Commit 4d1a1f1c introduced a systematic check on the kwargs passed to
transaction routes of modules integrating with online payments, but
failed to check the access token of documents whose ID is passed to
payment routes. This allowed retrieving the access token of such
documents by visiting a route that did not check the document access
(e.g., /my/payment_method) and passing an arbitrary document ID
(e.g, sale_order_id=123). The route's controller would reroute the
payment flow to the document's portal page and render the landing route
of the flow on the payment form, with the access token included.
This commit makes sure that we always check the access token of a
document before reading rerouting a payment flow.
closesodoo/odoo#138238
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
We removed CSS styling for these classes in
854083f70a,
but these were only used in the survey tour, and not
instrumental, so we can remove them.
Task-3525225
closesodoo/odoo#138095
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
The purpose of this commit is to resolve two issues relating to the properties field:
Issue 1:
========
In a list view, when you edit a property and then select another field
in the same record, the edition disappears.
How to resolve:
--------------
Do not delete the changes linked to the property in record.update.
How to reproduce:
----------------
- Go to a list view with a properties field containing a property char
- Insert a value in the char property
- Click on another field in the same record
Before this commit:
The inserted value disappears
After this commit:
The inserted value is still present
Issue 2:
========
The fields/activeFields only take into account properties received
during the initial web_read and not those added by an update or an onChange.
How to resolve:
--------------
Generate property fields and activeFields during parseServerValue
(web_read and onChange) and during an update.
How to reproduce:
----------------
- Go to a form view with a properties field
- Editing a field with an onChange
- The onChange returns a new property for the properties field
Before this commit:
A crash is displayed
After this commit:
The new property is displayed correctly
closesodoo/odoo#137989
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
Prior to this commit, lazy-loaded bundles weren't pregenerated,
potentially causing non-deterministic test failures when the
generation process took too long. Plus, each Python test loading these
bundles necessitated their regeneration.
With this commit, the lazy-loaded bundles are now included in the
pregenerated bundles.
task-3493014
runbot-24842
closesodoo/odoo#134464
Related: odoo/enterprise#46985
Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
When the stock module is installed some conditions changes in the sale orders
Here's the list and the implementation made to help this
Patched the kanban_record so that the asked_qty of a product cannot go below the delivered_qty
the delivered_qty is added in the productCatalogData of the record through the _get_catalog_info() hook in the following PR:
https://github.com/odoo/odoo/pull/132341/commits
Patched the sale_order_line xml to disabled removeProduct and decreaseProduct buttons when the quantity is equal to the
delivered quantity
if the user tries to remove an already delivered product it'll set to the delivered quantity instead of 0
if the user tries to set a quantity that is below the delivered quantity it'll set it to the delivered quantity
Added action action_product_forecast_report to the menuitem of the products
Task-3343547
closesodoo/odoo#127161
Related: odoo/enterprise#43469
Related: odoo/upgrade#4887
Signed-off-by: Xavier Bol (xbo) <xbo@odoo.com>
*: web_editor
This warning redirects users to the code snippets block and footer/body
code injection. We want to avoid editing the XML code for no good reason
because it complicates upgrades to the next version.
task-3229205
closesodoo/odoo#117051
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
Co-authored-by: qsm-odoo <qsm@odoo.com>
odoo/odoo#136944 removed the log from website_event_track, but despite
noting the discontinuity I missed that *a new instance of the log line
had been added in 16.1* and that is likely why 16.1 was suddently
spammed with that: website_event_track (likely) only installs its PWA
when opening an event on website, but since odoo/enterprise#35322 the
web client tries to install its PWA *every time it's loaded*, which
can be up to once per test for qunit tests (if they need a webclient).
In odoo/odoo#133560 this registration was moved from enterprise to
community, so needs to be nuked here as well.
Follows the removal of this log line in odoo/enterprise#48831.
closesodoo/odoo#138469
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Setting IAP sandbox as the endpoint for IAP doesn't really neutralize
the IAP services, it only prevents buying credits for it.
The existing credits could still be consumed by mistake.
In this new version, the account is kept as is, but the "+disabled"
suffix is appended to it. This will effectively disable the service by
raising a `InsufficientCreditError` for every IAP transactions.
This solution has multiple advantages:
- It's easy to revert, removing the "+disabled" suffix will re-activate
the account.
- It's retrocompatible as it doesn't require a new field on the IAP
account model.
- It's safer as the "disabled" information is directly part of the
token, its logic is handled on the IAP side and thus common to all
services.
