Commit Graph
100300 Commits
Author SHA1 Message Date
Xavier Morel 045b9019ef [FIX] base_import_module: CSRF handling
* disabled CSRF protection for login route
* return CSRF token from login and retransmit it during module upload

``deploy`` only sends CSRF token if given one by authenticate so that
the command can be used for non-updated modules.

Closes #9488
2016-01-12 19:05:43 +01:00
Christophe Simonis 33299fd689 [MERGE] forward port of branch saas-6 up to 5eee559 2016-01-12 18:46:23 +01:00
Denis Ledoux 85b342c3b1 [FIX] website_sale: my cart popover in other languages
When browsing the ecommerce in another language
than the default one,
the my cart popover, displayed when the mouse is over
the "My Cart" link in the menu, wasn't working.

This is because the Jquery selector was defined as
"the link must start with `/shop/cart`,
while, when browsing this link in another language,
this link is prefixed with the language code,
e.g. `/es_ES/shop/cart`.

The selector should therefore check that the links
ends by `/shop/cart`.

opw-666351
2016-01-12 18:35:52 +01:00
Christophe Simonis 5eee5591ab [MERGE] forward port of branch 8.0 up to 37ed5ce 2016-01-12 18:24:27 +01:00
Denis Ledoux 6a366b216b [FIX] models: order by translatable fields with multiple translations
When a model list is ordered on a translatable field,
a join on the `ir_translation` is done, so the order
is correctly done on the translation value rather
than the translation source (in English).

This join wasn't entirely correct: If there were
multiple translations for a same record field
(which should not happen, but which is not forbidden)
e.g. Two different translations for the name of a same product,
then this record appeared several times in the result of the query,
while this is expected to only have each record once
(Obviously, when you perform a search on products, you do not expect
to have multiple times the same products returned by the search query)

This had as side-effect, when searching records with a limit of 80
items, to return actually less than 80 items
(e.g. 72 products, with multiple translations),
and, as the limit of the search was not reached (e.g. 72 instead of 80),
the web client did not perform the `search_count`, as it does not do
it when the limit of the search is not reached (meaning there is no
more items than what has been returned by the search query), and therefore
the web client did not consider there was actually more results, more
pages of results.

In summary, the count of records of a model could be different
when performing the order on a translatable field from one
language to another.
(e.g. A database could return 150 products in English, but
only 72 in Spanish).

To solve this issue, we have required the use of the operator
`DISTINCT ON`, which provides the possibility to keep only
the first translation for each record according to a given
order (in this case, we keep the translation that has been
added the most recently)

From the PostgreSQL documentation:
DISTINCT ON ( expression [, ...] ) keeps only the first row
of each set of rows where the given expressions evaluate to equal.
The DISTINCT ON expressions are interpreted
using the same rules as for ORDER BY (see above).
Note that the "first row" of each set is unpredictable
unless ORDER BY is used to ensure that the desired row appears first

The performance of this new query is similar to the performance
of the former query.

opw-666071
2016-01-12 17:40:58 +01:00
Goffin Simon 1676f66ad3 [FIX] account: deprecated account
If an account is deprecated it should not be possible to use it anymore.

opw:665987
2016-01-12 16:51:54 +01:00
Goffin Simon 4142d6ed8e [FIX] purchase: unlink PO
A PO must be in state cancel to be canceled.
Before the fix, it was possible to cancel a draft PO
then if a PO linked to a procurement was deleted with being
canceled, the procurement stayed in running state.

opw:666311
2016-01-12 16:28:01 +01:00
Nicolas Lempereur b24d759036 [FIX] web_editor,base: transmit translation model
There is a logic on the front-end to escape translated text content when
saving them as ir.translation record.

This logic was in part base on html elements and if these element were
not coming from an html field other than "ir.ui.view" arch_db's field.

This logic was introduced in 8.0, and something similar was later
introduced in 9.0 with f5acea7, but in this instance, the information
[data-oe-model] on nodes was not available. Thus some html field from
other model than ui.ui.view would have their translation escaped
erroneously.

