Commit Graph
103774 Commits
Author SHA1 Message Date
Martin Trigaux 00a55f4428 [FIX] service: properly invalidate session of deteled users
If a user A deletes the res.users record of user B while B is connected,
the verification of the session token fails with a comparison of a boolean and
bytes values.
While the check should obviously fail, this patch gracefully inform the user B
its session has expired and redirect him to the login page.

Without the patch, the session is never invalidated in the user browser,
redirecting to a forbidden error page as long as the session has not been manually
cleared from the browser.

Fixes #25530
Closes #25654
Closes #25682

Cherry-Pick of 96f01c08f8
2018-07-10 16:03:23 +02:00
Andreas Perhab 8b25099aea [FIX] auth_oauth: validate db against db_filter 2018-07-09 18:55:11 +02:00
Florent de Labarre 95990a31b4 [FIX] ir.autovacuum: should be executed by the admin
Closes #23453
2018-07-09 18:55:10 +02:00
Damien Bouvy b1a373c664 Revert "[FIX] stock: do_new_transfer callable in xml-rpc"
This reverts commit ef444da57a.

Changing a function signature is not supposed to happen in stable;
we have already received 3 opw's about broken customizations or
modules that extend the stock because code such as:
res = self.do_next_transfer()
if not res:
	<bla bla>

stops without any warning.
2018-07-06 08:47:40 +02:00
Christophe Simonis b5c50fa824 [FIX] core: set up registry before running migration scripts
As `pre-` migration scripts may use the registry, we must ensure that
all fields are set up before execution in order to have a consistent
registry.

This is required when loading a registry which contains modules to
install/upgrade without `-u` flag. In this case, the setup was only done
*after* module loading.
2018-07-05 12:26:28 +02:00
Mykhailo Panarin 80b325bbb2 [CLA] create mpanarin
Backport to 9.0 of #23708

Closes #25595
2018-07-04 10:58:44 +02:00
Odoo Translation Bot 83d2dd5521 [I18N] Update translation terms from Transifex 2018-07-01 02:38:03 +02:00
Martin Trigaux 4ca9ee2548 [FIX] google_calendar: backport 052bc38805 to 9.0
Backport following opw-1851612

[FIX] google_calendar: do not create an event with an invalid id

The id is useful to update existing events but sometimes we are getting some
ids that are not accepted by Google

Getting an error:
odoo.addons.google_account.models.google_service: Bad google request : {
 "error": {
  "errors": [
   {
    "domain": "global",
    "reason": "invalid",
    "message": "Invalid resource id value."
   }
  ],
  "code": 400,
  "message": "Invalid resource id value."
 }
}

Looks like existing events can have a _ in their id but new one, no longer.
It seems that these events are created by outlook calendar when synchronized
with Google Calendar.
2018-06-29 10:32:28 +02:00
Toufik Benjaa 29c00a56da [IMP] http: Sessions implicit deactivation
- Store a token inside sessions to allow implicit session deactivation when needed.

backport of @da1f153d61d747d9357694382fe04f96c0ca886a @c8243e71c6da37547a19f61c58f25d5d03e13d38
2018-06-27 16:39:45 +02:00
Martin Trigaux c1b6cfaab8 [FIX] google_account: backport of c444b5a293
In this commit, our hero backport c444b5a293 to 9.0

[FIX] google_account: fix google request exception management

Error thrown by google request is an urllib2.HTTPError that can be read
and loaded in JSON. However in some cases the result of the read may
be void or not JSON-ready. This was causing a crash in the error
management and hid the actual issue.

This commit tries to read and JSON-load the error but fall back on
simply displaying the raw error in case of issue when handling it.

opw-1851612
2018-06-27 15:52:03 +02:00
Ruchir Shukla ef444da57a [FIX] stock: do_new_transfer callable in xml-rpc
When returning None, the XML-RPC can trigger an error, making
the api unusable in certain cases.
So, we added return True and if the context is None we
use an empty dict, so if the context is returned in a dict,
it is not returning None either.  Tests were adapted too.

