[FIX] calendar: view meeting detail when not logged
Since the new QWeb engine, `groups` directives on template rendered in a route with auth=none is simply ignored, since all is done as SUPERUSER_ID, it was impossible to instanciate the webclient to check if the session is valid and to display meeting info or redirect to event form view. It seems that we don't want to fix this because routes auth=none are rare, and special. So it is not considered as a bug. The fix for calendar is, however, to do redirection or template rendering server side.
This commit is contained in:
@@ -4,6 +4,9 @@ import openerp.http as http
|
||||
from openerp.http import request
|
||||
import openerp.addons.web.controllers.main as webmain
|
||||
import json
|
||||
import werkzeug
|
||||
|
||||
from odoo.api import Environment
|
||||
|
||||
|
||||
class meeting_invitation(http.Controller):
|
||||
@@ -31,31 +34,27 @@ class meeting_invitation(http.Controller):
|
||||
@http.route('/calendar/meeting/view', type='http', auth="calendar")
|
||||
def view(self, db, token, action, id, view='calendar'):
|
||||
registry = openerp.modules.registry.RegistryManager.get(db)
|
||||
meeting_pool = registry.get('calendar.event')
|
||||
attendee_pool = registry.get('calendar.attendee')
|
||||
partner_pool = registry.get('res.partner')
|
||||
with registry.cursor() as cr:
|
||||
attendee = attendee_pool.search_read(cr, openerp.SUPERUSER_ID, [('access_token', '=', token)], [])
|
||||
# Since we are in auth=none, create an env with SUPERUSER_ID
|
||||
env = Environment(cr, openerp.SUPERUSER_ID, {})
|
||||
attendee = env['calendar.attendee'].search([('access_token', '=', token)])
|
||||
timezone = attendee.partner_id.tz
|
||||
event = env['calendar.event'].with_context(tz=timezone).browse(int(id))
|
||||
|
||||
if attendee and attendee[0] and attendee[0].get('partner_id'):
|
||||
partner_id = int(attendee[0].get('partner_id')[0])
|
||||
tz = partner_pool.read(cr, openerp.SUPERUSER_ID, partner_id, ['tz'])['tz']
|
||||
else:
|
||||
tz = False
|
||||
# If user is logged, redirect to form view of event
|
||||
# otherwise, display the simplifyed web page with event informations
|
||||
if request.session.uid:
|
||||
return werkzeug.utils.redirect('/web?db=%s#id=%s&view_type=form&model=calendar.event' % (db, id))
|
||||
|
||||
attendee_data = meeting_pool.get_attendee(cr, openerp.SUPERUSER_ID, id, dict(tz=tz))
|
||||
|
||||
if attendee:
|
||||
attendee_data['current_attendee'] = attendee[0]
|
||||
|
||||
values = dict(
|
||||
init = """
|
||||
odoo.define('calendar.invitation_page', function (require) {
|
||||
require('base_calendar.base_calendar').showCalendarInvitation('%s', '%s', '%s', '%s', '%s');
|
||||
});
|
||||
""" % (db, action, id, 'form', json.dumps(attendee_data))
|
||||
)
|
||||
return request.render('web.webclient_bootstrap', values)
|
||||
# NOTE : calling render return a lazy response. The rendering result will be done when the
|
||||
# cursor will be closed. So it is requried to call `flatten` to make the redering before
|
||||
# existing the `with` clause
|
||||
response = request.render('calendar.invitation_page_anonymous', {
|
||||
'event': event,
|
||||
'attendee': attendee,
|
||||
})
|
||||
response.flatten()
|
||||
return response
|
||||
|
||||
# Function used, in RPC to check every 5 minutes, if notification to do for an event or not
|
||||
@http.route('/calendar/notify', type='json', auth="none")
|
||||
|
||||
@@ -221,7 +221,7 @@ WebClient.include({
|
||||
show_application: function() {
|
||||
return this._super.apply(this, arguments).then(this.check_notifications.bind(this));
|
||||
},
|
||||
//Override addons/web/static/src/js/chrome.js
|
||||
//Override addons/web/static/src/js/chrome.js
|
||||
// FIXME: on_logout is no longer used
|
||||
on_logout: function() {
|
||||
this._super();
|
||||
@@ -243,20 +243,7 @@ var Many2ManyAttendee = FieldMany2ManyTags.extend({
|
||||
},
|
||||
});
|
||||
|
||||
function showCalendarInvitation(db, action, id, view, attendee_data) {
|
||||
session.session_bind(session.origin).then(function () {
|
||||
if (session.session_is_valid(db) && session.username !== "anonymous") {
