Commit Graph
95 Commits
Author SHA1 Message Date
Christophe Simonis b4e1be8ab0 [MERGE] forward port branch saas-11.3 up to b09f624f20 2018-11-22 20:06:48 +01:00
Christophe Simonis b09f624f20 [MERGE] forward port branch 11.0 up to 263b388c50 2018-11-22 17:52:57 +01:00
Toufik Benjaa 23a7b15276 [FIX] http: avoid crash on jsonp POST+GET
- This commit fixes a crash that happens when the server receive a
  JSON-P call done in two requests (a POST followed by a GET).

  The issue is due to the fact that when the first request is done (POST
  one) the member `params` is never initialized.

  This parameter is then used in the module `auth_signup` on an override
  of the method `dispatch` thus crashing the code.

  To avoid the crash, we now initialize `params`.

closes odoo/odoo#27369
2018-11-21 10:09:10 +00:00
Denis Ledoux 3823dcacef [FIX] http, server: cross-platform memory limit management
This revision aims to support the memory limits
on Linux, Windows and MacOSX according to their own spefication
regarding their memory management.

Among others, it brings the possibility to
use the multi-workers mode on Windows and MacOSX.

e.g.
- Windows does not support `resource`,
  and therefore we skip to set the hard limit
- MacOSX allocates a large virtual memory for each process
  even if the memory is not actually used,
  and therefore using the VMS to limit the memory is pointless
  as it will always exceeds the default soft memory limit.
  We therefore choose to use the RSS to limit the memory

closes odoo/odoo#27848
2018-10-16 15:37:40 +00:00
mreficent dddd4072de [FIX] v12 urls
Was still pointing to old links

closes odoo/odoo#27443
2018-10-09 13:44:38 +00:00
Olivier Dony 9bae56acd4 [IMP] http: reinstate session rotation after login
Session rotation was introduced a long time ago, but deactivated at
login due to obscure side-effects related to #6949 (aka the "BBQ" PR).
This commit reinstates the rotation, which is better from a security
standpoint.

In order to also prevent session ID reuse, we force the renewal of
deleted sessions, at the SessionStore level (via `renew_missing`).
2018-10-02 01:00:37 +02:00
XavierDoandChristophe Monniez c44fe91232 [IMP] http,server: add query count and request times in logs
When there is a performance issue, it's sometimes difficult to discover
which request increased the query count or its duration.

With this commit, the query count, the query time and "python and io" time are displayed
in the logs at the end of each werkzeug request line.

Co-authored-by: Christophe Monniez <moc@odoo.com>
2018-09-07 10:27:46 +02:00
Christophe Simonis 7499b47ffa [MERGE] forward port branch saas-11.4 up to edd586002e 2018-08-10 13:37:21 +02:00
Christophe Simonis 7717f082c0 [MERGE] forward port branch saas-11.3 up to af35aea6b0 2018-08-09 19:33:32 +02:00
Christophe Simonis efe2dcd7ae [MERGE] forward port branch 11.0 up to ced9156a97 2018-08-07 19:08:07 +02:00
Raphael Collet 960360afe4 [REF] *: use native date/datetime for Date/Datetime fields
From this commit onwards, Date fields will return datetime.date objects and Datetime fields will return datetime.datetime objects, this implies a number of things that are clearly explained both in the ORM API for master.

This commit also introduces a number of helper functions for dates and datetimes that are exposed in tools.date_utils and fields.Date[time], explained in the documentation as well.

Task-ID: 47189
2018-08-06 14:37:19 +02:00
Xavier Morel aac21e4125 [CHG] Change login/auth internal protocol
* Make Users._login and session.authenticate always raise AccessDenied
  on authentication failure instead of only sometimes (cf
  Session.authenticate calling security.check() which raises and not
  catching the exception)
* Alter AccessDenied such that it's possible to add a custom access
  message, for use with login rate limiting instead of smuggling the
  information via the session
* Alter the RPC endpoints to catch and convert AccessDenied back to
  a boolean sentinel
2018-07-26 15:53:26 +02:00
Xavier Morel b67209b001 [FIX] : and / are not safe in content-attachment filename
Browsers accept it as they are wont to do, but the Content-Disposition
lib (introduced in 35d452cffb) does
not. Simply don't mark them as safe when %-escaping the filename so
they do get %-escaped properly.

RFC5987 states

ext-parameter = parmname "*" LWSP "=" LWSP ext-value
ext-value     = charset  "'" [ language ] "'" value-chars
value-chars   = *( pct-encoded / attr-char )
attr-char     = ALPHA / DIGIT
              / "!" / "#" / "$" / "&" / "+" / "-" / "."
              / "^" / "_" / "`" / "|" / "~"
              ; token except ( "*" / "'" / "%" )

Neither : nor / are in attr-char. This is further confirmed by
checking out RFC2616:

CTL            = <any US-ASCII control character (octets 0 - 31) and DEL (127)>
token          = 1*<any CHAR except CTLs or separators>
separators     = "(" | ")" | "<" | ">" | "@"
               | "," | ";" | ":" | "\" | <">
               | "/" | "[" | "]" | "?" | "="
               | "{" | "}" | SP | HT