Closes #22264
2018-06-26 15:07:23 +02:00
Lucas Perais (lpe) ea7bddcc3e [FIX] event, event_sale, website_event: allow portal access to own registrations
OPW 1859364
2018-06-26 13:13:15 +02:00
Nicolas Martinelli 22084bc52e [FIX] website_quote: token assignation
Speed up assignation of initial access tokens for large databases.

opw-1856946
2018-06-21 10:45:14 +02:00
Nicolas Martinelli 25b6dd6e88 [FIX] sale_mrp, sale_stock: sort moves
`sorted` returns a new sorted recordset, but doesn't modify the actual
one. Therefore, the current code doesn't work as expected.

opw-1824734
2018-06-21 10:34:49 +02:00
Goffin Simon 9cb37398f2 [FIX] calendar: Calendar recurring start date is wrong
Steps to reproduce the bug:

- Create a recurring meeting, with a start date with time (not all day) (for example 09:00),
a duration (for example 5 hours) , each week for example on fridays, for 3 occurences.

-Save

Bug:
- The start_datetime ("Starting at") was increased with the duration of the meeting.

PS: The displayed start and stop in calendar view were computed in function "calendar_id2real_id"
with the virtual id.

opw:1858154
2018-06-19 08:50:30 +02:00
Christophe Monniez 27e7d24256 [FIX] packaging: stop removing Odoo lib dir
When removing Odoo Debian package, the directory /var/lib/odoo is also
removed. This directory could contain important data like filestore or
custom modules.

With this commit, this directory is preserved on removal and deleted
when the purge command is issued with a Debian package manager.

Fixes #22138
2018-06-15 11:58:06 +02:00
Christophe Simonis 90165e2d96 [FIX] WorkerCron: keep registry alive after job processing 2018-06-14 17:17:13 +02:00
Christophe Simonis 5233dbdb54 [FIX] core: do not clear cache when removing registry from pool
No need to force other workers to reset their cache.
2018-06-14 17:17:13 +02:00
Christophe Simonis c13d67dd25 [FIX] website: valid time zone guessed from GeoIP
The timezone returned by GeoIP may be unknown by `pytz` due to
incompatibilities between GeoIP and pytz databases (which may be outdated).
2018-06-14 15:49:16 +02:00
qsm-odoo 50418c4811 [FIX] web_editor: properly save media dialog without any image
When saving the media dialog without any selected image, a crash
occurred. Now, it properly closes the dialog.

opw-1858614
2018-06-14 10:47:38 +02:00
Nicolas Lempereur c4ddf55880 [FIX] web_editor: link don't duplicate child text
If we applied a link eg. on:

```
<span>hello <b>world</b></span>
```

The system actually gets the "label": hello worldworld because there is
3 nodes:

 text node: hello
 element node: `<b>world</b>`
 text node: world

Also since "hello worldworld" is different than "hello world",
instead of just keeping existing nodes and adding the link, the system
would replace the selected range by:

 `<span><a>hello worldworld</a></span>'

instead of:

 `<span><a>hello </a><b><a>world</a></b></span>`

This commit ignores element nodes when creating a new link, since when
getting the label of the link from the selection, only the text nodes
insides the element nodes have any interest.

There was a second issue because if we had:

```
<i><a href="hello">world</a></i>!
```

and tried to put a link over "world!", the code would decide: "world" is
inside a link so we will just update that link.

Thus we would get:

```
<i><a href="hello">world!</a></i>!
```

instead of:

```
<i><a href="hello">world</a></i><a href="hello">!</a>
```

opw-1848351
closes #25187
2018-06-13 16:20:40 +02:00
Antonio Espinosa a8dd1de5c4 [IMP] doc: add i18n section to command line reference
Closes #14042
2018-06-13 15:13:52 +02:00
Aaron Bohy c7b1faa458 [FIX] web_calendar: color of sidebar filter
Before this rev., if you went to Sales > Sales order, switched to
calendar view, edited the arch such that 'color="state"' is
replaced by 'color="invoice_status"' on the root node, it crashed.

