[MERGE] forward port branch 11.0 up to b5a04fd29f

This commit is contained in:
Christophe Simonis
2019-06-19 12:07:56 +02:00
10 changed files with 61 additions and 21 deletions
+3 -2
View File
@@ -191,8 +191,9 @@ class MailActivity(models.Model):
self.env[model].browse(res_ids).check_access_rule(doc_operation)
except exceptions.AccessError:
raise exceptions.AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') %
(self._description, operation))
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('Records:'), res_ids[:6], _('User:'), self._uid)
)
@api.model
def create(self, values):
+6 -4
View File
@@ -591,8 +591,9 @@ class Message(models.Model):
WHERE message.message_type = %%s AND (message.subtype_id IS NULL OR subtype.internal IS TRUE) AND message.id = ANY (%%s)''' % (self._table), ('comment', self.ids,))
if self._cr.fetchall():
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') %
(self._description, operation))
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
)
# Read mail_message.ids to have their values
message_values = dict((res_id, {}) for res_id in self.ids)
@@ -691,8 +692,9 @@ class Message(models.Model):
if not (other_ids and self.browse(other_ids).exists()):
return
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') %
(self._description, operation))
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('Records:'), list(other_ids)[:6], _('User:'), self._uid)
)
@api.model
def _get_record_name(self, values):
+2 -1
View File
@@ -27,7 +27,8 @@ class report_product_pricelist(models.AbstractModel):
}
def _get_quantity(self, data):
return sorted([data['form'][key] for key in data['form'] if key.startswith('qty') and data['form'][key]])
form = data and data.get('form') or {}
return sorted([form[key] for key in form if key.startswith('qty') and form[key]])
def _get_categories(self, pricelist, products, quantities):
categ_data = []
+4 -1
View File
@@ -54,7 +54,10 @@ class MailMessage(models.Model):
if self.user_has_groups('base.group_public'):
self.env.cr.execute('SELECT id FROM "%s" WHERE website_published IS FALSE AND id = ANY (%%s)' % (self._table), (self.ids,))
if self.env.cr.fetchall():
raise AccessError(_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation))
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
)
return super(MailMessage, self).check_access_rule(operation=operation)
@api.multi
@@ -3,6 +3,7 @@ odoo.define('website_sale_comparison.comparison', function (require) {
require('web.dom_ready');
var ajax = require('web.ajax');
var concurrency = require('web.concurrency');
var core = require('web.core');
var _t = core._t;
var utils = require('web.utils');
@@ -26,6 +27,7 @@ var ProductComparison = Widget.extend({
init: function(){
this.comparelist_product_ids = JSON.parse(utils.get_cookie('comparelist_product_ids') || '[]');
this.product_compare_limit = 4;
this.guard = new concurrency.Mutex();
},
start:function(){
var self = this;
@@ -113,6 +115,9 @@ var ProductComparison = Widget.extend({
}
},
add_new_products:function(product_id){
this.guard.exec(this._add_new_products.bind(this, product_id));
},
_add_new_products: function (product_id) {
var self = this;
$('.o_product_feature_panel').show();
if (!_.contains(self.comparelist_product_ids, product_id)) {
@@ -120,8 +125,9 @@ var ProductComparison = Widget.extend({
if(_.has(self.product_data, product_id)){
self.update_content([product_id], false);
} else {
self.load_products([product_id]).then(function(){
return self.load_products([product_id]).then(function () {
self.update_content([product_id], false);
self.update_cookie();
});
}
}
@@ -139,6 +145,9 @@ var ProductComparison = Widget.extend({
this.refresh_panel();
},
rm_from_comparelist: function(e){
this.guard.exec(this._rm_from_comparelist.bind(this, e));
},
_rm_from_comparelist: function (e) {
this.comparelist_product_ids = _.without(this.comparelist_product_ids, $(e.currentTarget).data('product_product_id'));
$(e.currentTarget).parents('.o_product_row').remove();
this.update_cookie();
@@ -221,6 +221,7 @@
<field name="symbol">¥</field>
<field name="rounding">1.00</field>
<field name="active" eval="False"/>
<field name="position">before</field>
<field name="currency_unit_label">Yen</field>
<field name="currency_subunit_label">Cen</field>
</record>
+4 -1
View File
@@ -245,7 +245,10 @@ class IrActionsActWindow(models.Model):
existing = self.filtered(lambda rec: rec.id in ids)
if len(existing) < len(self):
# mark missing records in cache with a failed value
exc = MissingError(_("Record does not exist or has been deleted."))
exc = MissingError(
_("Record does not exist or has been deleted.")
