Commit Graph
259 Commits
Author SHA1 Message Date
Alexandre Kühn 11b4355a7b [FIX] mail: several discuss improvements (following MILK redesign)
closes odoo/odoo#121948

Forward-port-of: #121683
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2023-05-22 16:30:12 +02:00
Denis Ledoux 58ea5e7b43 [IMP] http.py: do not inject context by default in JSON routes
Before this revision, when you pass `context` in the arguments
of a JSON routes, this one gets automatically injected
in the environment context.

This is not the case for regular HTTP routes.

It makes sense to propagate the context for the JSONRPC protocol,
JSON routes used by the backend, such as `call_kw`,
but it doesn't make sense to pass this context automatically
for any other kind of routes, such as front-end routes
or routes used by custom Javascript widgets.

This change brings a more unified behavior for routes
of types HTTP and JSON.
In addition, most developers were not aware of this "feautre",
that passing `context` in the arguments of a JSON route leaded
to the injection of this context in the environment context.
This is actually reflected by the diff size this changes required,
only a dozens of routes needed to be adapted, to manually
add the context in their route arguments and to inject it
in their environment context.

closes odoo/odoo#121726

X-original-commit: a7a5655631e6d5b05fd2ba3d0c80617aae6d9cfe
Related: odoo/enterprise#41229
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
2023-05-22 11:43:04 +02:00
Zelong Lin ff122ac7ae [IMP] mail: avatar edit in channel and group
1. Display avatar in top bar next to channel name and description.
2. Edit icon appears on hover.
3. Clicking on the Edit icon opens file browser to upload a new avatar.
4. Certain file types are allowed.
5. Avatar can only be changed for group chat by any member of the channel.
6. For channel it can be done with admin rights.
7. Disable uploading text from file uploader in this case.

Also show avatar of channel/chat conversation in chat window.
Author avatar in message list no longer shown im status.
Chat window header color matches new systray color.

task-2684679

[FIX] mail: make chat window header match systray color

Part-of: odoo/odoo#117357
2023-05-16 14:42:05 +02:00
Pierre-Yves Dufays 3e57dc295c [IMP] mail, portal, website_slides, mass_mailing: unfollow record from email
Allow partner to unfollow a document from a follow up email of that document
through an unsubscribe URL in the email even if not connected.

It works for internal user for follow up on any document and for any partner on
follow up of document tagged as authorizing being unfollowed by any partner (
slide.channel and slide.slide).

Technical note:
The unfollow block is rendered in mail_thread and updated for each recipient in
mail_mail. We don't render it in mail_mail because we don't have the language
of the message at that point.

Depending on the partner and the related document, the unfollow block is:
- either removed if the user cannot unfollow the document (for example if it
doesn't follow it)
- or updated with partner and document information + a security token

Task-3061864

Part-of: odoo/odoo#107978
2023-05-10 13:21:07 +02:00
Pierre-Yves Dufays b3d9fbd3d5 [IMP] mail: allows unfollowing record from inbox
Allow users to unfollow easily document from the inbox for which he/she doesn't
want to be notified anymore.

When hovering on a follow up message with a related document followed by the
user, the interface displays an action to unfollow it that allows the user to
remove himself/herself as follower of the document. As a result of performing
that action a toast is displayed as a feedback.

Technical note:
The unfollow link is displayed on a message.canUnfollow is true which check
that the thread related to the message is followed by the user.

In order to know if the user follows the record related to the message, we now
transmit with each message the id of the follower table that link the user to
the related record if it follows it. This allows to insert the follower on
client side so that the unfollow action can use the standard mechaism already
developed to unfollow a record.

Unfortunately, that information coudn't be added in the already public method
message_format of mail message because that method is not always called on the
user retreiving the message but also by the one posting message. We didn't want
also to include all followers in the formated message so we rely on additional
method that add that information per partner.