The reason of the crash is that a possible value of the
'invoice_status' selection field is 'to invoice' (it contains a
whitespace), and the JQuery selector didn't wrap the value by
quotes.

OPW~1856305
2018-06-13 11:32:36 +02:00
Toufik Benjaa 444f0b6a7f [IMP] payment_ogone: Avoid requesting already owned data from Ogone
- When receiving a S2S payment feedback from Ogone server, we call the method '_ogone_form_get_tx_from_data' which does a "pre-process" of the data to retrieve the payment.transaction linked to this payment.
  It also checks the hash signature of the data to be sure it comes from Ogone.
  Right after, we call "_ogone_s2s_validate" which make a HTTP call to ogone, to retrieve the data related to the transaction which were already sent by Ogone (maybe to be sure the data comes from Ogone?).

  So instead of calling "_ogone_s2s_validate" we now call "_ogone_s2s_validate_tree" which processes the data from Ogone.
  We are sure they come from Ogone, since they passed the hash signature when calling "_ogone_form_get_tx_from_data".
2018-06-12 18:27:24 +02:00
Subodh Dahal c2f20f12b9 [FIX] doc: recommand to xpath on snippet_structure
Fixed the xpath expression for inserting snippet into Structure tab

Closes #22971
2018-06-12 17:45:36 +02:00
Subodh Dahal 3fc6624631 [CLA] SubodhDahal signs Odoo's CLA
Done at #22971
2018-06-12 17:45:36 +02:00
mehdi-ghezal 58e85bdec0 [FIX] sale_stock: qty calculation in procurement creation
When updating the qty on a confirmed sale order line,
we want the system to add new procurement qty
for the cancelled procurements. That way you can
leave the cancelled procurements for what they are.
2018-06-12 11:44:50 +02:00
Goffin Simon cb3e415a7c [FIX] mail: Allow modifying followers in multi company/with private channel
It's a backport for https://github.com/odoo/odoo/commit/b795d69ce8aca2e88182c6d6d6b7af54d536f9dd
It also backports this fix https://github.com/odoo/odoo/commit/c49265afa1b0610d52fd356df26491546f1905bf

It also fixes #13578
2018-06-12 09:52:12 +02:00
Yannick Tivisse 06a085b25f Revert "[FIX] event: fix rights for event.registration"
This reverts commit 05e914629b
while waiting a clear commit message to justify an access right
modification in a stable release.
2018-06-11 17:15:50 +02:00
Invitu e44cb0ae34 [FIX] hr_attendance: Correctly compute worked hours
Fixes #10381 (wrong calculation on datetime)

if worked hours > 24h, calculation is wrong because "seconds" funtion does not take into account days
See: https://docs.python.org/2.4/lib/datetime-timedelta.html

total_seconds() should be used instead of seconds function
2018-06-11 17:13:29 +02:00
RomainLibert 05e914629b [FIX] event: fix rights for event.registration 2018-06-11 17:12:23 +02:00
Martin trigaux 3419b260fb [CLA] backport of WT-IO-IT GmbH signature
backport to 9.0 as asked at #25185
2018-06-11 16:13:14 +02:00
David 561ac24ca7 [FIX] website_form: set meta field
backport of 682ae1cc64

Before this commit, if you enable website_form_enable_metadata, that
will crash with a "KeyError: 'meta'"

This commit closes #24888
2018-06-11 10:35:42 +02:00
Pedro M. Baeza 64645457dd [FIX] base: Allow to create a contact without type
If you don't define an explicit address type, then the
record is not going to be accessible.

