Commit Graph
497 Commits
Author SHA1 Message Date
Patrick Hoste 6088a1eb01 [FIX] website: fix get_dynamic_filter controller method
PURPOSE

Before this commit when the method returned an empty string, the calling
method _fetchData couldn't processed map() on the result.
After this commit the result will be an empty array thus the map method
won't fail.

LINKS

Task-2489680
PR : odoo/odoo#

closes odoo/odoo#76497

X-original-commit: ef813860b7582e9f1a92debb40d6dcda5519e607
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-09-14 13:32:33 +00:00
Oussama MESSAOUDIandqsm-odoo 7e8ba9bc2f [IMP] website, *: review the header templates + add CTA as an option
*: portal, website_sale, website_sale_wishlist

Part of https://github.com/odoo/odoo/pull/68149
task-2368576

Part-of: odoo/odoo#68149
Co-authored-by: qsm-odoo <qsm@odoo.com>
2021-09-03 14:29:51 +00:00
Benoit Socias 9f9c4bb7e4 [IMP] website(_*): replace search callbacks by a mixin
Before this commit the `_search_get_detail` result contained callback
functions to handle special behavior during fetching and rendering.

After this commit a `website.searchable.mixin` is introduced that must
be inherited by models that participate in website-based searches.
Custom behavior previously achieved with callbacks is now achieved by
overloading methods of this mixin.

task-2379555
https://github.com/odoo/odoo/pull/65871

Part-of: odoo/odoo#65871
2021-09-03 06:59:33 +00:00
Benoit Socias 7559626c54 [IMP] website, *: make a generic search bar snippet available
(*: website_blog, website_event, website_forum, website_sale,
website_slides)

Before this commit the search bar was specific to products.

After this commit a generic search bar is available as a general feature
of website which can be configured to inspect specific models.
The snippet is used to replace the old search bar in blog, courses,
event, forum, page and shop.
The search results of these pages and the autocomplete of the search bar
run through the same search mechanism.
A new hybrid results page has also been created as a target of a search
on "Everything".

In each involved module, `website._search_get_details()` is implemented
to return search metadata for every model related to the `search_type`
parameter.
Search metadata for a single model is returned by `_search_get_detail()`
on that specific model.

The autocomplete runs through the additional
`website._search_render_results()` pre-rendering step that prepares the
data to fit in the autocomplete template.

task-2379555
https://github.com/odoo/odoo/pull/65871

Part-of: odoo/odoo#65871
2021-09-03 06:59:33 +00:00
Benjamin Vray 5ffce116a6 [IMP] website_payment, *: new snippet make a donation
*=  website, website_sale, web_editor

This commit add a new snippet donation for the website builder.

PR-63133

task-2398403

Part-of: odoo/odoo#63133
2021-09-03 02:03:14 +00:00
Louis Wicket (wil) 80d74e7ee0 [IMP] mail, web, *: add support for guest users
* = crm_livechat, hr, hr_holidays, im_livechat, mail_bot, purchase, sms,
    snailmail, survey, test_discuss_full, test_mail, web_editor, website,
    website_livechat

 - Create new model `mail.guest` for guests.
 - Rewrite some RPCs to target routes rather than model methods so that
   guests are able to use them.
 - Patch JS and python models to support guests.
 - Create a stand-alone page and boot the channel in it.

task-2494829

closes odoo/odoo#75496

Related: odoo/enterprise#20417
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2021-09-02 00:43:34 +00:00
Jeremy Kersten ef531afe39 [IMP] website(_sale): allow to force numberOfRecord for dynamic snippet
Now you can specify into the dynamic_filter_template the number of record to
use for desktop, mobile, and the number of record to fetch.

Some template have only sense to be shown with 1 record e.g. a full width.

Syntax:
Add on root element one or more of these attributes:
  data-number-of-elements="2"  -> number of record on Desktop
  data-number-of-elements-sm="2" -> number of record on Mobile
  data-number-of-elements-fetch="2" -> number of record to fetch

closes odoo/odoo#75662

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-08-27 18:46:15 +00:00
Xavier-Do fdaee845d5 [FIX] base: remove options parameters
Regarding previous commit, the option parameter can be removed
from _get_asset_content api, followed by a nice snowball effect.

