Commit Graph

234 Commits

Author SHA1 Message Date
Katie Smith
329a418cc4 Bump utils to 46.1.0
This is to bring in the Zendesk changes which allow us to create tickets
using the Notify Form in Zendesk.
2021-09-24 08:16:06 +01:00
Ben Thorner
11e1a597da Bump utils to 46.0.0
This brings in some new polygon simplication code [1] so we need to
tweak any tests that rely on the exact number of polygons after this
operation.

[1]: https://github.com/alphagov/notifications-utils/pull/890
2021-09-08 14:36:13 +01:00
Chris Hill-Scott
f3e6d92046 Revert "Update utils to bring in coordinate transformation" 2021-08-20 16:05:39 +01:00
Chris Hill-Scott
a6135fb8ab Bump utils
This new version of utils implements the transformation of our polygons
to a Cartesian plane. In other words, it converts them from being
defined in spherical degrees to metres.

For the API this means our simplification will be slightly more
accurate.
2021-08-19 11:08:18 +01:00
Pea Tyczynska
2b2c240bee Update utils version to bring in too_late_to_cancel_letter
We need that method to show right errors to the user
when cancelling letter fails

Update dependencies
2021-07-28 16:33:01 +01:00
sakisv
7ff43939bc Revert werkzeug to the last non-2.0.0 version
We observe high memory usage since we bumped it (along with other
things) and because it only appears on the API and not on the workers
the hypothesis is that Werkzeug is responsible for it.
2021-07-19 16:06:56 +03:00
Pea Tyczynska
e82b8bc33c Bump utils to revert changes to placeholders that introduced
a bug.
2021-07-09 14:45:41 +01:00
Pea Tyczynska
9e8682ac29 Bump utils to bring in fix for optional placeholder bug
See https://github.com/alphagov/notifications-utils/pull/878 for
details.

Changes we had to make for our app and tests to work correctly
after the dependency updates:

1. Update emergency alerts polygons test because we changed
how exact we are with locations of the points on the map.

2. Use Flask's g object to set additional request attributes

So far we have been storing them in _request_ctx_stack which is
an innard for Flask's request context.

Because of major update to Werkzeug dependency, which Flask relies
on, the way we were using it stopped working, so we had a new
way to set those values.
The way we set those values now, by using g object, seems to also
be favoured in Flask documentation:
https://flask.palletsprojects.com/en/1.1.x/reqcontext/#how-the-context-works
2021-07-08 12:18:09 +01:00
David McDonald
04e23ca6a9 Revert "Bump utils version for new invalid address character" 2021-06-01 10:53:28 +01:00
Rebecca Law
50de85988e Fix dependency issues
We haven't bumped the test version for a while.
Also bumped the version of Flask and itsdangerous.
In order to fix flask warnings I needed to changed how the blueprints were registerd.
2021-05-27 13:02:24 +01:00
Rebecca Law
bd1498f49f Bump utils version which contains ~ as an invalid first character for a
postal address.
2021-05-25 08:29:25 +01:00
Richard Baker
2e34f7b18e Force pyup to ignore eventlet
Signed-off-by: Richard Baker <richard.baker@digital.cabinet-office.gov.uk>
2021-05-11 10:12:01 +01:00
Richard Baker
ab7c8b3946 Revert "Bump eventlet from 0.30.2 to 0.31.0"
Signed-off-by: Richard Baker <richard.baker@digital.cabinet-office.gov.uk>
2021-05-10 17:42:44 +01:00
dependabot[bot]
c7ae2ee06a Bump eventlet from 0.30.2 to 0.31.0
Bumps [eventlet](https://github.com/eventlet/eventlet) from 0.30.2 to 0.31.0.
- [Release notes](https://github.com/eventlet/eventlet/releases)
- [Changelog](https://github.com/eventlet/eventlet/blob/master/NEWS)
- [Commits](https://github.com/eventlet/eventlet/compare/v0.30.2...v0.31.0)

Signed-off-by: dependabot[bot] <support@github.com>
2021-05-08 16:37:31 +00:00
pyup-bot
022c3bf178 Update sqlalchemy from 1.3.23 to 1.4.10 2021-04-29 13:32:36 +01:00
Rebecca Law
85895a9e8b Revert "Scheduled weekly dependency update for week 16" 2021-04-28 10:17:16 +01:00
pyup-bot
c07e991c0a Update sqlalchemy from 1.3.23 to 1.4.10 2021-04-21 14:00:02 +01:00
Katie Smith
1f301fd0f1 Pin marshmallow-sqlalchemy below v0.24.0
This was pinned to `<0.24.1` not `<0.24.0` by mistake, which meant pyup
was trying to upgrade from version `0.23.1`.
2021-04-19 13:43:59 +01:00
Katie Smith
6287b40732 Stop pyup upgrading Cryptography
We'd specified that the version should be less than 3.4 previously, but
needed to also tell pyup not to change that.
2021-04-19 11:52:58 +01:00
pyup-bot
4943498107 Update prometheus-client from 0.9.0 to 0.10.1 2021-04-19 11:38:55 +01:00
pyup-bot
29c89ee03a Update gunicorn from 20.0.4 to 20.1.0 2021-04-19 11:38:55 +01:00
pyup-bot
f58221b0c0 Update eventlet from 0.30.1 to 0.30.2 2021-04-19 11:38:55 +01:00
Pea Tyczynska
a3aad24fe1 Bump utils to allow double hyphens in email address domain
It was requested by our user and it is an allowed domain format
with Amazon SES, so we started allowing it in our validation.
2021-03-29 17:53:29 +01:00
Katie Smith
1347e708c8 Bump lxml for security vulnerability
This bumps lxml to version 4.6.3 because version 4.6.2 had a
vulnerability (https://lxml.de/4.6/changes-4.6.3.html).
2021-03-24 11:09:07 +00:00
David McDonald
289c0ea0c6 Make freeze requirements 2021-03-08 15:56:42 +00:00
pyup-bot
9f39118991 Update notifications-python-client from 5.7.1 to 6.0.2 2021-03-03 13:00:06 +00:00
pyup-bot
b5f5114c59 Pin cryptography to latest version 3.4.6 2021-03-03 13:00:06 +00:00
pyup-bot
80891199f8 Update cachetools from 4.2.0 to 4.2.1 2021-03-03 13:00:05 +00:00
pyup-bot
8067ebdca5 Update sqlalchemy from 1.3.22 to 1.3.23 2021-03-03 13:00:05 +00:00
pyup-bot
49dac21739 Update pyjwt from 2.0.0 to 2.0.1 2021-03-03 13:00:05 +00:00
pyup-bot
b615f7192f Update marshmallow-sqlalchemy from 0.23.1 to 0.24.0 2021-03-03 13:00:04 +00:00
pyup-bot
e05ae8f413 Update iso8601 from 0.1.13 to 0.1.14 2021-03-03 13:00:04 +00:00
pyup-bot
6371975981 Update eventlet from 0.30.0 to 0.30.1 2021-03-03 13:00:03 +00:00
pyup-bot
d56430b3a8 Update flask-migrate from 2.5.3 to 2.7.0 2021-03-03 13:00:03 +00:00
pyup-bot
83c5a4f67c Update cffi from 1.14.4 to 1.14.5 2021-03-03 13:00:03 +00:00
Rebecca Law
5986a65005 Check international number for alpha: NO if true then use number to send
SMS.