In this new version, the tokens need to be transformed as follows:
original token | neutralized token
--------------------|-------------------
abcd1234 | acbd1234+disabled
my_token+suffix123 | my_token+disabled
abc+disabled | abc+disabled
closesodoo/odoo#138455
X-original-commit: 550595d84b9689f3fcc00f840e9d9d6d521c5ea9
Signed-off-by: Florian Daloze (fda) <fda@odoo.com>
Signed-off-by: Louis Baudoux (lba) <lba@odoo.com>
The help defined on a field via Studio is only visible when debug mode
is enabled
Steps to reproduce:
1. Install Contacts and Studio
2. Go to Contacts, open a contact and toggle Studio
3. Add a field in the form view and add a message in the Help Tooltip of
the field
4. Close Studio
5. Without debug mode, the small question mark is not displayed next to
the field so we cannot see the help tooltip
Solution:
First use the help defined on the field in the view, then the help
defined on the field in the model
Problem:
The tooltip help can also come from the view
opw-3511121
closesodoo/odoo#138416
X-original-commit: a70639b790471aec781c50274abbda78bf5bea7d
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
Signed-off-by: Guillaume Merlin (megu) <megu@odoo.com>
With long favorite names, the search menu overflows to the left of the
screen
Steps to reproduce:
1. Install any app with a search bar (e.g. CRM)
2. Open the app and save the current search as a favorite, enter a
really long name (200 characters or more)
3. The search left side of the search bar is not visible anymore
Solution:
Limit the width of the search bar menu and of the favorite menu. The
purpose of the maximum width on the search bar menu is for a correct
display in mobile view. We also take into account the comparison menu
(that can be displayed if you add a filter on creation date)
opw-3442705
closesodoo/odoo#138415
X-original-commit: 107f496b5e67ca3293e2c63a273cf8c491187fb5
Signed-off-by: Romeo Fragomeli (rfr) <rfr@odoo.com>
Signed-off-by: Guillaume Merlin (megu) <megu@odoo.com>
This commit makes bus tests more robust by implementing
functions that wait for some events instead of relying
on `nextTick` that might or not be sufficient.
fixes runbot-23097
closesodoo/odoo#138221
Signed-off-by: Matthieu Stockbauer (tsm) <tsm@odoo.com>
This commit cleans the bus tests by:
- flattening the tests structure by putting tests outside
of the `QUnit.module` function.
- removing unnecessary `assert.expect` calls.
- adding an helper to add common bus service to the registry
Part-of: odoo/odoo#138221
This commit adds the recently removed add condition button to the folded
domain field so the user can unfold the domain and add a new rule in one
click.
Task-3525269
closesodoo/odoo#137663
Signed-off-by: Mathieu Duckerts-Antoine (dam) <dam@odoo.com>
- Moved VAT report to Community repo
- Re-numbered XMLids of the report lines so that they correspond to the
tag names
- Changed the tax repartition line templates to use the new tax tags
defined in the VAT report
- Removed the obsolete tax tags and account tags
closesodoo/odoo#134590
Related: odoo/enterprise#47033
Related: odoo/upgrade#5122
Signed-off-by: Olivier Colson (oco) <oco@odoo.com>
With Mexican, Colombian, or Ecuadorian localization installed
Open a journal (example Customer Invoices)
In 'Advanced Settings' tab, edit Electronic invoicing (uncheck some options)
Update the account_edi module
Issue: The configuration of the journals is lost
It occurs that when updating the module we call the `account.edi.format`
create, which will call the compute method on all journals
This it not necessary when updating the module
opw-3472309
closesodoo/odoo#138447
X-original-commit: e0b7f02fbb5a0da3be61b396fbba5d85ddbeb7d4
Signed-off-by: Olivier Colson (oco) <oco@odoo.com>
Signed-off-by: Andrea Grazioso (agr) <agr@odoo.com>
This commit changes the name of the option which changes the color of
the header. Before this option was called 'Colors' this commit renames
it to 'Background'.
task-2904507
closesodoo/odoo#99732
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
This commit adds a new option to choose the text color when the nav bar
has the position "hover the content".
task-2904507
Part-of: odoo/odoo#99732
Co-authored-by: jpr-odoo <jpr@openerp.com>
This commit allows users to choose any background color for nav bars
that are over the content. Before this commit the available colors were:
- bg-black-{15/25/50/75}
- bg-white-{25/50/75/85}
Now the users can choose any color (except gradients).
task-2904507
Part-of: odoo/odoo#99732
Co-authored-by: jpr-odoo <jpr@openerp.com>
The page options code had a callback for header_text_color, this one was
useless because the select style code already does the job. This commit
removes this useless code and allows the page options not to have a
callback.
task-2904507
Part-of: odoo/odoo#99732
Before this commit, the font color was subject to animations, this
commit removes that because it doesn't look good with a header over the
content.