Part-of: odoo/odoo#75248
2021-08-26 10:21:10 +00:00
Martin Trigaux c7bac3dee0 [IMP] *: make ir.model.data helper private
No reason to interfact with them directly in RPC
2021-08-10 13:49:04 +02:00
Gorash 7df343dd1b [IMP] base: QWeb _render return Markup unicode instead of utf8 bytes
In order to limit encoding decoding, the _render method returns a
unicode string in the markup safe object instead of a MarkupSafeBytes

closes odoo/odoo#68299

Related: odoo/upgrade#2454
Related: odoo/enterprise#17270
Signed-off-by: Antony Lesuisse (al) <al@openerp.com>
2021-08-03 16:20:22 +00:00
Xavier Morel e84a72767e [FIX] website: de-traw-ify dynamic snippets
Mark the fragments as markup-safe after fetching them.

Also make _render private (don't see any reason for it to be publicly
accessible), and avoid unnecessary intermediate enc/dec in it.
2021-07-20 05:45:52 +00:00
Matthieu Stockbauer 2709602006 [REF] website, *: adapt files moved to website after website_form merge
*: website_crm, website_form_project, website_hr_recruitment,
   website_sale

Part of https://github.com/odoo/odoo/pull/69888
task-2462993
2021-07-16 19:13:18 +00:00
Matthieu Stockbauer f8882698e8 [MOV] website, website_form, *: merge website_form app into website
*: crm_iap_lead_website, website_crm, website_form_project,
   website_hr_recruitment, website_sale

Part of https://github.com/odoo/odoo/pull/69888
task-2462993
2021-07-16 19:13:18 +00:00
Jeremy Kersten 478068c829 [IMP] *: always use Odoo Response
This branch adds request.redirect on all requests.
In case of a front end request, we do an url_for to the location.

We removed redirect_with_hash that was only for retro compatibility

local_redirect has been renamed to redirect_query, and param keep_hash has been
removed and moved.

Default code for redirect is 303 now instead of 302.

Now redirect and redirect_query make local redirect by default, you need to
pass local=False to make external redirect.

All werkeug.utils.redirect has been replaced by request.redirect.

Http.redirect now use an http.Response type, and it become easy to add an
override like 'set_cookies' e.g.

Dispatch of a website.page return an http.response too, so we first need to
check if it is a cached version before to check if it is an Odoo Response.

Migrate your code:

http.redirect -> request.redirect(location, code, local)
http.local_redirect -> request.redirect_query(location, query, code, local)
http.redirect_with_hash -> request.redirect

Courtesy of odony for help and review ;)

closes odoo/odoo#72599

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-08 07:00:06 +00:00
Romain Derie ca385eecb4 [FIX] website: allow non-admin editor to get suggested links
New features to show suggested links as an autocomplete when creating a menu
was introduced with 9b9829416b.

But it was missing a sudo, so non-admin editor could not read module records.

task-2583737

closes odoo/odoo#73035

X-original-commit: d8206db3da541ba3f0c3e9cb63eab802e3ff096b
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
Signed-off-by: Romain Derie <rdeodoo@users.noreply.github.com>
2021-06-30 18:23:13 +00:00
Romain Derie c1ae086cdb [IMP] *: remove trailing slash from routes
* http, http_routing, website, website_sale_comparison

At an crawling engine/SEO level, having trailing slashes or not in URLs doesn't
change anything.
Still, whichever solution is chosen, it should be done consistantly: either all
URLs have trailing slashes, or none of them have it.

See https://developers.google.com/search/blog/2010/04/to-slash-or-not-to-slash
" Be consistent with the preferred version. Use it in your internal links. If
  you have a Sitemap, include the preferred version (and don't include the
  duplicate URL). "

opw-2505818
opw-2513575
Community: https://github.com/odoo/odoo/pull/71065
Enterprise: https://github.com/odoo/enterprise/pull/18615
2021-06-03 12:07:32 +00:00
Romain Derie 77b00d94d2 [FIX] website: don't show advanced tree hierarchy if not debug
The page manager shows an advanced structure if the user has multi website
enabled. It will show specific pages as a child of its generic one.
It is useful to directly understand and figure which pages are 'overiden'.

But it doesn't really makes sense for an end user, which doesn't know there is
actually generic and/or specific pages.

