From b61aad2f6b7a0b1fa5c4a2dad941a350f2c03236 Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Thu, 19 Apr 2018 18:50:42 +0200 Subject: [PATCH 1/5] [FIX] hr*: restrict personal employee fields at model level Fixes #12077 Closes #12160 --- addons/hr/hr.py | 16 ++++++++-------- addons/hr_contract/hr_contract.py | 10 +++++----- 2 files changed, 13 insertions(+), 13 deletions(-) diff --git a/addons/hr/hr.py b/addons/hr/hr.py index f9b536c6915..a88cc1db318 100644 --- a/addons/hr/hr.py +++ b/addons/hr/hr.py @@ -141,16 +141,16 @@ class hr_employee(osv.osv): #we need a related field in order to be able to sort the employee by name 'name_related': fields.related('resource_id', 'name', type='char', string='Name', readonly=True, store=True), 'country_id': fields.many2one('res.country', 'Nationality (Country)'), - 'birthday': fields.date("Date of Birth"), - 'ssnid': fields.char('SSN No', help='Social Security Number'), - 'sinid': fields.char('SIN No', help="Social Insurance Number"), - 'identification_id': fields.char('Identification No'), - 'gender': fields.selection([('male', 'Male'), ('female', 'Female'), ('other', 'Other')], 'Gender'), - 'marital': fields.selection([('single', 'Single'), ('married', 'Married'), ('widower', 'Widower'), ('divorced', 'Divorced')], 'Marital Status'), + 'birthday': fields.date("Date of Birth", groups="base.group_hr_user"), + 'ssnid': fields.char('SSN No', help='Social Security Number', groups="base.group_hr_user"), + 'sinid': fields.char('SIN No', help="Social Insurance Number", groups="base.group_hr_user"), + 'identification_id': fields.char('Identification No', groups="base.group_hr_user"), + 'gender': fields.selection([('male', 'Male'), ('female', 'Female'), ('other', 'Other')], 'Gender', groups="base.group_hr_user"), + 'marital': fields.selection([('single', 'Single'), ('married', 'Married'), ('widower', 'Widower'), ('divorced', 'Divorced')], 'Marital Status', groups="base.group_hr_user"), 'department_id': fields.many2one('hr.department', 'Department'), 'address_id': fields.many2one('res.partner', 'Working Address'), 'address_home_id': fields.many2one('res.partner', 'Home Address'), - 'bank_account_id': fields.many2one('res.partner.bank', 'Bank Account Number', domain="[('partner_id','=',address_home_id)]", help="Employee bank salary account"), + 'bank_account_id': fields.many2one('res.partner.bank', 'Bank Account Number', domain="[('partner_id','=',address_home_id)]", help="Employee bank salary account", groups="base.group_hr_user"), 'work_phone': fields.char('Work Phone', readonly=False), 'mobile_phone': fields.char('Work Mobile', readonly=False), 'work_email': fields.char('Work Email', size=240), @@ -162,7 +162,7 @@ class hr_employee(osv.osv): 'resource_id': fields.many2one('resource.resource', 'Resource', ondelete='cascade', required=True, auto_join=True), 'coach_id': fields.many2one('hr.employee', 'Coach'), 'job_id': fields.many2one('hr.job', 'Job Title'), - 'passport_id': fields.char('Passport No'), + 'passport_id': fields.char('Passport No', groups="base.group_hr_user"), 'color': fields.integer('Color Index'), 'city': fields.related('address_id', 'city', type='char', string='City'), 'login': fields.related('user_id', 'login', type='char', string='Login', readonly=1), diff --git a/addons/hr_contract/hr_contract.py b/addons/hr_contract/hr_contract.py index f649fb86636..aeb605f8aba 100644 --- a/addons/hr_contract/hr_contract.py +++ b/addons/hr_contract/hr_contract.py @@ -31,11 +31,11 @@ class hr_employee(osv.osv): _columns = { 'manager': fields.boolean('Is a Manager'), - 'medic_exam': fields.date('Medical Examination Date'), - 'place_of_birth': fields.char('Place of Birth'), - 'children': fields.integer('Number of Children'), - 'vehicle': fields.char('Company Vehicle'), - 'vehicle_distance': fields.integer('Home-Work Dist.', help="In kilometers"), + 'medic_exam': fields.date('Medical Examination Date', groups="base.group_hr_user"), + 'place_of_birth': fields.char('Place of Birth', groups="base.group_hr_user"), + 'children': fields.integer('Number of Children', groups="base.group_hr_user"), + 'vehicle': fields.char('Company Vehicle', groups="base.group_hr_user"), + 'vehicle_distance': fields.integer('Home-Work Dist.', help="In kilometers", groups="base.group_hr_user"), 'contract_ids': fields.one2many('hr.contract', 'employee_id', 'Contracts'), 'contract_id': fields.function(_get_latest_contract, string='Current Contract', type='many2one', relation="hr.contract", help='Latest contract of the employee'), 'contracts_count': fields.function(_contracts_count, type='integer', string='Contracts'), From cd6150fe9e63d7785f140ea1e2b3090bb1a2e10b Mon Sep 17 00:00:00 2001 From: "Lucas Perais (lpe)" Date: Wed, 18 Apr 2018 17:49:26 +0200 Subject: [PATCH 2/5] [FIX] web: NFD UTF-8 for safari in upload file Before this commit, when uploading a file as attachment in Safari, The file icon kept on showing 'downloading' whereas the request was successful This was because the return from the