Steps to reproduce the bug:
- Edit a website
- Set the header to "over the content"
- Put a dark background color on this header
- Scroll down and then up
=> The text color flicker.
Part-of: odoo/odoo#99732
This commit allows to restructure the header formatting options. The
font style option is now alone on one line. A new line of options is
added with the font size, font color and the alignment of the navigation
elements. Note that the font color option is a brand new one.
task-2904507
Part-of: odoo/odoo#99732
This commit allows the color picker widget to manage an SCSS variable
which can itself be a reference to another SCSS variable.
task-2904507
Part-of: odoo/odoo#99732
Purpose:
Improve the general usability of Email Marketing based on what has been observed on Userbrain.
Specification:
1) Provide instant feedback for small mailings and for onboardees.
2) Improve queue ribbon
3) Add subscription field in mailing contact
4) Remove system generated document
5) Improve widget domain view
6) Add buttons in mailing list to send email and sms from there.
TaskId-2702607
--
I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr
closesodoo/odoo#82107
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
This commit introduces a button "Send New Mailing" & "Send New SMS" on the mailing
list so that one can direct send mailing & sms from a mailing list.
The current list will be set as default one in the mailing.
TaskId-2702607
Part-of: odoo/odoo#82107
This commit will add create_date field in view to display
it as 'Subscription Date' to the user so that concerned people
can know when did the contact subscribed into a mailing list.
Here, now when we will import contacts in mailing.contacts
we are linking the mailing_list in subscription_list_ids
using Command to get the values of create_date.
TaskId-2702607
Part-of: odoo/odoo#82107
- Before this commit, it could happen sometime that the time for
which mailing was schedules has passed, but user was still
getting the same ribbon that mail was scheduled for a particular
time (which is a bit confusing). And also in the case of
schedule_type equals to now we are displaying the next_departure
datetime in ribbon.
This commit improves the behavior and in such cases, displays a new
ribbon message saying "This mailing will be sent as soon as possible."
and has as refresh button next to it, which reloads the page. Once
the mailing is sent, this ribbon will also be hidden.
For that, we introduce a new compute boolean `is_past_departure` which
will be true only if the scheduled time is in past and the mailing is
still in queue.
And for the case scedule_type equals to now we are displaying
a new message on ribbon with refresh button.
- Re-arranges the model container part of the form view of
a mailing in order to utilize the horizontal space.
It moves domain next to the model / filter related fields so that
everything is in a single row, and thus reducing vertical space.
TaskId-2702607
Part-of: odoo/odoo#82107
Issue:
On databases with lots of products (400k+ `product.product`), the action
Inventory > Operations > Replenishment takes a lots of memory to
complete, leading to "Out of Memory" errors in some use cases.
Analysis:
When triggering the action, we need to recompute the
`virtual_available` of a lot of products (regular occurrence when a
DB for example has a lot of variants). The compute
`_compute_quantities` uses the ORM `filtered` method to filter out
`services` out of the `product.product` we have. This method is
memory hungry, as for each `_prefetch_ids` (capped at 1000, cf.
`PREFETCH_MAX`) it will store in cache the `product_tmpl_id.type`,
which stores all fields of the product_template + the type,
bloating the cache with *useless* data, as it's not used beyond this
filtering process.
Solution:
Disable the prefetcher, the bulk of the work is done in
`_compute_quantities_dict`, which makes a lot of `read_group` and
doesn't benefit much from fields already cached (this function
itself also disables the prefetcher internally at some point).
Also correcting the looping order in `_get_orderpoint_action` to
avoid multiple cache invalidation when those can be batched in 1 call.
The `PREFETCH_MAX` makes sure the compute is only executed with 1k
records at a time, so explicitly dividing `all_products_ids` into
batches of 5k is unnecessary.
Results:
- Memory usage of `_get_orderpoint_action`:
| Memory usage | Before | After |
|--------------|---------|---------|
| Total Memory | 1.8 GiB | 363 MiB |
| Allocations | 10170 | 2804 |
(profiler data available on referenced ticket)
- Execution time of `_get_orderpoint_action`:
| `product.product` count | Before | After |
|-------------------------|----------|----------|
| 1k | 1.3s | 1.1s |
| 10k | 4.1s | 3.8s |
| 100k | 30s | 25.9s |
| 400k+ | 2min 25s | 1min 39s |
As we can observe, we've reduced drastically the memory usage of the
function and also the number of allocations quite drastically. As a
side effect there is also a slight speed improvement at small
scale, and at large scale the gains are up to ~40%
faster.