Here we can see "/" and ":" are both in "separators", which are
specifically *not* in token. attr-char restricts token further, so an
invalid token char can't be a valid attr-char.
2018-07-20 11:36:31 +02:00
Martin Trigaux 6d83f70014 [FIX] http: avoid corruption with domain name
Domain names may have been interpreted as a regex by mistake
2018-07-18 10:32:42 +02:00
Christophe Simonis 73652a0b19 [MERGE] forward port branch saas-11.3 up to 50860317cc
Note: 1aacc96262 has been ignored and will
be forward-ported later
2018-06-15 13:27:27 +02:00
Christophe Simonis b170a753e1 [MERGE] forward port branch 11.0 up to b05e4d5f95 2018-06-15 10:15:27 +02:00
Christophe Simonis d45c32baac [MERGE] forward port branch saas-15 up to bdd051bf78 2018-06-13 18:13:48 +02:00
Toufik Benjaa c8243e71c6 [FIX] http: Consume less cursors for session checks
- Each time we check if a session is valid we create a new cursor.
  This could lead to issues with db_maxconn that limits the number of
connections to the postgresql server.
  In a perfect world, a worker should use a single connection to
postgres to process the request.
  The only known side effect is that the cursor is created earlier in
the execution of the code.

- This commit fixes issues with the longpolling raising
Psycopg2.PoolError exceptions on databases with a lot of clients.
2018-06-12 18:10:37 +02:00
Christophe Simonis f36e6917bd [MERGE] forward port branch saas-11.3 up to 37eed7c509 2018-05-29 17:34:43 +02:00
Christophe Simonis f65528a74e [IMP] http: avoid saving sessions for some endpoints
Endpoints can be explicitly marked as `save_session=False` (default is
true across the board). In that case they will have an in-memory session
(either the existing one or a brand new one) but the session won't be
persisted to disk.

Currently used for non-browser RPC endpoints: the APIs don't use
cookies/sessions and we can't assume the RPC libraries keep cookies
across calls. This means a new session is created and saved to disk for
each RPC calls, for no useful reason.
2018-05-28 09:48:29 +02:00
Fabien Meghazi 32c5392f5f [ADD] http: addons preload opt-out for socket activation
Before this patch, early connections made to a 11.0 Odoo server running
on Python 3 and deployed in threaded mode with socket activation would
generate invalid registries.
With this patch it is now possible, when this deployment mode is used,
to opt-out addons preload by setting the following environment variable:

    ODOO_PRELOAD_ADDONS=no

Note: this environment variable is only available for v11.0 as later
versions does not preload anymore (cf: 1a39c9b)
2018-05-25 15:33:31 +02:00
Christophe Simonis 2bc6ea1b37 [MERGE] forward port branch 11.0 up to 02ee3fd88e 2018-05-23 19:33:40 +02:00
Christophe Simonis 8383181b8f [MERGE] forward port branch saas-15 up to 021d0e6a98 2018-05-18 18:59:06 +02:00
Christophe Simonis bfda65d894 [MERGE] forward port branch 9.0 up to 612fd33fb1 2018-05-18 16:19:21 +02:00
Jairo Llopis 285ead28e3 [IMP] Handle XMLRPC calls from standard controllers
This way, XMLRPC calls can get request details form the standard
`odoo.http.request` system.

Move jsonrpc to the same controller while at it, for coherence.

Fix #24183
2018-05-09 09:46:15 +02:00
Christophe Simonis 5f2d080cf8 [MERGE] forward port branch 11.0 up to ad825b673b 2018-04-16 18:34:56 +02:00
Kiril Vangelovski ff07f078fa [FIX] base: reason json payload using get_data
Replace `httprequest.stream.read()` by `httprequest.get_data()` so the
payload content remains available: get_data stores the request body (by
default) so it remains available for alternative processing or checks
(MAC checks for webhook validations for instance). With `stream.read()`,
once the data is read if it's not stored separately it is lost.
2018-04-16 10:29:13 +02:00
Christophe Simonis 860dfb5586 [MERGE] forward port branch 11.0 up to d277adf4d5 2018-04-06 15:36:10 +02:00
Nicolas Martinelli 9b6ca49b58 [FIX] http: Bokmål language code
- Install Website
- Load the 'Norwegian Bokmål' translation, and choose to translate the
  website
- Logout

When accessing the website, the language displayed is not consistent to
the browser language.
1. `no` shows homepage in `nb_NO` (Firefox only) => expected since
    Bokmål is the main language in Norway
2. `nb` shows homepage in `en_US` => unexpected
3. `nn` shows homepage in `en_US` => expected since 'Norwegian Nynorsk'
   is not a language available (this will be the topic of another PR)

The issues comes from Babel's side, since `nb` is not in the
`LOCALE_ALIASES` while `no` is. We monkey-patch the value to avoid this
while Babel is corrected.

