Commit Graph
1868 Commits
Author SHA1 Message Date
eitchtee 5a1c0ab818 chore(locale): update translation files
[skip ci] Automatically generated by Django makemessages workflow
2026-09-12 21:03:37 +00:00
Herculino Trotta f32805ba02 Merge pull request #602
feat(insights): replace fixed overviews with a single arrangeable overview
2026-09-12 18:03:14 -03:00
Herculino Trotta 82211567d0 feat(insights): replace fixed overviews with a single arrangeable overview
Categories, Tags and Entities Overview are merged into one Overview page.
Levels are chips that can be dragged (or moved with the arrow keys) to set
the hierarchy and clicked to switch off, so any ordering of the three is
reachable from the same page.

Only the results reload on change; the controls stay in place. The chip
order is kept in the session and defaults to categories by tags, matching
the old Categories Overview.
2026-09-12 18:02:24 -03:00
Herculino Trotta a39ee4b5d2 build(frontend): add @alpinejs/sort for drag sorting 2026-09-12 18:02:24 -03:00
eitchtee 398c783b53 chore(locale): update translation files
[skip ci] Automatically generated by Django makemessages workflow
2026-09-12 20:35:49 +00:00
Herculino Trotta d67482e9c6 Merge pull request #601 from eitchtee/dev
fix(ui): reserve scrollbar space to prevent layout shift
2026-09-12 17:35:15 -03:00
Herculino Trotta fef5c48077 fix(ui): reserve scrollbar space to prevent layout shift 2026-09-12 17:33:16 -03:00
Herculino Trotta 3a5e688a90 feat(insights): add tags and entities overview 2026-09-12 14:31:12 -03:00
eitchtee 4569dc6fdc chore(locale): update translation files
[skip ci] Automatically generated by Django makemessages workflow
2026-09-12 17:16:12 +00:00
Herculino Trotta 6bf335169c Merge pull request #600
feat(insights: categories-overview): searching shows the imedaite parents and children to provide better context
2026-09-12 14:15:52 -03:00
Herculino Trotta 5404716a81 feat(insights: categories-overview): searching shows the imedaite parents and children to provide better context 2026-09-12 14:15:31 -03:00
eitchtee fa05538c56 chore(locale): update translation files
[skip ci] Automatically generated by Django makemessages workflow
2026-09-12 16:46:42 +00:00
Herculino Trotta d77600add6 Merge pull request #599
feat(ui:transaction): deleting transactions is smoother and no longer requires a full list refresh
2026-09-12 13:46:03 -03:00
Herculino Trotta 52fe81f564 feat(ui:transaction): deleting transactions is smoother and no longer requires a full list refresh 2026-09-12 13:45:41 -03:00
eitchtee c3773ccd3a chore(locale): update translation files
[skip ci] Automatically generated by Django makemessages workflow
2026-09-12 15:07:56 +00:00
Herculino Trotta b2d29071f0 Merge pull request #598
feat(ui:filter): add quick clear button to filter button
2026-09-12 12:07:28 -03:00
Herculino Trotta 0ab2a41ccc feat(ui:filter): add quick clear button to filter button 2026-09-12 12:06:55 -03:00
eitchtee e892bfd3da chore(locale): update translation files
[skip ci] Automatically generated by Django makemessages workflow
2026-09-12 13:00:41 +00:00
Herculino Trotta c9133c559f Merge pull request #597
fix(ui): daily spending help text not showing up
2026-09-12 10:00:14 -03:00
Herculino Trotta 258254017f Merge pull request #596
Translations update from Weblate
2026-09-12 09:58:09 -03:00
Herculino Trotta 721b2dcd8d fix(ui): daily spending help text not showing up 2026-09-12 09:57:30 -03:00
Dimitri Decrock bed2b1d516 locale(Dutch): update translation
Currently translated at 100.0% (785 of 785 strings)

Translation: WYGIWYH/App
Translate-URL: https://translations.herculino.com/projects/wygiwyh/app/nl/
2026-09-07 16:57:24 +00:00
Herculino Trotta d500bef481 ci(translations): drop force push to protected main
Branch protection rejects force pushes to main (GH006), so the
translation commit never landed. The push is a fast-forward anyway.
0.23.1
2026-09-06 16:53:57 -03:00
eitchtee f280fcb172 chore(locale): update translation files
[skip ci] Automatically generated by Django makemessages workflow
2026-09-06 19:42:46 +00:00
Herculino Trotta 6c808eff38 Merge pull request #593 from eitchtee/dependabot/uv/djangorestframework-3.17.2
build(deps): bump djangorestframework from 3.17.1 to 3.17.2
2026-09-06 16:41:50 -03:00
Herculino Trotta 1690a153f9 Merge pull request #594 from eitchtee/dependabot/npm_and_yarn/frontend/browserslist-4.28.8
build(deps): bump browserslist from 4.28.2 to 4.28.8 in /frontend
2026-09-06 16:41:41 -03:00
Herculino Trotta 7116176c78 Merge pull request #595 from eitchtee/dependabot/uv/mistune-3.3.3
build(deps): bump mistune from 3.3.0 to 3.3.3
2026-09-06 16:41:15 -03:00
Herculino Trotta d9c9cbe7c3 Merge pull request #592 from hackking007/fix/owner-scoped-transaction-rule-endpoints
fix: BOLA on transaction-rule endpoints via get_owned_object_or_403
2026-09-06 16:41:00 -03:00
dependabot[bot] 11b03474c1 build(deps): bump mistune from 3.3.0 to 3.3.3
Bumps [mistune](https://github.com/lepture/mistune) from 3.3.0 to 3.3.3.
- [Release notes](https://github.com/lepture/mistune/releases)
- [Changelog](https://github.com/lepture/mistune/blob/main/docs/changes.rst)
- [Commits](https://github.com/lepture/mistune/compare/v3.3.0...v3.3.3)

