Before this revision, when you pass `context` in the arguments
of a JSON routes, this one gets automatically injected
in the environment context.
This is not the case for regular HTTP routes.
It makes sense to propagate the context for the JSONRPC protocol,
JSON routes used by the backend, such as `call_kw`,
but it doesn't make sense to pass this context automatically
for any other kind of routes, such as front-end routes
or routes used by custom Javascript widgets.
This change brings a more unified behavior for routes
of types HTTP and JSON.
In addition, most developers were not aware of this "feautre",
that passing `context` in the arguments of a JSON route leaded
to the injection of this context in the environment context.
This is actually reflected by the diff size this changes required,
only a dozens of routes needed to be adapted, to manually
add the context in their route arguments and to inject it
in their environment context.
closesodoo/odoo#121726
X-original-commit: a7a5655631e6d5b05fd2ba3d0c80617aae6d9cfe
Related: odoo/enterprise#41229
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
1. Display avatar in top bar next to channel name and description.
2. Edit icon appears on hover.
3. Clicking on the Edit icon opens file browser to upload a new avatar.
4. Certain file types are allowed.
5. Avatar can only be changed for group chat by any member of the channel.
6. For channel it can be done with admin rights.
7. Disable uploading text from file uploader in this case.
Also show avatar of channel/chat conversation in chat window.
Author avatar in message list no longer shown im status.
Chat window header color matches new systray color.
task-2684679
[FIX] mail: make chat window header match systray color
Part-of: odoo/odoo#117357
Allow partner to unfollow a document from a follow up email of that document
through an unsubscribe URL in the email even if not connected.
It works for internal user for follow up on any document and for any partner on
follow up of document tagged as authorizing being unfollowed by any partner (
slide.channel and slide.slide).
Technical note:
The unfollow block is rendered in mail_thread and updated for each recipient in
mail_mail. We don't render it in mail_mail because we don't have the language
of the message at that point.
Depending on the partner and the related document, the unfollow block is:
- either removed if the user cannot unfollow the document (for example if it
doesn't follow it)
- or updated with partner and document information + a security token
Task-3061864
Part-of: odoo/odoo#107978
Allow users to unfollow easily document from the inbox for which he/she doesn't
want to be notified anymore.
When hovering on a follow up message with a related document followed by the
user, the interface displays an action to unfollow it that allows the user to
remove himself/herself as follower of the document. As a result of performing
that action a toast is displayed as a feedback.
Technical note:
The unfollow link is displayed on a message.canUnfollow is true which check
that the thread related to the message is followed by the user.
In order to know if the user follows the record related to the message, we now
transmit with each message the id of the follower table that link the user to
the related record if it follows it. This allows to insert the follower on
client side so that the unfollow action can use the standard mechaism already
developed to unfollow a record.
Unfortunately, that information coudn't be added in the already public method
message_format of mail message because that method is not always called on the
user retreiving the message but also by the one posting message. We didn't want
also to include all followers in the formated message so we rely on additional
method that add that information per partner.
To support unfollowing a document in the inbox no matter the current company,
we have modified message_unsubscribe in mail_thread to allow internal user to
unsubscribe themself without checking any rights. Indeed, some document have
record rule that prevents reading it if the user is not in the right company
(ex. crm.lead) and then was preventing the user to unfollow the document using
that method.
Task-3061864
Part-of: odoo/odoo#107978
By this commit, If a user edits the message body or changes
the message attachments, the edited label in the blob,
shows the last edit Info.
Task-2664848
closesodoo/odoo#117896
Related: odoo/enterprise#40208
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
As a bonus, add cross-tab update for current user in chatter.
Part of task-3265211
closesodoo/odoo#120018
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Before this PR, link previews where not updated when a user was editing a
message.
This clear the current link previews and reprocess the updated message.
closesodoo/odoo#119917
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
The opportunity is taken to clean the methods to make the override
actually possible.
Part of task-3265211
closesodoo/odoo#119942
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
This commit focuses on removing all references to discuss.channel from
controllers of mail module.
In preparation of splitting discuss and mail modules.
Part of task-3265211
closesodoo/odoo#119523
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
This commit focuses on removing all references to discuss.channel from
code located in /models of mail module.
In preparation of splitting discuss and mail modules.
Part of task-3265211
closesodoo/odoo#119413
Signed-off-by: Debondt Didier (did) <did@odoo.com>
It is only used there.
