This release is a pre-release and may not be stable for production use.
zopyx.surveyjs
SurveyJS integration for Plone: create, publish, validate, store, export, and embed surveys and forms.
Online resources
- Documentation — installation, configuration, usage, endpoints, security, and development reference: docs.privacyforms.studio
- Online demo — try Privacy Forms Studio in a running Plone instance: demo.privacyforms.studio
- Website — product information and services: www.privacyforms.studio
Documentation topics
Development
uv venv --clear
uv pip install -r requirements.txt
.venv/bin/buildout
make test
make docs
See Development for the complete development setup.
License
GPL-2.0-or-later. SurveyJS Creator licensing is documented by SurveyJS and may require a commercial license.
Releasing
The release checklist (version bump, gates, tag, GitHub pre-release, PyPI
trusted publishing) lives in RELEASE.rst. Known gaps that a release notes
entry must mention are collected in docs/limitations.rst.
Contributors
- Andreas Jung, info@zopyx.com
Changelog
1.0b2 (unreleased)
- Set the package version to
1.0b2. - Add the optional GenericSetup profile
zopyx.surveyjs:demo(profiles/demo/, handlers indemo_profile.py). It seeds the four SurveyJS theme presets (light,dark,light-no-panels,dark-no-panels) and creates a publisheddemo-formsfolder with three complex English example forms, one per scope and each using a different theme: employee onboarding, customer satisfaction and conference registration. Both import steps are idempotent, and a form gets a new version only when its shipped definition changed, so re-applying the profile after an upgrade refreshes the demo content without duplicating anything. - Add the Plone site distribution
surveyjs(distributions.zcmlplusdistributions/surveyjs/). It creates a Classic UI site with this add-on installed and uses the demo profile as its example content, so the themes and thedemo-formsfolder are created when a site is created with example content (setup_content). Documented indocs/distribution.rst. - Add seven diagrams to the documentation (
docs/_static/diagrams/): the component overview and the submission lifecycle, the validation pipeline, the deployment topology, the token lifecycle, the export pipeline and the storage backends. Every raster image links to its interactive HTML artifact (zoom, pan, light/dark themes, guided views, search), the generator specifications ship alongside so the diagrams stay reproducible, and the images are embedded inoverview.rst,actions.rst,validation.rst,storage.rst,security.rst,exports.rstandinstallation.rst. - Fix
browser/ai.py:_to_jsonable()logged from itsexceptbranches through a module logger that was never defined, so a serializer method that raised turned the whole call into aNameErrorinstead of falling through to the next strategy (vars(value)). The logger is defined now, andtests/test_ai.py::AIViewTests::test_to_jsonable_survives_failing_serializer_methodscovers the fallback. - Make the repository pass
ruffcompletely:ruff formatandruff check --fixreformatted 41 files (docstring whitespace, blank lines after the import block, import grouping, comment indentation) without any behaviour change, and the ten findings that survived the automatic fixes were fixed by hand — the missing logger above, an unusedPDFFormNotFoundErrorre-export inbrowser/fillable_pdf.py, and unused locals in the token-store and theme-manager tests, which now assert the behaviour their comments only described.RELEASE.rstrequires a cleanruff check/ruff format --checkrun as part of the release gate and no longer tolerates pre-existing findings.
1.0b1 (released 2026-09-12)
First beta release. The functional changes since the last published version on
PyPI (1.0a4) are described in the 1.0a5–1.0a7 sections below; the
entries here are the release-preparation changes of the beta itself.