This commit adds a data-oe-model attribute on to-be-translated nodes
which will then be available to the frontend.

closes #10420

first-part-of: opw-659772
2016-01-12 15:14:07 +01:00
qsm-odoo cb79297a41 [FIX] web_editor: links edition (only website links)
Commit f3f7bd9f24 adds an improvement which allows the user to edit links in
an easier way. The problem is that it also allowed to edit... the edit
buttons (example: the discard button).

This commit moves the mentionned commit code below the code that checks
if the target can be edited or not.
2016-01-12 15:03:23 +01:00
Christophe Matthieu a830263992 [FIX] wesbite_sale: recompute taxes only when update checkout
Issue: We force to recompute the taxes on all lines in constrains. This forcing loose custom added taxes in the backend.
2016-01-12 15:01:08 +01:00
Nicolas Lempereur 37ed5ce844 [FIX] website_quote: don't unescape menu title
If we take content with $().text(), to insert it in another node we have to
used $().text(value) also. If like before this commit, we would use $().html()
the content would be unescaped one time too much.
2016-01-12 13:33:44 +01:00
Thibault Delavallée c3db39ee25 [FIX] res_partner: conditional colorize of avatar
colorize parameter was not taken into account when colorizing the image.
Thanks Wolfgang Taferner for pointing it out.
2016-01-12 10:29:59 +01:00
Martin Trigaux e636d98741 [FIX] website_sale: remove truplicated* code
I only blame kdiff3

* TM @rim-odoo
2016-01-12 10:14:43 +01:00
Mohammed Shekha 06a3609ac8 [FIX]calendar: use display_name instead of name, because of template change, now FieldMany2ManyTag uses display_name to show lable on tag 2016-01-12 10:13:43 +01:00
Nicolas Martinelli 8c51bb7476 [FIX] sale: unlink SO and procurement
When a SO is confirmed, cancelled then set to draft, the SO is still
linked to the pickings and the procurements which were created before
cancellation. This should not be the case, since a draft SO is not
supposed to be linked to any procurement.

The fix resets the procurement group of the SO, and resets the
procurements linked to a SO line.

Fixes #10277
2016-01-12 09:02:08 +01:00
Thibault Delavallée 929e060c07 [FIX][IMP] base: partner image
Do not compute the partner default image when being in testing or install mode.
For example when importing a huge list of contacts there is no need to compute
a default image for every contact.

Moreover the random colorize is more limited. There is no need to explore the
whole space of rgb. It is now limited by steps in the rgb random, leading to
less different images being possible. There are currently 512 possible
combinaisons.
2016-01-11 17:47:44 +01:00
Nicolas Martinelli db638d8b33 [FIX] account: currency in analytic line
Once accounting is installed, the currency of the amount must be the
currency of the company, while the amount currency contains amount in
the original currency.

opw-665821
2016-01-11 17:05:42 +01:00
David Monjoie e01dab102f [FIX] sale: unhide Sales button from product form view
Continuation of 4c1224f5ec.
2016-01-11 16:53:58 +01:00
Christophe Matthieu 0b2728d8b2 [FIX] web_editor: error when long delete keypress in mass_mailing html
issue: event does not a global var in firefox, and event is already prevented
2016-01-11 15:23:36 +01:00
Christophe Matthieu 50057c08aa [FIX] web_editor: clean pasted dom and avoid crappy dom
Chrome on windows add few comment tags and insert unwanted span.
2016-01-11 15:20:49 +01:00
Jérome Maes a1d8eccc7e [FIX] auth_oauth : propagate the context in signin process 2016-01-11 15:08:39 +01:00
Joren Van Onder 963edc634f [FIX] point_of_sale: remove references to self-checkout in docs
Version 7 (and saas-3) had a self-checkout mode that was removed in
8. There are still some fields that reference the feature in
point_of_sale.py but they're obsolete and unused in the
frontend.