Reference:
opw-3415087
closesodoo/odoo#138423
X-original-commit: 41442574159429ce29aa5c5adf0e1a0d8a7046dd
Signed-off-by: William Henrotin (whe) <whe@odoo.com>
Signed-off-by: Piryns Victor (pivi) <pivi@odoo.com>
Currently, when the user enters a value of `VAT` like '/' or
any single character, an error occurs.
Error: "IndexError: string index out of range"
This is because the recently applied PR [1] added a Line [1] that tries to
access the second digit of VAT, but the user added only one character.
This commit fixes the above issue by accessing the second character
when the length of the VAT is more than one character.
PR [1]-https://github.com/odoo/odoo/pull/136146
Line [1]-https://github.com/odoo/odoo/blob/422625615b2f6708667fa44d2a9e83ad3e66e5af/addons/base_vat/models/res_partner.py#L92
sentry-4524865338
closesodoo/odoo#138454
X-original-commit: 57f59f2088c46f4603ff83bbcf2db42d705331fe
Signed-off-by: Olivier Colson (oco) <oco@odoo.com>
Signed-off-by: ANSARI MAHAMADASIF (maan) <maan@odoo.com>
Before this commit, the security XML file of microsoft_calendar module was not added in manifest, ignoring rules previously defined there. After this commit, the security XML file is now properly added.
Issue from task-id: 3410651
closesodoo/odoo#138397
Signed-off-by: Arnaud Joset (arj) <arj@odoo.com>
Steps to reproduce:
- Enable manufacturing lead times in settings
- Create a BOM for product P with lead time 5 days
- Create and process an MO for product P
- End date is wrong
(add date_finished to the MO list view to check)
Bug:
when marking MO as done the end date is correctly set as today
but during the write the compute is triggered which delays it by
the lead time
Fix:
do not modify the end date of done MOs
opw-3536069
closesodoo/odoo#138431
X-original-commit: baa769a56a1236ec75a6042c56643464c2aabd3d
Signed-off-by: William Henrotin (whe) <whe@odoo.com>
Signed-off-by: Walid Hanniche (waha) <waha@odoo.com>
When issuing an invoice in foreign currency, a detailed table with the vat amounts in company currency is displayed. The table title was "Tax computation in XXX" and the translation was not optimal in other languages, for example French: "Calcul de la taxe dans EUR". We simplify the title to "Taxes XXX", with XXX being the currency code.
task-3501390
closesodoo/odoo#138429
X-original-commit: 99d408bbbc696e3ca139b6a1a14279fc13fa7f89
Signed-off-by: Brice Bartoletti (bib) <bib@odoo.com>
The commit https://github.com/odoo/odoo/pull/128376 fixed an issue related to rtl languages,
but at the cost of the pencil position.
By making the span containing the value a display: block the pencil could no longer be placed
on the side of the value and was instead pushed on top.
This small fix will just place the pencil inside the span, in order to get it back aside the amount.
Task id # 3548687
closesodoo/odoo#138408
X-original-commit: 718fe9396aebec1c0a15c5064202f6350cdf346a
Signed-off-by: William André (wan) <wan@odoo.com>
Before this commit:
When a new element is added in a nested form i.e. inside a table <td>[]</td>
or inside a nested list, it is not deleted on immediate backspace.
After this commit:
When a new element is added in a nested form i.e. inside a table <td>[]</td>
or inside a nested list, it is now deleted on immediate backspace.
task-3339625
closesodoo/odoo#138382
X-original-commit: 263b8b4e2ff622f25dedef078e7d99c94c8f04b3
Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
It is now possible for aggregations to be defined with the formula 'sum_children'. An expression using this formula will take all the expressions with the same label, belonging to child lines of the line this expression belongs to, and will sum their values. This is done as an improvement in stable, as this feature is needed for a cleaner upgrade of custom-made tax reports from 15.0 to 16.0, since the former tax report engine used to behave like that by default (no formula meant you had to sum the children).
Task 3499260
closesodoo/odoo#138358
X-original-commit: 276142f899e9050ccd39f52c502e6529bbaa0493
Related: odoo/enterprise#48784
Signed-off-by: John Laterre (jol) <jol@odoo.com>
Signed-off-by: Olivier Colson (oco) <oco@odoo.com>
before this commit, if profiling is enabled in the db,
and on trying to validate a sale order, a traceback is
shown
* enable profiling
* confirm a quotation
traceback:
Failed to render QWeb template : <div style="margin: 0px;
padding: 0px;">
<p style="margin: 0px; padding: 0px; font-size: 13px;">
introduced in: https://github.com/odoo/odoo/commit/016f26a9315c693bdeb894725898c2cf725d8989
here the options['ref'] is coming as the email template
body and it is failing on try to do int of options['ref']
after this commit, no traceback wont be shown on
confirming sale order, when profiling is enabled
closesodoo/odoo#138357
X-original-commit: 01548aff72b031389a7563948bb12bc3abb07bfc
Signed-off-by: Rémy Voet (ryv) <ryv@odoo.com>
The right arrow icon on the public page relies on odoo-ui.