In preparation of splitting discuss and mail modules.
Part of task-3265211
closesodoo/odoo#119306
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
It is only used there.
In preparation of splitting discuss and mail modules.
Part of task-3265211
closesodoo/odoo#119302
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
* = bus, calendar, crm_livechat, hr, hr_holidays, im_livechat, mail_bot,
mass_mailing, privacy_lookup, test_discuss_full, test_mail,
test_mail_full, website_crm_livechat, website_livechat, base
In preparation of splitting discuss and mail modules.
Part of task-3265211
closesodoo/odoo#118354
Related: odoo/upgrade#4553
Related: odoo/enterprise#39661
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
When using message_post, the body format must be explicitly specified.
If html is expected, a Markup object should be used.
If text is given, the content will be escaped.
Before this PR:
message_post was unaware if the content of a message was HTML or
text. This lead to multiple situation where the content was
incorrectly considered as HTML and led to display errors.
In
self.message_post(body="Hello %s!" % self.name)
if the name contained HTML, it would be evaluated.
In
self.message_post(body="Contact Raoul <raoul@caramail.be>")
the email would not be displayed as considered as unknown HTML and
discarded by the sanitizer
Now each call must explict the type of content.
Use the escape() helper to properly combine Markup and translations.
It would also be acceptable to use Markup() to wrap a static
translation but escape is better as one can not guarantee the content
of a translation.
closesodoo/odoo#111850
Related: odoo/documentation#3612
Related: odoo/enterprise#36728
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
With this commit, messages can be pinned on a channel and
chat conversation. There's a new menu listing all pinned
messages on a conversation, and we can jump to these messages
in the current conversation.
As this feature incentives to see older messages, this commit
also adds a "Jump to Present" button when looking at old messages.
closesodoo/odoo#116666
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Adapt code of message fetch so that fetching of
(needaction) messages are controlled in a way to
keep continuous sequence of messages at all time.
This code design solves the "holes" problem in a message
list by not allowing holes. This fixes many scenario that
generated these holes, resulting in unfetchable messages.
Example of such a scenario:
- post 40 messages
- post a new message that is reply of the oldest message
- page reload and scroll up until load more
=> 10 messages are missing in-between replied message and
following message (that should have been 11 messages apart)
This code also prepares for allowing jumps in a conversation.
Part-of: odoo/odoo#116666
Since [1], the `temporary_id` of a message is passed to the
`message_post` route in order to renconciliate the temporary
message on the client side and the real message created by the
server.
This led to crashes when sending message on the chatter because
this parameter was not allowed as a `_notify_thread` parameter.
Since this parameter is highly specific and isn't linked to any
business/model code, this parameter is now passed via the context
thus solving this issue.
[1]: https://github.com/odoo/odoo/pull/116085closesodoo/odoo#116333
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
This commit removes the "new message" separator when posting a
message on a channel.
At the same time, this commit solves an issue that caused messages
to flicker when the message came from the bus before the answer of
the rpc.
In order to do so:
- messages are marked as read immediately after
`message_post` for the member of user that posted it.
- a temporary id is passed to `message_post` in order
to reconcialiate temporary/server messages.
task-3232911
closesodoo/odoo#116085
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Before this commit:
Portal users are not able to join RTC Calls in Discuss.
After this commit:
Portal users are able to join RTC Calls.
Task-3050534
closesodoo/odoo#115963
X-original-commit: 0bfd2625fb89b93494c9df1aad9b7390723f1aa7
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
This issue was caught in Sentry.
The return type of the partner avatar for public users is `odoo.http.Stream`,
but the `route_wrapper` expects it to be `Response streamed`.
sentry-3929988311
closesodoo/odoo#114933
X-original-commit: 62ddfe0badf54375bc458bdb50cbcdbe4da5bbcd
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
This commit contains mainly code cleaning, docstrings and a small split
for notification tool methods. In this commit we
* make some notification groups variable explicit;
* move the filler of groups into its own submethod to ease being called
from other code (to be used soon);
* fix some strange overrides or code manipulation;
* propagate some additional parameters to ease future commits that will
improve rendering of groups-based notification emails;
* cleanup, fixup and improve docstrings;
This does not change anything from functional point of view, just preparing
further work.