opw-1827258
2018-04-05 11:01:11 +02:00
Christophe Simonis e0345a4a3f [MERGE] forward port branch 11.0 up to 2835d29979 2018-03-20 11:45:11 +01:00
Christophe Simonis 672a275c7f [MERGE] forward port branch saas-15 up to 3d9a2340d9 2018-03-19 21:26:01 +01:00
tbe-odoo da1f153d61 [IMP] http: Sessions implicit deactivation
- Store a token inside sessions to allow implicit session deactivation when needed.
2018-03-19 18:11:12 +01:00
Christophe Simonis 7e469eb77a [MERGE] forward port branch 11.0 up to f5e7b86686 2018-02-01 18:15:21 +01:00
Christophe Simonis f5e7b86686 [MERGE] forward port branch saas-16 up to 920aa6174c 2018-02-01 17:02:19 +01:00
Christophe Simonis 920aa6174c [MERGE] forward port branch saas-15 up to e0422bfd6c 2018-02-01 16:40:13 +01:00
Jeremy Kersten e15a7b4c65 [FIX] http: JsonRequest return code error as status code
+ Manage 404 error, avoiding tb in log and respecting status code
in response request.
2018-02-01 09:47:25 +01:00
Christophe Simonis 9af65a7efe [MERGE] forward port branch saas-16 up to 0b188b5804 2018-01-29 13:37:12 +01:00
Christophe Simonis 0b188b5804 [MERGE] forward port branch saas-15 up to 2629029d03 2018-01-29 13:29:14 +01:00
tbe-odoo 6d682cea25 [REV] http: Implicit session deactivation -> Explicit destruction
- This commit degrade the performance and introduce a bug for multiple database servers.

This reverts commit bc69b47073.
2018-01-29 13:25:21 +01:00
Christophe Simonis cb50970f3f [MERGE] forward port branch 11.0 up to eefe879a37 2018-01-25 15:41:45 +01:00
Christophe Simonis c6b2fa47ed Revert "[FIX] base: bad back-port"
This reverts commit 0ac6043ec7.
2018-01-25 12:43:02 +01:00
tbe-odoo c0f004205d [FIX] http: Implicit session deactivation -> Explicit destruction
- Replace the implicit session deactivation with explicit destruction.
2018-01-24 10:58:06 +01:00
tbe-odoo bc69b47073 [FIX] http: Implicit session deactivation -> Explicit destruction
- Replace the implicit session deactivation with explicit destruction.
2018-01-23 16:21:10 +01:00
Christophe Simonis 4708812b6c [MERGE] forward port branch 11.0 up to b37cc1f9b7 2017-12-12 18:50:59 +01:00
Jeremy Kersten 294dc70a38 [FIX] http_routing, website: fix and clean routing
Clean method _add_dispatch_parameters
Remove unused code for caching

Call super before to have the correct lang when we browse website.
Without it, menu was not loaded in correct language.
2017-12-12 17:47:08 +01:00
Miquel Raïch a578531ca3 [FIX] v11 urls
Was still pointing to old links

Closes #21590
2017-12-12 17:19:01 +01:00
Dave Lasley 8226aa1db8 [IMP] http.py: Allow to use odoo if unmet dependencies on uninstalled module
Purpose
=======

If an external dependency is unmet on a module that is not installed, it's actually impossible to launch an odoo server and load the web client without getting a traceback.

This commit removes this constraint and allow to use odoo in that case. Obviously the install will crash if the external dependency is still unmet.

Close https://github.com/odoo/odoo/pull/17790
Coming from https://github.com/odoo/odoo/pull/14850
2017-11-29 16:21:12 +01:00
Christophe Simonis 29590a61cd [MERGE] forward port branch 11.0 up to 8fb25e185b 2017-11-28 16:57:58 +01:00
Xavier Morel b46830858f [FIX] web: excel export of binary fields
* In Python 3 xlwt apparently does not support writing bytes values ->
  try to decode assuming the value may be base64-encoded, this is more
  or less the behaviour for CSV exports.

  This will most likely not allow the export anyway as Excel cells are
  limited to 32k data characters, which accounting for base64
  expansion means ~24k worth of data, but that is a pre-existing
  issue.
* Also removed support for way outdated browsers from
  content_disposition: the Safari case is for Safari 5 (circa 2012)
  but versioning apparently changed since then and modern Safari
  report their "external" version number rather than the webkit
  version number => the current Safari reports version 11, and gets
  routed to the "does not support unicode file names", which is
  further bugged in Python 3 as it %s's bytes, leading to a resulting
  filename of e.g. `b'res.partner.csv'.csv` (with the prefix and
  quotes).
* The IE case is for IE8, which has long been unsupported by the web
  client.
2017-11-27 11:11:48 +01:00
rde e19c6a5ead [IMP] website: set viewid in frontend & save template for dispatch
This commit is related to enterprise commit adding crm_track option to routes.

Before this commit:
We could not get template's name after dispatch() had been called. Indeed,
it will remove the template name from the response (response.flatten()) to
make it not considered as 'qweb' anymore (is_qweb()).

In some case (e.g. website_crm_score), we still need the template's name later.
(Eg: to retrieve the route's view being rendered and check if trackable or not)

Add view-id in template, when main_object is not an ir_ui_view, it avoid to
make extra rpc to get the view_id.

this commit closes #20313
2017-10-23 14:31:07 +02:00