To support unfollowing a document in the inbox no matter the current company,
we have modified message_unsubscribe in mail_thread to allow internal user to
unsubscribe themself without checking any rights. Indeed, some document have
record rule that prevents reading it if the user is not in the right company
(ex. crm.lead) and then was preventing the user to unfollow the document using
that method.

Task-3061864

Part-of: odoo/odoo#107978
2023-05-10 13:21:06 +02:00
Maryam Kia ec93077b8d [IMP] mail: Edited label on edited message
By this commit, If a user edits the message body or changes
the message attachments, the edited label in the blob,
shows the last edit Info.

Task-2664848

closes odoo/odoo#117896

Related: odoo/enterprise#40208
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2023-05-04 14:03:42 +02:00
Maryam Kia cd6f3e6373 [FIX] mail: sudo on message in link preview controller
closes odoo/odoo#120116

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-04-28 17:23:03 +02:00
Sébastien Theys 09ac15e2dd [REF] mail: clean code for message update
As a bonus, add cross-tab update for current user in chatter.

Part of task-3265211

closes odoo/odoo#120018

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-04-28 12:26:43 +02:00
Sébastien Theys 3d1a21dc18 [REF] mail: move channel of message post controller to discuss
Part of task-3265211

closes odoo/odoo#120002

Signed-off-by: Louis Wicket (wil) <wil@odoo.com>
2023-04-27 18:25:33 +02:00
Didier (did) 19abfc1f66 [IMP] mail: update link previews when editing a message
Before this PR, link previews where not updated when a user was editing a
message.
This clear the current link previews and reprocess the updated message.

closes odoo/odoo#119917

Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2023-04-27 18:25:13 +02:00
Sébastien Theys c1a3ad8e01 [REF] mail: move channel specific code of reaction to discuss
The opportunity is taken to clean the methods to make the override
actually possible.

Part of task-3265211

closes odoo/odoo#119942

Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2023-04-27 17:21:53 +02:00
Sébastien Theys ad58e0fdd8 [REF] mail: move discuss.channel code to its own folder (controllers)
This commit focuses on removing all references to discuss.channel from
controllers of mail module.

In preparation of splitting discuss and mail modules.

Part of task-3265211

closes odoo/odoo#119523

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-04-27 06:10:02 +02:00
Sébastien Theys b1772094b1 [REF] mail: move discuss.channel code to its own folder (models)
This commit focuses on removing all references to discuss.channel from
code located in /models of mail module.

In preparation of splitting discuss and mail modules.

Part of task-3265211

closes odoo/odoo#119413

Signed-off-by: Debondt Didier (did) <did@odoo.com>
2023-04-26 19:49:08 +02:00
Sébastien Theys 694d501a35 [REF] mail, im_livechat: move /mail/chat_post to im_livechat
It is only used there.

In preparation of splitting discuss and mail modules.

Part of task-3265211

closes odoo/odoo#119306

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-04-24 18:25:59 +02:00
Sébastien Theys bcce4be8e9 [REF] mail, im_livechat: move /mail/chat_history to im_livechat
It is only used there.

In preparation of splitting discuss and mail modules.

Part of task-3265211

closes odoo/odoo#119302

Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2023-04-22 05:51:59 +02:00
Sébastien Theys a1fcb6ffe6 [REM] mail: remove unused _default_request_uid
closes odoo/odoo#119301

Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2023-04-22 05:51:56 +02:00
Sébastien Theys 75bda9a79c [IMP] mail, bus: move "admin" password warning into bus notification
Remove complex dependency on discuss.channel for this simple warning.

closes odoo/odoo#119252

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-04-21 23:46:19 +02:00
Sébastien Theys 90cb44e1e1 [REF] mail, *: rename mail.channel to discuss.channel
* = bus, calendar, crm_livechat, hr, hr_holidays, im_livechat, mail_bot,
    mass_mailing, privacy_lookup, test_discuss_full, test_mail,
    test_mail_full, website_crm_livechat, website_livechat, base

In preparation of splitting discuss and mail modules.

