From 6ac32c655e66e6e70c85391cad60d3ed4db64af1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Manuel=20V=C3=A1zquez=20Acosta?= Date: Wed, 16 Jan 2019 06:51:43 -0500 Subject: [PATCH 1/8] [FIX] survey: don't disclose the survey via print To avoid bigger changes, only verify if the login is required. A proper refactoring has been implemented in master at 9771fdfe8f658fd0f Closes odoo/odoo#30166 --- addons/survey/controllers/main.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/addons/survey/controllers/main.py b/addons/survey/controllers/main.py index 553fc5ad4b2..331b8a8642c 100644 --- a/addons/survey/controllers/main.py +++ b/addons/survey/controllers/main.py @@ -252,6 +252,10 @@ class WebsiteSurvey(http.Controller): def print_survey(self, survey, token=None, **post): '''Display an survey in printable view; if is set, it will grab the answers of the user_input_id that has .''' + + if survey.auth_required and request.env.user == request.website.user_id: + return request.render("survey.auth_required", {'survey': survey, 'token': token}) + return request.render('survey.survey_print', {'survey': survey, 'token': token, From 92e4c4c347c9ca84d265c81ca9ab3e5a4620b593 Mon Sep 17 00:00:00 2001 From: Iryna Vyshnevska Date: Wed, 9 Jan 2019 13:42:50 +0000 Subject: [PATCH 2/8] [CLA] signature for ivyshnevska Backport to 10.0 of 3b14a7daa6c5a4d92b0 closes odoo/odoo#30090 --- doc/cla/individual/i-vyshnevska.md | 9 +++++++++ 1 file changed, 9 insertions(+) create mode 100644 doc/cla/individual/i-vyshnevska.md diff --git a/doc/cla/individual/i-vyshnevska.md b/doc/cla/individual/i-vyshnevska.md new file mode 100644 index 00000000000..0df4e78944d --- /dev/null +++ b/doc/cla/individual/i-vyshnevska.md @@ -0,0 +1,9 @@ +Ukraine, 2019-01-09 + +I hereby agree to the terms of the Odoo Individual Contributor License Agreement v1.0. + +I declare that I am authorized and able to make this agreement and sign this declaration. + +Signed, + +Vyshnevska Iryna i.vyshnevska@mobilunity.com https://github.com/i-vyshnevska/ \ No newline at end of file From 614babd1e78e4ea329c3628bedbca652207b7867 Mon Sep 17 00:00:00 2001 From: Nicolas Martinelli Date: Wed, 16 Jan 2019 11:09:21 +0000 Subject: [PATCH 3/8] [FIX] account: bank statement with many AML - Create a bank statement with more than 80 lines (therefore more than 80 AML) - Reconcile the lines - Go back to the bank statement, and try to add a new line An error arise: "You cannot do this modification on a posted journal entry, you can just change some non legal fields" The error arise on the `move_line_ids` field on which the web client tries to write. Actually, this field is hidden since it is only used in the domain of a stat button. We can make it read-only. opw-1921138 closes odoo/odoo#30266 --- addons/account/views/account_view.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/account/views/account_view.xml b/addons/account/views/account_view.xml index 6d7434b65bd..6973755853b 100644 --- a/addons/account/views/account_view.xml +++ b/addons/account/views/account_view.xml @@ -559,7 +559,7 @@