Club staff author body as Markdown in the control panel (help_text now explains the syntax); the public API renders it to sanitized HTML on the way out via news/services.py -- markdown for the conversion, nh3 (Rust/ammonia) to strip anything staff's raw Markdown source might smuggle through (script tags, event handler attributes, javascript: URLs) before it reaches someone else's public website. The control panel's own preview is untouched and still shows the raw source. Excerpt is now derived from the rendered HTML's plain text rather than the raw Markdown source, so syntax like ** or [text](url) doesn't leak into what's meant to be a short teaser.
70 lines
1.9 KiB
TOML
70 lines
1.9 KiB
TOML
[project]
|
|
name = "rosterchief"
|
|
version = "0.1.0"
|
|
requires-python = ">=3.14"
|
|
dependencies = [
|
|
"beautifulsoup4>=4.15.0",
|
|
"dj-database-url>=3.1.2",
|
|
"django>=6.0.6",
|
|
"django-allauth[mfa]>=65.18.0",
|
|
"django-countries>=9.0.0",
|
|
"django-lucide",
|
|
"django-ninja>=1.6.2",
|
|
"django-phonenumber-field[phonenumbers]>=8.4.0",
|
|
"django-redis>=7.0.0",
|
|
"django-storages[s3]>=1.14.6",
|
|
"django-waffle>=5.0.0",
|
|
"gunicorn>=26.0.0",
|
|
"markdown>=3.10.3",
|
|
"nh3>=0.3.6",
|
|
"openpyxl>=3.1.5",
|
|
"pillow>=12.3.0",
|
|
"psycopg[binary]>=3.3.4",
|
|
"python-dateutil>=2.9.0.post0",
|
|
"python-decouple>=3.8",
|
|
"requests>=2.34.2",
|
|
"weasyprint>=69.0",
|
|
"whitenoise>=6.12.0",
|
|
]
|
|
|
|
[dependency-groups]
|
|
dev = [
|
|
"coverage>=7.15.0",
|
|
"django-browser-reload>=1.21.0",
|
|
"ruff>=0.15.17",
|
|
]
|
|
|
|
[tool.ruff]
|
|
line-length = 250
|
|
target-version = "py314"
|
|
# Auto-generated migrations are not hand-maintained code.
|
|
extend-exclude = ["**/migrations/*"]
|
|
|
|
[tool.ruff.lint]
|
|
select = [
|
|
"E", # pycodestyle errors
|
|
"W", # pycodestyle warnings
|
|
"F", # pyflakes
|
|
"I", # isort
|
|
"UP", # pyupgrade
|
|
"B", # flake8-bugbear
|
|
"C4", # flake8-comprehensions
|
|
"DJ", # flake8-django
|
|
"RUF", # ruff-specific rules
|
|
]
|
|
ignore = [
|
|
"RUF012", # Django/Wagtail model attrs (panels, Meta.ordering, ...) are framework conventions, not mutable defaults to guard.
|
|
"RUF005", # Wagtail's `Page.content_panels + [...]` concatenation is the documented idiom.
|
|
]
|
|
|
|
[tool.ruff.lint.per-file-ignores]
|
|
# Settings legitimately use star imports and long generated values.
|
|
"rosterchief/settings/*" = ["F403", "F405", "E501"]
|
|
|
|
[tool.ruff.lint.isort]
|
|
known-first-party = [
|
|
"api", "billing", "authentication", "club", "members", "teams", "events", "formbuilder", "shop", "controlpanel", "management", "news", "pages", "home", "search", "rosterchief"]
|
|
|
|
[tool.uv.sources]
|
|
django-lucide = { git = "https://github.com/bsiebens/lucide" }
|