From 22cd9a5c13877201ecccc6c0c66f0137e517099e Mon Sep 17 00:00:00 2001 From: Paramjit Singh Sahota Date: Fri, 22 Mar 2013 16:47:15 +0530 Subject: [PATCH 01/14] [IMP]Improve label and help of /Skip 'Draft' State for Manual Entries/ bzr revid: psa@tinyerp.com-20130322111715-qbxuq3166o0z2puc --- addons/account/account.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/account/account.py b/addons/account/account.py index 8c7f058acc6..fda094efb5f 100644 --- a/addons/account/account.py +++ b/addons/account/account.py @@ -722,7 +722,7 @@ class account_journal(osv.osv): 'user_id': fields.many2one('res.users', 'User', help="The user responsible for this journal"), 'groups_id': fields.many2many('res.groups', 'account_journal_group_rel', 'journal_id', 'group_id', 'Groups'), 'currency': fields.many2one('res.currency', 'Currency', help='The currency used to enter statement'), - 'entry_posted': fields.boolean('Skip \'Draft\' State for Manual Entries', help='Check this box if you don\'t want new journal entries to pass through the \'draft\' state and instead goes directly to the \'posted state\' without any manual validation. \nNote that journal entries that are automatically created by the system are always skipping that state.'), + 'entry_posted': fields.boolean('Autopost created moves', help='Check this box to automatically post entries of this journal. Note that legally, some entries are automatically posted when the source document is validated (Invoices), whatever the status of this field.'), 'company_id': fields.many2one('res.company', 'Company', required=True, select=1, help="Company related to this journal"), 'allow_date':fields.boolean('Check Date in Period', help= 'If set to True then do not accept the entry if the entry date is not into the period dates'), From fb82744bac71db510c90a867350675dad601b631 Mon Sep 17 00:00:00 2001 From: Paramjit Singh Sahota Date: Fri, 22 Mar 2013 17:35:33 +0530 Subject: [PATCH 02/14] [IMP] Improved. bzr revid: psa@tinyerp.com-20130322120533-n6oofcl1c7d532cb --- addons/account/account.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/account/account.py b/addons/account/account.py index fda094efb5f..8709b59fa62 100644 --- a/addons/account/account.py +++ b/addons/account/account.py @@ -722,7 +722,7 @@ class account_journal(osv.osv): 'user_id': fields.many2one('res.users', 'User', help="The user responsible for this journal"), 'groups_id': fields.many2many('res.groups', 'account_journal_group_rel', 'journal_id', 'group_id', 'Groups'), 'currency': fields.many2one('res.currency', 'Currency', help='The currency used to enter statement'), - 'entry_posted': fields.boolean('Autopost created moves', help='Check this box to automatically post entries of this journal. Note that legally, some entries are automatically posted when the source document is validated (Invoices), whatever the status of this field.'), + 'entry_posted': fields.boolean('Autopost Created Moves', help='Check this box to automatically post entries of this journal. Note that legally, some entries are automatically posted when the source document is validated (Invoices), whatever the status of this field.'), 'company_id': fields.many2one('res.company', 'Company', required=True, select=1, help="Company related to this journal"), 'allow_date':fields.boolean('Check Date in Period', help= 'If set to True then do not accept the entry if the entry date is not into the period dates'), From 212081200289edd4c60253946514e6e1ed9e0a50 Mon Sep 17 00:00:00 2001 From: Paramjit Singh Sahota Date: Fri, 24 May 2013 17:26:13 +0530 Subject: [PATCH 03/14] [IMP] Little improvement. bzr revid: psa@tinyerp.com-20130524115613-vnj5i3pe0nc9rkdv --- addons/account/account.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/account/account.py b/addons/account/account.py index 66bbaacb91e..31b20c64c96 100644 --- a/addons/account/account.py +++ b/addons/account/account.py @@ -719,7 +719,7 @@ class account_journal(osv.osv): 'user_id': fields.many2one('res.users', 'User', help="The user responsible for this journal"), 'groups_id': fields.many2many('res.groups', 'account_journal_group_rel', 'journal_id', 'group_id', 'Groups'), 'currency': fields.many2one('res.currency', 'Currency', help='The currency used to enter statement'), - 'entry_posted': fields.boolean('Autopost Created Moves', help='Check this box to automatically post entries of this journal. Note that legally, some entries are automatically posted when the source document is validated (Invoices), whatever the status of this field.'), + 'entry_posted': fields.boolean('Autopost Created Moves', help='Check this box to automatically post entries of this journal. Note that legally, some entries may be automatically posted when the source document is validated (Invoices), whatever the status of this field.'), 'company_id': fields.many2one('res.company', 'Company', required=True, select=1, help="Company related to this journal"), 'allow_date':fields.boolean('Check Date in Period', help= 'If set to True then do not accept the entry if the entry date is not into the period dates'), From c61329943a702f88003bf4001806f3f23f744a89 Mon Sep 17 00:00:00 2001 From: Christophe Matthieu Date: Mon, 27 May 2013 14:18:23 +0200 Subject: [PATCH 04/14] [IMP] mail: add breadcrumb from inbox bzr revid: chm@openerp.com-20130527121823-tfjevhu5zl5at4ar --- addons/mail/static/src/js/mail.js | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/addons/mail/static/src/js/mail.js b/addons/mail/static/src/js/mail.js index 21b0f5a9a87..5d54a6acc48 100644 --- a/addons/mail/static/src/js/mail.js +++ b/addons/mail/static/src/js/mail.js @@ -967,6 +967,24 @@ openerp.mail = function (session) { this.$('.oe_reply').on('click', this.on_message_reply); this.$('.oe_star').on('click', this.on_star); this.$('.oe_msg_vote').on('click', this.on_vote); + this.$('.oe_mail_action_model').on('click', this.on_record_clicked); + }, + + on_record_clicked: function (event) { + event.stopPropagation(); + var state = { + 'model': this.model, + 'id': this.res_id, + 'title': this.record_name + }; + session.webclient.action_manager.do_push_state(state); + this.do_action({ + res_model: state.model, + res_id: state.id, + type: 'ir.actions.act_window', + views: [[false, 'form']] + }); + return false; }, /* Call the on_compose_message on the thread of this message. */ From c649ef07062008105ae0db319d358a2155e333d6 Mon Sep 17 00:00:00 2001 From: "Foram Katharotiya (OpenERP)" Date: Mon, 3 Jun 2013 14:15:49 +0530 Subject: [PATCH 05/14] [IMP] rename other information tab to Accounting Information bzr revid: fka@tinyerp.com-20130603084549-qyqsj5t8t11pwqus --- addons/hr_payroll/hr_payroll_view.