In the ORM:
>>> env['res.partner'].create({'name': 'Test', 'type': False})
res.partner(44356,)
>>> env['res.partner'].search([('type', '!=', 'private'), ('id', '=', 44356)])
res.partner()
>>> env['res.partner'].search([('type', '=', False), ('id', '=', 44356)])
res.partner(44356,)

due to the fact that NULL in the database is undefined and can't be
compared to a specific key.
2018-06-08 12:24:19 +02:00
Toufik Benjaa 4f2442c4f6 [FIX] crm: Access rights issues in contact merging
- When merging partners with fields restricted to certain groups which the user doesn't belong, an access error is raised.
  To avoid this, we only merge fields that are accessible by the user. We do so by using the method fields_get() that only returns the fields accessible by the current user.
2018-06-06 11:00:35 +02:00
Olivier-LAURENT a52c545d12 [FIX] base: timeout on smtp connections
Currently when connecting to a smtp server, if no response is returned
and no error is raised, the `SMTP()` instantiation method never ends.

This PR is inspired by 54a477d797 related to `fetchmail()`.
Possibly, a better way exists but it has to change some methods
signatures.

Closes #24877
opw-1851030
2018-06-06 10:33:30 +02:00
Adrian Torres ea23a1ac8c [FIX] orm: re-create constraints of extended fields
Before this commit:

* Module A defines a field X of model M
* Module B inherits from model M without touching field X
* Module C inherits from model M and extends field X by giving an INDEX
/ NOT NULL constraint.
* Module B and C depend from Module A, but not each other

If all three modules are installed and Module B is updated, the INDEX /
NOT NULL constraint could be dropped.

This happens because Module B can be loaded before Module C is loaded,
if that's the case, then after the upgrade of Module B, during the
schema checking, we verify that the field object we have and the field
on the DB are the same, since Module B doesn't introduce the index then
this check is false and we drop the index. When we get to loading Module
C, we do not do any schema checking because the module is not marked as
`to upgrade`, therefore the index is lost forever.

To solve this, we re-init the models that belong to the set of the intersection
between upgraded and modified models and loaded and modified models.

Fixes #24958
2018-06-06 10:00:54 +02:00
Goffin Simon 367fadc8d5 [FIX] account: Currency rate conversion issue in vendor bill
Steps to reproduce:

- Enable multi currencies
- Make sure that the current rate of a foreign currency (i.e. $) is not 1.0 (i.e. 0.5)
- Create a purchasable product with a cost (i.e. 100€)
- Create a vendor bill in a foreign currency (i.e. $)
- Add the product on the invoice

Bug:
The unit price was equal to 25$ instead of 50$

Technical reason:

The function "_onchange_product_id" was called twice (the second time by function
"_onchange_uom_id") and the price unit was converted twice in the currency of the vendor bill.
The idea of this fix is to only convert in the currency when the unit price is set
by the system.

Fixes #24751
opw:1849212
2018-06-06 09:43:44 +02:00
Olivier Colson 1040ce9231 [FIX] account: dashboard: display latest statement balance for bank and cash journals only if it is different from the balance in GL.
The condition to do that was already present, but it wasn't evaluated; the t-if needed to be oustide of the div.
2018-06-05 16:51:03 +02:00
Lucas Perais (lpe) 0046bf7292 [FIX] web_editor: disable button when html field loading
Backporting bed33e1 and 472c5a4f9f from v10.0

OPW 1853150
closes #25043
2018-06-05 09:52:09 +02:00
Nicolas Martinelli b837bbdd8b [FIX] mass_mailing: unsubscribe if trailing '/'
If the `web.base.url` contains a trailing `/`, the replacement of the
`/unsubscribe_from_list` link won't work since the string to replace
will be `my_url//unsubscribe_from_list` instead of
`my_url/unsubscribe_from_list`.

