #21988: Enforce view permissions when referencing related object by attributes in REST API 2026-07-16 11:38:33 -04:00
Jeremy Stretch 036456dc54 Revert "Merge pull request #22013 from netbox-community/21988-authorization-bypass-in-nested-object-resolution-via"
This reverts commit b3489cd529, reversing
changes made to 41f792c53b.
2026-07-16 10:15:51 -04:00
github-actions 6c501413ee Update source translation strings 2026-07-15 05:46:07 +00:00
bctiemann 425b70275e
Merge pull request #22676 from netbox-community/22675-rss
#22675 Validate RSS feed entry link schemes to prevent javascript: XSS
2026-07-14 22:18:07 -04:00
bctiemann 6068f41787
Merge pull request #22646 from netbox-community/20054-bulk-error-correlation
Closes #20054: Return per-object error details for failed bulk operations
2026-07-14 22:13:14 -04:00
bctiemann 63984e693c
Update netbox/netbox/api/viewsets/mixins.py
Co-authored-by: Jeremy Stretch <jstretch@netboxlabs.com>
2026-07-14 22:13:05 -04:00
bctiemann 3df0bc8e62
Update netbox/netbox/api/viewsets/mixins.py
Co-authored-by: Jeremy Stretch <jstretch@netboxlabs.com>
2026-07-14 22:12:28 -04:00
Sri Chandraja Reddy Allala 5198a640eb
Fix: Interface "Create & Add Another" does not pre-populate previous values (#22656) (#22680) 2026-07-14 17:25:43 -04:00
Arthur Hanson c1d8ff1216
#22644 Add ObjectChange to PortMapping (#22645) 2026-07-14 14:20:33 -07:00
bctiemann 16875c747c
Closes #22654: Redact install paths from debug tracebacks (#22655) 2026-07-14 15:44:19 -04:00
Brian Tiemann b61c232305 Return errors-only response for bulk operations, drop error_count
Rename the 'results' key to 'errors' and omit successful objects from
the bulk create/update/destroy error response, applied consistently
across all three mixins. len(errors) replaces the separate error_count
bookkeeping. Also change the ProtectedError/RestrictedError entry's
'detail' key to '__all__' to match the field-based error format used
by creates and updates, and correct a comment that implied bulk delete
enforces a permission boundary the single-object delete endpoint
doesn't actually have.

Addresses review feedback from @jeremystretch.
2026-07-14 14:19:08 -04:00
mburggraf ad054fc694
Fixes #22513: Make JournalEntry.created_by immutable after creation (#22547) 2026-07-14 10:46:53 -07:00
Martin Hauser 85ea61eb4f
Fixes #22565: Include Circuit distance in Cable Path length calculations (#22666) 2026-07-14 11:53:34 -05:00
bctiemann d13c98b9ea
Closes #19731: Add ModuleBayType to restrict which module types can be installed into a module bay (#22648)
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Closes #19731
2026-07-14 11:44:49 -05:00
Arthur aa3b570219 #22675 Validate RSS feed entry link schemes to prevent javascript: XSS 2026-07-14 09:31:51 -07:00
Martin Hauser bd562dd5c7
Fixes #22662: Fix database overflow when saving Cables with large lengths (#22668) 2026-07-14 11:25:56 -05:00
Arthur 31301cdb95 #22675 Validate RSS feed entry link schemes to prevent javascript: XSS 2026-07-14 09:17:02 -07:00
Arthur 9cf75b60c1 #22675 Validate RSS feed entry link schemes to prevent javascript: XSS 2026-07-14 09:13:29 -07:00
Jeremy Stretch ebee3578b9 Release v4.6.5 2026-07-14 08:45:54 -04:00
github-actions bc666ed226 Update source translation strings 2026-07-14 05:45:35 +00:00
JCWasmx86 c475cd12b7 chore(netbox): Cache serializers
Co-authored-by: Jeremy Stretch <jstretch@netboxlabs.com>
2026-07-13 17:54:11 -04:00
Martin Hauser 48ecc712bc
Closes #22603: Add experimental Python packaging support for NetBox (#22605)
Add initial Python package support for NetBox, including wheel and sdist
builds, generated package metadata, and Test PyPI publishing for maintainer
validation.