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/hr_payroll/hr_payroll_view.xml b/addons/hr_payroll/hr_payroll_view.xml index ccd87ba2616..a856bcdfdd4 100644 --- a/addons/hr_payroll/hr_payroll_view.xml +++ b/addons/hr_payroll/hr_payroll_view.xml @@ -322,7 +322,7 @@ - + From a7adac1189d062ad8797b8d7ead929b27715cf3c Mon Sep 17 00:00:00 2001 From: niv-openerp Date: Thu, 11 Jul 2013 12:34:22 +0200 Subject: [PATCH 06/14] Now OpenERPSession is a subclass of werkzeug's session bzr revid: nicolas.vanhoren@openerp.com-20130711103422-w7y05ox7tq0hz0og --- addons/web/controllers/main.py | 2 +- addons/web/http.py | 191 +++++++++----------------- addons/web/static/src/js/chrome.js | 2 +- addons/web/static/src/js/coresetup.js | 6 +- 4 files changed, 68 insertions(+), 133 deletions(-) diff --git a/addons/web/controllers/main.py b/addons/web/controllers/main.py index 846b9099555..2734692b5e9 100644 --- a/addons/web/controllers/main.py +++ b/addons/web/controllers/main.py @@ -916,7 +916,7 @@ class Session(http.Controller): @http.route('/web/session/destroy', type='json', auth="user") def destroy(self): - request.session._suicide = True + request.session.logout() class Menu(http.Controller): diff --git a/addons/web/http.py b/addons/web/http.py index 2f9016cf5cc..8c84083794a 100644 --- a/addons/web/http.py +++ b/addons/web/http.py @@ -101,6 +101,8 @@ class WebRequest(object): self.httprequest = httprequest self.httpresponse = None self.httpsession = httprequest.session + self.session = httprequest.session + self.session_id = httprequest.session.sid self.db = None self.uid = None self.func = None @@ -111,18 +113,10 @@ class WebRequest(object): def init(self, params): self.params = dict(params) - # OpenERP session setup - self.session_id = self.params.pop("session_id", None) - if not self.session_id: - i0 = self.httprequest.cookies.get("instance0|session_id", None) - if i0: - self.session_id = simplejson.loads(urllib2.unquote(i0)) - else: - self.session_id = uuid.uuid4().hex - self.session = self.httpsession.get(self.session_id) - if not self.session: - self.session = OpenERPSession() - self.httpsession[self.session_id] = self.session + + #remove now useless session id + if "session_id" in self.params: + del self.params["session_id"] with set_request(self): self.db = self.session._db or db_monodb() @@ -130,7 +124,7 @@ class WebRequest(object): # TODO: remove this # set db/uid trackers - they're cleaned up at the WSGI # dispatching phase in openerp.service.wsgi_server.application - if self.session._db: + if self.db: threading.current_thread().dbname = self.session._db if self.session._uid: threading.current_thread().uid = self.session._uid @@ -334,6 +328,7 @@ class JsonRequest(WebRequest): return self.jsonp_handler() response = {"jsonrpc": "2.0" } error = None + try: #if _logger.isEnabledFor(logging.DEBUG): # _logger.debug("--> %s.%s\n%s", func.im_class.__name__, func.__name__, pprint.pformat(self.jsonrequest)) @@ -626,32 +621,30 @@ class Model(object): return result return proxy -class OpenERPSession(object): - """ - An OpenERP RPC session, a given user can own multiple such sessions - in a web session. +class OpenERPSession(werkzeug.contrib.sessions.Session): + def __init__(self, *args, **kwargs): + self.inited = False + self.modified = False + super(OpenERPSession, self).__init__(*args, **kwargs) + self.inited = True + self.setdefault("_creation_time", time.time()) + self.setdefault("_db", False) + self.setdefault("_uid", False) + self.setdefault("_login", False) + self.setdefault("_password", False) + self.setdefault("context", {}) + self.setdefault("jsonp_requests", {}) + self.setdefault("modified", False) - .. attribute:: context - - The session context, a ``dict``. Can be reloaded by calling - :meth:`openerpweb.openerpweb.OpenERPSession.get_context` - - .. attribute:: domains_store - - A ``dict`` matching domain keys to evaluable (but non-literal) domains. - - Used to store references to non-literal domains which need to be - round-tripped to the client browser. - """ - def __init__(self): - self._creation_time = time.time() - self._db = False - self._uid = False - self._login = False - self._password = False - self._suicide = False - self.context = {} - self.jsonp_requests = {} # FIXME use a LRU + def __getattr__(self, attr): + return self.get(attr, None) + def __setattr__(self, k, v): + if getattr(self, "inited", False): + try: + object.__getattribute__(self, k) + except: + return self.__setitem__(k, v) + object.__setattr__(self, k, v) def authenticate(self, db, login=None, password=None, env=None, uid=None): """ @@ -660,6 +653,7 @@ class OpenERPSession(object): :param uid: If not None, that user id will be used instead the login to authenticate the user. """ + if uid is None: uid = openerp.netsvc.dispatch_rpc('common', 'authenticate', [db, login, password, env]) else: @@ -684,6 +678,10 @@ class OpenERPSession(object): raise SessionExpiredException("Session expired") security.check(self._db, self._uid, self._password) + def logout(self): + for k in self.keys(): + del self[k] + def get_context(self): """ Re-initializes the current user's session context (based on @@ -791,69 +789,6 @@ class OpenERPSession(object): return Model(self, model) -#---------------------------------------------------------- -# Session context manager -#---------------------------------------------------------- -@contextlib.contextmanager -def session_context(httprequest, session_store, session_lock, sid): - with session_lock: - if sid: - httprequest.session = session_store.get(sid) - else: - httprequest.session = session_store.new() - try: - yield httprequest.session - finally: - # Remove all OpenERPSession instances with no uid, they're generated - # either by login process or by HTTP requests without an OpenERP - # session id, and are generally noise - removed_sessions = set() - for key, value in httprequest.session.items(): - if not isinstance(value, OpenERPSession): - continue - if getattr(value, '_suicide', False) or ( - not value._uid - and not value.jsonp_requests - # FIXME do not use a fixed value - and value._creation_time + (60*5) < time.time()): - _logger.debug('remove session %s', key) - removed_sessions.add(key) - del httprequest.session[key] - - with session_lock: - if sid: - # Re-load sessions from storage and merge non-literal - # contexts and domains (they're indexed by hash of the - # content so conflicts should auto-resolve), otherwise if - # two requests alter those concurrently the last to finish - # will overwrite the previous one, leading to loss of data - # (a non-literal is lost even though it was sent to the - # client and client errors) - # - # note that domains_store and contexts_store are append-only (we - # only ever add items to them), so we can just update one with the - # other to get the right result, if we want to merge the - # ``context`` dict we'll need something smarter - in_store = session_store.get(sid) - for k, v in httprequest.session.iteritems(): - stored = in_store.get(k) - if stored