- Set the package version to
1.0b1. - Declare the runtime dependencies that previously existed only in this
repository's buildout:
privacyforms.ai(imported by the AI generator, the AI service and the model vocabulary) andprivacyforms.pdf(the fillable-PDF workflow). PDF filling needs PyMuPDF, which is shipped as the optional extrazopyx.surveyjs[pdf]instead of a hard requirement because it is dual-licensed (AGPL-3.0 or a commercial Artifex licence). - Import
privacyforms_ailazily (browser/services/ai.py:get_ai_helper()) instead of at module level inbrowser/ai.py. A deployment without the helper now fails the single AI feature with an actionable message instead of failing while Zope configures the add-on (ZCML resolves.ai.AIView). - Remove unreachable PDF code:
browser/services/pdf.py(no caller at all, itsextract_mode="llm"branch imported the deletedai_generatormodule) andpdf_forms.py(the unwired pdfcpu pipeline, reachable only from the removed module). The supported paths are the AI generator (@@ai-upload) and the fillable-PDF workflow. - Documentation corrections: the fillable-PDF pages no longer claim that
survey data is merged into a PDF template (values come from the fill form,
keyed by raw PDF field names; signature fields are never written), the
todopage is replaced bylimitations.rstdocumenting the known gaps (rate limiting, automatic PDF merge, security items tracked in SECURITY.md, multi-server KV behaviour), the stale test-baseline numbers inSECURITY.mdanddocs/security.rstare refreshed to the measured 475 Plone tests / 115 pytest tests, anddocs/old/carries a README marking its files as historical, non-authoritative notes. - Add
RELEASE.rstwith the release checklist, and use Python 3.14 in the PyPI/TestPyPI publish workflows so the publishing interpreter matches the one the test suite runs on. - Enable the
pdfextra in this repository's buildout (base.cfg) so the documented "Download Filled PDF" workflow actually works in the dev and demo instance; PyMuPDF was previously missing there, so the feature failed with "PyMuPDF is required". PyMuPDF stays an extra because of its dual licence (AGPL-3.0 or commercial). - Remove the pdfcpu binary from the container image and delete the unreachable
pdfcpu CLI wrapper
pdf_form_extract.pytogether with its tests. Withpdf_forms.pygone, nothing used the binary any more; the supported PDF extraction path isprivacyforms.pdf. - Remove the remaining add-on-template leftovers:
constraints.txt(it only contained-c constraints_plone52.txt),.travis.ymland.gitlab-ci.yml(both pinned topython:2.7). GitHub Actions is the CI. - Ignore the local buildout variant
test-6.2.x.cfgand the localuv.lockin.gitignore(requirements.txtpins the buildout toolchain). SECURITY.mdnow itemises the unfixed security findings with location, impact and recommendation — SSRF viapost_endpoint_url, missing rate limiting, CSV/XLSX formula injection, unaudited exports, token-store atomicity, key length/rotation, missing token/session binding, container hardening, dependency pinning, bot controls, output encoding and CSRF — instead of naming them in prose only.- Add
scripts/invalidate_tokens.pyto invalidate the tokens of a leaked CSV export across all surveys (dry run by default,--applyto write).
1.0a7 (unreleased)
- Update the vendored SurveyJS browser bundles, translations, and server-side validator to SurveyJS 3.0.4.
- Build the validator without Deno's 24-hour minimum-dependency-age window, so
a deliberately pinned
survey-corerelease compiles immediately instead of failing the CI validator job and install-time builds for a day after each upstream release. - Remove a timing race from the KV store TTL expiry test that failed intermittently on loaded CI runners.
- Correct the package metadata: the PyPI project URLs now point at the actual
repository (
zopyx/zopyx.surveyjs) instead of the never-existingcollective/zopyx.surveyjs, and they document where the documentation and the changelog live. The classifiers now list only the supported platform (Plone 6.2, replacing the obsolete Plone 5.2 entry) and the Python versions that CI actually exercises (3.12, 3.13, 3.14). - Add a CI job that installs the built distribution and runs the Plone-free test subset (converters, schema, validator wrapper) on Python 3.12, 3.13 and 3.14, so the advertised Python support is verified rather than assumed.
- Remove the legacy Plone 5.2 buildout configuration (
test_plone52.cfg) and thetox.iniinherited from the add-on template, which still targeted Python 2.7/3.7 and Plone 4.3–5.2 and referred to a constraints file that no longer exists. - Exclude local-only documentation from the source distribution:
docs/olddescribes removed features,docs/html/docs/_buildare artifacts of a localmake docsrun. - Tag pre-releases (
a/b/rc) are published as GitHub pre-releases instead of full releases, so a beta is never offered as the latest release. - Ignore generated security-review artifacts and local scratch files
(
tokens.csv, the vulnerability report snapshots,tmp/, local agent/tool directories) so they cannot be committed accidentally.
