[FIX] calendar: view meeting detail when not logged

Since the new QWeb engine, `groups` directives on template
rendered in a route with auth=none is simply ignored, since
all is done as SUPERUSER_ID, it was impossible to instanciate
the webclient to check if the session is valid and to display
meeting info or redirect to event form view.

It seems that we don't want to fix this because routes auth=none
are rare, and special. So it is not considered as a bug.

The fix for calendar is, however, to do redirection or template
rendering server side.
This commit is contained in:
Jérome Maes
2016-06-20 16:19:32 +02:00
parent 3cb64f517a
commit cfb8e8700a
4 changed files with 86 additions and 72 deletions
+21 -22
View File
@@ -4,6 +4,9 @@ import openerp.http as http
from openerp.http import request
import openerp.addons.web.controllers.main as webmain
import json
import werkzeug
from odoo.api import Environment
class meeting_invitation(http.Controller):
@@ -31,31 +34,27 @@ class meeting_invitation(http.Controller):
@http.route('/calendar/meeting/view', type='http', auth="calendar")
def view(self, db, token, action, id, view='calendar'):
registry = openerp.modules.registry.RegistryManager.get(db)
meeting_pool = registry.get('calendar.event')
attendee_pool = registry.get('calendar.attendee')
partner_pool = registry.get('res.partner')
with registry.cursor() as cr:
attendee = attendee_pool.search_read(cr, openerp.SUPERUSER_ID, [('access_token', '=', token)], [])
# Since we are in auth=none, create an env with SUPERUSER_ID
env = Environment(cr, openerp.SUPERUSER_ID, {})
attendee = env['calendar.attendee'].search([('access_token', '=', token)])
timezone = attendee.partner_id.tz
event = env['calendar.event'].with_context(tz=timezone).browse(int(id))
if attendee and attendee[0] and attendee[0].get('partner_id'):
partner_id = int(attendee[0].get('partner_id')[0])
tz = partner_pool.read(cr, openerp.SUPERUSER_ID, partner_id, ['tz'])['tz']
else:
tz = False
# If user is logged, redirect to form view of event
# otherwise, display the simplifyed web page with event informations
if request.session.uid:
return werkzeug.utils.redirect('/web?db=%s#id=%s&view_type=form&model=calendar.event' % (db, id))
attendee_data = meeting_pool.get_attendee(cr, openerp.SUPERUSER_ID, id, dict(tz=tz))
if attendee:
attendee_data['current_attendee'] = attendee[0]
values = dict(
init = """
odoo.define('calendar.invitation_page', function (require) {
require('base_calendar.base_calendar').showCalendarInvitation('%s', '%s', '%s', '%s', '%s');
});
""" % (db, action, id, 'form', json.dumps(attendee_data))
)
return request.render('web.webclient_bootstrap', values)
# NOTE : calling render return a lazy response. The rendering result will be done when the
# cursor will be closed. So it is requried to call `flatten` to make the redering before
# existing the `with` clause
response = request.render('calendar.invitation_page_anonymous', {
'event': event,
'attendee': attendee,
})
response.flatten()
return response
# Function used, in RPC to check every 5 minutes, if notification to do for an event or not
@http.route('/calendar/notify', type='json', auth="none")
+1 -14
View File
@@ -221,7 +221,7 @@ WebClient.include({
show_application: function() {
return this._super.apply(this, arguments).then(this.check_notifications.bind(this));
},
//Override addons/web/static/src/js/chrome.js
//Override addons/web/static/src/js/chrome.js
// FIXME: on_logout is no longer used
