From 085f6e0e6872cbfe2e4ee2c8db92bef0f1f23b8c Mon Sep 17 00:00:00 2001 From: Aaron Bohy Date: Tue, 8 Dec 2015 15:45:09 +0100 Subject: [PATCH 001/117] [FIX] mail: multiple clicks on navbar needactions icon Clicking on this icon redirects to the client action (for now at least). By quickly clicking several times on it, we try to restore the scroll position of a channel that not yet exists. This rev. prevents from getting a traceback in that case. --- addons/mail/static/src/js/client_action.js | 4 +++- addons/mail/static/src/js/systray.js | 5 ++++- 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/addons/mail/static/src/js/client_action.js b/addons/mail/static/src/js/client_action.js index fc9d73fbfb7..e06abc5a9de 100644 --- a/addons/mail/static/src/js/client_action.js +++ b/addons/mail/static/src/js/client_action.js @@ -120,7 +120,9 @@ var ChatAction = Widget.extend(ControlPanelMixin, { }, on_attach_callback: function () { - this.thread.scroll_to({offset: this.channels_scrolltop[this.channel.id]}); + if (this.channel) { + this.thread.scroll_to({offset: this.channels_scrolltop[this.channel.id]}); + } }, on_detach_callback: function () { this.channels_scrolltop[this.channel.id] = this.thread.get_scrolltop(); diff --git a/addons/mail/static/src/js/systray.js b/addons/mail/static/src/js/systray.js index c5d34f179bc..19e225c364f 100644 --- a/addons/mail/static/src/js/systray.js +++ b/addons/mail/static/src/js/systray.js @@ -29,11 +29,14 @@ var NotificationTopButton = Widget.extend({ }, on_click: function (event) { event.preventDefault(); + this.discuss_redirect(); + }, + discuss_redirect: _.debounce(function () { var discuss_ids = chat_manager.get_discuss_ids(); this.do_action(discuss_ids.action_id, {clear_breadcrumbs: true}).then(function () { core.bus.trigger('change_menu_section', discuss_ids.menu_id); }); - }, + }, 1000, true), }); SystrayMenu.Items.push(NotificationTopButton); From 6cf8ebab3d549e9ea28d662d1caf6cb2ccb1db82 Mon Sep 17 00:00:00 2001 From: Aaron Bohy Date: Wed, 9 Dec 2015 10:37:24 +0100 Subject: [PATCH 002/117] [FIX] mail: escape user and channel names to prevent xss However, users shouldn't be allowed to have xss in their name, imo. --- addons/mail/static/src/js/chat_manager.js | 2 +- addons/mail/static/src/js/client_action.js | 12 +++++++----- 2 files changed, 8 insertions(+), 6 deletions(-) diff --git a/addons/mail/static/src/js/chat_manager.js b/addons/mail/static/src/js/chat_manager.js index 2261b961410..9c2787e18ce 100644 --- a/addons/mail/static/src/js/chat_manager.js +++ b/addons/mail/static/src/js/chat_manager.js @@ -98,7 +98,7 @@ function add_message (data, options) { if (!query.is_displayed) { var title = _t('New message'); if (msg.author_id[1]) { - title += _t(' from ') + msg.author_id[1]; + title += _t(' from ') + _.escape(msg.author_id[1]); } var trunc_text = function (t, limit) { return (t.length > limit) ? t.substr(0, limit-1)+'…' : t; diff --git a/addons/mail/static/src/js/client_action.js b/addons/mail/static/src/js/client_action.js index e06abc5a9de..c26ee8fb60c 100644 --- a/addons/mail/static/src/js/client_action.js +++ b/addons/mail/static/src/js/client_action.js @@ -76,7 +76,7 @@ var PartnerInviteDialog = Dialog.extend({ var ChannelModel = new Model('mail.channel'); return ChannelModel.call('channel_invite', [], {ids : [this.channel_id], partner_ids: _.pluck(data, 'id')}) .then(function(){ - var names = _.pluck(data, 'text').join(', '); + var names = _.escape(_.pluck(data, 'text').join(', ')); var notification = _.str.sprintf(_t('You added %s to the conversation.'), names); self.do_notify(_t('New people'), notification); }); @@ -293,9 +293,10 @@ var ChatAction = Widget.extend(ControlPanelMixin, { return Channel.call('channel_search_to_join', [search_val]).then(function(result){ var values = []; _.each(result, function(channel){ + var escaped_name = _.escape(channel.name); values.push(_.extend(channel, { - 'value': channel.name, - 'label': channel.name, + 'value': escaped_name, + 'label': escaped_name, })); }); return values; @@ -307,9 +308,10 @@ var ChatAction = Widget.extend(ControlPanelMixin, { return Partner.call('im_search', [search_val, 20]).then(function(result){ var values = []; _.each(result, function(user){ + var escaped_name = _.escape(user.name); values.push(_.extend(user, { - 'value': user.name, - 'label': user.name, + 'value': escaped_name, + 'label': escaped_name, })); }); return values; From bff2fcde3cdb4adfdd501da9999ea5f6901edf76 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?G=C3=A9ry=20Debongnie?