Fixes #24731
opw-1848572
2018-06-05 08:35:50 +02:00
Nicolas Lempereur 66a60c70f3 [FIX] website_event: unblock button when no reserve
In 11.0, this change e9454e79 solved the use case of:

- opening the registration of a ticket
- discard

=> the page must be reloaded to register a ticket

A new report is that since 9.0, if we try to register 0 ticket we would
also have to reload the page.

This commit backports e9454e79 and solves the 0 ticket registration.

opw-1851622
closes #24966
2018-06-01 10:53:30 +02:00
Odoo Translation Bot ea3b895589 [I18N] Update translation terms from Transifex 2018-06-01 02:39:45 +02:00
qdp-odoo 579b233d38 [FIX] l10n_fr_certification: can't change module dependancies on stable version
Commit https://github.com/odoo/odoo/commit/2eb344f23b3a9daa8e7c7ddaead145a8b05b39bf changed the dependancies of l10n_fr_certification which is not acceptable on stable. Instead, the method to check is now moved in account module (to avoid duplicated) and it is called by l10n_fr_certification and account_lock module.
2018-05-31 14:37:24 +02:00
Laurent Smet fb59b56014 [FIX] account: fix test on closed period since account_lock module
Module account_lock has been introduced by:
https://github.com/odoo/odoo/commit/2eb344f23b3a9daa8e7c7ddaead145a8b05b39bf

A new constrains appears on the lock dates: their must not be set
after the last day of the previous month.
Then, it breaks the test on closed period that set the lock date 'yesterday'.
2018-05-31 13:13:14 +02:00
Laurent Smet 2eb344f23b [ADD] account_lock: new module making the lock date irreversible
Was task: https://www.odoo.com/web#id=38178&view_type=form&model=project.task&action=333&active_id=967&menu_id=4720
Was PR #22094
2018-05-31 10:06:19 +02:00
Lucas Perais (lpe) 1ad3d1847e [FIX] hw_escpos: complying to barcode method A
Have a XMLReceipt with the line:
<barcode encoding="CODE39">123456789</barcode>

Print the receipt.

Before this commit, jibbrish characters were printed and also kinda 'broke'
the spacing between commands
e.g. If you add an EAN13 barcode below the code39 it would have failed to print correctly too

After this commit, everything prints correctly

OPW 1849284
ref: https://reference.epson-biz.com/modules/ref_escpos/index.php?content_id=128
closes #24965
2018-05-30 14:05:26 +02:00
qsm-odoo ea0fcd52d9 [FIX] web_editor: properly save a t-field in a t-ignore environment
When a t-field element was in an editable t-ignore environement,
modifying it was leaving the edit mode style attached to it. This
was because of:
1) When the t-field element was changed, it was marked dirty but
   also its parent editable container. Fixing this, only solves
   the case where only the t-field (and not one of its neighbors)
   is changed but it was worth fixing anyway.
2) Before saving an element, the potential 'o_editable' and
   summernote classes were not removed of its descendant and were
   thus saved.

Bug found with task-38069, merged in stable as it might occur there
too.
2018-05-28 12:20:07 +02:00
Christophe Simonis 34f567dd39 Revert "[FIX] mass_mailing: unsubscribe not working in multi lang"
commit a3ab33f212 introduced invalid code
2018-05-24 16:50:09 +02:00
jem-odoo 919a1af936 [FIX] purchase: correct product cost in reporting
product.product inheritS from product.template, and they both
define the 'standard_price' field, but implement it differently;
 - product: the field is a company dependent one (so non stored)
 - template: the field is a computed one based on tis variants

For the first case, since the field is not stored in database, when
doing SQL query, we have to get the value from the table ir_property.
That is what purchase report does, but instead of searching on resource
'product.product', it does it on 'product.template'. There are
obviously no entries in ir_property table for 'standard_price' field
on product template. As consequence, the "product value" (cost)
is always null in purchase reporting.
This commit fixes that by modifying SQL query to get the good
value from ir_property table.
2018-05-24 16:21:06 +02:00