Currently, this file is not correctly imported into the public bundle, since
the icon is not showing.
This fix is to import the essential file into the public bundle.
closesodoo/odoo#138354
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Replace every mentions of 9925 to 0208 for Belgian companies (public
administration also have this 10 digits number). The EAS 0208
corresponds to the company_registry.
Introduce a mechanism to validate the `peppol_endpoint` and refactor the
computes for the `peppol_endpoint` and `peppol_eas` fields.
See: https://openpeppol.atlassian.net/wiki/spaces/Belgium/overview
task-3297311
closesodoo/odoo#138343
X-original-commit: 744bfa9e5f087a2aa9d714351a559c3320ecfda4
Signed-off-by: Laurent Smet (las) <las@odoo.com>
Signed-off-by: Julien Van Roy (juvr) <juvr@odoo.com>
This commit introduce the information button on the product card in the
self order mode. This button open a popup with the newly created field
"description_self_order" which is an HTML field allowing the user to
have a very customizable description for the product.
It also removes the description_ecommerce field from the product view
form as it is a field used in the website and not adapted for
the backend (css/js not compatible).
closesodoo/odoo#138216
Task-id: 3512835
Signed-off-by: Joseph Caburnay (jcb) <jcb@odoo.com>
'alias_user_id' field allows to set a user when creating records through the
mail gateway. This is however quite wrong and eases spoofing. The alias owner
is not the creator of any record, nor responsible.
Current possible ways of being owner / responsible of records created through
the mailgateway
* when you send an email to an alias: if you are recognized you are already
set as creating user and logged message author;
* it is possible to use alias_defaults notably to set fields like 'user_id'
if you want to be notified / responsible of records created through this
specific alias;
Those usages are therefore sufficient, no need to have another way to spoof
users. Moreover it is hidden in technical view of aliases, no model allows
to configure it by default. Moreover since odoo/odoo@3edf181 no default
value is given to alias_user_id as it adds more (ACLs / creator) issues than
really helping setting up mail gateway flows.
Task-3453482
Prepares Task-36879 (Mail: Multi-Domain Aliases)
closesodoo/odoo#138213
Related: odoo/upgrade#5259
Related: odoo/enterprise#48692
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Fix the duplicate message in the discuss and search
when the message type is email. This was caused by a wrong
rebase of https://github.com/odoo/odoo/pull/118794 that
did not take into account the branching on message body
for message of type email by https://github.com/odoo/odoo/pull/131202
The search highlight feature was not working on these email
message, so this commit also fixes that.
closesodoo/odoo#138205
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
In this commit, we remove three usages of the getBundle function from
@web/core/assets.js. The final goal is to remove it totally to simplify
the understanding of assets's API. To replace the use of getBundle in
mobile preview dialog, an xml template has been created on the server
side and then called by http requests. During the request, we retrieve
the list of assets (server side getbundle) to inject these into
the xml template.
taskId : 3266441
closesodoo/odoo#138055
Signed-off-by: Mathieu Duckerts-Antoine (dam) <dam@odoo.com>
Since the PR [1], the function autocompleteWithPages does not receive
a widget anymore and does not trigger an event on it when an url is
selected. Instead it is replaced by an optional function property
"urlChosen" which is called if given.
The error is that the optional check is wrong. The check is done on
the "options" parameter, not on its optional property "urlChosen".
This commit simply fixes this check.
[1]: https://github.com/odoo/odoo/pull/136271closesodoo/odoo#138047
Signed-off-by: Mathieu Duckerts-Antoine (dam) <dam@odoo.com>
This commit renames calendar's attribute quick_add to quick_create
to be more consistent with other views.
closesodoo/odoo#138042
Related: odoo/enterprise#48677
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
Since the PR [1], quick_add can be both a boolean and an id:
0 = without quick create
1 = with quick create and simple dialog
other number = with quick create and custom form view dialog
This is not great to have both behavior in a same attribute so this
commit split them back in two attributes as it was before [1].
It's easier to understand when we want a quick create and which view
to use in the dialog.
[1]: https://github.com/odoo/odoo/pull/122923
Part-of: odoo/odoo#138042