From 4bd8e3e2ed48eb05b9e155826fd47753a85b5731 Mon Sep 17 00:00:00 2001 From: rde Date: Fri, 29 Sep 2017 13:48:33 +0200 Subject: [PATCH] [IMP] website: Script injected in DOM: window.onerror empty params Before this commit, error thrown by scripts injected in DOM won't return a clean error on window.onerror. It would open the crash_manager's show_error's dialog that wouldn't display any informations except "Script Error." and "Traceback:". This is because of browser's security reason: it will just give you a 'Script error.' as message and nothing else for security issue. Now, this kind of error will show a clearer message informing that it is probably originating from a Javascript file served from a different origin. There is now also the possibility for developers to handle/override the behavior when this kind of error is catch to prevent the dialog to open for example. Might be of use: https://blog.sentry.io/2016/05/17/what-is-script-error.html https://stackoverflow.com/a/7778424 https://danlimerick.wordpress.com/2014/01/18/how-to-catch-javascript-errors-with-window-onerror-even-on-chrome-and-firefox/ (Search for Script Error) --- .../src/js/chrome/abstract_web_client.js | 35 +++++++++++++++---- .../static/src/js/backend/dashboard.js | 5 +++ .../static/src/xml/website.backend.xml | 1 + 3 files changed, 35 insertions(+), 6 deletions(-) diff --git a/addons/web/static/src/js/chrome/abstract_web_client.js b/addons/web/static/src/js/chrome/abstract_web_client.js index 9a629ec3393..febfecad0bc 100644 --- a/addons/web/static/src/js/chrome/abstract_web_client.js +++ b/addons/web/static/src/js/chrome/abstract_web_client.js @@ -167,12 +167,35 @@ var AbstractWebClient = Widget.extend(mixins.ServiceProvider, { // crash manager integration session.on('error', crash_manager, crash_manager.rpc_error); window.onerror = function (message, file, line, col, error) { - var traceback = error ? error.stack : ''; - crash_manager.show_error({ - type: _t("Odoo Client Error"), - message: message, - data: {debug: file + ':' + line + "\n" + _t('Traceback:') + "\n" + traceback} - }); + // Scripts injected in DOM (eg: google API's js files) won't return a clean error on window.onerror. + // The browser will just give you a 'Script error.' as message and nothing else for security issue. + // To enable onerror to work properly with CORS file, you should: + // 1. add crossorigin="anonymous" to your