Both README.md and static/description/index.html (and thus
odoo.com/apps) still referenced these features.

opw-666328
2016-01-11 15:04:23 +01:00
Goffin Simon 1ef52c9c3d [FIX] website_sale: state option in checkout page
option.style.display = “none” not working in safari

opw:665787
2016-01-11 14:41:08 +01:00
Géry Debongnie 53f4649334 [FIX] mail: use our own autoresize for composer inputs
Instead of duplicating the autoresize logic, we might as well use it for
everything.
2016-01-11 14:32:51 +01:00
Géry Debongnie 6567725ac8 [FIX] web_planner: fix autosize textarea 2016-01-11 14:32:51 +01:00
Géry Debongnie 29427bdcb3 [FIX] web: reimplement autosize for fun (and some bugfixing)
autosize does not work correctly (it moves the screen in all directions
sometimes when the user press enter in the bottom of the screen in some
browser),

So, we decided to have our own version, because of course, we can do it better.  A
few horrible hacks later, I proudly present you "autoresize" (it was
almost named "odooresize" but common sense prevailed).

As added benefits, it plays better with our web client, so when you open
a dialog in a modal for example, the autosize fields should have the
correct height automagically (or should I say 'odoomagically')
2016-01-11 14:32:51 +01:00
Simon Lejeune 7d30769980 [FIX] web_planner: cleaner way to handle initial percentage
Instead of using a default value of 5%, we now add a fictive first
step and consider it as done.

this is related to 9a8153ee55

(fp is watching my ugly commits)
2016-01-11 14:27:30 +01:00
Raphael Collet 02165536e4 [FIX] models: remove call to dead method log
Also remove the flag `_log_create` that was enabling the log.
2016-01-11 13:39:21 +01:00
Christophe Matthieu dd67cb1f23 [FIX] website_sale: responsive design for mobile does not align button and quantity selector 2016-01-11 13:25:57 +01:00
Christophe Matthieu 8d6f89fd44 [FIX] website_sale: better grid and list displaying in mobile view
issue:
* grid: overlap of the products if at least one product does not have a 1x1 size
* wrong product size for grid in small device
* long text get out the product container and hide the other informations
2016-01-11 13:25:57 +01:00
Denis Ledoux 1195eae010 [FIX] website_quote: correct company headers
When printing the online quote, using the "Print" button
in the online proposal in the front-end, the user
used to print the report is the SUPERUSER.

If `doc` or `o` is not set within the QWeb values,
the headers printed are the ones from the user company,
instead of the record company.

As this was the case in the `website_quote` report,
the company headers printed were not the sale order company
headers, but the SUPERUSER company headers.

opw-666306
2016-01-11 12:52:53 +01:00
Denis Ledoux 401d725096 [FIX] report: in report qweb, doc is an alias of o
In some reports,
e.g. the sale order report(report_saleorder),
the browse record is set under `doc` instead of
`o`.

Therefore, when printing a sale order as a user
from another company than the SO company,
the header printed were the one of the user company
instead of the one of the sale order company.

opw-666306
2016-01-11 12:52:53 +01:00
Jeremy Kersten 33e84a6622 [FIX] website: fix sitemap to avoid to get post route inside
Route with method="['POST']" should not appear in sitemap

This code had never works.

rule.method is not the list of methods declared on the endpoint but "the HTTP
method for the rule if there are different URLs for different methods on
the same endpoint" (src http://werkzeug.pocoo.org/docs/0.11/routing/)

The new code uses the method declared on endpoint and so will avoid to add
endpoint with method declared and wich doesn't support GET.
2016-01-11 12:49:34 +01:00
Thibault Delavallée 148c1ed51c [FIX] mail: html issue in invite email
Thanks Vitor Fernandes <vmlf01@gmail.com> for pointing it out.
2016-01-11 12:48:09 +01:00
Thibault Delavallée a35d2d5548 [FIX] mail: context propagation
Thanks michaelhwalther <michaelhwalther@gmail.com> for pointing it out.
2016-01-11 12:48:09 +01:00
Goffin Simon bb2549f531 [FIX] stock: location_id and location_dest_id
In "stock.move" model the fields location_id and location_dest_id
are required. But when disabling "Manage Multiple Locations and Warehouses"
in Technical Settings, these fields became hidden in stock.move.form and
then it was impossible to add an new product to consume in mrp.production.form.