= Date: Wed, 9 Dec 2015 10:39:21 +0100 Subject: [PATCH 003/117] [FIX] mail: correctly handle message on star/unread updates --- addons/mail/static/src/js/chat_manager.js | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/addons/mail/static/src/js/chat_manager.js b/addons/mail/static/src/js/chat_manager.js index 9c2787e18ce..852f1903429 100644 --- a/addons/mail/static/src/js/chat_manager.js +++ b/addons/mail/static/src/js/chat_manager.js @@ -450,6 +450,10 @@ function on_toggle_star_notification (data) { message.is_starred = data.starred; if (!message.is_starred) { remove_message_from_channel("channel_starred", message); + } else { + add_to_cache(message, []); + var channel_starred = chat_manager.get_channel('channel_starred'); + channel_starred.cache = _.pick(channel_starred.cache, "[]"); } chat_manager.bus.trigger('update_message', message); } @@ -487,8 +491,12 @@ function on_mark_as_unread_notification (data) { if (message) { invalidate_caches(message.channel_ids); add_channel_to_message(message, 'channel_inbox'); + add_to_cache(message, []); } }); + var channel_inbox = chat_manager.get_channel('channel_inbox'); + channel_inbox.cache = _.pick(channel_inbox.cache, "[]"); + _.each(data.channel_ids, function (channel_id) { var channel = chat_manager.get_channel(channel_id); if (channel) { From ad1486290739231696a39cdebeef78e209846f0b Mon Sep 17 00:00:00 2001 From: Aaron Bohy Date: Tue, 8 Dec 2015 16:00:33 +0100 Subject: [PATCH 004/117] [FIX] mail: various ui improvements/fixes - display full content of messages in Discuss - no content helpers in inbox and starred improved - mark as read tooltip instead of mark ad done - decrease font size in chat windows - increase chat windows dimensions - display avatars in chat windows - chat window background is now white - notes are displayed with a darker background --- addons/mail/static/src/js/chat_window.js | 3 +-- addons/mail/static/src/js/client_action.js | 3 ++- addons/mail/static/src/js/thread.js | 1 + addons/mail/static/src/js/window_manager.js | 2 +- addons/mail/static/src/less/chat_window.less | 12 +++++++++--- addons/mail/static/src/less/thread.less | 5 +++++ addons/mail/static/src/xml/thread.xml | 16 ++++++++-------- 7 files changed, 27 insertions(+), 15 deletions(-) diff --git a/addons/mail/static/src/js/chat_window.js b/addons/mail/static/src/js/chat_window.js index e9fcaa9fe09..e7b841cc972 100644 --- a/addons/mail/static/src/js/chat_window.js +++ b/addons/mail/static/src/js/chat_window.js @@ -33,7 +33,6 @@ return Widget.extend({ this.thread = new ChatThread(this, { channel_id: this.channel_id, - display_avatar: false, display_needactions: false, display_stars: this.options.display_stars, }); @@ -64,7 +63,7 @@ return Widget.extend({ fold: function () { this.update_header(); this.$el.animate({ - height: this.folded ? "28px" : "333px" + height: this.folded ? "28px" : "400px" }); }, toggle_fold: function (fold) { diff --git a/addons/mail/static/src/js/client_action.js b/addons/mail/static/src/js/client_action.js index c26ee8fb60c..d4d2cb69d4f 100644 --- a/addons/mail/static/src/js/client_action.js +++ b/addons/mail/static/src/js/client_action.js @@ -164,7 +164,8 @@ var ChatAction = Widget.extend(ControlPanelMixin, { this.composer = new ChatComposer(this); this.thread = new ChatThread(this, { - display_help: true + display_help: true, + shorten_messages: false, }); this.$buttons = $(QWeb.render("mail.chat.ControlButtons", {})); diff --git a/addons/mail/static/src/js/thread.js b/addons/mail/static/src/js/thread.js index 86b34255cf7..5381c9f89c3 100644 --- a/addons/mail/static/src/js/thread.js +++ b/addons/mail/static/src/js/thread.js @@ -51,6 +51,7 @@ var Thread = Widget.extend({ display_stars: true, display_document_link: true, display_avatar: true, + shorten_messages: true, squash_close_messages: true, }); }, diff --git a/addons/mail/static/src/js/window_manager.js b/addons/mail/static/src/js/window_manager.js index 5a62c15ed8b..fe60dff4bd5 100644 --- a/addons/mail/static/src/js/window_manager.js +++ b/addons/mail/static/src/js/window_manager.js @@ -11,7 +11,7 @@ var web_client = require('web.web_client'); // chat window management //---------------------------------------------------------------- var chat_sessions = []; -var CHAT_WINDOW_WIDTH = 260; +var CHAT_WINDOW_WIDTH = 300; function open_chat (session) { if (!