on_logout: function() {
this._super();
@@ -243,20 +243,7 @@ var Many2ManyAttendee = FieldMany2ManyTags.extend({
},
});
function showCalendarInvitation(db, action, id, view, attendee_data) {
session.session_bind(session.origin).then(function () {
if (session.session_is_valid(db) && session.username !== "anonymous") {
window.location.href = _.str.sprintf('/web?db=%s#id=%s&view_type=form&model=calendar.event', db, id);
} else {
$("body").prepend(QWeb.render('CalendarInvitation', {attendee_data: JSON.parse(attendee_data)}));
}
});
}
core.form_widget_registry.add('many2manyattendee', Many2ManyAttendee);
return {
showCalendarInvitation: showCalendarInvitation,
};
});
@@ -28,40 +28,4 @@
</t>
</t>
<div t-name="CalendarInvitation" class="o_calendar_invitation_page">
<div class="pull-right">
<t t-esc="attendee_data['current_attendee'].cn"/> (<t t-esc="attendee_data['current_attendee'].email"/>)
<div t-if="attendee_data['current_attendee'].state !== 'needsAction'" t-attf-class="o_#{attendee_data['current_attendee'].state}">
<t t-if="attendee_data['current_attendee'].state === 'accepted'">Yes I'm going.</t>
<t t-if="attendee_data['current_attendee'].state === 'declined'">No I'm not going.</t>
</div>
</div>
<div class="pull-left o_logo">
<img class="img img-responsive" src='/web/binary/company_logo'/>
</div>
<div class="o_event_title">
<h2>Calendar Invitation</h2>
<h3><t t-esc="attendee_data['meeting'].event"/></h3>
</div>
<table class="o_event_table table table-striped">
<tr>
<th>When</th>
<td><t t-esc="attendee_data['meeting'].when"/></td>
</tr>
<tr>
<th>Where</th>
<td><t t-esc="attendee_data['meeting'].where or '-'"/></td>
</tr>
<tr>
<th>Who</th>
<td>
<ul>
<li t-foreach="attendee_data['attendee']" t-as="attendee" t-attf-class="o_#{attendee.status}">
<t t-esc="attendee.name"/>
</li>
</ul>
</td>
</tr>
</table>
</div>
</template>
+64
View File
@@ -6,4 +6,68 @@
<script type="text/javascript" src="/calendar/static/src/js/base_calendar.js"></script>
</xpath>
</template>
<!-- Template rendered in route auth=None, for anonymous user. This allow them to see meeting details -->
<template id="invitation_page_anonymous" name="Calendar InvitationPAge for anonymous users">
<t t-call="web.layout">
<t t-set="head">
<t t-call-assets="web.assets_common" t-js="false"/>
<t t-call-assets="web.assets_frontend" t-js="false"/>
</t>
<div class="row">
<div class="col-md-12">
<div class="o_logo">
<img class="img img-responsive center-block" src="/web/binary/company_logo"/>
</div>
</div>
</div>
<div class="row">
<div class="col-md-6 col-md-offset-3">
<div class="panel panel-default">
<div class="panel-heading">
<h2>Calendar Invitation <small><t t-esc="event.name"/></small></h2>
</div>
<div class="panel-body">
<div class="pull-right mb16" t-if="attendee.state != 'needsAction'">
<span class="label label-info">
<t t-if="attendee.state == 'accepted'">Yes I'm going.</t>
<t t-if="attendee.state == 'declined'">No I'm not going.</t>
</span>
</div>
<table class="o_event_table table table-striped">
<tr>
<th>Invitation for</th>
<td><t t-esc="attendee.cn"/> (<t t-esc="attendee.email"/>)</td>
</tr>
<tr>
<th>Date</th>
<td><t t-esc="event.display_time"/></td>
</tr>
<tr>
<th>Location</th>
<td><t t-esc="event.location or '-'"/></td>
</tr>
<tr>
<th>Attendees</th>
<td>
<ul>
<li t-foreach="event.attendee_ids" t-as="attendee" t-attf-class="o_#{attendee.state}">
<t t-esc="attendee.cn"/>
</li>
</ul>
</td>
</tr>
</table>
</div>
</div>
</div>
</div>
</t>
</template>
</odoo>