server had a different UTF-8 norm than Safari After this commit, it works well OPW 1836545 closes #24307 --- addons/web/controllers/main.py | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/addons/web/controllers/main.py b/addons/web/controllers/main.py index d8cb0e6a36f..a1ead7e5d1a 100644 --- a/addons/web/controllers/main.py +++ b/addons/web/controllers/main.py @@ -19,6 +19,7 @@ import time import zlib from xml.etree import ElementTree from cStringIO import StringIO +import unicodedata import babel.messages.pofile import werkzeug.utils @@ -1069,16 +1070,23 @@ class Binary(http.Controller): var win = window.top.window; win.jQuery(win).trigger(%s, %s); """ + + filename = ufile.filename + if request.httprequest.user_agent.browser == 'safari': + # Safari sends NFD UTF-8 (where é is composed by 'e' and [accent]) + # we need to send it the same stuff, otherwise it'll fail + filename = unicodedata.normalize('NFD', ufile.filename).encode('UTF-8') + try: attachment_id = Model.create({ - 'name': ufile.filename, + 'name': filename, 'datas': base64.encodestring(ufile.read()), - 'datas_fname': ufile.filename, + 'datas_fname': filename, 'res_model': model, 'res_id': int(id) }, request.context) args = { - 'filename': ufile.filename, + 'filename': filename, 'mimetype': ufile.content_type, 'id': attachment_id } From 3bee6ebb0a8b1f8909af810aa2cc5c24e040d286 Mon Sep 17 00:00:00 2001 From: Christophe Simonis Date: Fri, 6 Jan 2017 17:55:04 +0100 Subject: [PATCH 3/5] [FIX] core: effectively warn on invalid custom views Since new-api migration of `ir.ui.view`, the method that check views raises exceptions instead of returning a boolean. Show them as warning. Related to #14521 --- openerp/modules/loading.py | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/openerp/modules/loading.py b/openerp/modules/loading.py index 92d174dcd23..be94697ad1d 100644 --- a/openerp/modules/loading.py +++ b/openerp/modules/loading.py @@ -402,8 +402,10 @@ def load_modules(db, force_demo=False, status=None, update_module=False): if update_module: Views = registry['ir.ui.view'] for model in registry.models.keys(): - if not Views._validate_custom_views(cr, SUPERUSER_ID, model): - _logger.warning('Invalid custom view(s) for model %s', model) + try: + Views._validate_custom_views(cr, SUPERUSER_ID, model) + except Exception as e: + _logger.warning('invalid custom view(s) for model %s: %s', model, tools.ustr(e)) if report.failures: _logger.error('At least one test failed when loading the modules.') From 04b0d761e4a6ce0229e1e9e53fe85ff95d691ba7 Mon Sep 17 00:00:00 2001 From: Stefan Rijnhart Date: Tue, 13 Mar 2018 19:14:00 +0100 Subject: [PATCH 4/5] [FIX] core: Validate custom views without an XML ID Regression of fc91feda3033f Closes #23646 Closes #23626 --- openerp/addons/base/ir/ir_ui_view.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openerp/addons/base/ir/ir_ui_view.py b/openerp/addons/base/ir/ir_ui_view.py index 8a799789123..11e5544701e 100644 --- a/openerp/addons/base/ir/ir_ui_view.py +++ b/openerp/addons/base/ir/ir_ui_view.py @@ -1169,7 +1169,7 @@ class view(osv.osv): cr.execute("""SELECT max(v.id) FROM ir_ui_view v LEFT JOIN ir_model_data md ON (md.model = 'ir.ui.view' AND md.res_id = v.id) - WHERE md.module NOT IN (SELECT name FROM ir_module_module) + WHERE md.module IN (SELECT name FROM ir_module_module) IS NOT TRUE AND v.model = %s AND v.active = true GROUP BY coalesce(v.inherit_id, v.id) From c9e7433c23712f41fa2a93f3ee6464eb94173608 Mon Sep 17 00:00:00 2001 From: qsm-odoo Date: Thu, 19 Apr 2018 12:55:06 +0200 Subject: [PATCH 5/5] [FIX] web_editor: prevent crash on outside-iframe click The editor is performing text selection check when clicking on the window. However, when clicking outside the iframe an editor is running in, a crash may occur as the editor was trying to check a range outside of its environment (the iframe). Related to opw-1837818 --- addons/web_editor/static/src/js/rte.summernote.js | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/addons/web_editor/static/src/js/rte.summernote.js b/addons/web_editor/static/src/js/rte.summernote.js index c5a6656ea28..25d966b354d 100644 --- a/addons/web_editor/static/src/js/rte.summernote.js +++ b/addons/web_editor/static/src/js/rte.summernote.js @@ -630,7 +630,15 @@ function summernote_mousedown (event) { } // restore range if range lost after clicking on non-editable area - var r = range.create(); + try { + var r = range.create(); + } catch (e) { + // If this code is running inside an iframe-editor and that the range + // is outside of this iframe, this will fail as the iframe does not have + // the permission to check the outside content this way. In that case, + // we simply ignore the exception as it is as if there was no range. + return; + } var editables = $(".o_editable[contenteditable], .note-editable[contenteditable]"); var r_editable = editables.has((r||{}).sc); if (!r_editable.closest('.note-editor').is($editable) && !r_editable.filter('.o_editable').is(editables)) {