From 0a506d63c68cbe1da5ca616333d91acf6c8a32a6 Mon Sep 17 00:00:00 2001 From: std-odoo Date: Wed, 21 Jun 2023 07:34:00 +0200 Subject: [PATCH] [IMP] mail: convert the "Reset Password" template into QWeb Purpose ======= Convert the "Reset Password" template into QWeb, so the users can't modify it. All values are manually overwritten anyway, and we don't want the users to be able to change it. Technical ========= Now we also manually rollback the transaction, to be sure to not keep any record in database related to the password change. We manually create the because all methods that allow to send an email from a QWeb template in mail thread use the mail composer, and `user_notification` is not supported for the `message_type` in this wizard. Before, force_send was set to False only when we import users. Now we just skip the email sending when we import and always set force_send to True. Task-3265210 closes odoo/odoo#125874 Related: odoo/upgrade#4807 Signed-off-by: Thibault Delavallee (tde) --- addons/auth_signup/__manifest__.py | 1 + .../auth_signup/data/mail_template_data.xml | 96 ------------------- addons/auth_signup/models/res_users.py | 37 ++++--- .../views/auth_signup_templates_email.xml | 87 +++++++++++++++++ 4 files changed, 112 insertions(+), 109 deletions(-) create mode 100644 addons/auth_signup/views/auth_signup_templates_email.xml diff --git a/addons/auth_signup/__manifest__.py b/addons/auth_signup/__manifest__.py index a8a26cc8e3a..a294e54423f 100644 --- a/addons/auth_signup/__manifest__.py +++ b/addons/auth_signup/__manifest__.py @@ -22,6 +22,7 @@ Allow users to sign up and reset their password 'views/res_config_settings_views.xml', 'views/res_users_views.xml', 'views/auth_signup_login_templates.xml', + 'views/auth_signup_templates_email.xml', 'views/webclient_templates.xml', ], 'bootstrap': True, diff --git a/addons/auth_signup/data/mail_template_data.xml b/addons/auth_signup/data/mail_template_data.xml index b25859d5531..6480ca86e29 100644 --- a/addons/auth_signup/data/mail_template_data.xml +++ b/addons/auth_signup/data/mail_template_data.xml @@ -1,102 +1,6 @@ - - - Settings: User Reset Password - - Password reset - {{ (object.company_id.email_formatted or user.email_formatted) }} - {{ object.email_formatted }} - Sent to user who requested a password reset - - - - -
- - - - - - - - - - - - - - - -
- - - -
- Your Account
- - Marc Demo - -
- -
-
-
-
- - - -
-
- Dear Marc Demo,

- A password reset was requested for the Odoo account linked to this email. - You may change your password by following this link which will remain valid during 24 hours:
- - If you do not expect this, you can safely ignore this email.

- Thanks, - -
- --
Mitchell Admin
-
-
-
-
-
-
- - - -
- YourCompany -
- +1 650-123-4567 - - - | info@yourcompany.com - - - | http://www.example.com - -
-
-
- - -
- Powered by Odoo -
-
-
- {{ object.lang }} - -
- Settings: New Portal Signup diff --git a/addons/auth_signup/models/res_users.py b/addons/auth_signup/models/res_users.py index ba62303d683..86ab0385f70 100644 --- a/addons/auth_signup/models/res_users.py +++ b/addons/auth_signup/models/res_users.py @@ -1,6 +1,7 @@ # -*- coding: utf-8 -*- # Part of Odoo. See LICENSE file for full copyright and licensing details. +import contextlib import logging from ast import literal_eval @@ -170,7 +171,7 @@ class ResUsers(models.Model): def _action_reset_password(self): """ create signup token for each user, and send their signup url by email """ - if self.env.context.get('install_mode', False): + if self.env.context.get('install_mode') or self.env.context.get('import_file'): return if self.filtered(lambda user: not user.active): raise UserError(_("You cannot perform this action on an archived user.")) @@ -183,15 +184,12 @@ class ResUsers(models.Model): self.mapped('partner_id').signup_prepare(signup_type="reset", expiration=expiration) # send email to users with their signup url - template = False + account_created_template = None if create_mode: - try: - template = self.env.ref('auth_signup.set_password_email', raise_if_not_found=False) - except ValueError: - pass - if not template: - template = self.env.ref('auth_signup.reset_password_email') - assert template._name == 'mail.template' + account_created_template = self.env.ref('auth_signup.set_password_email', raise_if_not_found=False) + if account_created_template and account_created_template._name != 'mail.template': + _logger.error("Wrong set password template %r", account_created_template) + return email_values = { 'email_cc': False, @@ -206,10 +204,23 @@ class ResUsers(models.Model): if not user.email: raise UserError(_("Cannot send email: user %s has no email address.", user.name)) email_values['email_to'] = user.email - # TDE FIXME: make this template technical (qweb) - with self.env.cr.savepoint(): - force_send = not(self.env.context.get('import_file', False)) - template.send_mail(user.id, force_send=force_send, raise_exception=True, email_values=email_values) + with contextlib.closing(self.env.cr.savepoint()): + if account_created_template: + account_created_template.send_mail( + user.id, force_send=True, + raise_exception=True, email_values=email_values) + else: + body = self.env['mail.render.mixin']._render_template( + self.env.ref('auth_signup.reset_password_email'), + model='res.users', res_ids=user.ids, + engine='qweb_view', options={'post_process': True})[user.id] + mail = self.env['mail.mail'].sudo().create({ + 'subject': _('Password reset'), + 'email_from': user.company_id.email_formatted or user.email_formatted, + 'body_html': body, + **email_values, + }) + mail.send() _logger.info("Password reset email sent for user <%s> to <%s>", user.login, user.email) def send_unregistered_user_reminder(self, after_days=5): diff --git a/addons/auth_signup/views/auth_signup_templates_email.xml b/addons/auth_signup/views/auth_signup_templates_email.xml new file mode 100644 index 00000000000..0fd6a252158 --- /dev/null +++ b/addons/auth_signup/views/auth_signup_templates_email.xml @@ -0,0 +1,87 @@ + + + +