Repository navigation
Conversation
Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.1.1 to 12.2.0. - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@12.1.1...12.2.0) --- updated-dependencies: - dependency-name: pillow dependency-version: 12.2.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Olivier Bado-Faustin <12731381+Badatos@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary
Prevents the Podfile widget from generating invalid URLs such as `/podfile/undefined` and fixes malformed markup in the video channel link.
## Changes
- Only generate typed Podfile URLs when the type is explicitly `image` or `file`.
- Ignore invalid folder types when building dynamic folder links in JavaScript.
- Resolve clicks on nested folder elements with `closest("a.folder")` so folder links keep their expected `data-target`.
- Close the opening `<a>` tag for channel links in `video-info.html`.
## configuration.json * Add missing "ARCHIVE_ROOT" param * Uniformize `attribute_scores` in FR and EN ## check obsolete video * no more send emails when there is no deleted or archived videos ## check_video_owner * Format email sent with HTML table
Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.2.0 to 12.3.0. - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@12.2.0...12.3.0) --- updated-dependencies: - dependency-name: pillow dependency-version: 12.3.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- Replace the full `Video.save()` used when attaching `overview.vtt` with a targeted update. - Prevent stale video instances from clearing a thumbnail attached by another encoding callback. - Add a regression test covering concurrent thumbnail persistence.
Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.2.0 to 12.3.0. - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@12.2.0...12.3.0) --- updated-dependencies: - dependency-name: pillow dependency-version: 12.3.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Several minor bugfixes --------- Co-authored-by: Céline Didier <ceine.didier@univ-lorraine.fr>
Bumps [djangorestframework](https://github.com/encode/django-rest-framework) from 3.15.2 to 3.17.2. - [Release notes](https://github.com/encode/django-rest-framework/releases) - [Commits](encode/django-rest-framework@3.15.2...3.17.2) --- updated-dependencies: - dependency-name: djangorestframework dependency-version: 3.17.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Olivier Bado-Faustin <12731381+Badatos@users.noreply.github.com>
## Summary - Display complete filenames, including extensions, in Podfile cards and tooltips. - Add dedicated icons for ODT, ODS, ODP, and VTT files. - Show an extension badge when no dedicated icon is available. - Add template filters and regression tests for filenames, extensions, icons, and image previews. - Convert png files to webp files ## Related issue Fixes #1504
## Summary - Add a configurable Runner Manager administration URL while preserving the default /admin URL. - Support the /api/health endpoint introduced in Esup-Runner Manager 1.8.0, with a fallback to the legacy /manager/health endpoint. - Add timestamped output modes to process_tasks: concise by default, detailed with --verbose, and silent with --verbosity 0. - Add regression tests covering administration URLs, health endpoint compatibility, and command output modes.
Il m'est arrivé d'avoir des fichier "migration" manquants après un transfert ou une migration. Cette commande permet de s'assurer qu'il ne manque aucun fichier de migration, et s'il en manque, il en fait la liste avec pour chacun l'emplacement où il est sensé se trouver.
…abilize Tests (#1510) ## Summary - Fix statistics access controls to address security advisory GHSA-9543-4fhq-r448. Restrict statistics pages, JSON responses and aggregate queries to authorized videos on the current site. - Preserve password authorization across statistics requests while rechecking access restrictions and invalidating authorization when the video password changes. - Validate redirect targets, safely render alerts and theme labels, and prevent internal exception details from being exposed to users. - Declare explicit GitHub Actions token permissions and address unsafe patterns to reduce GitHub code scanning alerts. - Prevent concurrent Runner result imports from callbacks and periodic workers using per-task file locks under the shared `MEDIA_ROOT`. Mark tasks as completed only after successful local import, keeping failed attempts eligible for retry. - Preserve generated thumbnails when submitting video edit forms opened during encoding. - Fix v3-to-v4 exports by correcting invalid meeting recurrence end dates and merging duplicate video deletion dates while preserving video relationships. - Fix video tag serialization in the REST API, preserve Elasticsearch authentication and TLS options in test settings, and load debug toolbar URLs only when the application is enabled. - Use timezone-aware datetimes for upcoming-event filtering, personal meeting room creation and test fixtures. - Run Elasticsearch indexing and deletion synchronously in test settings to avoid SQLite locking and cross-test races, while restoring the active language after indexing. - Expand regression coverage and isolate encoding, transcription and recorder workers in tests. Verify worker dispatch and ensure video duplication copies the source file correctly. - Fix videos missing from a channel’s root when they belong to a theme in another channel, with regression tests for page rendering and AJAX loading. - Refresh translation catalogs. ## Related issues Fixes #1501 Fixes #1448 Fixes #1447
Badatos
marked this pull request as ready for review
September 11, 2026 09:04
Bump Esup-Pod to 4.4.0 and some fixes: # Playlists : * Use Bootstrap colors for playlist add/remove buttons * Add js Unit tests for playlists * Ensure preventRefreshButton use json format # Video Comments: * Add titles on "voted" icons * Fix for `Uncaught TypeError: can't access property "toLocaleString", since is undefined` in comment-script.js * Run unit tests for javascript files * Add margin bellow comments
## Summary - Enforce playlist permissions for editing, video additions, removals and reordering. - Apply password protection consistently across playlist pages and players, with session access invalidated when the password changes. - Preserve ownership, co-owners and existing passwords when editing playlists. - Fix playback order, empty playlists, AJAX pagination and atomic reordering. - Restore favorites controls and icons, and handle missing form fields or card buttons. - Add regression tests and complete missing Python docstrings. ## Testing - 340 Django tests passed across playlists, video and enrichment using isolated test services. - JavaScript regression tests passed. - Flake8 passed on the modified Python scope. - Manual checks covered favorites, public/private playlists and access restrictions between accounts.
## Summary - Update pytubefix from 10.7.3 to 11.1.0. - Prefer the ANDROID client for progressive downloads, retaining ANDROID_VR and WEB as fallbacks. - Update the regression test to cover the new client fallback order. ## Validation - Pending: run the 7 import video view tests. - Pending: verify a YouTube download with audio using pytubefix 11.1.0.
## Summary - Restrict redirects after playlist removal to same-origin HTTP(S) URLs. - Use Django password hashing for new playlist passwords. - Upgrade legacy SHA-256 hashes after successful verification, preserving whitespace compatibility and protecting concurrent password changes. - Add regression tests for unsafe redirects, password compatibility, session access and concurrent updates. ## Compatibility Upgrading a legacy hash invalidates existing playlist access sessions. Affected visitors must enter the same password again. ## Validation - 429 Django tests passed using an isolated local runner with pod.main.test_settings. - 70 JavaScript tests passed. - flake8, Black formatting checks and git diff --check passed.
## Summary - Fix French encoding notifications: use “terminé” and “encodée”, preserving transcription agreement. - Add missing spaces after the author and date labels. - Apply EMAIL_SUBJECT_PREFIX exactly once, falling back to the site name when empty. - Refresh French and Dutch translation catalogs. - Add regression tests for email prefixes, French wording, and encoding push notifications. ## Validation - Flake8 passes. - All 188 tests pass across pod.video.tests and pod.video_encode_transcript.tests.test_utils. - make lang and make compilelang complete successfully. - All 11 encoding utility tests pass again after translation compilation.
+ Fix bug preventing video from being removed from playlist + dispose bootstrap tooltip before removing videocard from playlist
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prepare next 4.4.0 release