_.findWhere(chat_sessions, {id: session.id})) { diff --git a/addons/mail/static/src/less/chat_window.less b/addons/mail/static/src/less/chat_window.less index b911ef467ed..ee6ea89b539 100644 --- a/addons/mail/static/src/less/chat_window.less +++ b/addons/mail/static/src/less/chat_window.less @@ -1,11 +1,12 @@ -@o-chat-window-bg: lighten(lightgray, 13%); +@o-chat-window-bg: white; .o_chat_window { .o-flex-display(); .o-flex-flow(column, nowrap); position: fixed; - width: 260px; - height: 333px; + width: 300px; + height: 400px; + font-size: 12px; background-color: @o-chat-window-bg; border: 1px solid gray; border-radius: 3px; @@ -44,6 +45,11 @@ background-color: @o-chat-window-bg; } } + .o_thread_message { + .o_thread_message_sidebar { + margin-right: 5px; + } + } } .o_chat_input > input { diff --git a/addons/mail/static/src/less/thread.less b/addons/mail/static/src/less/thread.less index e28b949bd5d..f2971dcf17e 100644 --- a/addons/mail/static/src/less/thread.less +++ b/addons/mail/static/src/less/thread.less @@ -1,6 +1,7 @@ @mail-thread-avatar-size: 36px; @mail-thread-icon-opacity: 0.6; @mail-thread-side-date-opacity: 0.6; +@mail-thread-note: @gray-lighter; .o_mail_thread { .o_thread_show_more { @@ -97,6 +98,10 @@ .o_thread_message_core { .o-flex(1, 1, auto); + &.o_mail_note { + background-color: @gray-lighter; + } + .o_mail_subject { font-style: italic; } diff --git a/addons/mail/static/src/xml/thread.xml b/addons/mail/static/src/xml/thread.xml index f1a364999b5..0e7777dda1a 100644 --- a/addons/mail/static/src/xml/thread.xml +++ b/addons/mail/static/src/xml/thread.xml @@ -21,12 +21,12 @@
-
Congratulation, your inbox is empty
-
New messages will appear here.
+
Congratulations, your inbox is empty
+
New messages appear here.
-
No message starred
-
You can mark any message as 'starred', and it will show up in this channel.
+
No starred message
+
You can mark any message as 'starred', and it shows up in this channel.
@@ -67,7 +67,7 @@ t-att-class="'fa o_thread_message_star ' + (message.is_starred ? 'fa-star' : 'fa-star-o')" t-att-data-message-id="message.id" t-att-title="_t('Mark as Todo')"/> -
+

Note by @@ -102,7 +102,7 @@ t-att-data-message-id="message.id" t-att-title="_t('Mark as Todo')"/> + t-att-data-message-id="message.id" t-att-title="_t('Mark as Read')"/>

@@ -113,7 +113,7 @@

Subject:

- +
@@ -121,7 +121,7 @@
- + From afa28f075abdbe865f35d41b72c15646718626a7 Mon Sep 17 00:00:00 2001 From: Nicolas Martinelli Date: Wed, 9 Dec 2015 11:32:38 +0100 Subject: [PATCH 005/117] [FIX] website_quote: message if SO not confirmed Commit 486cd3309 was not correctly forward ported. We also add a specific message if the quotation is in state 'draft'. Fixes #9226 --- addons/website_quote/static/src/js/website_quotation.js | 3 ++- addons/website_quote/views/website_quotation.xml | 7 ++++--- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/addons/website_quote/static/src/js/website_quotation.js b/addons/website_quote/static/src/js/website_quotation.js index f4e17c92bed..ef0389e187a 100644 --- a/addons/website_quote/static/src/js/website_quotation.js +++ b/addons/website_quote/static/src/js/website_quotation.js @@ -102,8 +102,9 @@ if(!$('.o_website_quote').length) { 'signer': signer_name, 'sign': signature?JSON.stringify(signature[1]):false, }).then(function (data) { + var message_id = (data) ? 3 : 4; self.$el.modal('hide'); - window.location.href = '/quote/'+order_id.toString()+'/'+token+'?message=3'; + window.location.href = '/quote/'+order_id.toString()+'/'+token+'?message='+message_id; }); return false; } diff --git a/addons/website_quote/views/website_quotation.xml b/addons/website_quote/views/website_quotation.xml index 5cd9545d17e..be4fe376270 100644 --- a/addons/website_quote/views/website_quotation.xml +++ b/addons/website_quote/views/website_quotation.xml @@ -227,9 +227,10 @@
- This order has already been - cancelled - validated + This order + has not yet been sent + has already been cancelled + has already been validated ! You can contact us for any question.
