Commit Graph
958 Commits
Author SHA1 Message Date
Nicolas Martinelli eaff0a71bd [FIX] web: export field with '/'
- Activate lots and SN
- Go to Inventory > Inventory Adjustments
- Export a record
- Select the field 'Inventories > Lot/Serial Number'

The `name_get` of the field is exported, not its XMLID.

This is because the parsing made in order to limit the depth of export
is made on the label, not on the field name.

Actually, it is not clear WHY this limitation exists, but we keep it for
compatibility purpose.

opw-1877092
2018-09-04 11:40:19 +02:00
Christophe Simonis 5decf4ab3d [FIX] web: clean data_file after restore
The file used for the restoration was not properly removed
2018-06-18 19:35:42 +02:00
gmarcon baf6b29d45 [FIX] web: build xls file with maximum size
An MS Excel file can have maximum 32767 characters

Fixes #25653 
Closes #25700 

https://support.office.com/en-us/article/excel-specifications-and-limits-1672b34d-7043-467e-8e27-269d656771c3
2018-07-10 16:25:04 +02:00
len-odoo 8194e2cb80 [FIX] web: correctly handle admin svg images in channel
When posting an svg image, Odoo tries to resize it for thumbnailing
(like any image).
However this is of no interest since this is a vectorial file format, and
furthermore it distastefully makes the image library Pillow crash, since it only
supports raster formats.
The result would be a broken thumbnail instead of the image itself.

By not setting the thumbnail size if the mimetype contains svg,
we ignore the thumbnailing altogether.

Note that this only applies to the admin user, as otherwise the file is
treated as binary and thus no thumbnailing occurs anyway.

opw 1841153
2018-05-18 13:33:30 +02:00
Goffin Simon 871387ca9e [FIX] web: Impossible to add an attachment on Safari
Fine tuning of cd6150fe9e

opw:1840373
2018-05-15 09:20:02 +02:00
Christophe Simonis 3ab25b60bc [MERGE] forward port branch saas-15 up to cae950e826 2018-04-23 17:59:59 +02:00
Christophe Simonis 0bf642cb27 [MERGE] forward port branch saas-14 up to 2bc3fd89f2 2018-04-23 14:47:23 +02:00
Christophe Simonis 2bc3fd89f2 [MERGE] forward port branch 10.0 up to 2d12ae3202 2018-04-23 14:39:41 +02:00
Christophe Simonis 2d12ae3202 [MERGE] forward port branch 9.0 up to c9e7433c23 2018-04-23 14:07:12 +02:00
Lucas Perais (lpe) cd6150fe9e [FIX] web: NFD UTF-8 for safari in upload file
Before this commit, when uploading a file as attachment in Safari,
The file icon kept on showing 'downloading' whereas the request was successful

This was because the return from the server had a different UTF-8 norm than Safari

After this commit, it works well

OPW 1836545
closes #24307
2018-04-23 09:00:11 +02:00
Christophe Simonis 16ec176620 [MERGE] forward port branch saas-14 up to 67054b6dcb 2018-04-18 13:49:24 +02:00
Christophe Simonis 67054b6dcb [MERGE] forward port branch 10.0 up to 2f037a13ca 2018-04-18 12:14:53 +02:00
Christophe Simonis 2f037a13ca [MERGE] forward port branch 9.0 up to cf163d19ee 2018-04-18 11:32:27 +02:00
Alexandre Kühn cf163d19ee [FIX] board,web: edit custom views in place
Before this commit, whenever we do an operation on any of these custom views,
such as folding it, the custom view was saved by creating a new one.

This behaviour comes from a lost feature to undo operations on custom views.
Since we do not have this feature anymore, it makes no sense to create new
custom views on save, instead of applying the changes in place.

With this commit, custom views are edited in place.

Fixes #23712
2018-04-17 17:32:27 +02:00
Alexandre Kühn b15e805b5a [FIX] board,web: edit custom views in place
Before this commit, whenever we do an operation on any of these custom views,
such as folding it, the custom view was saved by creating a new one.