and isinstance(v, OpenERPSession): - if hasattr(v, 'contexts_store'): - del v.contexts_store - if hasattr(v, 'domains_store'): - del v.domains_store - if not hasattr(v, 'jsonp_requests'): - v.jsonp_requests = {} - v.jsonp_requests.update(getattr( - stored, 'jsonp_requests', {})) - - # add missing keys - for k, v in in_store.iteritems(): - if k not in httprequest.session and k not in removed_sessions: - httprequest.session[k] = v - - session_store.save(httprequest.session) - def session_gc(session_store): if random.random() < 0.001: # we keep session one week @@ -931,8 +866,7 @@ class Root(object): # Setup http sessions path = session_path() - self.session_store = werkzeug.contrib.sessions.FilesystemSessionStore(path) - self.session_lock = threading.Lock() + self.session_store = werkzeug.contrib.sessions.FilesystemSessionStore(path, session_class=OpenERPSession) _logger.debug('HTTP sessions stored in: %s', path) @@ -953,39 +887,44 @@ class Root(object): httprequest.parameter_storage_class = werkzeug.datastructures.ImmutableDict httprequest.app = self + session_gc(self.session_store) + sid = httprequest.cookies.get('sid') if not sid: sid = httprequest.args.get('sid') + if sid is None: + httprequest.session = self.session_store.new() + else: + httprequest.session = self.session_store.get(sid) - session_gc(self.session_store) + request = self._build_request(httprequest) + db = request.db - with session_context(httprequest, self.session_store, self.session_lock, sid) as session: - request = self._build_request(httprequest) - db = request.db + if db: + updated = openerp.modules.registry.RegistryManager.check_registry_signaling(db) + if updated: + with self.db_routers_lock: + del self.db_routers[db] - if db: - updated = openerp.modules.registry.RegistryManager.check_registry_signaling(db) - if updated: - with self.db_routers_lock: - del self.db_routers[db] + with set_request(request): + self.find_handler() + result = request.dispatch() - with set_request(request): - self.find_handler() - result = request.dispatch() + if db: + openerp.modules.registry.RegistryManager.signal_caches_change(db) - if db: - openerp.modules.registry.RegistryManager.signal_caches_change(db) + if isinstance(result, basestring): + headers=[('Content-Type', 'text/html; charset=utf-8'), ('Content-Length', len(result))] + response = werkzeug.wrappers.Response(result, headers=headers) + else: + response = result - if isinstance(result, basestring): - headers=[('Content-Type', 'text/html; charset=utf-8'), ('Content-Length', len(result))] - response = werkzeug.wrappers.Response(result, headers=headers) - else: - response = result + if httprequest.session.should_save: + self.session_store.save(httprequest.session) + if hasattr(response, 'set_cookie'): + response.set_cookie('sid', httprequest.session.sid) - if hasattr(response, 'set_cookie'): - response.set_cookie('sid', session.sid) - - return response(environ, start_response) + return response(environ, start_response) except werkzeug.exceptions.HTTPException, e: return e(environ, start_response) diff --git a/addons/web/static/src/js/chrome.js b/addons/web/static/src/js/chrome.js index 0c73a9b8a3c..1c976cb619e 100644 --- a/addons/web/static/src/js/chrome.js +++ b/addons/web/static/src/js/chrome.js @@ -1599,7 +1599,7 @@ instance.web.EmbeddedClient = instance.web.Client.extend({ if (s.session_is_valid() && s.db === this.dbname && s.login === this.login) { return $.when(); } - return instance.session.session_authenticate(this.dbname, this.login, this.key, true); + return instance.session.session_authenticate(this.dbname, this.login, this.key); }, bind_credentials: function(dbname, login, key) { diff --git a/addons/web/static/src/js/coresetup.js b/addons/web/static/src/js/coresetup.js index 7d37dc2261d..81de547d0c1 100644 --- a/addons/web/static/src/js/coresetup.js +++ b/addons/web/static/src/js/coresetup.js @@ -58,7 +58,7 @@ instance.web.Session = instance.web.JsonRPC.extend( /** @lends instance.web.Sess session_init: function () { var self = this; // TODO: session store in cookie should be optional - this.session_id = this.get_cookie('session_id'); + this.session_id = this.get_cookie('sid'); return this.session_reload().then(function(result) { var modules = instance._modules.join(','); var deferred = self.rpc('/web/webclient/qweblist', {mods: modules}).then(self.load_qweb.bind(self)); @@ -107,14 +107,10 @@ instance.web.Session = instance.web.JsonRPC.extend( /** @lends instance.web.Sess return $.Deferred().reject(); } _.extend(self, result); - if (!_volatile) { - self.set_cookie('session_id', self.session_id); - } return self.load_modules(); }); }, session_logout: function() { - this.set_cookie('session_id', ''); $.bbq.removeState(); return this.rpc("/web/session/destroy", {}); }, From 47b5a82ae85e795ae888799426f098066583ecbc Mon Sep 17 00:00:00 2001 From: niv-openerp Date: Thu, 11 Jul 2013 14:20:34 +0200 Subject: [PATCH 07/14] Completely removed all ways to specify session identifiers and reduced them to 2 possibilities: * The http argument 'session_id' (higher priority) * The cookie 'session_id' (lower priority) bzr revid: nicolas.vanhoren@openerp.com-20130711122034-3nvmkw4q5z4io4tm --- addons/web/controllers/main.py | 2 -- addons/web/http.py | 14 ++++++-------- addons/web/static/src/js/corelib.js | 10 +++------- addons/web/static/src/js/coresetup.js | 3 +-- 4 files changed, 10 insertions(+), 19 deletions(-) diff --git a/addons/web/controllers/main.py b/addons/web/controllers/main.py index 2734692b5e9..124ca979c5c 100644 --- a/addons/web/controllers/main.py +++ b/addons/web/controllers/main.py @@ -362,8 +362,6 @@ def login_and_redirect(db, login, key, redirect_url='/'): def set_cookie_and_redirect(redirect_url): redirect = werkzeug.utils.redirect(redirect_url, 303) redirect.autocorrect_location_header = False - cookie_val = urllib2.quote(simplejson.dumps(request.session_id)) - redirect.set_cookie('instance0|session_id', cookie_val) return redirect def load_actions_from_ir_values(key, key2, models, meta): diff --git a/addons/web/http.py b/addons/web/http.py index 8c84083794a..1493f3b8f89 100644 --- a/addons/web/http.py +++ b/addons/web/http.py @@ -114,10 +114,6 @@ class WebRequest(object): def init(self, params): self.params = dict(params) - #remove now useless session id - if "session_id" in self.params: - del self.params["session_id"] - with set_request(self): self.db = self.session._db or db_monodb() @@ -360,7 +356,7 @@ class JsonRequest(WebRequest): # If we use jsonp, that's mean we are called from another host # Some browser (IE and Safari) do no allow third party cookies # We need then to manage http sessions manually. - response['httpsessionid'] = self.httpsession.sid + response['session_id'] = self.session_id mime = 'application/javascript' body = "%s(%s);" % (self.jsonp, simplejson.dumps(response),) else: @@ -424,6 +420,8 @@ class HttpRequest(WebRequest): def __init__(self, *args): super(HttpRequest, self).