This is not a catch all for international SMS, the rules are quite
complex and still not completely understood. We are talking with our
provider who maybe able to sort this out for us. But in the meantime,
this should solve for the case that we understand.
2021-02-24 15:12:03 +00:00
Chris Hill-Scott
0bb671df45 Validate content length on broadcast API
The maximum content count of a broadcast varies depending on its
encoding, so we can’t simply validate it against a schema. This commit
moves to using the validation from `notifications-utils`, and raising a
custom error response.
2021-02-16 09:30:40 +00:00
Rebecca Law
87cf3afdc9 Update notifications-utils version.
Postal address validation now includes `< >` in the invalid characters allowed at the start of an address line.
2021-02-10 10:26:00 +00:00
Pea Tyczynska
7cc8371c7f Pin cryptography to a version < 3.4
One of our dependencies has a dependency on cryptography, which has
recently released version 3.4.

This version introduced a circular import error
(pyca/cryptography#5756) which was fixed in
3.4.1.

However, 3.4.1 has a different error where it fails because it cannot
find a rust compiler.

The suggested
solutions are:

Install a newer version of pip which will install a pre-compiled
cryptography wheel OR
Have rust installed and available on our PATH so that it can be used
to build the package.
Since we can't change the buildpack's pip version and we cannot install
rust ourselves, the only we're left with is to avoid upgrading to 3.4 -
at least until PaaS updates their python buildpacks.
2021-02-08 17:05:46 +00:00
Katie Smith
fc9ecaba1d Bump utils to 43.8.1
This brings in the change to stop TV numbers from being treated as
international numbers.
2021-01-29 15:53:35 +00:00
Chris Hill-Scott
c9d55039eb Simplify polygons before storing them
We’re going to let people pass in fairly complex polygons, but:
- we don’t want to store massive polygons
- we don’t want to pass the CBCs massive polygons

So this commit adds a step to simplify the polygons before storing them.

We think it’s best for us to do this because:
- writing code to do polygon simplification is non-trivial, and we don’t
  want to make all potential integrators do it
- the simplification we’ve developed is domain-specific to emergency
  alerting, so should throw away less information than

There’s a bit more detail about how we simplify polygons in
https://github.com/alphagov/notifications-admin/pull/3590/files
2021-01-26 16:24:45 +00:00
Chris Hill-Scott
26871eeacc Validate CAP against the spec
This gives us some extra confidence that there aren’t any problems with
the data we’re getting from the other service. It doesn’t address any
specific problems we’ve seen, rather it seems like a sensible precaution
to take.
2021-01-26 16:24:45 +00:00
Chris Hill-Scott
f98aca05e9 Add translators from CAP to dict
Other systems we’re working with won’t easily be adapted to emit JSON
instead of CAP, so it’s less work for us to do that conversion.

This commit adds to code to parse the XML and turn it into a dict that
we can work with, including converting the polygon string into native
Python lists.
2021-01-26 16:24:44 +00:00
Leo Hemsted
ee2bec2f72 pin marshmallow-sqlalchemy
to keep marshmallow <=3.0 dep
2020-12-31 13:56:18 +00:00
Leo Hemsted
156c7aa32a bump python client
brings in jwt2.0 compat
2020-12-31 13:56:04 +00:00
pyup-bot
b298440f00 Update sqlalchemy from 1.3.20 to 1.3.22 2020-12-31 13:55:37 +00:00
pyup-bot
97d35b86b5 Update pyjwt from 1.7.1 to 2.0.0 2020-12-31 13:55:37 +00:00
pyup-bot
659a43e435 Update cachetools from 4.1.1 to 4.2.0 2020-12-31 13:55:37 +00:00
pyup-bot
e4c5633150 Update eventlet from 0.29.1 to 0.30.0 2020-12-31 13:55:37 +00:00
pyup-bot
0c0821b9f9 Update prometheus-client from 0.8.0 to 0.9.0 2020-12-31 13:55:37 +00:00