Task-3046371 (Mail: Better Language Support in Composer)
Part-of: odoo/odoo#106177
Follow up of https://github.com/odoo/odoo/pull/90415
After removing the public field, the equivalent access is to set the
allowed group to empty.
closesodoo/odoo#114729
X-original-commit: fcafd602dda4f896ac8b91c81c00ee723afd6634
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
request.geoip is no more a dictionnary cached in the session. It is now
a full blown object with lazy and smart geolocalisation capabilities.
Among other things, the previous dictionnary API is now deprecated. The
changes are:
* `request.geoip['country_name']` -> `request.geoip.country_name`
* `request.geoip['country_code']` -> `request.geoip.country_code`
* `request.geoip['city']` -> `request.geoip.city.name`
* `request.geoip['latitude']` -> `request.geoip.location.latitude`
* `request.geoip['longitude']` -> `request.geoip.location.longitude`
* `request.geoip['region']` -> `(request.geoip.subdivisions[0].iso_code if request.geoip.subdivisions else None)`
* `request.geoip['time_zone']` -> `request.geoip.location.time_zone`
It is safe to access all the attributes. Doing `request.geoip.city.name`
when the geolocalization failed (missing db, invalid address, ...)
evaluates to None. It does not raise an AttributeError.
Task: 2848206
Part-of: odoo/odoo#91337
When having falsy values, we may end up with 'False' as a string. Better be
defensive when trying to parse res_id.
Task-3025143
closesodoo/odoo#102576closesodoo/odoo#103378
X-original-commit: ac8d97262d196c7bb4c4fc15db63cc66512be838
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
*: bus, hr_holidays.
The `/bus/im_status` route polls the server every minute in order for
the user im_status to be up to date. This commit removes this poll
by sending the im_status on the bus when updating the current user
presence.
Moreover, before [1], the user bus presence was updated on each poll.
When the user didn't poll for 50 seconds, we assumed the user was
disconnected. Since [1], the bus presence is updated each 30 seconds
by the `im_status` service. This is too frequent: there is no need
to update the user presence so often.
In order not to overhelm the server with unnecessary requests, the update
presence interval as well as the delay to be considered disconnected
have been updated: the former from 30 to 60 seconds, the later from
55 to 65 seconds (assuming that a user that has missed an update
presence tick is disconnected).
[1]: odoo/odoo@a5623d2closesodoo/odoo#100249
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
*: im_livechat, website_livechat
Access right should be based on channel type and membership instead.
Chat always private, group always private, channel private should
disapear and be a group instead (migration needed), and other channel
always public (but they can still be further restricted with
the "allowed groups" feature)
task-2632861
closesodoo/odoo#90415
Related: odoo/enterprise#30980
Related: odoo/upgrade#3850
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
* = bus, hr_holidays, test_discuss_full
- use channel member instead of partner for typing
- use channel member instead of partner for all other return values from server
- remove temporary partner hack in livechat and keep public partner
- remove some obsolete convert data
- adapt format methods accordingly
task-2664853
closesodoo/odoo#98923
Related: odoo/enterprise#30760
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Purpose
=======
Move the code which updates the mail message from the message model to mail
thread. Most other thread methods (like `_message_update_content_after_hook`)
are defined at record model level. It makes sense to delegate the update to
documents and not to the message. Message is a low-level technical object
that should not really hold business code.
While modifying this code, an update is done in the update content. We now
also allow to update the body without removing all attachments.
Finally tests are added as this feature was added without really testing
model code.
Task-2207626 (Rating: Delay rating notification to ease feedback)
Part-of: odoo/odoo#95623
Co-authored-by: Thibault Delavallée <tde@odoo.com>
*: hr_presence, web_editor.
This commit is part of the websocket integration in Odoo.
It focuses on adapting the bus to support websockets:
- last notification id is now kept on the server
- channel list is built by overriding the `_build_bus_channel_list`
method of the `ir_websocket` model instead of overriding the `_poll`
method of the bus controller.
- The bus presence was updated during polls, since there is no more poll,
bus presence update will be the responsability of the client.
- The `/websocket/peek_notifications`, `/websocket/update_bus_presence`
routes will be available so that odoo sh can access notifications/update presence
from http requests.
- /longpolling routes are now prefixed with /bus thus won't be redirected to the
gevent worker anymore except for `/longpolling/health` which is the
health check route of the gevent server.
Since websocket now handle incoming messages, a way to manage authentication
have been introduced :
- The session is retrieved from the HTTP handshake.
- When a websocket message comes/leaves the session is retrieved
on the file system so that we're sure it still exists and that
it is up to date.
