From aa1c3946daa08bc948c0e423554c603aa8cc67a2 Mon Sep 17 00:00:00 2001 From: Nicolas Martinelli Date: Mon, 25 Jul 2016 10:56:06 +0200 Subject: [PATCH 1/4] [FIX] product: rounding in pricelist report The pricelist report might show price incorrectly rounded. For example, a calculated price of 20.625 will be displayed as 20.62 in the report since `formatLang` does not apply a rounding but simply truncate the value. Fixes #12875 --- addons/product/report/product_pricelist.py | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/addons/product/report/product_pricelist.py b/addons/product/report/product_pricelist.py index cd7054aa1a3..6a49250734f 100644 --- a/addons/product/report/product_pricelist.py +++ b/addons/product/report/product_pricelist.py @@ -22,6 +22,7 @@ import time from openerp.osv import osv from openerp.report import report_sxw +from openerp.tools import float_round class product_pricelist(report_sxw.rml_parse): @@ -106,10 +107,11 @@ class product_pricelist(report_sxw.rml_parse): pricelist = self.pool.get('product.pricelist').browse(self.cr, self.uid, [pricelist_id], context=self.localcontext)[0] price_dict = self.pool.get('product.pricelist').price_get(self.cr, self.uid, [pricelist_id], product_id, qty, context=self.localcontext) if price_dict[pricelist_id]: - price = self.formatLang(price_dict[pricelist_id], digits=sale_price_digits, currency_obj=pricelist.currency_id) + price = float_round(price_dict[pricelist_id], precision_digits=sale_price_digits) else: res = self.pool.get('product.product').read(self.cr, self.uid, [product_id]) - price = self.formatLang(res[0]['list_price'], digits=sale_price_digits, currency_obj=pricelist.currency_id) + price = float_round(res[0]['list_price'], precision_digits=sale_price_digits) + price = self.formatLang(price, digits=sale_price_digits, currency_obj=pricelist.currency_id) return price From 7e162e899318410e836a08907a51070ba21014f4 Mon Sep 17 00:00:00 2001 From: "Pedro M. Baeza" Date: Sat, 14 May 2016 18:15:40 +0200 Subject: [PATCH 2/4] [FIX] account: total_invoiced field should be only for customer "total_invoiced" must only take customer invoices into account because when you click on the button "invoiced" in the partner view form you just see the customer invoices. Adaptation for 8.0 of 9.0 fix made at 37569695 Closes #12044 --- addons/account/partner.py | 1 + 1 file changed, 1 insertion(+) diff --git a/addons/account/partner.py b/addons/account/partner.py index 36011714cdf..ca2a4d73fe2 100644 --- a/addons/account/partner.py +++ b/addons/account/partner.py @@ -276,6 +276,7 @@ class res_partner(osv.osv): AND cr.currency_id = %%s AND (COALESCE(account_invoice_report.date, NOW()) >= cr.date_start) AND (COALESCE(account_invoice_report.date, NOW()) < cr.date_end OR cr.date_end IS NULL) + AND account_invoice_report.type in ('out_invoice', 'out_refund') """ % where_clause # price_total is in the currency with rate = 1 From 8596a4ccaa71d693ef4d2075ee793f3665ed605b Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Wed, 20 Jul 2016 21:35:40 +0200 Subject: [PATCH 3/4] [FIX] portal: avoid users sharing non-portal groups --- addons/portal/wizard/portal_wizard.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/addons/portal/wizard/portal_wizard.py b/addons/portal/wizard/portal_wizard.py index 2c7f7162964..c4c46a66c9e 100644 --- a/addons/portal/wizard/portal_wizard.py +++ b/addons/portal/wizard/portal_wizard.py @@ -158,12 +158,15 @@ class wizard_user(osv.osv_memory): return error_msg def action_apply(self, cr, uid, ids, context=None): + self.pool['res.partner'].check_access_rights(cr, uid, 'write') error_msg = self.get_error_messages(cr, uid, ids, context=context) if error_msg: raise osv.except_osv(_('Contacts Error'), "\n\n".join(error_msg)) for wizard_user in self.browse(cr, SUPERUSER_ID, ids, context): portal = wizard_user.wizard_id.portal_id + if not portal.is_portal: + raise osv.except_osv("Error", "Not a portal: " + portal.name) user = self._retrieve_user(cr, SUPERUSER_ID, wizard_user, context) if wizard_user.partner_id.email != wizard_user.email: wizard_user.partner_id.write({'email': wizard_user.email}) From 43cff22950a638a69d4f0ad0036ed034815c8f6c Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Mon, 25 Jul 2016 11:42:45 +0200 Subject: [PATCH 4/4] [FIX] base: fix broken URLs when redirecting Similarly to werkzeug.urls.url_fix(), attempt to correct some leftover special characters that should have been URL-encoded. We cannot actually use `werkzeug.urls.url_fix` or `werkzeug.urls.url_quote`, as they expect more/most characters to be un-encoded. We have many existing cases where the redirect URL is already fully encoded or mostly encoded, and those functions would cause double-encoding, breaking the final URL. --- openerp/http.py | 1 + 1 file changed, 1 insertion(+) diff --git a/openerp/http.py b/openerp/http.py index 3c4bf69b62a..5b85c07efff 100644 --- a/openerp/http.py +++ b/openerp/http.py @@ -160,6 +160,7 @@ def redirect_with_hash(url, code=303): # See extensive test page at http://greenbytes.de/tech/tc/httpredirects/ if request.httprequest.user_agent.browser in ('firefox',): return werkzeug.utils.redirect(url, code) + url = url.replace("'", "%27").replace("<", "%3C") return "" % url class WebRequest(object):