From c867927b2eac9747a814e8888bf2f45cfdf100b6 Mon Sep 17 00:00:00 2001 From: Cedric Snauwaert Date: Tue, 1 Dec 2015 17:10:57 +0100 Subject: [PATCH 006/117] [FIX] mail: sanitize incoming mail to remove unwanted class + add test some incoming mail containing class like "fa-spin" or "modal in" have an unwanted behavior in Odoo, incoming mail should not have special classes, so we remove all the class that are not in the whitelist. --- openerp/addons/base/tests/test_mail.py | 7 ++++ .../addons/base/tests/test_mail_examples.py | 37 +++++++++++++++++-- openerp/tools/mail.py | 20 +++++++++- 3 files changed, 60 insertions(+), 4 deletions(-) diff --git a/openerp/addons/base/tests/test_mail.py b/openerp/addons/base/tests/test_mail.py index ec9877f895d..8186674b964 100644 --- a/openerp/addons/base/tests/test_mail.py +++ b/openerp/addons/base/tests/test_mail.py @@ -330,6 +330,13 @@ class TestCleaner(unittest.TestCase): for ext in test_mail_examples.BUG_3_OUT: self.assertNotIn(ext, new_html, 'html_email_cleaner did not removed invalid content') + def test_80_remove_classes(self): + new_html = html_email_clean(test_mail_examples.REMOVE_CLASS, remove=True) + for ext in test_mail_examples.REMOVE_CLASS_IN: + self.assertIn(ext, new_html, 'html_email_cleaner wrongly removed classes') + for ext in test_mail_examples.REMOVE_CLASS_OUT: + self.assertNotIn(ext, new_html, 'html_email_cleaner did not removed correctly unwanted classes') + def test_90_misc(self): # False boolean for text must return empty string new_html = html_email_clean(False) diff --git a/openerp/addons/base/tests/test_mail_examples.py b/openerp/addons/base/tests/test_mail_examples.py index 97a34c45e55..3342876bf73 100644 --- a/openerp/addons/base/tests/test_mail_examples.py +++ b/openerp/addons/base/tests/test_mail_examples.py @@ -91,12 +91,12 @@ OERP_WEBSITE_HTML_1 = """ OERP_WEBSITE_HTML_1_IN = [ 'Manage your company most important asset: People', - 'img class="img-rounded img-responsive" src="/website/static/src/img/china_thumb.jpg"', + 'src="/website/static/src/img/china_thumb.jpg"', ] OERP_WEBSITE_HTML_1_OUT = [ 'Break down information silos.', 'Keep track of the vacation days accrued by each employee', - 'img class="img-rounded img-responsive" src="/website/static/src/img/deers_thumb.jpg', + 'src="/website/static/src/img/deers_thumb.jpg', ] OERP_WEBSITE_HTML_2 = """ @@ -205,7 +205,7 @@ OERP_WEBSITE_HTML_2_IN = [ ] OERP_WEBSITE_HTML_2_OUT = [ 'Make every employee feel more connected', - 'img class="img-responsive shadow" src="/website/static/src/img/text_image.png', + 'src="/website/static/src/img/text_image.png', ] TEXT_1 = """I contact you about our meeting tomorrow. Here is the schedule I propose: @@ -1173,3 +1173,34 @@ BUG_3_IN = [ BUG_3_OUT = [ 'New kanban view of documents' ] + +REMOVE_CLASS = """ +
+
Hello
+
I have just installed Odoo 9 and I've got the following error:
+
 
+
+ +
+ + +
+""" + +REMOVE_CLASS_IN = [ + 'An error occured in a modal and I will send you back the html to try opening one on your end' +] +REMOVE_CLASS_OUT = [ + '