Add package-aware CLI support, `netbox setup` scaffolding for instance-local
files, and centralized wheel-vs-checkout path handling while preserving the
existing source/archive install layout.

Bundle pre-rendered embedded documentation in the wheel, and extend CI to
verify dependency pins, wheel metadata, artifact contents, CLI behavior, sdist
rebuilds, and smoke-test upgrades.
2026-07-13 16:28:04 +02:00
github-actions 84bbaaa5a0 Update source translation strings 2026-07-12 05:59:57 +00:00
bctiemann ca7caecac5
Closes #22652: Disable autoescaping for Config Templates (#22653)
Force autoescape=False in ConfigTemplate.get_environment_params() after
merging user-supplied environment parameters. Config templates produce
plain-text network configurations and scripts, so HTML autoescaping is
not applicable.

Keep the override out of the shared render_jinja2() helper so export
templates can continue to use autoescape=True for HTML output. Add
regression coverage for both behaviors.
2026-07-11 18:37:52 +02:00
bctiemann d88b6a65dd
Closes #18159: Expose snapshots to Event Rule condition evaluation (#22637)
Expose an event's prechange and postchange snapshots to event rule
condition evaluation, making snapshots.prechange.<attr> and
snapshots.postchange.<attr> available through the existing dot-path
syntax.

Add changed and unchanged snapshot operators for comparing an attribute
across the two snapshots without requiring a condition value. These
operators support rules such as firing only when a field transitions to a
specific state.

Make condition values optional only for snapshot operators by introducing
a missing-value sentinel, while preserving value requirements for all
other operators. Reject invalid combinations such as using changed or
unchanged with an explicit value or with an attr starting with snapshots.

Fail closed when condition paths traverse invalid snapshot structures,
including raw scalar snapshot values such as status strings, by treating
unresolvable snapshot-operator paths as missing and converting invalid
direct paths to InvalidCondition.

Document the new snapshot path syntax, changed and unchanged operators,
create/delete snapshot behavior, and the serialization differences
between snapshot data and REST API data. Add regression and integration
tests covering validation, transition behavior, null snapshot edge cases,
direct snapshot paths, and event rule evaluation.
2026-07-11 18:32:22 +02:00
github-actions f250586b4c Update source translation strings 2026-07-11 05:50:53 +00:00
Martin Hauser 8e525c89fb
feat(dcim): Support multiple Terminations per side in Cable bulk import (#22641)
Enable comma-separated Device, Power Panel, and Termination name lists
in Cable CSV/JSON/YAML imports. Each side accepts either one parent for
all terminations or one parent per name, preserving submission order for
connector assignment.

Add validation for duplicate terminations, empty names, parent count
mismatches, and MultipleObjectsReturned cases. Change side_a/b_device
and side_a/b_power_panel fields from CSVModelChoiceField to
CSVModelMultipleChoiceField with updated help text.

Fixes #18645
2026-07-10 10:27:31 -07:00
bctiemann a5071064d7
Merge pull request #22650 from netbox-community/22544-provide-a-rest-api-method-to-updateoverwrite-an-existing
Closes: #22544: Add support for updating Custom Script Modules via REST API
2026-07-10 13:14:55 -04:00
bctiemann 6ec79402cc
Closes #22657: escape exception message in render_widget before mark_safe (#22658) 2026-07-10 10:26:40 -05:00
Martin Hauser a0debf0e3b
feat(extras): Allow updating uploaded Script Modules via API
Add PUT/PATCH support to ScriptModuleViewSet for replacing Script Module
content in place. Modules can be addressed by numeric ID or file name,
and the uploaded file name must match the existing file path.
The module's scripts are re-synchronized from the new content after
successful update.