It makes more sense to show that behavior only in debug and not in multi
websites, even more since pages are overiden even in mono website.

closes odoo/odoo#68902

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-05-05 11:56:13 +00:00
Romain Derie 2c8c079c05 [FIX] http_routing, website: prevent crash when using fw in url
Before this commit, the routing map generated and used would be the one from
the website the request is performed, instead of the one from the `fw` website
ID which will be the one we redirect the user to.

This issue was introduced with the routing map by website, be8fc2296b and is
restricted to a single case: a publisher using the website switcher, and it
won't happen on next page naviguation/refresh as the `fw` website id will be
the same as the current website's ID. Thus there won't be any routing map
mismatch.

Step to reproduce:
  - Create a page on website 2, set it as homepage
  - Naviguate to website 1 on '/' url
  - Naviguate to website 2 on '/' url
This will raise a werkzeug error about `EndPoint not iterable`.

----- Technical analysis ------

This is the current flow:
1. `_dispatch()` is setting `website_routing` to `get_current_website()` -> 2
2. `_dispatch()` is calling `_match()`
3. `_match()` is calling `routing_map()` with key = `website_routing`, which
   was set to 2 in step 1.
4. `routing_map()` is calling `_generate_routing_rules()` which generate the
   rules based on `website_routing`, which was set to 2 in step 1.
5. `_dispatch()` authenticate the user by calling `_authenticate()`
6. `_dispatch()` is calling `_add_dispatch_parameter()`, where URL param `fw`
   is forced in session, so `get_current_website()` now return the correct
   `website_id` -> 1

The issue: in order to handle the `fw` URL parameter (step 6.), we need to
check the rights to ensure we can allow the website switch.
To check rights, user need to be authenticated (step 5.), which is done after
generating the routing map (2. & 3. & 4.).
The routing map is generated based on the current website (step 1.)

Step 6 depends of steps 5 which depends of steps 2/3/4 which depend of step 1,
but step 1 should depend of step 6, which is an impossible cycle.

closes odoo/odoo#70397

X-original-commit: 4eb26497a774e934d7e1a6be9f505400fd9e2cdb
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Signed-off-by: Romain Derie <rdeodoo@users.noreply.github.com>
2021-05-05 11:01:15 +00:00
Xavier Morel 01875541b1 [CHG] core, web: deprecate t-raw
Add a big fat warning when the qweb compiler finds a `t-raw`.

`t-esc` should now be used everywhere, the use-case for `t-raw` should
be handled by converting the corresponding values to `Markup`
objects. Even though it's convenient, this constructor *should never
be made available in the qweb rendering context* (maybe that should be
checked for explicitely?).

Replace `werkzeug.escape` by `markupsafe.escape` in
`odoo.tools.html_escape`, this means the output of `html_escape` is
markup-safe.

Updated qweb to work correctly with escaping and `Markup`, amongst
other things QWeb bodies should be markup-safe internally (so that a
`t-set` value can be fed into a `t-esc`). See at the bottom for the
attributes handling as it's a bit complicated.

`to_text` needed updating: `markupsafe.Markup` is a subclass of `str`,
but `str` is not a passthrough for strings. So `Markup` instances
going through would be converted to normal `str`, losing their safety
flag. Since qweb internally uses `to_text` on pretty much
everything (in order to handle None / False), this would then cause
almost every `Markup` to get mistakenly double-escaped.

Also mark a bunch of APIs as markup-safe by default

* html_sanitize output.
* HTML fields content, sanitization is applied on intake (so stripped
  by the trip through the database) and if the field is unsanitised
  the injection is very much intentional, probably. Note: this
  includes automatically decoding bytes as a number of default values
  & computes yield bytes, which Markup will happily accept... by
  repr-ing them which is useless. This is hard to notice without `-b`.
* Script-safe json, it's rather the point (though it uses a
  non-standard escaping scheme).
* Note that `nl2br`, kinda: it should work correctly whether or not
  the input is markup-safe, this means we should not need to escape
  values fed to `nl2br`, but it doesn't hurt either.

Update some qweb field serialisations to mark their output as
markup-safe when necessary (e.g. monetary, barcode,
contact). Otherwise either using proper escaping internally or doing
nothing should do the trick.

Also update qweb to return markup-safe bytes: we want qweb to return
markup-safe contents as a common use-case is to render something with
one template, and inject its content in an other one (with Python code
inbetween, as `t-call` works a bit differently and does not go through
the external rendering interface).