Part of task-3265211

closes odoo/odoo#118354

Related: odoo/upgrade#4553
Related: odoo/enterprise#39661
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-04-21 02:21:53 +02:00
Martin Trigaux 69f911d994 [IMP] *: enforce usage of Markup in mail
When using message_post, the body format must be explicitly specified.
If html is expected, a Markup object should be used.
If text is given, the content will be escaped.

Before this PR:
message_post was unaware if the content of a message was HTML or
text. This lead to multiple situation where the content was
incorrectly considered as HTML and led to display errors.
In
  self.message_post(body="Hello %s!" % self.name)
if the name contained HTML, it would be evaluated.

In
  self.message_post(body="Contact Raoul <raoul@caramail.be>")
the email would not be displayed as considered as unknown HTML and
discarded by the sanitizer

Now each call must explict the type of content.
Use the escape() helper to properly combine Markup and translations.
It would also be acceptable to use Markup() to wrap a static
translation but escape is better as one can not guarantee the content
of a translation.

closes odoo/odoo#111850

Related: odoo/documentation#3612
Related: odoo/enterprise#36728
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2023-04-13 16:39:48 +02:00
tsm-odoo 1c1604466f [IMP] mail, im_livechat: add pin messages feature to channels
With this commit, messages can be pinned on a channel and
chat conversation. There's a new menu listing all pinned
messages on a conversation, and we can jump to these messages
in the current conversation.

As this feature incentives to see older messages, this commit
also adds a "Jump to Present" button when looking at old messages.

closes odoo/odoo#116666

Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2023-04-13 04:08:11 +02:00
Alexandre Kühn fc9d46f3b9 [REF] mail: clean message fetch code
Adapt code of message fetch so that fetching of
(needaction) messages are controlled in a way to
keep continuous sequence of messages at all time.

This code design solves the "holes" problem in a message
list by not allowing holes. This fixes many scenario that
generated these holes, resulting in unfetchable messages.

Example of such a scenario:
- post 40 messages
- post a new message that is reply of the oldest message
- page reload and scroll up until load more
=> 10 messages are missing in-between replied message and
 following message (that should have been 11 messages apart)

This code also prepares for allowing jumps in a conversation.

Part-of: odoo/odoo#116666
2023-04-13 04:08:11 +02:00
tsm-odoo b34d0fd7c9 [FIX] mail: fix temporary_id not supported as message_post parameter
Since [1], the `temporary_id` of a message is passed to the
`message_post` route in order to renconciliate the temporary
message on the client side and the real message created by the
server.

This led to crashes when sending message on the chatter because
this parameter was not allowed as a `_notify_thread` parameter.

Since this parameter is highly specific and isn't linked to any
business/model code, this parameter is now passed via the context
thus solving this issue.

[1]: https://github.com/odoo/odoo/pull/116085

closes odoo/odoo#116333

Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2023-03-24 07:45:01 +01:00
tsm-odoo 55f06fd5aa [IMP] mail: no new message separator when posting a message
This commit removes the "new message" separator when posting a
message on a channel.

At the same time, this commit solves an issue that caused messages
to flicker when the message came from the bus before the answer of
the rpc.

In order to do so:
-  messages are marked as read immediately after
`message_post` for the member of user that posted it.
- a temporary id is passed to `message_post` in order
to reconcialiate temporary/server messages.

task-3232911

closes odoo/odoo#116085

Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2023-03-22 14:52:13 +01:00
tsm-odoo 14b0da3d0a [IMP] mail: mark message as unread
task-3232911

Part-of: odoo/odoo#116085
2023-03-22 14:52:13 +01:00
Rahul Prajapati 4d71ae5a13 [FIX] mail: portal users can not join rtc calls
Before this commit:

Portal users are not able to join RTC Calls in Discuss.

After this commit:

Portal users are able to join RTC Calls.