Fixes #22544
2026-07-10 13:18:36 +02:00
github-actions 817b35de49 Update source translation strings 2026-07-10 06:17:51 +00:00
Brian Tiemann 48e08779d1 Drop explicit status key from bulk operation results
Success is now inferred from the absence of an errors key, matching
Jeremy's suggestion. Error entries carry only {id/index, errors};
successful entries carry only {id/index}. Update all tests accordingly.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-09 15:24:09 -04:00
Brian Tiemann 3c77972f59 Address review feedback on bulk operation mixins
- Move single-object create back inside transaction.atomic() (comment 1)
- Replace repeated result-list iterations with local error_count counters
  in create(), perform_bulk_update(), and perform_bulk_destroy() (comments 3, 4, 6)
- Rewrite perform_bulk_update() from two-pass (validate-all, save-all) to
  sequential per-object validate+save, matching SequentialBulkCreatesMixin;
  subsequent validators now see DB state from prior saves so cross-object
  uniqueness conflicts are caught at validation time (comment 5)
- Update bulk_update() and bulk_destroy() callers to unpack new return tuples
  and use the counters directly

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-09 15:08:00 -04:00
bctiemann 517804758f
Merge pull request #22634 from netbox-community/22205-eol
#22205 - Add EOL to DeviceType, ModuleType
2026-07-09 14:50:14 -04:00
Jeremy Stretch feeff9c376
Closes #22649: Add Korean language support (#22651) 2026-07-09 08:48:21 -07:00
github-actions ff50ad8ae2 Update source translation strings 2026-07-09 06:18:24 +00:00
Brian Tiemann d1310ed580 Address PR #22646 review findings from automated reviewer
- Security: remove object names/PKs from ProtectedError detail; report count only
  to avoid exposing objects the caller may lack permission to view
- i18n: wrap new error detail strings with _().format() to match codebase convention
- Redundancy: remove superfluous `results and` guard in bulk_destroy (any() on an
  empty list already returns False)
- Comment: explain that SequentialBulkCreatesMixin continues provisionally creating
  after a failure so cross-object validators see a realistic state

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-08 18:42:05 -04:00
Brian Tiemann 94197efcfb Improve test_bulk_create_objects_validation_error with mixed ok/error case
Use a valid first item (create_data[0]) alongside an invalid second item ({})
so the test exercises both the 'ok' result shape and the atomic rollback of an
item that would otherwise have been persisted.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-08 18:11:34 -04:00
Brian Tiemann d8506f178e Address PR review feedback for #20054 bulk error correlation
- Use pre-captured `pk` consistently in perform_bulk_destroy error path
- Add comment clarifying the `if results:` sentinel in bulk_update
- Add per-field atomicity assertion to test_bulk_update_objects_validation_error
- Use ID-keyed dict instead of positional index in test_bulk_delete_objects_protected

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-08 18:04:44 -04:00
Brian Tiemann 3d8f8289d9 Closes #20054: Return per-object error details for failed bulk operations
Bulk update (PATCH), sequential bulk create (POST), and bulk delete (DELETE) on
list endpoints now collect per-object errors instead of aborting on the first
failure. When any objects fail, the entire operation is rolled back atomically
and a 400/409 response is returned with a structured payload:

  {
    "detail": "1 of 3 objects failed validation.",
    "results": [
      {"id": 1, "status": "ok"},
      {"id": 2, "status": "error", "errors": {"name": ["..."]}},
      {"id": 3, "status": "ok"}
    ]
  }

For bulk creates via SequentialBulkCreatesMixin the correlator is "index"
(zero-based position in the request list) since no IDs exist yet. For bulk
delete the status code remains 409 and the correlator is "id".

Successful operations are unchanged (200/201/204).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-08 17:10:25 -04:00
Arthur Hanson c3bc1fb04a
#22231 - Add nulls-first parameter for custom field ordering (#22476) 2026-07-08 11:45:53 -07:00
Arthur f9b5df87c5 fix 2026-07-08 10:45:34 -07:00
Jeremy Stretch 1391e5185f
Closes #22636: Feature plugins in the README & installation docs (#22638) 2026-07-08 09:37:32 -07:00
bctiemann 800db5727f
Closes #18821: Simplify setting/updating primary MAC through interface model (#22520) 2026-07-08 09:31:16 -07:00