---
updated-dependencies:
- dependency-name: mistune
  dependency-version: 3.3.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-02 16:45:07 +00:00
Herculino Trotta e2f26b3629 fix(sharing): enforce object-level authorization outside the rules app
The rules endpoints were one instance of a pattern repeated across every
SharedObject-backed app. Route the rest through the same helper.

DCA entries were the worst case and are strictly wider than the reported
rules bug: DCAEntry has an unscoped default manager, so filtering by
strategy__id alone reached entries on strategies the caller could not see
at all. No public or shared strategy was needed -- only a guessable
integer. strategy_entry_add/edit/delete now resolve through the parent
strategy with via="strategy".

Every SharedObject delete view carried an inverted condition:

    if obj.owner != request.user and request.user in obj.shared_with.all():
        obj.shared_with.remove(request.user)
    else:
        obj.delete()

An object its owner had made public matched neither branch's intent and
fell through to delete(), so any authenticated user could destroy it.
Confirmed reachable for accounts, account groups, categories, tags,
entities and DCA strategies. The owner now deletes, a shared user revokes
only their own access, and anyone else gets a 403.

The API viewsets had no object-level check at all. DjangoModelPermissions
gated them shut for ordinary users, who hold no model permissions, so this
was not reachable in a default install -- but the check belongs there
regardless, and a user granted change_account in the admin could write any
visible account. SharedObjectPermission adds it for the SharedObject
viewsets, leaving reads to SharedObjectManager.

account_toggle_untracked only flips the calling user's own row in the
untracked_by m2m, so it takes READ rather than EDIT.

Refs GHSA-83g9-vjqf-2j5q
2026-09-01 23:15:41 -03:00
dependabot[bot] 10c8fcfb97 build(deps): bump browserslist from 4.28.2 to 4.28.8 in /frontend
Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.28.2 to 4.28.8.
- [Release notes](https://github.com/browserslist/browserslist/releases)
- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md)
- [Commits](https://github.com/browserslist/browserslist/compare/4.28.2...4.28.8)

---
updated-dependencies:
- dependency-name: browserslist
  dependency-version: 4.28.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-02 01:27:54 +00:00
Herculino Trotta 039ad225d3 test(rules): cover object-level authorization for transaction rules
Regression tests for GHSA-83g9-vjqf-2j5q, one per endpoint the advisory
named plus the delete and view paths found alongside them: a non-owner
gets 403 on every mutation of a public or shared rule, and the object is
asserted unchanged afterwards.

Also covers the parts that are easy to regress in the other direction:
shared users keep read access, a shared user deleting only revokes their
own access, unowned rules stay claimable, and children of invisible rules
answer 404 rather than 403.

SharedObjectPredicateParityTests asserts is_visible_to agrees with
SharedObjectManager across every owner/visibility/shared combination.
The manager builds a Q and the predicate tests an instance, so they
cannot share an implementation and can otherwise drift apart.
2026-09-01 21:43:13 -03:00
Herculino Trotta 18d4ab7d11 fix(rules): enforce object-level authorization on rule endpoints
SharedObjectManager scopes querysets to what a user may see, which
includes other people's public and shared-with-them objects. Several
mutating rule endpoints treated that visibility as permission to write.

Generalise get_owned_object_or_403 into get_shared_object_or_error, which
takes an explicit access level instead of inferring one:

- READ requires the object to be visible; denial is 404 so the response
  does not confirm that an id exists.
- EDIT requires ownership; denial is 403, but only after the visibility
  check, so 403 never leaks the existence of an invisible object. This
  matters for TransactionRuleAction, whose manager is unscoped.

The previous owner_path resolved to a User and discarded the object, so
it could not express visibility at all. via= now points at the governing
SharedObject and is resolved with a plain getattr, so an unresolvable
path raises instead of silently granting access.

is_visible_to/is_editable_by replace is_accessible_by, which was never
called and tested visibility == "shared", a value that does not exist in
Visibility.