__init__(*args) params = dict(self.httprequest.args) + if "session_id" in params: + params.pop("session_id") params.update(self.httprequest.form) params.update(self.httprequest.files) self.init(params) @@ -889,9 +887,9 @@ class Root(object): session_gc(self.session_store) - sid = httprequest.cookies.get('sid') + sid = httprequest.args.get('session_id') if not sid: - sid = httprequest.args.get('sid') + sid = httprequest.cookies.get('session_id') if sid is None: httprequest.session = self.session_store.new() else: @@ -922,7 +920,7 @@ class Root(object): if httprequest.session.should_save: self.session_store.save(httprequest.session) if hasattr(response, 'set_cookie'): - response.set_cookie('sid', httprequest.session.sid) + response.set_cookie('session_id', httprequest.session.sid) return response(environ, start_response) except werkzeug.exceptions.HTTPException, e: diff --git a/addons/web/static/src/js/corelib.js b/addons/web/static/src/js/corelib.js index 116ddf2e8c2..01ff92c88a0 100644 --- a/addons/web/static/src/js/corelib.js +++ b/addons/web/static/src/js/corelib.js @@ -1068,13 +1068,12 @@ instance.web.JsonRPC = instance.web.Class.extend(instance.web.PropertiesMixin, { var data = { session_id: this.session_id, id: payload.id, - sid: this.httpsessionid, }; var set_sid = function (response, textStatus, jqXHR) { // If response give us the http session id, we store it for next requests... - if (response.httpsessionid) { - self.httpsessionid = response.httpsessionid; + if (response.session_id) { + self.session_id = response.session_id; } }; @@ -1090,7 +1089,7 @@ instance.web.JsonRPC = instance.web.Class.extend(instance.web.PropertiesMixin, { ajax.async = false; var payload_str = JSON.stringify(payload); var payload_url = $.param({r:payload_str}); - if(payload_url.length < 2000) { + if (payload_url.length < 2000) { // Direct jsonp request ajax.data.r = payload_str; return $.ajax(ajax).done(set_sid); @@ -1139,9 +1138,6 @@ instance.web.JsonRPC = instance.web.Class.extend(instance.web.PropertiesMixin, { var qs = ''; if (!_.isNull(params)) { params = _.extend(params || {}, {session_id: this.session_id}); - if (this.httpsessionid) { - params.sid = this.httpsessionid; - } qs = '?' + $.param(params); } var prefix = _.any(['http://', 'https://', '//'], _.bind(_.str.startsWith, null, path)) ? '' : this.prefix; diff --git a/addons/web/static/src/js/coresetup.js b/addons/web/static/src/js/coresetup.js index 81de547d0c1..f153d3ad73a 100644 --- a/addons/web/static/src/js/coresetup.js +++ b/addons/web/static/src/js/coresetup.js @@ -23,7 +23,6 @@ instance.web.Session = instance.web.JsonRPC.extend( /** @lends instance.web.Sess this.qweb_mutex = new $.Mutex(); }, rpc: function(url, params, options) { - params.session_id = this.session_id; return this._super(url, params, options); }, /** @@ -58,7 +57,7 @@ instance.web.Session = instance.web.JsonRPC.extend( /** @lends instance.web.Sess session_init: function () { var self = this; // TODO: session store in cookie should be optional - this.session_id = this.get_cookie('sid'); + this.session_id = this.get_cookie('session_id'); return this.session_reload().then(function(result) { var modules = instance._modules.join(','); var deferred = self.rpc('/web/webclient/qweblist', {mods: modules}).then(self.load_qweb.bind(self)); From 9aaf79ffd2f80e797481cf5bed9cba35dbea9625 Mon Sep 17 00:00:00 2001 From: niv-openerp Date: Thu, 11 Jul 2013 15:23:01 +0200 Subject: [PATCH 08/14] more and more cleaning bzr revid: nicolas.vanhoren@openerp.com-20130711132301-5fl5giqio4n9yzgk --- addons/web/http.py | 55 +++++++++++------------------ addons/web/static/src/js/corelib.js | 5 ++- 2 files changed, 23 insertions(+), 37 deletions(-) diff --git a/addons/web/http.py b/addons/web/http.py index 1493f3b8f89..81435a6d577 100644 --- a/addons/web/http.py +++ b/addons/web/http.py @@ -110,37 +110,17 @@ class WebRequest(object): self._cr_cm = None self._cr = None self.func_request_type = None - - def init(self, params): - self.params = dict(params) - + self.debug = self.httprequest.args.get('debug', False) is not False with set_request(self): self.db = self.session._db or db_monodb() - - # TODO: remove this # set db/uid trackers - they're cleaned up at the WSGI # dispatching phase in openerp.service.wsgi_server.application if self.db: threading.current_thread().dbname = self.session._db if self.session._uid: threading.current_thread().uid = self.session._uid - - self.context = self.params.pop('context', {}) - self.debug = self.params.pop('debug', False) is not False - # Determine self.lang - lang = self.params.get('lang', None) - if lang is None: - lang = self.context.get('lang') - if lang is None: - lang = self.httprequest.cookies.get('lang') - if lang is None: - lang = self.httprequest.accept_languages.best - if not lang: - lang = 'en_US' - # tranform 2 letters lang like 'en' into 5 letters like 'en_US' - lang = babel.core.LOCALE_ALIASES.get(lang, lang) - # we use _ as seprator where RFC2616 uses '-' - self.lang = lang.replace('-', '_') + self.context = self.session.context + self.lang = self.context["lang"] def _authenticate(self): if self.auth_method == "none": @@ -313,7 +293,8 @@ class JsonRequest(WebRequest): # Read POST content or POST Form Data named "request" self.jsonrequest = simplejson.loads(request, object_hook=reject_nonliteral) - self.init(self.jsonrequest.get("params", {})) + self.params = dict(self.jsonrequest.get("params", {})) + self.context = self.params.pop('context', self.session.context) def dispatch(self): """ Calls the method asked for by the JSON-RPC2 or JSONP request @@ -420,11 +401,13 @@ class HttpRequest(WebRequest): def __init__(self, *args): super(HttpRequest, self).__init__(*args) params = dict(self.httprequest.args) - if "session_id" in params: - params.pop("session_id") + ex = set(["session_id", "debug", "db"]) + for k in params.keys(): + if k in ex: + del params[k] params.update(self.httprequest.form) params.update(self.httprequest.files) - self.init(params) + self.params = params def dispatch(self): akw = {} @@ -630,9 +613,9 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): self.setdefault("_uid", False) self.setdefault("_login", False) self.setdefault("_password", False) - self.setdefault("context", {}) + self.setdefault("context", {'tz': "UTC", "uid": None}) self.setdefault("jsonp_requests", {}) - self.setdefault("modified", False) + self.modified = False def __getattr__(self, attr): return self.get(attr, None) @@ -895,6 +878,11 @@ class Root(object): else: httprequest.session = self.session_store.get(sid) + if not "lang" in httprequest.session.context: + lang = httprequest.accept_languages.best or "en_US" + lang = babel.core.LOCALE_ALIASES.get(lang, lang).replace('-', '_') + httprequest.session.context["lang"] = lang + request = self._build_request(httprequest) db = request.db @@ -1053,19 +1041,18 @@ def db_list(force=False): return dbs def db_redirect(match_first_only_if_unique): - req = request db = False redirect = False # 1 try the db in the url - db_url = req.params.get('db') + db_url = request.httprequest.args.get('db') if db_url: return (db_url, False) dbs = db_list(True) # 2 use the database from the cookie if it's listable and still listed - cookie_db = req.httprequest.cookies.get('last_used_database') + cookie_db = request.httprequest.cookies.get('last_used_database') if cookie_db in dbs: db = cookie_db @@ -1075,9 +1062,9 @@ def db_redirect(match_first_only_if_unique): # redirect to the chosen db if multiple are available if db and len(dbs) > 1: - query = dict(urlparse.parse_qsl(req.httprequest.query_string, keep_blank_values=True)) + query = dict(urlparse.parse_qsl(request.httprequest.query_string, keep_blank_values=True)) query.update({'db': db}) - redirect = req.httprequest.path + '?' + urllib.urlencode(query) + redirect = request.httprequest.path + '?' + urllib.urlencode(query) return (db, redirect) def db_monodb(): diff --git a/addons/web/static/src/js/corelib.js b/addons/web/static/src/js/corelib.js index 01ff92c88a0..007a0adc803 100644 --- a/addons/web/static/src/js/corelib.js +++ b/addons/web/static/src/js/corelib.js @@ -1000,8 +1000,6 @@ instance.web.JsonRPC = instance.web.Class.extend(instance.web.PropertiesMixin, { context: this.user_context || {} }); // Construct a JSON-RPC2 request, method is currently unused - if (this.debug) - params.debug = 1; var payload = { jsonrpc: '2.0', method: 'call', @@ -1011,7 +1009,8 @@ instance.web.JsonRPC = instance.web.Class.extend(instance.web.PropertiesMixin, { var deferred = $.Deferred(); if (! options.shadow) this.trigger('request', url, payload); - + payload.debug = this.debug ? true : false; + this.rpc_function(url, payload).then( function (response, textStatus, jqXHR) { if (! options.shadow) From 0d7ec71bc9d2c0fed4999d7a796166b05293ea6f Mon Sep 17 00:00:00 2001 From: niv-openerp Date: Thu, 11 Jul 2013 15:39:28 +0200 Subject: [PATCH 09/14] Renamed all _shit in session to remove the underscore bzr revid: nicolas.vanhoren@openerp.com-20130711133928-zp40wl2t5q54wrnv --- addons/web/http.py | 86 ++++++++++++++++++++++++++++++---------------- 1 file changed, 57 insertions(+), 29 deletions(-) diff --git a/addons/web/http.py b/addons/web/http.py index 81435a6d577..aed64cc9183 100644 --- a/addons/web/http.py +++ b/addons/web/http.py @@ -112,13 +112,13 @@ class WebRequest(object): self.func_request_type = None self.debug = self.httprequest.args.get('debug', False) is not False with set_request(self): - self.db = self.session._db or db_monodb() + self.db = self.session.db or db_monodb() # set db/uid trackers - they're cleaned up at the WSGI # dispatching phase in openerp.service.wsgi_server.application if self.db: - threading.current_thread().dbname = self.session._db - if self.session._uid: - threading.current_thread().uid = self.session._uid + threading.current_thread().dbname = self.session.db + if self.session.uid: + threading.current_thread().uid = self.session.uid self.context = self.session.context self.lang = self.context["lang"] @@ -127,7 +127,7 @@ class WebRequest(object): self.db = None self.uid = None elif self.auth_method == "admin": - self.db = self.session._db or db_monodb() + self.db = self.session.db or db_monodb() if not self.db: raise SessionExpiredException("No valid database for request %s" % self.httprequest) self.uid = openerp.SUPERUSER_ID @@ -136,8 +136,8 @@ class WebRequest(object): self.session.check_security() except SessionExpiredException, e: raise SessionExpiredException("Session expired for request %s" % self.httprequest) - self.db = self.session._db - self.uid = self.session._uid + self.db = self.session.db + self.uid = self.session.uid @property def registry(self): @@ -584,8 +584,8 @@ class Model(object): def proxy(*args, **kw): # Can't provide any retro-compatibility for this case, so we check it and raise an Exception # to tell the programmer to adapt his code - if not request.db or not request.uid or self.session._db != request.db \ - or self.session._uid != request.uid: + if not request.db or not request.uid or self.session.db != request.db \ + or self.session.uid != request.uid: raise Exception("Trying to use Model with badly configured database or user.") mod = request.registry.get(self.model) @@ -608,11 +608,10 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): self.modified = False super(OpenERPSession, self).__init__(*args, **kwargs) self.inited = True - self.setdefault("_creation_time", time.time()) - self.setdefault("_db", False) - self.setdefault("_uid", False) - self.setdefault("_login", False) - self.setdefault("_password", False) + self.setdefault("db", False) + self.setdefault("uid", False) + self.setdefault("login", False) + self.setdefault("password", False) self.setdefault("context", {'tz': "UTC", "uid": None}) self.setdefault("jsonp_requests", {}) self.modified = False @@ -639,10 +638,10 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): uid = openerp.netsvc.dispatch_rpc('common', 'authenticate', [db, login, password, env]) else: security.check(db, uid, password) - self._db = db - self._uid = uid - self._login = login - self._password = password + self.db = db + self.uid = uid + self.login = login + self.password = password request.db = db request.uid = uid @@ -655,9 +654,9 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): should be called at each request. If the authentication fails, a ``SessionExpiredException`` is raised. """ - if not self._db or not self._uid: + if not self.db or not self.uid: raise SessionExpiredException("Session expired") - security.check(self._db, self._uid, self._password) + security.check(self.db, self.uid, self.password) def logout(self): for k in self.keys(): @@ -671,9 +670,9 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): :returns: the new context """ - assert self._uid, "The user needs to be logged-in to initialize his context" + assert self.uid, "The user needs to be logged-in to initialize his context" self.context = request.registry.get('res.users').context_get(request.cr, request.uid) or {} - self.context['uid'] = self._uid + self.context['uid'] = self.uid self._fix_lang(self.context) return self.context @@ -697,6 +696,35 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): context['lang'] = lang or 'en_US' + """ + Damn properties for retro-compatibility. All of that is deprecated, all + of that. + """ + @property + def _db(self): + return self.db + @_db.setter + def _db(self, value): + self.db = value + @property + def _uid(self): + return self.uid + @_uid.setter + def _uid(self, value): + self.uid = value + @property + def _login(self): + return self.login + @_login.setter + def _login(self, value): + self.login = value + @property + def _password(self): + return self.password + @_password.setter + def _password(self, value): + self.password = value + def send(self, service_name, method, *args): """ .. deprecated:: 8.0 @@ -718,11 +746,11 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): Ensures this session is valid (logged into the openerp server) """ - if self._uid and not force: + if self.uid and not force: return # TODO use authenticate instead of login - self._uid = self.proxy("common").login(self._db, self._login, self._password) - if not self._uid: + self.uid = self.proxy("common").login(self.db, self.login, self.password) + if not self.uid: raise AuthenticationError("Authentication failure") def ensure_valid(self): @@ -730,11 +758,11 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): .. deprecated:: 8.0 Use ``check_security()`` instead. """ - if self._uid: + if self.uid: try: self.assert_valid(True) except Exception: - self._uid = None + self.uid = None def execute(self, model, func, *l, **d): """ @@ -751,7 +779,7 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): Use the resistry and cursor in ``openerp.addons.web.http.request`` instead. """ self.assert_valid() - r = self.proxy('object').exec_workflow(self._db, self._uid, self._password, model, signal, id) + r = self.proxy('object').exec_workflow(self.db, self.uid, self.password, model, signal, id) return r def model(self, model): @@ -765,7 +793,7 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): :type model: str :rtype: a model object """ - if self._db == False: + if self.db == False: raise SessionExpiredException("Session expired") return Model(self, model) From 89c8698cb3c1ea629d8027d7d157e33ad2f3b388 Mon Sep 17 00:00:00 2001 From: niv-openerp Date: Thu, 11 Jul 2013 15:48:25 +0200 Subject: [PATCH 10/14] Make the server always check the identity of the logged user and switch default values of db, uid, login and password to None bzr revid: nicolas.vanhoren@openerp.com-20130711134825-teiuidqv7z2bzsuq --- addons/web/http.py | 28 ++++++++++++++++------------ 1 file changed, 16 insertions(+), 12 deletions(-) diff --git a/addons/web/http.py b/addons/web/http.py index aed64cc9183..612260fbdbd 100644 --- a/addons/web/http.py +++ b/addons/web/http.py @@ -61,8 +61,9 @@ class WebRequest(object): .. attribute:: httpsession - a :class:`~collections.Mapping` holding the HTTP session data for the - current http session + .. deprecated:: 8.0 + + Use ``self.session`` instead. .. attribute:: params @@ -77,7 +78,8 @@ class WebRequest(object): .. attribute:: session - :class:`~session.OpenERPSession` instance for the current request + a :class:`OpenERPSession` holding the HTTP session data for the + current http session .. attribute:: context @@ -95,7 +97,7 @@ class WebRequest(object): .. attribute:: uid ``int``, the id of the user related to the current request. Can be ``None`` - if the current request uses the ``none`` or the ``db`` authenticatoin. + if the current request uses the ``none`` authenticatoin. """ def __init__(self, httprequest): self.httprequest = httprequest @@ -123,6 +125,12 @@ class WebRequest(object): self.lang = self.context["lang"] def _authenticate(self): + if self.session.uid: + try: + self.session.check_security() + except SessionExpiredException, e: + self.session.logout() + raise SessionExpiredException("Session expired for request %s" % self.httprequest) if self.auth_method == "none": self.db = None self.uid = None @@ -132,10 +140,6 @@ class WebRequest(object): raise SessionExpiredException("No valid database for request %s" % self.httprequest) self.uid = openerp.SUPERUSER_ID else: # auth - try: - self.session.check_security() - except SessionExpiredException, e: - raise SessionExpiredException("Session expired for request %s" % self.httprequest) self.db = self.session.db self.uid = self.session.uid @@ -608,10 +612,10 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): self.modified = False super(OpenERPSession, self).__init__(*args, **kwargs) self.inited = True - self.setdefault("db", False) - self.setdefault("uid", False) - self.setdefault("login", False) - self.setdefault("password", False) + self.setdefault("db", None) + self.setdefault("uid", None) + self.setdefault("login", None) + self.setdefault("password", None) self.setdefault("context", {'tz': "UTC", "uid": None}) self.setdefault("jsonp_requests", {}) self.modified = False From 3569ff8654748e9fc12a5852dce42d9254672f0c Mon Sep 17 00:00:00 2001 From: niv-openerp Date: Thu, 11 Jul 2013 16:05:19 +0200 Subject: [PATCH 11/14] Some details + documentation bzr revid: nicolas.vanhoren@openerp.com-20130711140519-hdsu75efwvfq4h4q --- addons/web/http.py | 72 +++++++++++++++++++--------------------------- 1 file changed, 29 insertions(+), 43 deletions(-) diff --git a/addons/web/http.py b/addons/web/http.py index 612260fbdbd..0dbfd871667 100644 --- a/addons/web/http.py +++ b/addons/web/http.py @@ -192,21 +192,18 @@ def route(route, type="http", auth="user"): Decorator marking the decorated method as being a handler for requests. The method must be part of a subclass of ``Controller``. - Decorator to put on a controller method to inform it does not require a user to be logged. When this decorator - is used, ``request.uid`` will be ``None``. The request will still try to detect the database and an exception - will be launched if there is no way to guess it. - :param route: string or array. The route part that will determine which http requests will match the decorated method. Can be a single string or an array of strings. See werkzeug's routing documentation for the format of route expression ( http://werkzeug.pocoo.org/docs/routing/ ). :param type: The type of request, can be ``'http'`` or ``'json'``. :param auth: The type of authentication method, can on of the following: - * ``auth``: The user must be authenticated. - * ``db``: There is no need for the user to be authenticated but there must be a way to find the current - database. + * ``user``: The user must be authenticated and the current request will perform using the rights of the + user. + * ``admin``: The user may not be authenticated and the current request will perform using the admin user. * ``none``: The method is always active, even if there is no database. Mainly used by the framework and - authentication modules. + authentication modules. There request code will not have any facilities to access the database nor have any + configuration indicating the current database nor the current user. """ assert type in ["http", "json"] assert auth in ["user", "admin", "none"] @@ -234,8 +231,7 @@ class JsonRequest(WebRequest): --> {"jsonrpc": "2.0", "method": "call", - "params": {"session_id": "SID", - "context": {}, + "params": {"context": {}, "arg1": "val1" }, "id": null} @@ -247,8 +243,7 @@ class JsonRequest(WebRequest): --> {"jsonrpc": "2.0", "method": "call", - "params": {"session_id": "SID", - "context": {}, + "params": {"context": {}, "arg1": "val1" }, "id": null} @@ -302,8 +297,6 @@ class JsonRequest(WebRequest): def dispatch(self): """ Calls the method asked for by the JSON-RPC2 or JSONP request - - :returns: an utf8 encoded JSON-RPC2 or JSONP reply """ if self.jsonp_handler: return self.jsonp_handler() @@ -382,14 +375,10 @@ def to_jsonable(o): return u"%s" % o def jsonrequest(f): - """ Decorator marking the decorated method as being a handler for a - JSON-RPC request (the exact request path is specified via the - ``$(Controller._cp_path)/$methodname`` combination. + """ + .. deprecated:: 8.0 - If the method is called, it will be provided with a :class:`JsonRequest` - instance and all ``params`` sent during the JSON-RPC request, apart from - the ``session_id``, ``context`` and ``debug`` keys (which are stripped out - beforehand) + Use the ``route()`` decorator instead. """ f.combine = True base = f.__name__ @@ -469,14 +458,10 @@ class HttpRequest(WebRequest): return werkzeug.exceptions.NotFound(description) def httprequest(f): - """ Decorator marking the decorated method as being a handler for a - normal HTTP request (the exact request path is specified via the - ``$(Controller._cp_path)/$methodname`` combination. + """ + .. deprecated:: 8.0 - If the method is called, it will be provided with a :class:`HttpRequest` - instance and all ``params`` sent during the request (``GET`` and ``POST`` - merged in the same dictionary), apart from the ``session_id``, ``context`` - and ``debug`` keys (which are stripped out beforehand) + Use the ``route()`` decorator instead. """ f.combine = True base = f.__name__ @@ -797,7 +782,7 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): :type model: str :rtype: a model object """ - if self.db == False: + if not self.db: raise SessionExpiredException("Session expired") return Model(self, model) @@ -890,10 +875,7 @@ class Root(object): def dispatch(self, environ, start_response): """ - Performs the actual WSGI dispatching for the application, may be - wrapped during the initialization of the object. - - Call the object directly. + Performs the actual WSGI dispatching for the application. """ try: httprequest = werkzeug.wrappers.Request(environ) @@ -1042,12 +1024,7 @@ class Root(object): def find_handler(self): """ - Tries to discover the controller handling the request for the path - specified by the provided parameters - - :param path: path to match - :returns: a callable matching the path sections - :rtype: ``Controller | None`` + Tries to discover the controller handling the request for the path specified in the request. """ path = request.httprequest.path urls = self.get_db_router(request.db).bind("") @@ -1073,13 +1050,13 @@ def db_list(force=False): return dbs def db_redirect(match_first_only_if_unique): - db = False - redirect = False + db = None + redirect = None # 1 try the db in the url db_url = request.httprequest.args.get('db') if db_url: - return (db_url, False) + return (db_url, None) dbs = db_list(True) @@ -1100,7 +1077,16 @@ def db_redirect(match_first_only_if_unique): return (db, redirect) def db_monodb(): - # if only one db exists, return it else return False + """ + Magic function to find the current database. + + Implementation details: + + * Magic + * More magic + + Return ``None`` if the magic is not magic enough. + """ return db_redirect(True)[0] From e6fc23d9802d467c8229dba060c655b2b56cf24c Mon Sep 17 00:00:00 2001 From: niv-openerp Date: Thu, 11 Jul 2013 16:18:32 +0200 Subject: [PATCH 12/14] Forgot some refactoring bzr revid: nicolas.vanhoren@openerp.com-20130711141832-8y5yj3lj7h4gb94q --- addons/web/controllers/main.py | 30 +++++++++++++++--------------- 1 file changed, 15 insertions(+), 15 deletions(-) diff --git a/addons/web/controllers/main.py b/addons/web/controllers/main.py index 124ca979c5c..d485d58443d 100644 --- a/addons/web/controllers/main.py +++ b/addons/web/controllers/main.py @@ -810,16 +810,16 @@ class Session(http.Controller): request.session.ensure_valid() return { "session_id": request.session_id, - "uid": request.session._uid, - "user_context": request.session.get_context() if request.session._uid else {}, - "db": request.session._db, - "username": request.session._login, + "uid": request.session.uid, + "user_context": request.session.get_context() if request.session.uid else {}, + "db": request.session.db, + "username": request.session.login, } @http.route('/web/session/get_session_info', type='json', auth="none") def get_session_info(self): - request.uid = request.session._uid - request.db = request.session._db + request.uid = request.session.uid + request.db = request.session.db return self.session_info() @http.route('/web/session/authenticate', type='json', auth="none") @@ -853,7 +853,7 @@ class Session(http.Controller): @http.route('/web/session/sc_list', type='json', auth="user") def sc_list(self): return request.session.model('ir.ui.view_sc').get_sc( - request.session._uid, "ir.ui.menu", request.context) + request.session.uid, "ir.ui.menu", request.context) @http.route('/web/session/get_lang_list', type='json', auth="none") def get_lang_list(self): @@ -928,7 +928,7 @@ class Menu(http.Controller): s = request.session Menus = s.model('ir.ui.menu') # If a menu action is defined use its domain to get the root menu items - user_menu_id = s.model('res.users').read([s._uid], ['menu_id'], + user_menu_id = s.model('res.users').read([s.uid], ['menu_id'], request.context)[0]['menu_id'] menu_domain = [('parent_id', '=', False)] @@ -1125,7 +1125,7 @@ class View(http.Controller): def add_custom(self, view_id, arch): CustomView = request.session.model('ir.ui.view.custom') CustomView.create({ - 'user_id': request.session._uid, + 'user_id': request.session.uid, 'ref_id': view_id, 'arch': arch }, request.context) @@ -1134,7 +1134,7 @@ class View(http.Controller): @http.route('/web/view/undo_custom', type='json', auth="user") def undo_custom(self, view_id, reset=False): CustomView = request.session.model('ir.ui.view.custom') - vcustom = CustomView.search([('user_id', '=', request.session._uid), ('ref_id' ,'=', view_id)], + vcustom = CustomView.search([('user_id', '=', request.session.uid), ('ref_id' ,'=', view_id)], 0, False, False, request.context) if vcustom: if reset: @@ -1317,9 +1317,9 @@ class Binary(http.Controller): def company_logo(self, dbname=None): # TODO add etag, refactor to use /image code for etag uid = None - if request.session._db: - dbname = request.session._db - uid = request.session._uid + if request.session.db: + dbname = request.session.db + uid = request.session.uid elif dbname is None: dbname = db_monodb() @@ -1685,14 +1685,14 @@ class Reports(http.Controller): raise ValueError("action['datas']['ids'] and context['active_ids'] are undefined") report_id = report_srv.report( - request.session._db, request.session._uid, request.session._password, + request.session.db, request.session.uid, request.session.password, action["report_name"], report_ids, report_data, context) report_struct = None while True: report_struct = report_srv.report_get( - request.session._db, request.session._uid, request.session._password, report_id) + request.session.db, request.session.uid, request.session.password, report_id) if report_struct["state"]: break From a0a05454aa2e04c7b66425c40c3812890fc35458 Mon Sep 17 00:00:00 2001 From: niv-openerp Date: Thu, 11 Jul 2013 17:41:37 +0200 Subject: [PATCH 13/14] Solved a problem appearing in share module bzr revid: nicolas.vanhoren@openerp.com-20130711154137-vwgb5cd4wj26jed8 --- addons/web/http.