* disabled CSRF protection for login route
* return CSRF token from login and retransmit it during module upload
``deploy`` only sends CSRF token if given one by authenticate so that
the command can be used for non-updated modules.
Closes#9488
When browsing the ecommerce in another language
than the default one,
the my cart popover, displayed when the mouse is over
the "My Cart" link in the menu, wasn't working.
This is because the Jquery selector was defined as
"the link must start with `/shop/cart`,
while, when browsing this link in another language,
this link is prefixed with the language code,
e.g. `/es_ES/shop/cart`.
The selector should therefore check that the links
ends by `/shop/cart`.
opw-666351
When a model list is ordered on a translatable field,
a join on the `ir_translation` is done, so the order
is correctly done on the translation value rather
than the translation source (in English).
This join wasn't entirely correct: If there were
multiple translations for a same record field
(which should not happen, but which is not forbidden)
e.g. Two different translations for the name of a same product,
then this record appeared several times in the result of the query,
while this is expected to only have each record once
(Obviously, when you perform a search on products, you do not expect
to have multiple times the same products returned by the search query)
This had as side-effect, when searching records with a limit of 80
items, to return actually less than 80 items
(e.g. 72 products, with multiple translations),
and, as the limit of the search was not reached (e.g. 72 instead of 80),
the web client did not perform the `search_count`, as it does not do
it when the limit of the search is not reached (meaning there is no
more items than what has been returned by the search query), and therefore
the web client did not consider there was actually more results, more
pages of results.
In summary, the count of records of a model could be different
when performing the order on a translatable field from one
language to another.
(e.g. A database could return 150 products in English, but
only 72 in Spanish).
To solve this issue, we have required the use of the operator
`DISTINCT ON`, which provides the possibility to keep only
the first translation for each record according to a given
order (in this case, we keep the translation that has been
added the most recently)
From the PostgreSQL documentation:
DISTINCT ON ( expression [, ...] ) keeps only the first row
of each set of rows where the given expressions evaluate to equal.
The DISTINCT ON expressions are interpreted
using the same rules as for ORDER BY (see above).
Note that the "first row" of each set is unpredictable
unless ORDER BY is used to ensure that the desired row appears first
The performance of this new query is similar to the performance
of the former query.
opw-666071
A PO must be in state cancel to be canceled.
Before the fix, it was possible to cancel a draft PO
then if a PO linked to a procurement was deleted with being
canceled, the procurement stayed in running state.
opw:666311
There is a logic on the front-end to escape translated text content when
saving them as ir.translation record.
This logic was in part base on html elements and if these element were
not coming from an html field other than "ir.ui.view" arch_db's field.
This logic was introduced in 8.0, and something similar was later
introduced in 9.0 with f5acea7, but in this instance, the information
[data-oe-model] on nodes was not available. Thus some html field from
other model than ui.ui.view would have their translation escaped
erroneously.
This commit adds a data-oe-model attribute on to-be-translated nodes
which will then be available to the frontend.
closes#10420
first-part-of: opw-659772
Commit f3f7bd9f24 adds an improvement which allows the user to edit links in
an easier way. The problem is that it also allowed to edit... the edit
buttons (example: the discard button).
This commit moves the mentionned commit code below the code that checks
if the target can be edited or not.
If we take content with $().text(), to insert it in another node we have to
used $().text(value) also. If like before this commit, we would use $().html()
the content would be unescaped one time too much.
When a SO is confirmed, cancelled then set to draft, the SO is still
linked to the pickings and the procurements which were created before
cancellation. This should not be the case, since a draft SO is not
supposed to be linked to any procurement.
The fix resets the procurement group of the SO, and resets the
procurements linked to a SO line.
Fixes#10277
Do not compute the partner default image when being in testing or install mode.
For example when importing a huge list of contacts there is no need to compute
a default image for every contact.
Moreover the random colorize is more limited. There is no need to explore the
whole space of rgb. It is now limited by steps in the rgb random, leading to
less different images being possible. There are currently 512 possible
combinaisons.