+ '\n\n({} {}, {} {})'.format(_('Records:'), (self - existing).ids[:6], _('User:'), self._uid)
)
for record in (self - existing):
record._cache.set_failed(self._fields, exc)
return existing
+1
View File
@@ -1242,6 +1242,7 @@ class IrModelAccess(models.Model):
else:
msg_tail = _("Please contact your system administrator if you think this is an error.") + "\n\n(" + _("Document model") + ": %s)"
msg_params = (model,)
msg_tail += ' - ({} {}, {} {})'.format(_('Operation:'), mode, _('User:'), self._uid)
_logger.info('Access Denied by ACLs for operation: %s, uid: %s, model: %s', mode, self._uid, model)
msg = '%s %s' % (msg_heads[mode], msg_tail)
raise AccessError(msg % msg_params)
+28 -10
View File
@@ -2567,9 +2567,13 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
if invalid_fields:
_logger.info('Access Denied by ACLs for operation: %s, uid: %s, model: %s, fields: %s',
operation, self._uid, self._name, ', '.join(invalid_fields))
raise AccessError(_('The requested operation cannot be completed due to security restrictions. '
'Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
(self._description, operation))
raise AccessError(
_(
'The requested operation cannot be completed due to security restrictions. '
'Please contact your system administrator.\n\n(Document type: %s, Operation: %s)'
) % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('User:'), self._uid, _('Fields:'), ', '.join(invalid_fields))
)
return fields
@@ -2792,8 +2796,8 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
(self._name, 'read', ','.join([str(r.id) for r in self][:6]), self._uid))
# store an access error exception in existing records
exc = AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
(self._name, 'read')
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, 'read')
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
)
self.env.cache.set_failed(forbidden, self._fields.values(), exc)
@@ -2877,8 +2881,10 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
if self._uid == SUPERUSER_ID:
return
_logger.info('Access Denied by record rules for operation: %s on record ids: %r, uid: %s, model: %s', operation, forbidden_ids, self._uid, self._name)
raise AccessError(_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
(self._description, operation))
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {}, {})'.format(_('Records:'), forbidden_ids[:6], _('User:'), self._uid)
)
else:
# If we get here, the missing_ids are not in the database
if operation in ('read','unlink'):
@@ -2887,7 +2893,13 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
# errors for non-transactional search/read sequences coming from clients
return
_logger.info('Failed operation on deleted record(s): %s, uid: %s, model: %s', operation, self._uid, self._name)
raise MissingError(_('Missing document(s)') + ':' + _('One of the documents you are trying to access has been deleted, please try again after refreshing.'))
raise MissingError(
_('Missing document(s)') + ':' + _('One of the documents you are trying to access has been deleted, please try again after refreshing.')
+ '\n\n({} {}, {} {}, {} {}, {} {})'.format(
_('Document type:'), self._description, _('Operation:'), operation,
_('Records:'), missing_ids[:6], _('User:'), self._uid,
)
)
@api.model
def check_access_rights(self, operation, raise_exception=True):
@@ -3231,7 +3243,10 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
for sub_ids in cr.split_for_in_conditions(set(self.ids)):
cr.execute(query, params + [sub_ids])
if cr.rowcount != len(sub_ids):
raise MissingError(_('One of the records you are trying to modify has already been deleted (Document type: %s).') % self._description)
raise MissingError(
_('One of the records you are trying to modify has already been deleted (Document type: %s).') % self._description
+ '\n\n({} {}, {} {})'.format(_('Records:'), sub_ids[:6], _('User:'), self._uid)
)
for name in updated:
field = self._fields[name]
@@ -3964,7 +3979,10 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
existing = self.browse(ids + new_ids)
if len(existing) < len(self):
# mark missing records in cache with a failed value
exc = MissingError(_("Record does not exist or has been deleted."))
exc = MissingError(
_("Record does not exist or has been deleted.")
+ '\n\n({} {}, {} {})'.format(_('Records:'), (self - existing).ids[:6], _('User:'), self._uid)
)
self.env.cache.set_failed(self - existing, self._fields.values(), exc)
return existing
+2 -1
View File
@@ -159,7 +159,7 @@ def image_resize_image_small(base64_source, size=(64, 64), encoding='base64', fi
# ----------------------------------------
# Crop Image
# ----------------------------------------
def crop_image(data, type='top', ratio=False, size=None, image_format="PNG"):
def crop_image(data, type='top', ratio=False, size=None, image_format=None):
""" Used for cropping image and create thumbnail
:param data: base64 data of image.
:param type: Used for cropping position possible
@@ -188,6 +188,7 @@ def crop_image(data, type='top', ratio=False, size=None, image_format="PNG"):
new_h = h
new_w = (h * w_ratio) // h_ratio
image_format = image_format or image_stream.format or 'JPEG'
if type == "top":
cropped_image = image_stream.crop((0, 0, new_w, new_h))
cropped_image.save(output_stream, format=image_format)