Task-3050534

closes odoo/odoo#115963

X-original-commit: 0bfd2625fb89b93494c9df1aad9b7390723f1aa7
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2023-03-21 12:38:53 +01:00
7710c3331e [REF] mail, *: refactor Discuss
This commit refactors discuss code to use OWL components
and new tools and services in web/.
Functionally, Discuss app should work relatively the same as
before this commit.

closes https://github.com/odoo/odoo/pull/110188

Related:
https://github.com/odoo/enterprise/pull/38058
https://github.com/odoo/upgrade/pull/4423

closes odoo/odoo#110188

Related: odoo/upgrade#4423
Related: odoo/enterprise#38058
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Co-authored-by: Alexandre (aku) <aku@odoo.com>
Co-authored-by: Didier (did) <did@odoo.com>
Co-authored-by: Géry (ged) <ged@odoo.com>
Co-authored-by: Louis (wil) <wil@odoo.com>
Co-authored-by: Maël (mapa) <mapa@odoo.com>
Co-authored-by: Maryam (maki) <maki@odoo.com>
Co-authored-by: Sébastien (seb) <seb@odoo.com>
Co-authored-by: Thanh (tso) <tso@odoo.com>
Co-authored-by: Matthieu (tsm) <tsm@odoo.com>
Co-authored-by: Zelong (zel) <zel@odoo.com>
2023-03-17 11:47:09 +01:00
Rahul Prajapati d8a18a9d16 [FIX] mail: channel partner avatar response for public user
This issue was caught in Sentry.
The return type of the partner avatar for public users is `odoo.http.Stream`,
but the `route_wrapper` expects it to be `Response streamed`.

sentry-3929988311

closes odoo/odoo#114933

X-original-commit: 62ddfe0badf54375bc458bdb50cbcdbe4da5bbcd
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-03-10 14:38:59 +01:00
Thibault Delavallée c088d5423e [IMP] mail: cleanup _notify_get_recipients code bits
This commit contains mainly code cleaning, docstrings and a small split
for notification tool methods. In this commit we

  * make some notification groups variable explicit;
  * move the filler of groups into its own submethod to ease being called
    from other code (to be used soon);
  * fix some strange overrides or code manipulation;
  * propagate some additional parameters to ease future commits that will
    improve rendering of groups-based notification emails;
  * cleanup, fixup and improve docstrings;

This does not change anything from functional point of view, just preparing
further work.

Task-3046371 (Mail: Better Language Support in Composer)

Part-of: odoo/odoo#106177
2023-03-09 15:54:12 +01:00
Sébastien Theys 94845bb63f [FIX] mail: allow non-internal users to create chat from token
Follow up of https://github.com/odoo/odoo/pull/90415
After removing the public field, the equivalent access is to set the
allowed group to empty.

closes odoo/odoo#114729

X-original-commit: fcafd602dda4f896ac8b91c81c00ee723afd6634
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-03-09 12:00:56 +01:00
Julien Castiaux 3d1f486bcc [IMP] *: update modules to use the new geoip API
request.geoip is no more a dictionnary cached in the session. It is now
a full blown object with lazy and smart geolocalisation capabilities.

Among other things, the previous dictionnary API is now deprecated. The
changes are:

* `request.geoip['country_name']` -> `request.geoip.country_name`
* `request.geoip['country_code']` -> `request.geoip.country_code`
* `request.geoip['city']` -> `request.geoip.city.name`
* `request.geoip['latitude']` -> `request.geoip.location.latitude`
* `request.geoip['longitude']` -> `request.geoip.location.longitude`
* `request.geoip['region']` -> `(request.geoip.subdivisions[0].iso_code if request.geoip.subdivisions else None)`
* `request.geoip['time_zone']` -> `request.geoip.location.time_zone`

It is safe to access all the attributes. Doing `request.geoip.city.name`
when the geolocalization failed (missing db, invalid address, ...)
evaluates to None. It does not raise an AttributeError.

Task: 2848206
Part-of: odoo/odoo#91337
2023-01-03 13:16:02 +01:00
Thibault Delavallée 29c0b49fd1 [FIX] mail: be defensive when trying to parse res_id from redirect controller
When having falsy values, we may end up with 'False' as a string. Better be
defensive when trying to parse res_id.