In 8.0, to be in group_stock_user implies to be in stock.group_locations.

Introduced by e58b16a

opw:660032
2016-01-11 12:19:23 +01:00
Ludovic LAFFINEUR 5ce0cf7e96 Merge pull request #10395 from odoo-dev/saas-6-scheduler-performance-lla
[FIX] Improve performance of the scheduler.
2016-01-11 11:43:13 +01:00
Géry Debongnie cf294f723f [FIX] mail: prevent double scrollbar with notification bar
when the bar asking for notification permission appears, it can cause
two scrollbars to appear in the client action.  This commit moves the
notification bar inside the chat content, which solves the issue.
2016-01-11 11:00:18 +01:00
Sathors 903cde0522 [IMP] doc: dotted names not supported in @constrains
or in @onchange for that matter. They should already generate a warning,
but only the first time they're used.

This is done lazily because it introspects the instance/class which can
be costly when performed during the repeated setup of registry setup.

closes #5595
2016-01-11 10:59:56 +01:00
Ludovic Laffineur lla f975cefcb8 [FIX] Improve performance of the scheduler.
This commit improves performances of the scheduler when the database
is big (lots of products with lots of fields). This avoids prefetching
all the fields for every 1000 products while we only use 2 of them.
2016-01-11 10:49:45 +01:00
Thibault Delavallée b38cd437e4 [FIX] hr_holidays: year filter
This filter shows the leaves of the current year and allocation linked to
active types. However this does not make sense anytime you have allocation
overlapping a year.

It now shows leaves and allocations linked to active types. It is easier
and more consistent.
2016-01-11 10:29:46 +01:00
Christophe Matthieu 12f97e5242 [FIX] base: add mimetype for url attachment 2016-01-11 10:17:19 +01:00
Christophe Matthieu fa1e30394e [FIX] base: remove unnecessary code (td.oe-actions does not exist) 2016-01-11 10:12:05 +01:00
Jared Kipe 20a8c210fd [FIX] sale: A new 'task' line should not generate (and overwrite) the sales order analytic account
(A or B and not C) => (A or (B and not C)) which means that
A will always cause the creation of a new analytic account
regardless of C (which is checking if the sales order already
has a 'project_id').

The 'poject_id' check should always prevent the call
to `_create_analytic_account()`.
2016-01-11 09:49:29 +01:00
Odoo Translation Bot 1c33197828 [I18N] Update translation terms from Transifex 2016-01-10 03:04:15 +01:00
Odoo Translation Bot 9c911d0364 [I18N] Update translation terms from Transifex 2016-01-10 01:28:32 +01:00
Jeremy Kersten 91aa450533 [FIX] website_slide: add domain on controller pdf_content for SEO
Add domain on route to avoid sitemap to index this route if
nothing to display.

Return empty data if route called for a slide without datas.
2016-01-08 23:55:44 +01:00
Jeremy Kersten ce3f797068 [FIX] website_event: avoid traceback when page doesn't exists
The controller /event/<event_id>/page/<page> raise exception if page is not existing.

Allow to pass the template reference when user are creating a new page.
Without it, it is impossible for the end user to create a website_event page without
change manually the xml id because the xml id is based on the module from the template.

This fix is retro compatible, because from_template will be ignored until next update
of website. And during update from website, website_event will be updated because it's a
dependance and so the default_page template created.
2016-01-08 23:19:29 +01:00
Jeremy Kersten 2afadfe444 [FIX] website_sale: force to get a pricelist to avoid traceback
If a user or a bot arrive on /checkout, /cart or other routes which
call sale_get_order without browse other ecommerce page.
None pricelist was selected by default

Avoid crash when standard workflow of ecommerce is not followed.
2016-01-08 19:18:34 +01:00
Jeremy Kersten e2925909b2 [FIX] website_forum: escape search by tag, quote char to search, don't create empty tag, only display alphanum first char in pager of tags, ... 2016-01-08 19:14:31 +01:00