Once accounting is installed, the currency of the amount must be the
currency of the company, while the amount currency contains amount in
the original currency.
opw-665821
Version 7 (and saas-3) had a self-checkout mode that was removed in
8. There are still some fields that reference the feature in
point_of_sale.py but they're obsolete and unused in the
frontend.
Both README.md and static/description/index.html (and thus
odoo.com/apps) still referenced these features.
opw-666328
autosize does not work correctly (it moves the screen in all directions
sometimes when the user press enter in the bottom of the screen in some
browser),
So, we decided to have our own version, because of course, we can do it better. A
few horrible hacks later, I proudly present you "autoresize" (it was
almost named "odooresize" but common sense prevailed).
As added benefits, it plays better with our web client, so when you open
a dialog in a modal for example, the autosize fields should have the
correct height automagically (or should I say 'odoomagically')
Instead of using a default value of 5%, we now add a fictive first
step and consider it as done.
this is related to 9a8153ee55
(fp is watching my ugly commits)
issue:
* grid: overlap of the products if at least one product does not have a 1x1 size
* wrong product size for grid in small device
* long text get out the product container and hide the other informations
When printing the online quote, using the "Print" button
in the online proposal in the front-end, the user
used to print the report is the SUPERUSER.
If `doc` or `o` is not set within the QWeb values,
the headers printed are the ones from the user company,
instead of the record company.
As this was the case in the `website_quote` report,
the company headers printed were not the sale order company
headers, but the SUPERUSER company headers.
opw-666306
In some reports,
e.g. the sale order report(report_saleorder),
the browse record is set under `doc` instead of
`o`.
Therefore, when printing a sale order as a user
from another company than the SO company,
the header printed were the one of the user company
instead of the one of the sale order company.
opw-666306
Route with method="['POST']" should not appear in sitemap
This code had never works.
rule.method is not the list of methods declared on the endpoint but "the HTTP
method for the rule if there are different URLs for different methods on
the same endpoint" (src http://werkzeug.pocoo.org/docs/0.11/routing/)
The new code uses the method declared on endpoint and so will avoid to add
endpoint with method declared and wich doesn't support GET.
In "stock.move" model the fields location_id and location_dest_id
are required. But when disabling "Manage Multiple Locations and Warehouses"
in Technical Settings, these fields became hidden in stock.move.form and
then it was impossible to add an new product to consume in mrp.production.form.
In 8.0, to be in group_stock_user implies to be in stock.group_locations.
Introduced by e58b16a
opw:660032
when the bar asking for notification permission appears, it can cause
two scrollbars to appear in the client action. This commit moves the
notification bar inside the chat content, which solves the issue.
or in @onchange for that matter. They should already generate a warning,
but only the first time they're used.
This is done lazily because it introspects the instance/class which can
be costly when performed during the repeated setup of registry setup.
closes#5595
This commit improves performances of the scheduler when the database
is big (lots of products with lots of fields). This avoids prefetching
all the fields for every 1000 products while we only use 2 of them.
This filter shows the leaves of the current year and allocation linked to
active types. However this does not make sense anytime you have allocation
overlapping a year.
It now shows leaves and allocations linked to active types. It is easier
and more consistent.
(A or B and not C) => (A or (B and not C)) which means that
A will always cause the creation of a new analytic account
regardless of C (which is checking if the sales order already
has a 'project_id').
The 'poject_id' check should always prevent the call
to `_create_analytic_account()`.
The controller /event/<event_id>/page/<page> raise exception if page is not existing.
Allow to pass the template reference when user are creating a new page.
Without it, it is impossible for the end user to create a website_event page without
change manually the xml id because the xml id is based on the module from the template.
This fix is retro compatible, because from_template will be ignored until next update
of website. And during update from website, website_event will be updated because it's a
dependance and so the default_page template created.
If a user or a bot arrive on /checkout, /cart or other routes which
call sale_get_order without browse other ecommerce page.
None pricelist was selected by default
Avoid crash when standard workflow of ecommerce is not followed.