Now forum only allow to post message of type 'question'.
New 'modern' UI with Bootstrap 4
New moderation modal for bulk spam
Co-authored-by: qha <qha@odoo.com>
Co-authored-by: qsm <qsm@odoo.com>
Co-authored-by: jke <jke@odoo.com>
Thanks to @qha-odoo for UI
Thanks to @qsm-odoo for reviewSsss
closesodoo/odoo#29235
The input-group-addon class has been replaced by a combination of the
input-group-text and the input-group-append/prepend classes. The
input-group-btn class is replaced by the input-group-append/prepend
classes.
Message are now fetched and display using javascript
to optimize performance.
Also the chatter is completely rewrite : add pager,
filter possiblity, ...
This commit is mainly technical: posting feature does
not change. Only the display with pager is new.
The goal is also to prepare frontend chatter for a
better integration with rating widget.
The mail.thread mixin is extended to manage the field
website_message_ids (display all messages that can be
seen on frontend by user (employee or not).
When fetching or posting message, a check is done to see
if we need to do it as sudo(). website_mail implement posting
messages with token or sha_in (using in website_quote).
The same verification is now done when fetching messages, via
'_special_access_object' method.
The _message_post_helper() method historically allowed
passing a `sha_in` signature to let an unauthenticated
user post a message on a record.
This option is unused and an alternative is preferred:
passing a `token` value that matches the value of a
given field of the record.
In light of the increasingly grim future of SHA-1
as a cryptographic hash function, we consider it
better to entirely remove this specific option.
It has been unused for a while, and a simple
alternative exists.
As a temporary measure, the feature was also
deactivated in 10.0 at 2cffcfd860
Several modules defines records with the external ID `base.foo_bar` while it is
created inside this module (typically menus and groups).
While there is no technical reasons to do so but this may introduce issues:
- these records will not be deleted during uninstall
- if a language is loaded before the installation of the module, it won't be
translated
The uninstallation will only remove the records with an external id linked to
this module (these would only be removed when removing base).
Installing a language before the module will drop the translations not linked
to an existing external id (as it can not be resolved).
This commit correct all the external ids tagged as from base or other incorrect
modules.
On the font-end view of project.issue, only the messages of type `note` were
display. This excluded the messages recieved via email which makes hard to
understand a conversation (e.g. a customer does not sees his own answers).
Instead, only filter out the notifications (change of states, responsible...)
opw-677426
Previous commit (3304b31938) was not performant enough for AL, so got special autorization to make a particular controller for mail.message author avatar. Avatar of message is avaiblable if current user has 'read' access right to the document. Otherwise the default avatar is one white pixel.
To display author avatar to public user, using the /web/image url with res.partner returns the placeholder since public doesn't have access. Using the url on mail.message will display the avatar according to the access right defined on res_model/res_id of mail.message. However this executes mush query to fetch the avatar image (1 per message, against 1 per partner).
Maybe this wasn't a bug, but since it is a regression, this deserves to be fixed ...
* make CSRF protection the default on all non-SAFE methods
note: there currently is no way to call a CSRF-protected endpoint
without a form-encoded entity-body as that's the only place we get the
CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
the purpose of a CSRF token in the database manager screens.
There is no request database to obtain the
secret and generate a CSRF token.
Transform POST param into GET param when redirecting to login page can cause security issues. Now, instead of displaying textarea (even if public user) and the redirect to login page keeping written comment, we display the login button with a redirection to the page to comment.
The redirection happen before commenting, avoiding to remenber param such comment text, rating, ...
To post a comment, the user must:
- be connected
- have a token
- or have a sha_sign
Add 'force_display' param for the frontend chatter to allow public user to see the textarea. When submitting his comment, he will be redirect to login page (like it was before generic chatter) in both mode (json and post mode). This required changing the error handeling of json mode : when a login is required, the user switch to post mode to allow http redirect, keeping its submitted params (rating, comment, ...).
Replace deprecate controllers like /web/binary/image, /web/binary/saveas...
Use ETag for all content with 'unique' option to cache the content if the content is never changed.
A new generic chatter template is available in website_mail
This template allows access rights escalation when some kind of token or uuid
is available on the model or if you use the object_shasign function in the
main controller of website_maill to generate a cryptographic signature to allow
commenting on any object.
To use this chatter, you need to make a t-call to website_maill.thread in your
template after having set the following variables:
- chatter_object: the browserecord of the mail_thread object (mandatory)
- token: if you use a token system (optional)
- token_field: name of the field that stores the token on your object (optional)
- sha_in: if you use a shasign to allow public comment (optional)
- nosubscribe: set False if you want the partner to be set as follower of the object (optional)
- message_type, subtype: see message_post in mail_thread.py
Bootstrap's CSS depends on the input-group-btn
element being the first/last child of its parent.
This was not the case because of the invisible
and useless alert.
1. The merge of the "email_template" module into the "mail" module.
2. The send action of the mass mailing has been moved from the frontend to a cron, because it was too slow to send over 10,000 mails (the user's browser was blocked for 15 - 20 minutes). Mass mailings have now their own process in the kanban view.
3. Mails sent from the mail form are sent immediatly instead of from the mail queue (for instance, when you go to sales > customers > list view > select 2 -3 customers > More > Partner Mass Mailing).
4. Users have now the choice from which mailing list they want to unsubscribe when they click on the unsubscribe link at the bottom of the mail.
5. Mass mailings inherit from their campaign UTMs and mass mailing campaigns are linked to an UTM campaign.
6. Many little improvements
Button "Save and continue" was wrongly named as it worked only once the template
is not in edit mode (so already saved).
Hide the button to only get it in readonly mode and rename it for better
understanding of its purpose. (opw 614563)
website.snippet: The methods described in javascript will be called automatically from the data-method_name = value on li snippets options. The methods are called in the order relative to children of xml (eg: <li data-method1=value1> ... <li data-method2=value2> ... </ li>, the method1 is then called method2). Methods receive two arguments: type (over, click, reset) and value. data-snippet-id-option becomes data-snippet-id. Several xml options can use the same data-snippet-id.
add a new gallery snippet
convert website_sale to the new option system
- remove the default footer for mail.group messages,
replace with specific footer with archive and unsubscribe
link
- remove the automatic addition of user signature in
mail.group messages, as many of them will be posted
via the mail gateway and already contain a user signature.
- make it easier to unsubscribe even when not logged in,
as followers who have not signed up will have no
way to login short of signing up.
- remove tests looking for user signature in mail.group posts