This behaviour comes from a lost feature to undo operations on custom views.
Since we do not have this feature anymore, it makes no sense to create new
custom views on save, instead of applying the changes in place.

With this commit, custom views are edited in place.

Fixes #23712
2018-04-17 17:28:49 +02:00
Toufik Benjaa 4787bc7553 [FIX] reports: Remove dead code for non qweb reports 2018-03-22 15:33:18 +01:00
Christophe Simonis 2a9d3812a6 [MERGE] forward port branch saas-15 up to 3fce2b769e 2018-03-22 15:02:58 +01:00
Christophe Simonis 3fce2b769e [MERGE] forward port branch saas-14 up to d8c6e56975 2018-03-22 14:13:59 +01:00
Christophe Simonis f16a6c90d3 [MERGE] forward port branch 10.0 up to 9aa1b7ba12 2018-03-22 11:41:27 +01:00
Toufik Benjaa 9aa1b7ba12 [FIX] web: Access issue for non qweb reports
- With the removal of the password field on the sessions (https://github.com/odoo/odoo/commit/da1f153d61d747d9357694382fe04f96c0ca886a) the non qweb reports going through the route '/web/report' were not able to be generated.
We address this issue by avoiding to call dispatch_rpc and by using the functions to generate the report directly.
This doesn't cause any security issue because the route '/web/report' is callable only by logged in user.
Meaning that the session is already validated.
2018-03-22 11:29:01 +01:00
Christophe Simonis e8f630e44d [MERGE] forward port branch saas-15 up to 7a45296cf1 2018-03-21 18:20:22 +01:00
Christophe Simonis 7a45296cf1 [MERGE] forward port branch saas-14 up to 78dced6bc2 2018-03-21 16:49:15 +01:00
Christophe Simonis 78dced6bc2 [MERGE] forward port branch 10.0 up to c2b3ad1899 2018-03-21 15:55:26 +01:00
Jeremy Kersten c17170b9c1 [FIX] web: all routes should have **kw to support utm/extra params
Without this commit, a valid route /web/content with an extra
params eg utm or adwords will return a 500 with:
TypeError: content_common() got an unexpected keyword argument 'extra_param_name'

This commit closes #21221

Task-32836 should fix for all routes in a future version
2018-03-21 12:20:33 +01:00
Christophe Simonis bd16df15ea [MERGE] forward port branch saas-16 up to 98d01e46e5 2018-02-20 11:53:06 +01:00
Christophe Simonis 98d01e46e5 [MERGE] forward port branch saas-15 up to 482370d014 2018-02-20 11:08:54 +01:00
Christophe Simonis 8b527229bf [MERGE] forward port branch saas-14 up to e3d39b0e5f 2018-02-19 19:01:54 +01:00
Christophe Simonis e3d39b0e5f [MERGE] forward port branch 10.0 up to de62e33618 2018-02-19 17:07:29 +01:00
Xavier Morel a583a56324 [FIX] base, web: don't fold M2M when not in import compatible mode
Before this commit, if the first exported field of an M2M is `id` (the
xid) the entire M2M is folded into a single cell with comma-separated
xids and any following field is ignored. If `id` is any but the first
field, the export behaves normally (with the m2m exported as a "table"
inside the parent record).

This behaviour makes sense for import-compatible exports where the id
is the only thing which can be exported anyway, but it is troublesome
outside of that mode as the behaviour of m2m under export becomes
incoherent/unpredictable (ish) as it depends on the position of the
m2m's `id` in the exports list.

Change it so we only perform folding in import-compatible mode (which
is the default for backwards compatibility with e.g. API calling
export_data directly & the like).

opw-813361

Fixes #22600
2018-02-19 10:43:15 +01:00
Christophe Simonis b42b9c936b [MERGE] forward port branch saas-16 up to 3b7bf3a4b8 2018-01-12 18:15:23 +01:00
Christophe Simonis 3b7bf3a4b8 [MERGE] forward port branch saas-15 up to 8962b8ecc2 2018-01-12 17:23:10 +01:00
Christophe Simonis 8962b8ecc2 [MERGE] forward port branch saas-14 up to d35a76ee17 2018-01-12 16:47:12 +01:00
Christophe Simonis d35a76ee17 [MERGE] forward port branch 10.0 up to d76237e038 2018-01-12 16:16:51 +01:00
Jerther 270b2ebf81 [FIX] service, web: memory error on large DB
Fixes MemoryError when restoring large database archive.

