From 3b85900fafc9469dca6e7c01fca6dac4f55d20f5 Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Mon, 26 Nov 2018 13:40:15 +0100 Subject: [PATCH 1/2] [DOC] install: update info about wkhtmltopdf We now support version 0.12.5(.1), which is available for all recent Debian and Ubuntu versions, and contains quite a few bug fixes. An up-to-date version of Odoo 10 or later is required, for pixel-perfect compatibility with the result of 0.12.1.3. See also the wiki for more info: https://github.com/odoo/odoo/wiki/Wkhtmltopdf --- doc/setup/install.rst | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/doc/setup/install.rst b/doc/setup/install.rst index cc78652f15e..e213a694f46 100644 --- a/doc/setup/install.rst +++ b/doc/setup/install.rst @@ -181,12 +181,14 @@ This will install Odoo as a service, create the necessary PostgreSQL_ user and automatically start the server. .. danger:: to print PDF reports, you must install wkhtmltopdf_ yourself: - the version of wkhtmltopdf_ available in debian repositories does - not support headers and footers so it can not be installed - automatically. The recommended version is 0.12.1 and is available on - `the wkhtmltopdf download page`_, in the archive section. As there - is no official release for Debian Jessie, you can find ours on the - extra_ section of our nightly server. + the version of wkhtmltopdf_ available in Debian repositories does + not support headers and footers so it is not used as a direct dependency. + The recommended version is 0.12.5 and is available on + `the wkhtmltopdf download page`_, in the archive section. Previously + recommended version 0.12.1 is a good alternative. + More details on the various versions and their respective quirks can be + found in our `wiki `_. + Configuration ''''''''''''' @@ -546,7 +548,7 @@ default db to serve on localhost:8069 http://www.enterprisedb.com/products-services-training/pgdownload .. _Quilt: http://en.wikipedia.org/wiki/Quilt_(software) .. _saas: https://www.odoo.com/page/start -.. _the wkhtmltopdf download page: https://github.com/wkhtmltopdf/wkhtmltopdf/releases/tag/0.12.1 +.. _the wkhtmltopdf download page: https://github.com/wkhtmltopdf/wkhtmltopdf/releases/tag/0.12.5 .. _UAC: http://en.wikipedia.org/wiki/User_Account_Control .. _wkhtmltopdf: http://wkhtmltopdf.org .. _pip: https://pip.pypa.io From 6639630de11e5e3b4046968f8981415d6ccca6cd Mon Sep 17 00:00:00 2001 From: Denis Roussel Date: Tue, 27 Nov 2018 10:14:43 +0100 Subject: [PATCH 2/2] [FIX] base: make check_credentials more consistent with alternatives The other methods do test password length before verifying it, so even if check_credentials() is not meant to be called directly, it's better to keep it consistent with the alternatives. Closes #29023 --- odoo/addons/base/res/res_users.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/odoo/addons/base/res/res_users.py b/odoo/addons/base/res/res_users.py index 866ab65ec85..8c7194d4279 100644 --- a/odoo/addons/base/res/res_users.py +++ b/odoo/addons/base/res/res_users.py @@ -444,6 +444,8 @@ class Users(models.Model): @api.model def check_credentials(self, password): """ Override this method to plug additional authentication methods""" + if not password: + raise AccessDenied() user = self.sudo().search([('id', '=', self._uid), ('password', '=', password)]) if not user: raise AccessDenied()