Task-3025143

closes odoo/odoo#102576

closes odoo/odoo#103378

X-original-commit: ac8d97262d196c7bb4c4fc15db63cc66512be838
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-10-18 13:17:31 +02:00
tsm-odoo 5471bd4cb8 [IMP] mail: remove im status route
*: bus, hr_holidays.

The `/bus/im_status` route polls the server every minute in order for
the user im_status to be up to date. This commit removes this poll
by sending the im_status on the bus when updating the current user
presence.

Moreover, before [1], the user bus presence was updated on each poll.
When the user didn't poll for 50 seconds, we assumed the user was
disconnected. Since [1], the bus presence is updated each 30 seconds
by the `im_status` service. This is too frequent: there is no need
to update the user presence so often.

In order not to overhelm the server with unnecessary requests, the update
presence interval as well as the delay to be considered disconnected
have been updated: the former from 30 to 60 seconds, the later from
55 to 65 seconds (assuming that a user that has missed an update
presence tick is disconnected).

[1]: odoo/odoo@a5623d2

closes odoo/odoo#100249

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-09-20 11:33:51 +02:00
Zelong Lin d57c64f95b [IMP] mail, *: remove 'public' field in channel
*: im_livechat, website_livechat

Access right should be based on channel type and membership instead.
Chat always private, group always private, channel private should
disapear and be a group instead (migration needed), and other channel
always public (but they can still be further restricted with
the "allowed groups" feature)

task-2632861

closes odoo/odoo#90415

Related: odoo/enterprise#30980
Related: odoo/upgrade#3850
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-09-06 10:57:59 +02:00
Didier (did) 7ceb079455 [IMP] mail: implement link preview with OpenGraph Protocol
OpenGraph Protocol https://ogp.me/ allow us to get some data from the link that
are shared in message.

task-2365881

closes odoo/odoo#82641

Related: odoo/enterprise#30867
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-09-05 14:49:30 +02:00
Sébastien Theys 545d23888b [IMP] mail, im_livechat, *: add typing for guest and clean code
* = bus, hr_holidays, test_discuss_full

- use channel member instead of partner for typing
- use channel member instead of partner for all other return values from server
- remove temporary partner hack in livechat and keep public partner
- remove some obsolete convert data
- adapt format methods accordingly

task-2664853

closes odoo/odoo#98923

Related: odoo/enterprise#30760
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2022-09-01 20:21:58 +02:00
std-odooandThibault Delavallée eb75a77646 [REF] mail: update the message content in the mail thread model
Purpose
=======

Move the code which updates the mail message from the message model to mail
thread. Most other thread methods (like `_message_update_content_after_hook`)
are defined at record model level. It makes sense to delegate the update to
documents and not to the message. Message is a low-level technical object
that should not really hold business code.

While modifying this code, an update is done in the update content. We now
also allow to update the body without removing all attachments.

Finally tests are added as this feature was added without really testing
model code.

Task-2207626 (Rating: Delay rating notification to ease feedback)

Part-of: odoo/odoo#95623
Co-authored-by: Thibault Delavallée <tde@odoo.com>
2022-08-25 19:57:16 +02:00
tsm-odoo de6de48deb [IMP] bus, *: adapt server to use websocket instead of longpolling
*: hr_presence, web_editor.

This commit is part of the websocket integration in Odoo.
It focuses on adapting the bus to support websockets:
   - last notification id is now kept on the server
   - channel list is built by overriding the `_build_bus_channel_list`
     method of the `ir_websocket` model instead of overriding the `_poll`
     method of the bus controller.
   - The bus presence was updated during polls, since there is no more poll,
     bus presence update will be the responsability of the client.
   - The `/websocket/peek_notifications`, `/websocket/update_bus_presence`
     routes will be available so that odoo sh can access notifications/update presence
      from http requests.
   - /longpolling routes are now prefixed with /bus thus won't be redirected to the
     gevent worker anymore except for `/longpolling/health` which is the
     health check route of the gevent server.