Closes #17663
opw-788273
2018-01-12 10:17:42 +01:00
Denis Ledoux 78d0a32470 [FIX] web: force a determinist installed modules order for the assets
The backend assets includes a list of the installed modules with:
```
odoo._modules = <t t-raw="get_modules_order()"/>;
```

Because of the randomization of Python 3.5 in the dict keys,
the order of the installed modules could change from time to
time, therefore making the assets being regenerated unnecessarily

This revision is a bit linked to the below one:
f3bb9ae679

In addition to have the dict keys always in the same
order, it's important for the values to always be
the same, and it was not the case for this list
which was in the content of the backend assets,
in various order.

opw-804747
2018-01-11 15:48:08 +01:00
Christophe Simonis f02ed9ab9a [MERGE] forward port branch saas-16 up to 0af13af5de 2018-01-02 16:54:38 +01:00
Christophe Simonis 0af13af5de [MERGE] forward port branch saas-15 up to ddd293065e 2018-01-02 15:36:25 +01:00
Christophe Simonis ddd293065e [MERGE] forward port branch saas-14 up to ba2a83ddfa 2018-01-02 15:02:26 +01:00
Christophe Simonis ba2a83ddfa [MERGE] forward port branch 10.0 up to e336dc38ca 2018-01-02 13:56:49 +01:00
Christophe Simonis e336dc38ca [MERGE] forward port branch 9.0 up to 62aa3be24c 2018-01-02 13:20:04 +01:00
Olivier Dony f65f065901 [FIX] web tests: correct wrong route visibility 2017-12-19 10:12:34 +01:00
Xavier Morel b46830858f [FIX] web: excel export of binary fields
* In Python 3 xlwt apparently does not support writing bytes values ->
  try to decode assuming the value may be base64-encoded, this is more
  or less the behaviour for CSV exports.

  This will most likely not allow the export anyway as Excel cells are
  limited to 32k data characters, which accounting for base64
  expansion means ~24k worth of data, but that is a pre-existing
  issue.
* Also removed support for way outdated browsers from
  content_disposition: the Safari case is for Safari 5 (circa 2012)
  but versioning apparently changed since then and modern Safari
  report their "external" version number rather than the webkit
  version number => the current Safari reports version 11, and gets
  routed to the "does not support unicode file names", which is
  further bugged in Python 3 as it %s's bytes, leading to a resulting
  filename of e.g. `b'res.partner.csv'.csv` (with the prefix and
  quotes).
* The IE case is for IE8, which has long been unsupported by the web
  client.
2017-11-27 11:11:48 +01:00
Aaron Bohy 9bc5009481 [FIX] web(_editor): enable mobile tests
This rev. introduces a new test suite meant to test the webclient
components on mobile devices. The key 'config.device.isMobile' is
forced to true in this test suite, so that mobile specific JS files
are properly executed, which isn't the case in the classic JS test
suite (setting isMobile to true in the test definition is too late,
as the JS files are already processed).

For now, this new test suite contains a single test, which was
skipped until this rev. as it couldn't be executed in the classical
JS test suite.

Both suites are executed at each build of the runbot, and they
can be manually executed from the webclient as well (via the debug
manager).
2017-11-10 10:24:42 +01:00
Raphael Collet 446be392ea [FIX] base_import, web: error messages related to data import modules
OPW 777366
2017-10-25 15:44:18 +02:00
Xavier Morel 90d9605c86 [FIX] web: encoding issue with moment locales
I don't quite get how it can trigger on user systems (as it apparently
requires resetlocale() to fail to set up an UTF-8-encoded-locale
somehow, disabling resetlocale() is how I could get the issue
triggered on my system), but anyway it's apparently possible for Odoo
to run with an ASCII system encoding, and it turns out Python 3 will
not use UTF-8 everywhere but will rather use whatever
locale.getpreferredencoding(False) yields, which in theory could be
completely bonkers.