1.0a6 (unreleased)
- Add per-survey SurveyJS theme selection with default theme support.
- Add the Theme Manager configlet, theme creation/upload actions, and improved upload and creation button styling with icons.
- Improve the theme editor toolbar with semantic action colors and a restore version action icon.
- Apply panelless SurveyJS themes correctly in the editor preview.
- Show version numbers in the theme history and restore-version dialog.
- Update the vendored SurveyJS browser bundles, translations, and server-side validator to SurveyJS 3.0.2.
- Fix CI buildout action paths and use Python 3.14 for the Plone environment.
1.0a5 (unreleased)
- Version bump to 1.0a5 to trigger a fresh CI run of all workflows.
1.0a4 (released 2026-08-11)
- Fix: the generated demo site (
scripts/init_plone.py) showed up without any theme.addPloneSitewas called with an invaliddistributionkeyword (the parameter isdistribution_namesince Plone 6.1), so the classic distribution never ran and the Plone Classic theme (Barceloneta) was never applied. Usedistribution_nameand enable thebarcelonetatheme instead ofprivacyforms.theme.
1.0a3 (released 2026-08-11)
- Nothing changed yet.
1.0a2 (released 2026-08-11)
- Nothing changed yet.
1.0a1 (unreleased)
- Initial release. [zopyx]
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file zopyx_surveyjs-1.0b2.tar.gz.
File metadata
- Download URL: zopyx_surveyjs-1.0b2.tar.gz
- Upload date:
- Size: 15.2 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5c2d07acfe6469c147a73d196e0474867760d35c2111a2c4d2d8612f2f205d38
|
|
| MD5 |
829c72ba709b4db34c821eb15102b61d
|
|
| BLAKE2b-256 |
ed42e4d152c379a11fe4a63423c384776716ef13f37b067c0b9bf3cd5ed1e9f5
|
Provenance
The following attestation bundles were made for zopyx_surveyjs-1.0b2.tar.gz:
Publisher:
publish-pypi.yml on zopyx/zopyx.surveyjs
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
zopyx_surveyjs-1.0b2.tar.gz -
Subject digest:
5c2d07acfe6469c147a73d196e0474867760d35c2111a2c4d2d8612f2f205d38 - Sigstore transparency entry: 2817681283
- Sigstore integration time:
-
Permalink:
zopyx/zopyx.surveyjs@9248ce534771d33a8962eb007128ff02d79c858a -
Branch / Tag:
refs/tags/v1.0b2 - Owner: https://github.com/zopyx
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@9248ce534771d33a8962eb007128ff02d79c858a -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file zopyx_surveyjs-1.0b2-py3-none-any.whl.
File metadata
- Download URL: zopyx_surveyjs-1.0b2-py3-none-any.whl
- Upload date:
- Size: 9.6 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a412868909c148c0172445e052cb4850fcd9107f8d2dfb72c482320d877a562d
|
|
| MD5 |
a1906ff1e2410ed354c945459e38c83d
|
|
| BLAKE2b-256 |
3d56f14478bbdf6a2a2a5a24f1affd6e91cc57e3e38f21dbcdd4693b2c0475c8
|
Provenance
The following attestation bundles were made for zopyx_surveyjs-1.0b2-py3-none-any.whl:
Publisher:
publish-pypi.yml on zopyx/zopyx.surveyjs
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
zopyx_surveyjs-1.0b2-py3-none-any.whl -
Subject digest:
a412868909c148c0172445e052cb4850fcd9107f8d2dfb72c482320d877a562d - Sigstore transparency entry: 2817681294
- Sigstore integration time:
-
Permalink:
zopyx/zopyx.surveyjs@9248ce534771d33a8962eb007128ff02d79c858a -
Branch / Tag:
refs/tags/v1.0b2 - Owner: https://github.com/zopyx
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@9248ce534771d33a8962eb007128ff02d79c858a -
Trigger Event:
workflow_dispatch
-
Statement type: