From b18a4cba0e21c518a3f6e6c5a70acf67f9fcf669 Mon Sep 17 00:00:00 2001 From: Martin Trigaux Date: Fri, 28 Sep 2018 11:54:37 +0200 Subject: [PATCH 01/10] [CLA] Inspur signs Odoo CCLA Done at opw-1889259 --- doc/cla/corporate/inspur.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 doc/cla/corporate/inspur.md diff --git a/doc/cla/corporate/inspur.md b/doc/cla/corporate/inspur.md new file mode 100644 index 00000000000..88999bdf10b --- /dev/null +++ b/doc/cla/corporate/inspur.md @@ -0,0 +1,17 @@ +China, 2018-09-28 + +Inspur Genersoft Co., Ltd agrees to the terms of the Odoo Corporate Contributor +License Agreement v1.0. + +I declare that I am authorized and able to make this agreement and sign this +declaration. + +Signed, + +David Yu, yudw@inspur.com + +List of contributors: + +Brain Wang wangbuke@inspur.com +David Yu yudw@inspur.com +Alex Aisin-Gioro wubai@inspur.com From 8eb8495710f127e5edd5a03c13ec956401300221 Mon Sep 17 00:00:00 2001 From: Xavier Morel Date: Tue, 25 Sep 2018 16:23:38 +0200 Subject: [PATCH 02/10] [FIX] doc: backport of ac37ca39e github_link compatibility with Sphinx 1.8 Backport to 11.0 --- doc/_extensions/github_link.py | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/doc/_extensions/github_link.py b/doc/_extensions/github_link.py index 155e4083025..72d51bfeb60 100644 --- a/doc/_extensions/github_link.py +++ b/doc/_extensions/github_link.py @@ -91,17 +91,17 @@ def make_github_link(app, path, line=None, mode="blob"): '', '' if line is None else 'L%d' % line )) - def add_doc_link(app, pagename, templatename, context, doctree): """ Add github_link function linking to the current page on github """ if not app.config.github_user and app.config.github_project: return - # FIXME: find other way to recover current document's source suffix - # in Sphinx 1.3 it's possible to have mutliple source suffixes and that - # may be useful in the future source_suffix = app.config.source_suffix - source_suffix = source_suffix if isinstance(source_suffix, pycompat.string_types) else source_suffix[0] + # in 1.3 source_suffix can be a list + # in 1.8 source_suffix can be a mapping + # FIXME: will break if we ever add support for !rst markdown documents maybe + if not isinstance(source_suffix, pycompat.string_types): + source_suffix = next(iter(source_suffix)) # can't use functools.partial because 3rd positional is line not mode context['github_link'] = lambda mode='edit': make_github_link( app, 'doc/%s%s' % (pagename, source_suffix), mode=mode) From 2a697f1c5b06e741968dcd9b1f698ec5fc55f62e Mon Sep 17 00:00:00 2001 From: len-odoo Date: Thu, 27 Sep 2018 10:10:56 +0000 Subject: [PATCH 03/10] [FIX] document: update environment before attachments update Fine-tuning of commit: b3a3ad80991265c50f38fd20588df9a69b6bcf67 ac1e187eea33266095f49a9e1e1ea6b0698be865 The environment should be updated before the call to _updateAttachments, as it depends on the env active_id. opw 1888651 closes odoo/odoo#27277 --- addons/document/static/src/js/document.js | 1 + 1 file changed, 1 insertion(+) diff --git a/addons/document/static/src/js/document.js b/addons/document/static/src/js/document.js index 5c33a3f3cff..b8437d70417 100644 --- a/addons/document/static/src/js/document.js +++ b/addons/document/static/src/js/document.js @@ -50,6 +50,7 @@ Sidebar.include({ * @override */ updateEnv: function (env) { + this.env = env; var _super = _.bind(this._super, this, env); var def = this.hasAttachments ? this._updateAttachments() : $.when(); def.then(_super); From 51b7168d1bceddcf41d021479a36cc93c485a5c5 Mon Sep 17 00:00:00 2001 From: Olivier Colson Date: Fri, 28 Sep 2018 10:30:58 +0200 Subject: [PATCH 04/10] [FIX] l10n_lu: rename duplicate tax xml id The second tax with the same xml id was never created, and caused a psql error to be logged. --- addons/l10n_lu/account.tax.template-2015.csv | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/addons/l10n_lu/account.tax.template-2015.csv b/addons/l10n_lu/account.tax.template-2015.csv index 704a943502e..4eb2d74b274 100644 --- a/addons/l10n_lu/account.tax.template-2015.csv +++ b/addons/l10n_lu/account.tax.template-2015.csv @@ -404,5 +404,5 @@ lu_2015_tax_VP-PA-17,Vente Prestations 17% - Pays,VP-PA-17,sale,percent,17,lu_20 lu_2011_tax_VP-PA-3,Vente Prestations 3% - Pays,VP-PA-3,sale,percent,3,lu_2011_account_4614111,lu_2011_account_4614111,lu_2011_chart_1,503,,"tag_lu_281,tag_lu_203" lu_2011_tax_VP-PA-6,Vente Prestations 6% - Pays,VP-PA-6,sale,percent,6,lu_2011_account_4614111,lu_2011_account_4614111,lu_2011_chart_1,504,,"tag_lu_200,tag_lu_278" lu_2015_tax_VP-PA-8,Vente Prestations 8% - Pays,VP-PA-8,sale,percent,8,lu_2011_account_4614111,lu_2011_account_4614111,lu_2011_chart_1,505,,"tag_lu_294,tag_lu_218" -lu_2015_tax_SANS,Sans Taxes,SANS,purchase,percent,0,,,lu_2011_chart_1,506,,tag_lu_598 -lu_2015_tax_SANS,Sans Taxes,SANS,sale,percent,0,,,lu_2011_chart_1,507,,tag_lu_598 \ No newline at end of file +lu_2015_tax_SANS_purchase,Sans Taxes,SANS,purchase,percent,0,,,lu_2011_chart_1,506,,tag_lu_598 +lu_2015_tax_SANS_sale,Sans Taxes,SANS,sale,percent,0,,,lu_2011_chart_1,507,,tag_lu_598 \ No newline at end of file From 7c9a3840f871eed3f761b461d6866494f7765aad Mon Sep 17 00:00:00 2001 From: Olivier Colson Date: Fri, 28 Sep 2018 10:38:01 +0200 Subject: [PATCH 05/10] [FIX] l10n_jp: remove duplicate account code Two account had the same account code. Because of that, one of them always failed to be created and logged a psql error. To fix that, we totally remove this account, as it never got created anyway. --- addons/l10n_jp/data/account.account.template.csv | 1 - 1 file changed, 1 deletion(-) diff --git a/addons/l10n_jp/data/account.account.template.csv b/addons/l10n_jp/data/account.account.template.csv index ec2f2984771..671b57d5ad2 100644 --- a/addons/l10n_jp/data/account.account.template.csv +++ b/addons/l10n_jp/data/account.account.template.csv @@ -9,7 +9,6 @@ A11219,A11219,出庫請求仮,account.data_account_type_current_assets,,FALSE,,l A11301,A11301,未収収益,account.data_account_type_current_assets,,FALSE,,l10n_jp1 A11401,A11401,有価証券,account.data_account_type_current_assets,,FALSE,,l10n_jp1 A11501,A11501,商品,account.data_account_type_current_assets,,FALSE,,l10n_jp1 -A11503,A11503,製品,account.data_account_type_current_assets,,FALSE,,l10n_jp1 A11504,A11504,仕掛品,account.data_account_type_current_assets,,FALSE,,l10n_jp1 A11505,A11505,原材料,account.data_account_type_current_assets,,FALSE,,l10n_jp1 A11506,A11506,資材,account.data_account_type_current_assets,,FALSE,,l10n_jp1 From 22cd49bafbfa51ca3c661a527d4bd0ae46c43720 Mon Sep 17 00:00:00 2001 From: Stefan Rijnhart Date: Fri, 28 Sep 2018 12:06:18 +0200 Subject: [PATCH 06/10] =?UTF-8?q?[IMP]=20l10n=5Fjp:=20reintroduce=20accoun?= =?UTF-8?q?t=20=E8=A3=BD=E5=93=81=20with=20correct=20account=20code?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- addons/l10n_jp/data/account.account.template.csv | 1 + 1 file changed, 1 insertion(+) diff --git a/addons/l10n_jp/data/account.account.template.csv b/addons/l10n_jp/data/account.account.template.csv index 671b57d5ad2..f7046bf9915 100644 --- a/addons/l10n_jp/data/account.account.template.csv +++ b/addons/l10n_jp/data/account.account.template.csv @@ -9,6 +9,7 @@ A11219,A11219,出庫請求仮,account.data_account_type_current_assets,,FALSE,,l A11301,A11301,未収収益,account.data_account_type_current_assets,,FALSE,,l10n_jp1 A11401,A11401,有価証券,account.data_account_type_current_assets,,FALSE,,l10n_jp1 A11501,A11501,商品,account.data_account_type_current_assets,,FALSE,,l10n_jp1 +A11502,A11502,製品,account.data_account_type_current_assets,,FALSE,,l10n_jp1 A11504,A11504,仕掛品,account.data_account_type_current_assets,,FALSE,,l10n_jp1 A11505,A11505,原材料,account.data_account_type_current_assets,,FALSE,,l10n_jp1 A11506,A11506,資材,account.data_account_type_current_assets,,FALSE,,l10n_jp1 From 70028701b3907ccc65f06cde5800619d7507aa5c Mon Sep 17 00:00:00 2001 From: Olivier Colson Date: Fri, 28 Sep 2018 12:16:25 +0200 Subject: [PATCH 07/10] [IMP] l10n_lu: make 9.0 fix match the one done by mat in 11.5 --- addons/l10n_lu/account.tax.template-2015.csv | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/l10n_lu/account.tax.template-2015.csv b/addons/l10n_lu/account.tax.template-2015.csv index 4eb2d74b274..75bc07098eb 100644 --- a/addons/l10n_lu/account.tax.template-2015.csv +++ b/addons/l10n_lu/account.tax.template-2015.csv @@ -404,5 +404,5 @@ lu_2015_tax_VP-PA-17,Vente Prestations 17% - Pays,VP-PA-17,sale,percent,17,lu_20 lu_2011_tax_VP-PA-3,Vente Prestations 3% - Pays,VP-PA-3,sale,percent,3,lu_2011_account_4614111,lu_2011_account_4614111,lu_2011_chart_1,503,,"tag_lu_281,tag_lu_203" lu_2011_tax_VP-PA-6,Vente Prestations 6% - Pays,VP-PA-6,sale,percent,6,lu_2011_account_4614111,lu_2011_account_4614111,lu_2011_chart_1,504,,"tag_lu_200,tag_lu_278" lu_2015_tax_VP-PA-8,Vente Prestations 8% - Pays,VP-PA-8,sale,percent,8,lu_2011_account_4614111,lu_2011_account_4614111,lu_2011_chart_1,505,,"tag_lu_294,tag_lu_218" -lu_2015_tax_SANS_purchase,Sans Taxes,SANS,purchase,percent,0,,,lu_2011_chart_1,506,,tag_lu_598 +lu_2015_tax_SANS,Sans Taxes,SANS,purchase,percent,0,,,lu_2011_chart_1,506,,tag_lu_598 lu_2015_tax_SANS_sale,Sans Taxes,SANS,sale,percent,0,,,lu_2011_chart_1,507,,tag_lu_598 \ No newline at end of file From 46f2e1918fc6e135b1c82af19a13f9cb01c81470 Mon Sep 17 00:00:00 2001 From: Nicolas Lempereur Date: Tue, 28 Aug 2018 14:51:46 +0000 Subject: [PATCH 08/10] [FIX] base: access_token error handling correctly When an attachment is requested with an access_token, a server error would occur in some situation. With this changeset when an access token is specified: - returns a 404 error if the attachment does not exist - returns a 403 error if the attachment has no access_token Without this change, the added test would fail with: ``` status = test_access(access_token='Secret') self.assertEqual(status, 403, "no access if access token for attachment without access token") | if not consteq(obj.access_token, access_token): | TypeError: unsupported operand types(s) or combination of types: 'bool' and 'str' status = test_access(access_token='Secret') self.assertEqual(status, 404, "no access with access token for deleted attachment") | if not consteq(obj.access_token, access_token): | odoo.exceptions.MissingError: ('Record does not exist or has been deleted.', None) ``` close #26647 opw-1884419 closes #27275 Co-authored-by: Wolfgang Taferner --- odoo/addons/base/ir/ir_http.py | 10 +++-- odoo/addons/base/tests/test_ir_http.py | 51 ++++++++++++++++++++++++++ 2 files changed, 57 insertions(+), 4 deletions(-) diff --git a/odoo/addons/base/ir/ir_http.py b/odoo/addons/base/ir/ir_http.py index 751f4aed9ee..eab07d2768e 100644 --- a/odoo/addons/base/ir/ir_http.py +++ b/odoo/addons/base/ir/ir_http.py @@ -278,10 +278,6 @@ class IrHttp(models.AbstractModel): obj = None if xmlid: obj = env.ref(xmlid, False) - elif id and model == 'ir.attachment' and access_token: - obj = env[model].sudo().browse(int(id)) - if not consteq(obj.access_token, access_token): - return (403, [], None) elif id and model in env.registry: obj = env[model].browse(int(id)) @@ -289,6 +285,12 @@ class IrHttp(models.AbstractModel): if not obj or not obj.exists() or field not in obj: return (404, [], None) + # access token grant access + if model == 'ir.attachment' and access_token: + obj = obj.sudo() + if not consteq(obj.access_token or '', access_token): + return (403, [], None) + # check read access try: last_update = obj['__last_update'] diff --git a/odoo/addons/base/tests/test_ir_http.py b/odoo/addons/base/tests/test_ir_http.py index 420a16004ce..2cdcaf74dcf 100644 --- a/odoo/addons/base/tests/test_ir_http.py +++ b/odoo/addons/base/tests/test_ir_http.py @@ -79,3 +79,54 @@ class test_ir_http_mimetype(common.TransactionCase): ) mimetype = dict(headers).get('Content-Type') self.assertEqual(mimetype, 'image/gif') + + def test_ir_http_attachment_access(self): + """ Test attachment access with and without access token """ + public_user = self.env.ref('base.public_user') + attachment = self.env['ir.attachment'].create({ + 'datas': GIF, + 'name': 'Test valid access token with image', + 'datas_fname': 'image.gif' + }) + + defaults = { + 'id': attachment.id, + 'default_mimetype': 'image/gif', + 'env': public_user.sudo(public_user.id).env, + } + + def test_access(**kwargs): + status, _, _ = self.env['ir.http'].binary_content( + **defaults, **kwargs + ) + return status + + status = test_access() + self.assertEqual(status, 403, "no access") + + status = test_access(access_token='Secret') + self.assertEqual(status, 403, + "no access if access token for attachment without access token") + + attachment.access_token = 'Secret' + status = test_access(access_token='Secret') + self.assertEqual(status, 200, "access for correct access token") + + status = test_access(access_token='Wrong') + self.assertEqual(status, 403, "no access for wrong access token") + + attachment.public = True + status = test_access() + self.assertEqual(status, 200, "access for attachment with access") + + status = test_access(access_token='Wrong') + self.assertEqual(status, 403, + "no access for wrong access token for attachment with access") + + attachment.unlink() + status = test_access() + self.assertEqual(status, 404, "no access for deleted attachment") + + status = test_access(access_token='Secret') + self.assertEqual(status, 404, + "no access with access token for deleted attachment") From 1b5f2ac42053fe173a04f1518337e3fde9d8fad3 Mon Sep 17 00:00:00 2001 From: Gert Pellin Date: Wed, 26 Sep 2018 13:44:43 +0000 Subject: [PATCH 09/10] [FIX] hw_scale: read values from Adam scale with migration from python2 to python3 not all regexes where converted to byte-array. backport of b4bcf86f8e to 11.0 closes odoo/odoo#27252 --- addons/hw_scale/controllers/main.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/hw_scale/controllers/main.py b/addons/hw_scale/controllers/main.py index 162ab7a866d..ed8f92c73ea 100644 --- a/addons/hw_scale/controllers/main.py +++ b/addons/hw_scale/controllers/main.py @@ -95,7 +95,7 @@ ADAMEquipmentProtocol = ScaleProtocol( parity=serial.PARITY_NONE, timeout=0.2, writeTimeout=0.2, - weightRegexp=r"\s*([0-9.]+)kg", # LABEL format 3 + KG in the scale settings, but Label 1/2 should work + weightRegexp=b"\s*([0-9.]+)kg", # LABEL format 3 + KG in the scale settings, but Label 1/2 should work statusRegexp=None, statusParse=None, commandTerminator=b"\r\n", From a9a556178d5fb4cb3fc657c4ffc455c521f1396c Mon Sep 17 00:00:00 2001 From: Gustavo Valverde Date: Fri, 28 Sep 2018 12:38:34 +0000 Subject: [PATCH 10/10] [FIX] stock_account: Use product display_name in errors When working with product variants, if the error which gets displayed does not include the product attributes, it's harder to identify the variant with the error. closes odoo/odoo#27298 --- addons/stock_account/models/stock.py | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/addons/stock_account/models/stock.py b/addons/stock_account/models/stock.py index 7bcb3844b96..251c975ba92 100644 --- a/addons/stock_account/models/stock.py +++ b/addons/stock_account/models/stock.py @@ -507,9 +507,9 @@ class StockMove(models.Model): if not accounts_data.get('stock_journal', False): raise UserError(_('You don\'t have any stock journal defined on your product category, check if you have installed a chart of accounts')) if not acc_src: - raise UserError(_('Cannot find a stock input account for the product %s. You must define one on the product category, or on the location, before processing this operation.') % (self.product_id.name)) + raise UserError(_('Cannot find a stock input account for the product %s. You must define one on the product category, or on the location, before processing this operation.') % (self.product_id.display_name)) if not acc_dest: - raise UserError(_('Cannot find a stock output account for the product %s. You must define one on the product category, or on the location, before processing this operation.') % (self.product_id.name)) + raise UserError(_('Cannot find a stock output account for the product %s. You must define one on the product category, or on the location, before processing this operation.') % (self.product_id.display_name)) if not acc_valuation: raise UserError(_('You don\'t have any stock valuation account defined on your product category. You must define one before processing this operation.')) journal_id = accounts_data['stock_journal'].id @@ -538,7 +538,7 @@ class StockMove(models.Model): # check that all data is correct if self.company_id.currency_id.is_zero(debit_value): - raise UserError(_("The cost of %s is currently equal to 0. Change the cost or the configuration of your product to avoid an incorrect valuation.") % (self.product_id.name,)) + raise UserError(_("The cost of %s is currently equal to 0. Change the cost or the configuration of your product to avoid an incorrect valuation.") % (self.product_id.display_name,)) credit_value = debit_value partner_id = (self.picking_id.partner_id and self.env['res.partner']._find_accounting_partner(self.picking_id.partner_id).id) or False