This is an issue when using text IO with an implicit encoding, which
is what load_locale (/web/webclient/locale/<lang>) was doing.

* Fix by using binary IO
* Fix (2) by using direct-passthrough IO with specified encoding, that
  way we let the WSGI server handle the file streaming

Fixes #20075
2017-10-17 16:04:35 +02:00
Olivier Dony b02dea7688 [IMP] config: allow blocking access to db manager
- The `--no-database-list` option will now also block access to database
  management functions and screens.
  Presumably this flag should only be used in production when all
  databases have been provisioned, so the admin should like to block
  access to the db manager at the same time.

- If no `--database` or `-d` parameter is provided, the system will be
  unable to fetch a list of databases at all, so users will be blocked
  with an error message.

- Hide the link on the login screen to the DB manager when it is
  disabled, to prevent sending users to an error page.

- Weak attempt at updating the documentation

Note: the security check for RPC methods could have been done in the RPC
dispatcher, however that would not have protected service methods when
called directly, e.g. by a controller (e.g. the dump method).
2017-10-03 12:46:03 +02:00
Olivier Dony 7d16769263 [IMP] config: support hashed master passwords
- Add support for hashed master passwords (super-admin password) using a
  strong scheme (PBKDF2_SHA512).

- Replace the password with a hash in memory (tools.config map), after
  verifying it

- Automatically replace the plaintext master password with a hash when
  saving it after a password change

- Preserve support for setting/using plaintext passwords when necessary
  (e.g. as a temporary deployment thing)
2017-10-03 12:45:22 +02:00
Jeremy Kersten 1b52b00d2a [IMP] website*: clean sitemap + add method to declare sitemap function.
Don't add useless routes or route that will return 404.
Improve generate function from ModelConverter to have a better management of
query_string.

Now we have an helper sitemap_qs2dom that will analyse the current route and
check if query string is plausible and if yes, generate a domain, when the
query_string don't seems to match the route, we return a Falsy domain.

Before this commit, if qs was /product/ipad, enumerate_page check for each
modelconverter of the route a name ilike '/product/ipad'.

Now we check all routes that contains product and one converter that match ipad
or routes that contains ipad and one converter that match product.

This commit a new way to declare the sitemap for a route.
    def sitemap_xx(env, rule, query_string):
        yield {'loc': '/my_url'}
    @http.route(..., sitemap=sitemap_xx)

    In this case, only the loc returned by this function will be in the sitemap
    for all rules.

    You can pass sitempa=False, if you don't want that route are into the sitemap
2017-09-27 21:33:49 +02:00
Olivier Dony 2257583bb5 [ADD] ir.attachment: add token field for external access
Introduce a new attachment field (access_token) to allow external
unauthenticated access. This will be an opaque unique number
(typically a UUID) that should be provided via an appropriate
controller, for unauthenticated display.

The field is intended to be NULL unless unauthenticated access has been
allowed, in which case a value will be set for the access_token.

This could be used e.g. for allowing access to images within mailings,
even when the recipient is not logged in (which is sometimes entirely
impossible, when email providers use restricted proxy servers to
load images)

Note 1: this is still a work-in-progress, but serves to freeze the API.
The implementation of the access check and provisioning of the new
field will be added later.

Note 2: namimg collisions with the file download token prevent the use
of a shorter 'token' parameter for download routes.

Apologies for the late (and incomplete) addition in saas-18 :-/
2017-09-21 23:48:36 +02:00
Yannick Tivisse 2e3848b394 [IMP] web: Add the possibility to crop an image in web/image controller
Purpose
=======

Could be useful if you want to load a preview of an image as a thumbnail
2017-09-05 15:52:15 +02:00