However qweb returns `bytes` while `Markup` extends `str`. After a
quick experiment with changing qweb rendering to return `str` (rather
unmitigated failure I fear), it looks like the safest tack is to add a
somewhat similar bytes-based type, which decodes to a `Markup` but
keeps to bytes semantics.

For debugging and convenience reasons, MarkupSafeBytes does *not*
stringify and raises an error instead (`__repr__` works fine). This is
to avoid implicit stringifications which do the wrong thing (namely
create a string `"b'foo'"`).

Also add some configuration around BytesWarning (which still has to be
enabled at the interpreter level via `-b`, there's no way to enable it
programmatically smh), and monkeypatch `showwarning` to show warning
tracebacks, as it's common for warnings to be triggered in the bowels
of the application, and hard to relate to business logic without the
complete traceback.

`t-out`
=======

`t-esc` is a bit confusing for the new behaviour of "maybe escape
maybe not", so add a `t-out` alias with the same behaviour.

Unlike `t-raw`, `t-esc` is only soft-deprecated for now: there are
thousands of instances, so editing all the templates is not
great. Eventually we'll add a `ci/style` to prevent addition of new
ones, and eventually we might do a bulk-replace and hard-deprecate.

Attributes handling
===================

There are a few issues with respect to attributes. The first issue is
that markup-safe content is not necessarily attributes-safe
e.g. markup-safe content can contain unescaped `<` or double-quotes
while attributes can not. So we must forcefully escape the input, even
if it's supposedly markup-safe already.

This causes a problem for script-safe JSON: it's markup-safe but
really does its own thing. So instead of escaping it up-front and
wrapping it in Markup, make script-safe JSON its own type which
applies JSON-escaping *during the `__html__` call.

This way if a script-safe JSON object goes through `markupsafe.escape`
we'll apply script-safe escaping, otherwise it'll be treated as a
regular strings and eventually escaped the normal way.

A second issue was the processing of format-valued
attributes (`t-attf`): literal segments should always be markup-safe,
while non-literal may or may not be. This turns out to be an issue if
the non-literal segment *is* markup-safe: in that case when the
literal and non-literal segments get concatenated the literal segments
will get escaped, then attributes serialization will escape
them *again* leading to doubly-escaped content in attributes.

The most visible instance of this was the `snippet_options` template,
specifically:

    <t t-set="so_content_addition_selector" t-translation="off">blockquote, ...</t>
    <div id="so_content_addition"
        t-att-data-selector="so_content_addition_selector"
        t-attf-data-drop-near="p, h1, h2, h3, .row > div > img, #{so_content_addition_selector}"
        data-drop-in=".content, nav"/>

Here `so_content_addition_selector` is a qweb body therefore
markup-safe, When concatenated with the literal part of
`t-atff-data-drop-near` it would cause the HTML-escaping of that
yielding a new Markup object. Normal attributes processing would then
strip the markup flag (using `str()`) and escape it again, leading to
doubly-escaped literals.

The original hack around was to unescape() `Markup` content before
stringifying it and escaping it again, in the attribute serialization
method (`_append_attributes`).

That's pretty disgusting, after some more consideration & testing it
looks like a much better and safer fix is to ensure the
expression (non-literal) segments of format strings always result in
`str`, never `Markup`, which is easy enough: just all `str()` on the
output of strexpr. We could also have concatenated all the bits using
`''.join` instead of repeated concatenation (`+`).

Also add a check on the type of the format string for safety, I think
it should always be a proper str and the bytes thing is only when
running in py2 (where lxml uses bytestrings as a space optimization
for ascii-only values) but it should not hurt too much to perform a
single typecheck assertion on the value... instead of performing one
per literal segment.

Note: we may need to implement unescape anyway, because it's still
possible to get double-escaping with the current scheme: given an
explicitly escape-ed `foo` and `t-att-foo="foo"`, `foo` will be
re-escaped.

fixup! [CHG] core, web: deprecate t-raw
2021-04-29 05:34:19 +00:00
Sébastien Mottet (oms) f4eed6547a [IMP] website: configurator changes and adaptations to iap module
The following two points are necessary adaptations for
the correct functioning of the configurator with the
module deployed on iap-services.

