[IMP] website: Script injected in DOM: window.onerror empty params

Before this commit, error thrown by scripts injected in DOM won't return a
clean error on window.onerror.
It would open the crash_manager's show_error's dialog that wouldn't display
any informations except "Script Error." and "Traceback:".
This is because of browser's security reason: it will just give you a
'Script error.' as message and nothing else for security issue.

Now, this kind of error will show a clearer message informing that it is
probably originating from a Javascript file served from a different origin.
There is now also the possibility for developers to handle/override the
behavior when this kind of error is catch to prevent the dialog to open for
example.

Might be of use:
https://blog.sentry.io/2016/05/17/what-is-script-error.html
https://stackoverflow.com/a/7778424
https://danlimerick.wordpress.com/2014/01/18/how-to-catch-javascript-errors-with-window-onerror-even-on-chrome-and-firefox/ (Search for Script Error)
This commit is contained in:
rde
2017-09-30 12:21:27 +02:00
committed by Jeremy Kersten
parent c837eaca9f
commit 4bd8e3e2ed
3 changed files with 35 additions and 6 deletions
@@ -167,12 +167,35 @@ var AbstractWebClient = Widget.extend(mixins.ServiceProvider, {
// crash manager integration
session.on('error', crash_manager, crash_manager.rpc_error);
window.onerror = function (message, file, line, col, error) {
var traceback = error ? error.stack : '';
crash_manager.show_error({
type: _t("Odoo Client Error"),
message: message,
data: {debug: file + ':' + line + "\n" + _t('Traceback:') + "\n" + traceback}
});
// Scripts injected in DOM (eg: google API's js files) won't return a clean error on window.onerror.
// The browser will just give you a 'Script error.' as message and nothing else for security issue.
// To enable onerror to work properly with CORS file, you should:
// 1. add crossorigin="anonymous" to your <script> tag loading the file
// 2. enabling 'Access-Control-Allow-Origin' on the server serving the file.
// Since in some case it wont be possible to to this, this handle should have the possibility to be
// handled by the script manipulating the injected file. For this, you will use window.onOriginError
// If it is not handled, we should display something clearer than the common crash_manager error dialog
// since it won't show anything except "Script error."
// This link will probably explain it better: https://blog.sentry.io/2016/05/17/what-is-script-error.html
if (message === "Script error." && !file && !line && !col && !error) {
if (window.onOriginError) {
window.onOriginError();
delete window.onOriginError;
} else {
crash_manager.show_error({
type: _t("Odoo Client Error"),
message: _t("Unknown CORS error"),
data: {debug: _t("An unknown CORS error occured. The error probably originates from a JavaScript file served from a different origin.")},
});
}
} else {
var traceback = error ? error.stack : '';
crash_manager.show_error({
type: _t("Odoo Client Error"),
message: message,
data: {debug: file + ':' + line + "\n" + _t('Traceback:') + "\n" + traceback},
});
}
};
},
set_action_manager: function () {
@@ -198,10 +198,15 @@ var Dashboard = Widget.extend(ControlPanelMixin, {
$analytics_components.empty();
// 1. Authorize component
var $analytics_auth = $('<div>').addClass('col-md-12');
window.onOriginError = function () {
$analytics_components.find('.js_unauthorized_message').remove();
self.display_unauthorized_message($analytics_components, 'not_initialized');
};
gapi.analytics.auth.authorize({
container: $analytics_auth[0],
clientid: client_id
});
$analytics_auth.appendTo($analytics_components);
self.handle_analytics_auth($analytics_components);
@@ -89,6 +89,7 @@
<div t-name="website.unauthorized_analytics" class="col-xs-12 js_unauthorized_message mb16">
<span t-if="reason === 'not_connected'">You need to log in to your Google Account before: </span>
<span t-if="reason === 'no_right'">You do not seem to have access to this Analytics Account.</span>
<span t-if="reason === 'not_initialized'">Google Analytics initialization failed. Maybe this domain is not whitelisted in your Google Analytics project for this client ID.</span>
</div>
<div t-name="website.ga_dialog_content">