Since websocket now handle incoming messages, a way to manage authentication
have been introduced :
    - The session is retrieved from the HTTP handshake.
    - When a websocket message comes/leaves the session is retrieved
      on the file system so that we're sure it still exists and that
      it is up to date.
    - The session is checked
    - If no session is found on the file system or `check_session`
      fails, the websocket connection is closed with the `SESSION_EXPIRED`
      close code (which is a custom close code: 4001).
    - Note that websocket connections are closed every `KEEP_ALIVE_TIMEOUT`
      seconds to ensure no websocket connection will stay open if the user
      clears its cookies.
    - Note that a wsrequest object is available when processing incoming
      messages. It is similar to the http request and contains various
      useful informations (session, env, ...).

Part-of: odoo/odoo#75510
2022-08-23 17:55:10 +02:00
Sébastien Theys 34d775e873 [IMP] mail, *: remove explicit usage of insert-and-replace
* = calendar, im_livechat, rating, snailmail, test_discuss_full, test_mail,
    website_livechat

Distinction between "replace" and "insert-and-replace" can be guessed based on
the type of the provided data.

task-2957295

closes odoo/odoo#98404

Related: odoo/enterprise#30580
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2022-08-19 11:53:05 +02:00
Louis Wicket (wil) 8537944b4b [IMP] mail: rewrite MessageReactionGroup/message to not use compute
closes odoo/odoo#98344

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-08-18 13:46:51 +02:00
tsm-odoo 75007b578e [MOV] bus, *: move startServer test helper to the bus module
*: calendar, hr, hr_holidays, im_livechat, note, rating, snailmail,
test_mail, test_mail_full, website_livechat, website_slides.

Part-of: odoo/odoo#97771
2022-08-10 14:43:41 +02:00
Didier (did) 633f58f8a4 [IMP] mail: im_status for guests
task-2883466

closes odoo/odoo#97076

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-08-08 21:02:21 +02:00
Sébastien Theys 13245211a1 [IMP] mail: move mark_all_as_read into message_fetch
This removes an extra request, targets fetched messages more reliably and
simplifies the code.

task-2847909

closes odoo/odoo#96840

Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2022-07-28 03:51:33 +02:00
Louis Wicket (wil) fdcaa53ca0 [IMP] mail, *: rename mail.channel.partner to mail.channel.member
* = calendar, crm_livechat, hr_holidays, im_livechat, privacy_lookup,
privacy_lookup, test_discuss_full, test_mail_full, website_livechat

closes odoo/odoo#95912

Related: odoo/upgrade#3681
Related: odoo/enterprise#29433
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-07-19 11:50:37 +02:00
Thanh Dodeur fcc6a008da [REF] mail, *: make rtc invitations use the new ChannelMember model
* test_discuss_full

channel invitation to rtc calls are now using the `ChannelMember` and
`mail.channel.partner` models instead of the `partner` and `guest`
models.

part of task-2692836

closes odoo/odoo#95898

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-07-15 14:21:50 +02:00
Hubert Van de Walle (huvw) 5212b01cfd [FIX] mail: permission error when editing a mail.message
Steps to follow:

  On a runbot,
  - Login as Mitchell Admin
  - Set the Administration permission of Marc Demo to Access Rights
  - Login as Mark Demo
  - Go to the Discuss App
  - Edit a message from someone else by clicking on the pencil
  -> A Traceback occurs

Cause of the issue:

  - The pencil button is only displayed for another user if the logged in user
    is admin. This is done by checking if the user is superUser or if he
    has the group `base.group_erp_manager`
    This is the case here
  - When editing the message, the `base.group_system` is checked.
    In this case, it is not present.