- The session is checked
- If no session is found on the file system or `check_session`
fails, the websocket connection is closed with the `SESSION_EXPIRED`
close code (which is a custom close code: 4001).
- Note that websocket connections are closed every `KEEP_ALIVE_TIMEOUT`
seconds to ensure no websocket connection will stay open if the user
clears its cookies.
- Note that a wsrequest object is available when processing incoming
messages. It is similar to the http request and contains various
useful informations (session, env, ...).
Part-of: odoo/odoo#75510
* = calendar, im_livechat, rating, snailmail, test_discuss_full, test_mail,
website_livechat
Distinction between "replace" and "insert-and-replace" can be guessed based on
the type of the provided data.
task-2957295
closesodoo/odoo#98404
Related: odoo/enterprise#30580
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
This removes an extra request, targets fetched messages more reliably and
simplifies the code.
task-2847909
closesodoo/odoo#96840
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
* test_discuss_full
channel invitation to rtc calls are now using the `ChannelMember` and
`mail.channel.partner` models instead of the `partner` and `guest`
models.
part of task-2692836
closesodoo/odoo#95898
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Steps to follow:
On a runbot,
- Login as Mitchell Admin
- Set the Administration permission of Marc Demo to Access Rights
- Login as Mark Demo
- Go to the Discuss App
- Edit a message from someone else by clicking on the pencil
-> A Traceback occurs
Cause of the issue:
- The pencil button is only displayed for another user if the logged in user
is admin. This is done by checking if the user is superUser or if he
has the group `base.group_erp_manager`
This is the case here
- When editing the message, the `base.group_system` is checked.
In this case, it is not present.
Solution:
Check the `base.group_erp_manager` in both cases
opw-2892740
closesodoo/odoo#95502
X-original-commit: bd8ed439d1d9342b24926eee332e8c26c6f0cd7c
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Signed-off-by: Hubert Van De Walle <huvw@odoo.com>
Observed Behaviour
When assigning someone to a task (in project), the employee
will receive a link be email. If he opens this link in a
browser where he isn't already logged, he will be redirected
to the logging page and, after have successfully logged in,
he will be redirected to the Odoo mail module
Expected Behaviour
After a successful loggin, the user should be redirected to
the task view
Reproducibility
This issue can be reproduced with the following steps:
1. Connect as Mitchell Admin
2. Go to the project module
3. Create a new task and assign it to Marc Demo
4. Go to Mark Demo's email and open the related mail
5. Open the link in the mail in an incognito window
6. Log in as Marc Demo
Fix Description
The issue is coming from the fact that, when no user is
logged in and if the url isn't public, we redirect the
url to the connection page without ensuring we have the
correct redirection after the loggin. This is fixed by
editing the url to web/login?redirect= + target url
Related Issues/PR
opw-2802439
closesodoo/odoo#93091
X-original-commit: 0b9d49f33713fc2d5a76f25523f2d4bb5ddb3b44
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Access `/web/image/82303?height=16`, traceback because the placeholder
image cannot be resized to `"16"`.
closesodoo/odoo#92891
Signed-off-by: Julien Castiaux <juc@odoo.com>
Purpose: Before it was hard to view expense attachments from sheet record.
To do so, the user should have gone through clicking on each expense first and
checking attachments, or could have clicked on a attachments smart button on embedded
expense table, which is redirecting to another view that only displays attachments for the one expense only.
Thus, checking all the attachments from sheet was an tedious task.
After this commit, the user can see in the sheet attachment preview all the associated expenses' attachments.
To make it possible, we ovveride 'mail.thread' method that is called to
fetch the data for the chatter. In the override, we fetch extra, associated expenses' attachments.
task - 2320177
closesodoo/odoo#92724
Signed-off-by: Kevin Baptiste <kba@odoo.com>
Rationnals
----------
Web servers can serve some resources (e.g. static files) right away
without any interaction with the web application. The network model of
most web servers makes them capable of handling thousands of
simultaneous requests when it comes to intensive IO operations such as
streaming data from a file. The network model of Odoo is different: it
is capable of a lot of processing power but can only serve a handful of
requests at a time, i.e. Odoo (with some help from postgres) is
optimized for CPU operations, not IO.
Some users don't configure their web server, they use a basic
configuration that relay all requests to Odoo. The result is that many
Odoo HTTP Workers can be busy streaming static files instead of
processing other requests. This can lead to a worker starvation, i.e.
all workers are busy streaming files and cannot process new requests.