Also fixes two further holes in the same module:

- transaction_rule_delete fell through to delete() whenever the caller
  was not in shared_with, so any user could delete a public rule. Now
  only the owner deletes; a shared user revokes their own access.
- transaction_rule_view was read-only but is now explicitly READ, so
  rules shared with a user stay viewable.

The activate/deactivate control is hidden for rules the user does not
own, instead of rendering a button that always fails.

Refs GHSA-83g9-vjqf-2j5q
2026-09-01 21:25:46 -03:00
dependabot[bot] c64a363126 build(deps): bump djangorestframework from 3.17.1 to 3.17.2
Bumps [djangorestframework](https://github.com/encode/django-rest-framework) from 3.17.1 to 3.17.2.
- [Release notes](https://github.com/encode/django-rest-framework/releases)
- [Commits](https://github.com/encode/django-rest-framework/compare/3.17.1...3.17.2)

---
updated-dependencies:
- dependency-name: djangorestframework
  dependency-version: 3.17.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-02 00:14:06 +00:00
Moshe Levi 68a9286ce5 Fix BOLA on transaction-rule endpoints via get_owned_object_or_403
Add apps.common.functions.get_owned_object_or_403, an ownership-enforcing
variant of get_object_or_404, and apply it across every rules handler that
resolved a TransactionRule / (UpdateOrCreate)TransactionRuleAction from a URL id
without an owner check. Mirrors the check in transaction_rule_edit
(obj.owner and obj.owner != request.user); objects with no owner remain
accessible, preserving existing behaviour. Nested ownership (actions owned via
their parent rule) is handled with owner_path='rule.owner'.
2026-08-31 20:14:40 +03:00
Herculino Trotta 1357688e7b Merge pull request #591 from eitchtee/dependabot/uv/sqlparse-0.6.0
build(deps): bump sqlparse from 0.5.5 to 0.6.0
2026-08-30 15:13:33 -03:00
Herculino Trotta ba1f421ad3 Merge pull request #590 from eitchtee/weblate
Translations update from Weblate
2026-08-30 15:13:24 -03:00
renardspark f60f86a5cb locale(French): update translation
Currently translated at 98.8% (776 of 785 strings)

Translation: WYGIWYH/App
Translate-URL: https://translations.herculino.com/projects/wygiwyh/app/fr/
2026-08-23 16:57:26 +00:00
renardspark 5588eb33b1 locale(French): update translation
Currently translated at 98.8% (776 of 785 strings)

Translation: WYGIWYH/App
Translate-URL: https://translations.herculino.com/projects/wygiwyh/app/fr/
2026-08-23 15:57:24 +00:00
renardspark 934e6bd8e0 locale(French): update translation
Currently translated at 98.8% (776 of 785 strings)

Translation: WYGIWYH/App
Translate-URL: https://translations.herculino.com/projects/wygiwyh/app/fr/
2026-08-23 14:57:25 +00:00
dependabot[bot] 7933f1c316 build(deps): bump sqlparse from 0.5.5 to 0.6.0
Bumps [sqlparse](https://github.com/andialbrecht/sqlparse) from 0.5.5 to 0.6.0.
- [Changelog](https://github.com/andialbrecht/sqlparse/blob/master/CHANGELOG)
- [Commits](https://github.com/andialbrecht/sqlparse/compare/0.5.5...0.6.0)

---
updated-dependencies:
- dependency-name: sqlparse
  dependency-version: 0.6.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-17 21:31:28 +00:00
Dimitri Decrock 00f87bea3d locale(Dutch): update translation
Currently translated at 100.0% (785 of 785 strings)

Translation: WYGIWYH/App
Translate-URL: https://translations.herculino.com/projects/wygiwyh/app/nl/
2026-08-17 15:57:28 +00:00
Herculino Trotta 53ed0d791a Merge pull request #589 from eitchtee/weblate
Translations update from Weblate
0.23.0
2026-08-16 19:03:53 -03:00
Herculino Trotta 5147d939ef locale(Portuguese (Brazil)): update translation
Currently translated at 100.0% (785 of 785 strings)

Translation: WYGIWYH/App
Translate-URL: https://translations.herculino.com/projects/wygiwyh/app/pt_BR/
2026-08-16 22:03:32 +00:00
eitchtee 716bd6f57f chore(locale): update translation files
[skip ci] Automatically generated by Django makemessages workflow
2026-08-16 04:46:49 +00:00
Herculino Trotta ded4cb37d5 Merge pull request #588 from eitchtee/feat/filter-presets
feat(transactions): add filter presets
2026-08-16 01:46:18 -03:00
Herculino Trotta cd48edddab feat(transactions): add htmx filter presets 2026-08-16 01:40:11 -03:00
Herculino Trotta 9e135560fe feat(transactions): add filter preset model 2026-08-16 01:40:03 -03:00
eitchtee bdbccdec16 chore(locale): update translation files
[skip ci] Automatically generated by Django makemessages workflow
2026-08-15 18:12:40 +00:00
Herculino Trotta 907c511b59 Merge pull request #587
feat(dca): add chart zoom navigation
2026-08-15 15:12:14 -03:00