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/web/http.py b/addons/web/http.py index 0dbfd871667..5e48749df45 100644 --- a/addons/web/http.py +++ b/addons/web/http.py @@ -394,7 +394,7 @@ class HttpRequest(WebRequest): def __init__(self, *args): super(HttpRequest, self).__init__(*args) params = dict(self.httprequest.args) - ex = set(["session_id", "debug", "db"]) + ex = set(["session_id", "debug"]) for k in params.keys(): if k in ex: del params[k] From 12f58092f2df0d7236dbadf346765bcb37ae5929 Mon Sep 17 00:00:00 2001 From: niv-openerp Date: Thu, 11 Jul 2013 18:07:02 +0200 Subject: [PATCH 14/14] [IMP] some refactoring due to changes in the web client bzr revid: nicolas.vanhoren@openerp.com-20130711160702-qs6pfyqsxmzd7cgy --- addons/im/im.py | 16 +++++---- addons/im_livechat/im_livechat.py | 45 ++++++++++++++---------- addons/point_of_sale/controllers/main.py | 4 +-- 3 files changed, 37 insertions(+), 28 deletions(-) diff --git a/addons/im/im.py b/addons/im/im.py index 4a867789cbc..505ca3627b6 100644 --- a/addons/im/im.py +++ b/addons/im/im.py @@ -101,17 +101,19 @@ class LongPollingController(http.Controller): raise Exception("Not usable in a server not running gevent") from openerp.addons.im.watcher import ImWatcher if db is not None: - request.session.authenticate(db=db, uid=uid, password=password) + openerp.service.security.check(db, uid, password) else: - request.session.authenticate(db=request.session._db, uid=request.session._uid, password=request.session._password) + uid = request.session.uid + db = request.session.db - with request.registry.cursor() as cr: - request.registry.get('im.user').im_connect(cr, request.uid, uuid=uuid, context=request.context) - my_id = request.registry.get('im.user').get_by_user_id(cr, request.uid, uuid or request.session._uid, request.context)["id"] + registry = openerp.modules.registry.RegistryManager.get(db) + with registry.cursor() as cr: + registry.get('im.user').im_connect(cr, uid, uuid=uuid, context=request.context) + my_id = registry.get('im.user').get_by_user_id(cr, uid, uuid or uid, request.context)["id"] num = 0 while True: - with request.registry.cursor() as cr: - res = request.registry.get('im.message').get_messages(cr, request.uid, last, users_watch, uuid=uuid, context=request.context) + with registry.cursor() as cr: + res = registry.get('im.message').get_messages(cr, uid, last, users_watch, uuid=uuid, context=request.context) if num >= 1 or len(res["res"]) > 0: return res last = res["last"] diff --git a/addons/im_livechat/im_livechat.py b/addons/im_livechat/im_livechat.py index adceebc7cba..b68a0079c3a 100644 --- a/addons/im_livechat/im_livechat.py +++ b/addons/im_livechat/im_livechat.py @@ -37,36 +37,45 @@ env.filters["json"] = json.dumps class LiveChatController(http.Controller): - @http.route('/im_livechat/loader') + def _auth(self, db): + reg = openerp.modules.registry.RegistryManager.get(db) + uid = openerp.netsvc.dispatch_rpc('common', 'authenticate', [db, "anonymous", "anonymous", None]) + return reg, uid + + @http.route('/im_livechat/loader', auth="none") def loader(self, **kwargs): p = json.loads(kwargs["p"]) db = p["db"] channel = p["channel"] user_name = p.get("user_name", None) - request.session.authenticate(db=db, login="anonymous", password="anonymous") - info = request.session.model('im_livechat.channel').get_info_for_chat_src(channel) - info["db"] = db - info["channel"] = channel - info["userName"] = user_name - return request.make_response(env.get_template("loader.js").render(info), - headers=[('Content-Type', "text/javascript")]) - @http.route('/im_livechat/web_page') + reg, uid = self._auth(db) + with reg.cursor() as cr: + info = reg.get('im_livechat.channel').get_info_for_chat_src(cr, uid, channel) + info["db"] = db + info["channel"] = channel + info["userName"] = user_name + return request.make_response(env.get_template("loader.js").render(info), + headers=[('Content-Type', "text/javascript")]) + + @http.route('/im_livechat/web_page', auth="none") def web_page(self, **kwargs): p = json.loads(kwargs["p"]) db = p["db"] channel = p["channel"] - request.session.authenticate(db=db, login="anonymous", password="anonymous") - script = request.session.model('im_livechat.channel').read(channel, ["script"])["script"] - info = request.session.model('im_livechat.channel').get_info_for_chat_src(channel) - info["script"] = script - return request.make_response(env.get_template("web_page.html").render(info), - headers=[('Content-Type', "text/html")]) + reg, uid = self._auth(db) + with reg.cursor() as cr: + script = reg.get('im_livechat.channel').read(cr, uid, channel, ["script"])["script"] + info = reg.get('im_livechat.channel').get_info_for_chat_src(cr, uid, channel) + info["script"] = script + return request.make_response(env.get_template("web_page.html").render(info), + headers=[('Content-Type', "text/html")]) - @http.route('/im_livechat/available', type='json') + @http.route('/im_livechat/available', type='json', auth="none") def available(self, db, channel): - request.session.authenticate(db=db, login="anonymous", password="anonymous") - return request.session.model('im_livechat.channel').get_available_user(channel) > 0 + reg, uid = self._auth(db) + with reg.cursor() as cr: + return reg.get('im_livechat.channel').get_available_user(cr, uid, channel) > 0 class im_livechat_channel(osv.osv): _name = 'im_livechat.channel' diff --git a/addons/point_of_sale/controllers/main.py b/addons/point_of_sale/controllers/main.py index b189c8f204a..a4a06e94eaa 100644 --- a/addons/point_of_sale/controllers/main.py +++ b/addons/point_of_sale/controllers/main.py @@ -14,9 +14,7 @@ class PointOfSaleController(openerp.addons.web.http.Controller): js = "\n ".join('' % i for i in manifest_list(req, None, 'js')) css = "\n ".join('' % i for i in manifest_list(req, None, 'css')) - cookie = req.httprequest.cookies.get("instance0|session_id") - session_id = cookie.replace("%22","") - template = html_template.replace('