Solution:

  Check the `base.group_erp_manager` in both cases

opw-2892740

closes odoo/odoo#95502

X-original-commit: bd8ed439d1d9342b24926eee332e8c26c6f0cd7c
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Signed-off-by: Hubert Van De Walle <huvw@odoo.com>
2022-07-07 14:44:37 +02:00
Sébastien Theys 0c30945d36 [IMP] mail, *: clean up attachment format and isolate legacy calls
* = im_livechat, portal, portal_rating, test_mail

Part of task-2886642

Part-of: odoo/odoo#93895
2022-06-20 18:56:18 +02:00
anhe-odoo 3017392f91 [FIX] mail: fix url redirection in case of non-logged user
Observed Behaviour

When assigning someone to a task (in project), the employee
will receive a link be email. If he opens this link in a
browser where he isn't already logged, he will be redirected
to the logging page and, after have successfully logged in,
he will be redirected to the Odoo mail module

Expected Behaviour

After a successful loggin, the user should be redirected to
the task view

Reproducibility

This issue can be reproduced with the following steps:
1. Connect as Mitchell Admin
2. Go to the project module
3. Create a new task and assign it to Marc Demo
4. Go to Mark Demo's email and open the related mail
5. Open the link in the mail in an incognito window
6. Log in as Marc Demo

Fix Description

The issue is coming from the fact that, when no user is
logged in and if the url isn't public, we redirect the
url to the connection page without ensuring we have the
correct redirection after the loggin. This is fixed by
editing the url to web/login?redirect= + target url

Related Issues/PR

opw-2802439

closes odoo/odoo#93091

X-original-commit: 0b9d49f33713fc2d5a76f25523f2d4bb5ddb3b44
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-06-08 15:46:12 +02:00
Julien Castiaux fc115ebdf7 [FIX] web: invalid image placeholder resizing
Access `/web/image/82303?height=16`, traceback because the placeholder
image cannot be resized to `"16"`.

closes odoo/odoo#92891

Signed-off-by: Julien Castiaux <juc@odoo.com>
2022-06-03 18:34:49 +02:00
sofiagvaladze cef01fa521 [IMP] mail, hr_expense: show expense attachments on sheet
Purpose: Before it was hard to view expense attachments from sheet record.
To do so, the user should have gone through clicking on each expense first and
checking attachments, or could have clicked on a attachments smart button on embedded
expense table, which is redirecting to another view that only displays attachments for the one expense only.
Thus, checking all the attachments from sheet was an tedious task.

After this commit, the user can see in the sheet attachment preview all the associated expenses' attachments.

To make it possible, we ovveride 'mail.thread' method that is called to
fetch the data for the chatter. In the override, we fetch extra, associated expenses' attachments.

task - 2320177

closes odoo/odoo#92724

Signed-off-by: Kevin Baptiste <kba@odoo.com>
2022-06-02 16:54:22 +02:00
Julien Castiaux da8def8e41 [IMP] core, web: Delegate delivery of static files
Rationnals
----------

Web servers can serve some resources (e.g. static files) right away
without any interaction with the web application. The network model of
most web servers makes them capable of handling thousands of
simultaneous requests when it comes to intensive IO operations such as
streaming data from a file. The network model of Odoo is different: it
is capable of a lot of processing power but can only serve a handful of
requests at a time, i.e. Odoo (with some help from postgres) is
optimized for CPU operations, not IO.

Some users don't configure their web server, they use a basic
configuration that relay all requests to Odoo. The result is that many
Odoo HTTP Workers can be busy streaming static files instead of
processing other requests. This can lead to a worker starvation, i.e.
all workers are busy streaming files and cannot process new requests.

X-Sendfile
----------

In this work, we add the support for the [X-Sendfile] header family,
they are multiples http headers that can be used by the web application
to communicate with the web server in order to delegate the delivery of
files stored on the file system. Odoo still receives the request but it
does no more stream the file content from within its HTTP worker,
instead it skips the response body altogether and sets the `X-Sendfile`
special header with the path of the file on the filesystem. The web
server intercepts that special header, open the file and stream it.