|
||||
window.location.href = _.str.sprintf('/web?db=%s#id=%s&view_type=form&model=calendar.event', db, id);
|
||||
} else {
|
||||
$("body").prepend(QWeb.render('CalendarInvitation', {attendee_data: JSON.parse(attendee_data)}));
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
core.form_widget_registry.add('many2manyattendee', Many2ManyAttendee);
|
||||
|
||||
return {
|
||||
showCalendarInvitation: showCalendarInvitation,
|
||||
};
|
||||
|
||||
});
|
||||
|
||||
@@ -28,40 +28,4 @@
|
||||
</t>
|
||||
</t>
|
||||
|
||||
<div t-name="CalendarInvitation" class="o_calendar_invitation_page">
|
||||
<div class="pull-right">
|
||||
<t t-esc="attendee_data['current_attendee'].cn"/> (<t t-esc="attendee_data['current_attendee'].email"/>)
|
||||
<div t-if="attendee_data['current_attendee'].state !== 'needsAction'" t-attf-class="o_#{attendee_data['current_attendee'].state}">
|
||||
<t t-if="attendee_data['current_attendee'].state === 'accepted'">Yes I'm going.</t>
|
||||
<t t-if="attendee_data['current_attendee'].state === 'declined'">No I'm not going.</t>
|
||||
</div>
|
||||
</div>
|
||||
<div class="pull-left o_logo">
|
||||
<img class="img img-responsive" src='/web/binary/company_logo'/>
|
||||
</div>
|
||||
<div class="o_event_title">
|
||||
<h2>Calendar Invitation</h2>
|
||||
<h3><t t-esc="attendee_data['meeting'].event"/></h3>
|
||||
</div>
|
||||
<table class="o_event_table table table-striped">
|
||||
<tr>
|
||||
<th>When</th>
|
||||
<td><t t-esc="attendee_data['meeting'].when"/></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th>Where</th>
|
||||
<td><t t-esc="attendee_data['meeting'].where or '-'"/></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th>Who</th>
|
||||
<td>
|
||||
<ul>
|
||||
<li t-foreach="attendee_data['attendee']" t-as="attendee" t-attf-class="o_#{attendee.status}">
|
||||
<t t-esc="attendee.name"/>
|
||||
</li>
|
||||
</ul>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
</template>
|
||||
|
||||
@@ -6,4 +6,68 @@
|
||||
<script type="text/javascript" src="/calendar/static/src/js/base_calendar.js"></script>
|
||||
</xpath>
|
||||
</template>
|
||||
|
||||
<!-- Template rendered in route auth=None, for anonymous user. This allow them to see meeting details -->
|
||||
<template id="invitation_page_anonymous" name="Calendar InvitationPAge for anonymous users">
|
||||
<t t-call="web.layout">
|
||||
|
||||
<t t-set="head">
|
||||
<t t-call-assets="web.assets_common" t-js="false"/>
|
||||
<t t-call-assets="web.assets_frontend" t-js="false"/>
|
||||
</t>
|
||||
|
||||
<div class="row">
|
||||
<div class="col-md-12">
|
||||
<div class="o_logo">
|
||||
<img class="img img-responsive center-block" src="/web/binary/company_logo"/>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="row">
|
||||
<div class="col-md-6 col-md-offset-3">
|
||||
<div class="panel panel-default">
|
||||
<div class="panel-heading">
|
||||
<h2>Calendar Invitation <small><t t-esc="event.name"/></small></h2>
|
||||
</div>
|
||||
<div class="panel-body">
|
||||
|
||||
<div class="pull-right mb16" t-if="attendee.state != 'needsAction'">
|
||||
<span class="label label-info">
|
||||
<t t-if="attendee.state == 'accepted'">Yes I'm going.</t>
|
||||
<t t-if="attendee.state == 'declined'">No I'm not going.</t>
|
||||
</span>
|
||||
</div>
|
||||
|
||||
<table class="o_event_table table table-striped">
|
||||
<tr>
|
||||
<th>Invitation for</th>
|
||||
<td><t t-esc="attendee.cn"/> (<t t-esc="attendee.email"/>)</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th>Date</th>
|
||||
<td><t t-esc="event.display_time"/></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th>Location</th>
|
||||
<td><t t-esc="event.location or '-'"/></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th>Attendees</th>
|
||||
<td>
|
||||
<ul>
|
||||
<li t-foreach="event.attendee_ids" t-as="attendee" t-attf-class="o_#{attendee.state}">
|
||||
<t t-esc="attendee.cn"/>
|
||||
</li>
|
||||
</ul>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
</t>
|
||||
</template>
|
||||
</odoo>
|
||||
|
||||
Reference in New Issue
Block a user