Coming from the sudo() modification. The mail.message is created in sudo,
but the user is still the public user, who doesn't have a email address,
leading to an raised error.
Using studio, add a file field on a form. Using the web form builder,
append that field on a form. Upload a file, `x_field_filename` is left
empty thus the filename is lost.
opw-2028071
closesodoo/odoo#34491
Signed-off-by: Julien Castiaux <Julien00859@users.noreply.github.com>
This commit removes the field `datas_fname` from `ir.attachment` as
it was unnecessary and most of the time the duplicate of `name` or
`url`.
Task #1909865closesodoo/odoo#32976
Signed-off-by: Martin Geubelle (mge) <mge@openerp.com>
There was a code that on:
- a form that sent a mail
- with a custom file field
would set the file as attachments, but the code was dead because of a
typo in `if` statement order.
opw-1906883
closes#28525
Issue:
An additional information page is part of our shop process to allow
additional information to be submitted. If this form is left blank,
then selecting the next button allows the process to continue.
However, if data is added to the form the form freezes and the process
will not continue when 'next' is selected.
Why:
Public user can not read the field 'model' of 'ir.model' (to save the
attachments)
opw-1818592
In case of custom field 'upload file', the attachement
name will be the technical name of the input tag of the
form (aka 'attachments'). It is more user friendly to have
the name of the uploaded file.
Custory reading seems to denote that field names are probably already
text in the normal case, and thus should not need decoding? It only
blows up in a tour so...
Now that we're closer to switching to P3 for good, these helpers have
outlived their usefulness, and mostly add noise.
All remaining dict.iter*() or dict.view*() must be converted to the
normal keys(), values() or items() calls.
Whenever the result is likely to be used for more than the scope of a
loop, or when the dict needs to be modified during iteration, the calls
must be wrapped in a ``list()``, to protect the new P3 semantics.
Those cases are very exceptional.
Also removed some dead code or improved the API to remove unnecessary
conversions.
In Python 3:
* various builtins and dict methods were changed to return
view/iterable objects rather than lists
* and the separate Python 2 view/iterable builtins and methods were
removed altogether
This is problematic when using these items as list (which the happens
repeatedly in Odoo), but more viciously when iterating *multiple times*
over them (which also happens, which I've messed up multiple times while
writing this, and which is a pain to debug even when you've just created
the issue).
Convert all code using these to semantics-matching cross-version
helper functions to get the LCD behaviour between P2 and P3, and
forbid the builtins via lint.
issue #8530
As administrator is used to create all records from website form he is
also put into followers. This creates a lot of unnecessary notifications
and/or emails depending on the system configuration.
Using the magic context key this behavior is modified. Administrator
will not follow every records created through the website form anymore.
Improve thank page after the application to a job.
Stop duplicate Magic field, using global fields
Add helper method on website to retreive the last created record
This partially reverts commits 5d746d0ac6 and
73de86c768.
The tightening of access rights was too strong: regular users need to be able
to read models and fields (to create an email templace, for instance.)
[FIX] ir_values: in `get_actions`, exclude field `code`
Remove unrestricted "read" access. To make code internally using `ir.model`
work, add a private method `_get` on `ir.model` to retrieve the record
corresponding to a model name, without access rights issue.
Change signature of method `get_authorized_fields` to make it use a model name
instead of a model id. This removes the necessity of a search on `ir.model`.
The form builder offers the possibility to add a "Custom File Upload"
field. When the user clicks on "Send", an error occurs ("An error has
occured, the form has not been sent.").
This is because we try to send a mail linked to "mail.mail", which
doesn't make sense.
The case was actually taken into account in the code, there was just an
oversight in the code.
opw-684040
By default, werkzeug doesn't preserve the order
of the parameters sent to routes.
As stated in the werkzeug documentation:
```
parameter_storage_class
the class to use for args and form.
The default is an ImmutableMultiDict which supports multiple values per key.
alternatively it makes sense to use an ImmutableOrderedMultiDict
which preserves order or a ImmutableDict which is the fastest
but only remembers the last key.
It is also possible to use mutable structures, but this is not recommended.
New in version 0.6.
```
For some of our use cases, it makes sense to keep the order
of the route parameters.
e.g. In the website builder, when building a form
with a bunch of inputs values that will be concatened
in a lead note, the user expects the answer to be displayed
in the same order than the form inputs.
This change is seen as a bit risky as it could lead to
performances issues in the http routes processing, and this
is the reason we do not merge this in stable 9.0 at the moment.
If needed, it could be back ported later to 9.0, after
several weeks/months of testing in this release(saas-10 atm).
opw-677508
* The compiled templates are cached per user, lang, inherit context values
* ir.ui.fields: attributes method return an dict, and record_to_html return only the content value of the field
* all rendered text use build_text and all attributes use build_attribute
* t-esc-options is removed and replace by format_value method
* AssetsBundle receive the list files and remains
Adding date & datetime inputs in the website
form builder couldn't work, because
the posted values for these input
types were not treated at all,
and they were not in the format
the date/datetime were stored in database.
opw-672674
* blacklist all fields by default
* don't use blacklist in get_authorized_fields which is called to see if
a field can be added to a form, instead only use it afterwards to see
if the field can be written to by the formbuilder. That way
formbuilder can whitelist fields which are actually added to forms
on-demand resulting in a more secure interaction
In some instance, the mail content of a sent form would only be text
formatted. This could lead to a message with no newline, thus making it
illegible.
This fix has to be ugly since body_html field of a mail.mail is of type
text.
In the form builder, custom field name could contain special char but
the get key values are of the type str whilst the value are in unicode
type.
Thus when concatenating them, one should be converted so they are
uniform and don't lead to an encoding error.
opw-656745
- Fixed the module name and category in manifest
- Fixed website_form_blacklisted being ignored
- Unauthorized readonly and magic fields
- Reset the form on successfull submit
- Added missing date field
- Added date and datetime validation