Using those headers, we can use the best of both the web application and
the web server. The web application is still responsible to locate the
resource and verify the access rights, the web server is still
responsible of streaming the content.

Using X-Sendfile is opt-in via the `--x-sendfile` CLI flag. We set both
`X-Sendfile` (apache) and `X-Accel-Redirect` (nginx). If you are using
apache, make sure `mod_xsendfile` is enabled. If you are using NGINX
you have to add the following location block:

    location /web/filestore {  # custom path, hardcoded within Odoo
        # Prevent access from the outside world, i.e. makes this
        # route only accessible via X-Accel. MANDATORY!!!
        internal;

        # Give access to the filestore using this server's
        # permissions. Odoo is in charge of verifying the access
        # rights.
        alias /path/to/odoo/data-dir/filestore;
    }

The Odoo [deployment documentation] has been updated accordingly.

[X-Sendfile]: https://www.nginx.com/resources/wiki/start/topics/examples/xsendfile/
[deployment documentation]: https://www.odoo.com/documentation/master/administration/install/deploy.html#serving-static-files-and-attachments

Changes to the API
------------------

To benefit most from X-Sendfile, all APIs related to streaming content
over HTTP has to be adapted. They are: (1) `request._serve_static`,
(2) `ir.http._serve_fallback`, (3) `/web/content` and (4) `/web/image`.

Each used it own way to deliver content: (1) `_serve_static` was using
`send_file` (flask's send_file that as been vendored with odoo 10
years ago and not maintenained since then), (2) _serve_fallback was
handcrafting a `werkzeug.wrappers.Response`, (3) /web/content-image were
using the "binary server" `ir.http.binary_content` API.

I has been decided to remove all 3 APIs and to merge the code inside of
the new `http.Stream` object and the `ir.binary` helper model.

A Stream wraps what is going to be sent to the browser, it can be a path
to a file on the locale filesystem, a blob of raw data or an URL to an
external resource. The Stream also holds various metadata that are
mainly used for caching. The preferred way to create a Stream is via one
of its three factories so that all the metadata are set. The factories
are: `from_path`, `from_attachment` and `from_binary_field`. A stream
instance exposes a single method `get_response()` used to create the
corresponding HTTP response object out of the stream.

Inside of `ir.http` were a few methods that were not related to the http
routing and formed what was called the "binary server". All those
methods have been removed and the feature have been refactored inside of
the new `ir.binary` model. The removed methods are:

- `_xmlid_to_obj`
- `_get_record_and_check`
- `_binary_ir_attachment_redirect_content`
- `_binary_record_content`
- `_binary_set_headers`
- `binary_content`
- `_response_by_status`
- `_get_content_common`
- `_content_image`
- `_content_image_get_response`
- `_placeholder_image_get_response`

The new `ir.binary` abstract model exposes the following utilities:

**`_find_record`**

Find an attachment or a record with a binary-field out of an xmlid or
out of a pair record-model/record-id. Check the access rights and the
access token.

**`_get_stream_from`**

Create a Stream from an attachment or a record with a binary-field.

**`_get_image_stream_from`**

Same as `_get_stream_from` but adapted for images. It sets a sensible
ETag on the stream and has image resizing support.

**`_placeholder`**

Get the image placeholder blob.

Testing
-------

It is possible to test the web server configuration using the
`test_http` module. Install the module then run the unittest using the
`webserver` test-tag. By default it attempts to connect to a web-server
running on `http://localhost:80`, you can change this URL by setting the
`WEB_SERVER_URL` environment variable.

    odoo-bin -i test_http --stop-after-init
    WEB_SERVER_URL='http://localhost:80' odoo-bin --test-tags webserver --stop-after-init

closes odoo/odoo#88134

Task: 2801675
Related: odoo/documentation#2083
Related: odoo/enterprise#26191
Signed-off-by: Julien Castiaux <juc@odoo.com>
2022-06-01 02:53:59 +02:00