[IMP] website: Script injected in DOM: window.onerror empty params

Cherry-pick (and improvement) of 4bd8e3e (11.0) which should have landed in 10.0

Closes #21032
This commit is contained in:
Romain Derie
2018-03-16 16:12:29 +01:00
parent 9035378d4b
commit 9f1438d5f1
3 changed files with 37 additions and 6 deletions
@@ -120,12 +120,37 @@ var WebClient = Widget.extend({
// crash manager integration
session.on('error', crash_manager, crash_manager.rpc_error);
window.onerror = function (message, file, line, col, error) {
var traceback = error ? error.stack : '';
crash_manager.show_error({
type: _t("Client Error"),
message: message,
data: {debug: file + ':' + line + "\n" + _t('Traceback:') + "\n" + traceback}
});
// Scripts injected in DOM (eg: google API's js files) won't return a clean error on window.onerror.
// The browser will just give you a 'Script error.' as message and nothing else for security issue.
// To enable onerror to work properly with CORS file, you should:
// 1. add crossorigin="anonymous" to your <script> tag loading the file
// 2. enabling 'Access-Control-Allow-Origin' on the server serving the file.
// Since in some case it wont be possible to to this, this handle should have the possibility to be
// handled by the script manipulating the injected file. For this, you will use window.onOriginError
// If it is not handled, we should display something clearer than the common crash_manager error dialog
// since it won't show anything except "Script error."
// This link will probably explain it better: https://blog.sentry.io/2016/05/17/what-is-script-error.html
if (!file && !line && !col) {
// Chrome and Opera set "Script error." on the `message` and hide the `error`
// Firefox handles the "Script error." directly. It sets the error thrown by the CORS file into `error`
if (window.onOriginError) {
window.onOriginError();
delete window.onOriginError;
} else {
crash_manager.show_error({
type: _t("Odoo Client Error"),
message: _t("Unknown CORS error"),
data: {debug: _t("An unknown CORS error occured. The error probably originates from a JavaScript file served from a different origin. (Opening your browser console might give you a hint on the error.)")},
});
}
} else {
var traceback = error ? error.stack : '';
crash_manager.show_error({
type: _t("Odoo Client Error"),
message: message,
data: {debug: file + ':' + line + "\n" + _t('Traceback:') + "\n" + traceback},
});
}
};
},
set_action_manager: function() {
@@ -174,6 +174,10 @@ var Dashboard = Widget.extend(ControlPanelMixin, {
$analytics_components.empty();
// 1. Authorize component
var $analytics_auth = $('<div>').addClass('col-md-12');
window.onOriginError = function () {
$analytics_components.find('.js_unauthorized_message').remove();
self.display_unauthorized_message($analytics_components, 'not_initialized');
};
gapi.analytics.auth.authorize({
container: $analytics_auth[0],
clientid: client_id
@@ -182,6 +186,7 @@ var Dashboard = Widget.extend(ControlPanelMixin, {
self.handle_analytics_auth($analytics_components);
gapi.analytics.auth.on('signIn', function() {
delete window.onOriginError;
self.handle_analytics_auth($analytics_components);
});
@@ -38,6 +38,7 @@
<div t-name="website.unauthorized_analytics" class="col-xs-12 js_unauthorized_message mb16">
<span t-if="reason === 'not_connected'">You need to log in to your Google Account before: </span>
<span t-if="reason === 'no_right'">You do not seem to have access to this Analytics Account.</span>
<span t-if="reason === 'not_initialized'">Google Analytics initialization failed. Maybe this domain is not whitelisted in your Google Analytics project for this client ID.</span>
</div>
<div t-name="website.ga_dialog_content">