- This commit fixes a crash that happens when the server receive a
JSON-P call done in two requests (a POST followed by a GET).
The issue is due to the fact that when the first request is done (POST
one) the member `params` is never initialized.
This parameter is then used in the module `auth_signup` on an override
of the method `dispatch` thus crashing the code.
To avoid the crash, we now initialize `params`.
closesodoo/odoo#27369
This revision aims to support the memory limits
on Linux, Windows and MacOSX according to their own spefication
regarding their memory management.
Among others, it brings the possibility to
use the multi-workers mode on Windows and MacOSX.
e.g.
- Windows does not support `resource`,
and therefore we skip to set the hard limit
- MacOSX allocates a large virtual memory for each process
even if the memory is not actually used,
and therefore using the VMS to limit the memory is pointless
as it will always exceeds the default soft memory limit.
We therefore choose to use the RSS to limit the memory
closesodoo/odoo#27848
Session rotation was introduced a long time ago, but deactivated at
login due to obscure side-effects related to #6949 (aka the "BBQ" PR).
This commit reinstates the rotation, which is better from a security
standpoint.
In order to also prevent session ID reuse, we force the renewal of
deleted sessions, at the SessionStore level (via `renew_missing`).
When there is a performance issue, it's sometimes difficult to discover
which request increased the query count or its duration.
With this commit, the query count, the query time and "python and io" time are displayed
in the logs at the end of each werkzeug request line.
Co-authored-by: Christophe Monniez <moc@odoo.com>
From this commit onwards, Date fields will return datetime.date objects and Datetime fields will return datetime.datetime objects, this implies a number of things that are clearly explained both in the ORM API for master.
This commit also introduces a number of helper functions for dates and datetimes that are exposed in tools.date_utils and fields.Date[time], explained in the documentation as well.
Task-ID: 47189
* Make Users._login and session.authenticate always raise AccessDenied
on authentication failure instead of only sometimes (cf
Session.authenticate calling security.check() which raises and not
catching the exception)
* Alter AccessDenied such that it's possible to add a custom access
message, for use with login rate limiting instead of smuggling the
information via the session
* Alter the RPC endpoints to catch and convert AccessDenied back to
a boolean sentinel
Browsers accept it as they are wont to do, but the Content-Disposition
lib (introduced in 35d452cffb) does
not. Simply don't mark them as safe when %-escaping the filename so
they do get %-escaped properly.
RFC5987 states
ext-parameter = parmname "*" LWSP "=" LWSP ext-value
ext-value = charset "'" [ language ] "'" value-chars
value-chars = *( pct-encoded / attr-char )
attr-char = ALPHA / DIGIT
/ "!" / "#" / "$" / "&" / "+" / "-" / "."
/ "^" / "_" / "`" / "|" / "~"
; token except ( "*" / "'" / "%" )
Neither : nor / are in attr-char. This is further confirmed by
checking out RFC2616:
CTL = <any US-ASCII control character (octets 0 - 31) and DEL (127)>
token = 1*<any CHAR except CTLs or separators>
separators = "(" | ")" | "<" | ">" | "@"
| "," | ";" | ":" | "\" | <">
| "/" | "[" | "]" | "?" | "="
| "{" | "}" | SP | HT
Here we can see "/" and ":" are both in "separators", which are
specifically *not* in token. attr-char restricts token further, so an
invalid token char can't be a valid attr-char.
- Each time we check if a session is valid we create a new cursor.
This could lead to issues with db_maxconn that limits the number of
connections to the postgresql server.
In a perfect world, a worker should use a single connection to
postgres to process the request.
The only known side effect is that the cursor is created earlier in
the execution of the code.
- This commit fixes issues with the longpolling raising
Psycopg2.PoolError exceptions on databases with a lot of clients.
Endpoints can be explicitly marked as `save_session=False` (default is
true across the board). In that case they will have an in-memory session
(either the existing one or a brand new one) but the session won't be
persisted to disk.
Currently used for non-browser RPC endpoints: the APIs don't use
cookies/sessions and we can't assume the RPC libraries keep cookies
across calls. This means a new session is created and saved to disk for
each RPC calls, for no useful reason.
Before this patch, early connections made to a 11.0 Odoo server running
on Python 3 and deployed in threaded mode with socket activation would
generate invalid registries.
With this patch it is now possible, when this deployment mode is used,
to opt-out addons preload by setting the following environment variable:
ODOO_PRELOAD_ADDONS=no
Note: this environment variable is only available for v11.0 as later
versions does not preload anymore (cf: 1a39c9b)
This way, XMLRPC calls can get request details form the standard
`odoo.http.request` system.
Move jsonrpc to the same controller while at it, for coherence.
Fix#24183
Replace `httprequest.stream.read()` by `httprequest.get_data()` so the
payload content remains available: get_data stores the request body (by
default) so it remains available for alternative processing or checks
(MAC checks for webhook validations for instance). With `stream.read()`,
once the data is read if it's not stored separately it is lost.
- Install Website
- Load the 'Norwegian Bokmål' translation, and choose to translate the
website
- Logout
When accessing the website, the language displayed is not consistent to
the browser language.
1. `no` shows homepage in `nb_NO` (Firefox only) => expected since
Bokmål is the main language in Norway
2. `nb` shows homepage in `en_US` => unexpected
3. `nn` shows homepage in `en_US` => expected since 'Norwegian Nynorsk'
is not a language available (this will be the topic of another PR)
The issues comes from Babel's side, since `nb` is not in the
`LOCALE_ALIASES` while `no` is. We monkey-patch the value to avoid this
while Babel is corrected.
opw-1827258
Clean method _add_dispatch_parameters
Remove unused code for caching
Call super before to have the correct lang when we browse website.
Without it, menu was not loaded in correct language.
Purpose
=======
If an external dependency is unmet on a module that is not installed, it's actually impossible to launch an odoo server and load the web client without getting a traceback.
This commit removes this constraint and allow to use odoo in that case. Obviously the install will crash if the external dependency is still unmet.
Close https://github.com/odoo/odoo/pull/17790
Coming from https://github.com/odoo/odoo/pull/14850
* In Python 3 xlwt apparently does not support writing bytes values ->
try to decode assuming the value may be base64-encoded, this is more
or less the behaviour for CSV exports.
This will most likely not allow the export anyway as Excel cells are
limited to 32k data characters, which accounting for base64
expansion means ~24k worth of data, but that is a pre-existing
issue.
* Also removed support for way outdated browsers from
content_disposition: the Safari case is for Safari 5 (circa 2012)
but versioning apparently changed since then and modern Safari
report their "external" version number rather than the webkit
version number => the current Safari reports version 11, and gets
routed to the "does not support unicode file names", which is
further bugged in Python 3 as it %s's bytes, leading to a resulting
filename of e.g. `b'res.partner.csv'.csv` (with the prefix and
quotes).
* The IE case is for IE8, which has long been unsupported by the web
client.
This commit is related to enterprise commit adding crm_track option to routes.
Before this commit:
We could not get template's name after dispatch() had been called. Indeed,
it will remove the template name from the response (response.flatten()) to
make it not considered as 'qweb' anymore (is_qweb()).
In some case (e.g. website_crm_score), we still need the template's name later.
(Eg: to retrieve the route's view being rendered and check if trackable or not)
Add view-id in template, when main_object is not an ir_ui_view, it avoid to
make extra rpc to get the view_id.
this commit closes#20313