X-Sendfile
----------
In this work, we add the support for the [X-Sendfile] header family,
they are multiples http headers that can be used by the web application
to communicate with the web server in order to delegate the delivery of
files stored on the file system. Odoo still receives the request but it
does no more stream the file content from within its HTTP worker,
instead it skips the response body altogether and sets the `X-Sendfile`
special header with the path of the file on the filesystem. The web
server intercepts that special header, open the file and stream it.
Using those headers, we can use the best of both the web application and
the web server. The web application is still responsible to locate the
resource and verify the access rights, the web server is still
responsible of streaming the content.
Using X-Sendfile is opt-in via the `--x-sendfile` CLI flag. We set both
`X-Sendfile` (apache) and `X-Accel-Redirect` (nginx). If you are using
apache, make sure `mod_xsendfile` is enabled. If you are using NGINX
you have to add the following location block:
location /web/filestore { # custom path, hardcoded within Odoo
# Prevent access from the outside world, i.e. makes this
# route only accessible via X-Accel. MANDATORY!!!
internal;
# Give access to the filestore using this server's
# permissions. Odoo is in charge of verifying the access
# rights.
alias /path/to/odoo/data-dir/filestore;
}
The Odoo [deployment documentation] has been updated accordingly.
[X-Sendfile]: https://www.nginx.com/resources/wiki/start/topics/examples/xsendfile/
[deployment documentation]: https://www.odoo.com/documentation/master/administration/install/deploy.html#serving-static-files-and-attachments
Changes to the API
------------------
To benefit most from X-Sendfile, all APIs related to streaming content
over HTTP has to be adapted. They are: (1) `request._serve_static`,
(2) `ir.http._serve_fallback`, (3) `/web/content` and (4) `/web/image`.
Each used it own way to deliver content: (1) `_serve_static` was using
`send_file` (flask's send_file that as been vendored with odoo 10
years ago and not maintenained since then), (2) _serve_fallback was
handcrafting a `werkzeug.wrappers.Response`, (3) /web/content-image were
using the "binary server" `ir.http.binary_content` API.
I has been decided to remove all 3 APIs and to merge the code inside of
the new `http.Stream` object and the `ir.binary` helper model.
A Stream wraps what is going to be sent to the browser, it can be a path
to a file on the locale filesystem, a blob of raw data or an URL to an
external resource. The Stream also holds various metadata that are
mainly used for caching. The preferred way to create a Stream is via one
of its three factories so that all the metadata are set. The factories
are: `from_path`, `from_attachment` and `from_binary_field`. A stream
instance exposes a single method `get_response()` used to create the
corresponding HTTP response object out of the stream.
Inside of `ir.http` were a few methods that were not related to the http
routing and formed what was called the "binary server". All those
methods have been removed and the feature have been refactored inside of
the new `ir.binary` model. The removed methods are:
- `_xmlid_to_obj`
- `_get_record_and_check`
- `_binary_ir_attachment_redirect_content`
- `_binary_record_content`
- `_binary_set_headers`
- `binary_content`
- `_response_by_status`
- `_get_content_common`
- `_content_image`
- `_content_image_get_response`
- `_placeholder_image_get_response`
The new `ir.binary` abstract model exposes the following utilities:
**`_find_record`**
Find an attachment or a record with a binary-field out of an xmlid or
out of a pair record-model/record-id. Check the access rights and the
access token.
**`_get_stream_from`**
Create a Stream from an attachment or a record with a binary-field.
**`_get_image_stream_from`**
Same as `_get_stream_from` but adapted for images. It sets a sensible
ETag on the stream and has image resizing support.
**`_placeholder`**
Get the image placeholder blob.
Testing
-------
It is possible to test the web server configuration using the
`test_http` module. Install the module then run the unittest using the
`webserver` test-tag. By default it attempts to connect to a web-server
running on `http://localhost:80`, you can change this URL by setting the
`WEB_SERVER_URL` environment variable.
odoo-bin -i test_http --stop-after-init
WEB_SERVER_URL='http://localhost:80' odoo-bin --test-tags webserver --stop-after-init
closesodoo/odoo#88134
Task: 2801675
Related: odoo/documentation#2083
Related: odoo/enterprise#26191
Signed-off-by: Julien Castiaux <juc@odoo.com>