- The routes of the api_website module deployed on
iap-services.odoo.com use model converters to retrieve
the industry selected by the user. The configurator
has been updated accordingly. We now use industry id
instead of industry name. Using id instead of name make
record retrieval faster and model converters handle
exception if the record doesn't exist.

- 'homepage' is now added to the requested pages by
the client. Previously, this page was added by the iap
module to the requested pages.

The following two points are changes to the configurator
route handling:

- multilang=False has been added to the route rendering
the configurator in order to avoid having the lang in
the url.

- If no step is specified in the url, the implicit step
is 1. Therefore /website/configurator/1 has been changed
to /website/configurator.

closes odoo/odoo#69370

X-original-commit: b6efa4caf6514484c254869cb2f1965d207e7c65
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Signed-off-by: Sébastien Mottet <smottet@users.noreply.github.com>
2021-04-16 09:02:09 +00:00
Sébastien Mottet (oms) e8a5af2e28 [IMP] website: configurator for automatic website generation
On website app  installation and on new website creation a configurator is launched.
The purpose of this configurator is to generate a website that meet the user's needs.

The configurator is composed of 4 steps:

1) Business description: the user is asked to describe its need with its website purpose (dropdown), its industry (autocomplete search) and its objective (dropdown).

2) Logo and palette selection: the user must select a color palette for its website. He can also upload its logo. In this case color palettes recommendations are generated based on the logo's colors.

3) Features selection: the user select the pages and applications he needs.

4) Theme selection: three themes are recommended to the user based on its industry. This screen display a preview of these three themes.

task-id: 2451965
ENT PR: odoo/enterprise#16949
UPG PR: odoo/upgrade#2316

closes odoo/odoo#67537

Signed-off-by: Sébastien Mottet <smottet@users.noreply.github.com>
2021-04-02 13:04:03 +00:00
Benoit Socias 3355dc1623 [REF] website, website_sale: support recently viewed in product snippet
Before this commit the recently viewed products were handled differently
from the dynamic product snippet.

After this commit the dynamic product snippet supports the functionality
of the recently viewed products snippet:
- its template used to show each product
- its filter of displayed products
- its "Add to cart" feature (with the animation)
- its "Forget" feature (only applicable when viewing recently viewed)
Also added "Accessories" and "Recently Sold With" filterings.

Several kinds of filtering can be combined.
- Products can be restricted to a given category
  - Pseudo categories for all products or current category can be used
- Products can be restricted to matching names
- Products can be obtained from one of the following:
  - Newest
  - Latest sold: ordered by descending frequency in last 8 orders
  - Latest viewed
  - Accessories (of the current product)
  - Recently sold with (the current product)
Accessories and recently sold with are only available in product pages.

Also, generic templates have been considered useless and the whole
mechanism allowing them has been removed (this includes the
pre-rendering mechanism for the fields specified in the filter).

task-2453416
https://github.com/odoo/odoo/pull/65554
2021-03-26 15:41:44 +00:00
Denis Mudarisov b9a882817a [FIX] website: _handle_exception takes only two arguments
Before the commit, if an exception occurs there was an error saying:
`TypeError: _handle_exception() takes 2 positional arguments but 3 were given`

Impacted versions:

 - 12.0
 - 13.0
 - 14.0

X-original-commit: 47d6fa4ff6e78a33691c22b08504ce03e6796c9a
2021-03-22 13:28:26 +00:00
Benoit Socias 0cede3fa14 [IMP] website: display sample data for dynamic snippets
Before this commit when a dynamic snippet was fully configured but
returned no data, the rendered section remained empty in edit mode.

After this commit when a dynamic snippet is fully configured but has no
data to display, some sample data is generated in edit mode to give a
feel of how the page will look like when data will be available.

task-2446024
https://github.com/odoo/odoo/pull/65176
2021-02-16 10:17:58 +00:00
Simran Gajsinghani 6f9a2ca2fb [IMP] website: show searched pages count on website pages
in this commit, when activated 'Show # found' option in Customize menu,
the count of searched records for the manage your pages, event, and form page
displayed on the search button(#found).

task-2115526

closes odoo/odoo#40121

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-12-17 10:25:28 +00:00
Jeremy Kersten 3685b9c85b [FIX] website: only toggle view in toggle state
Before this commit, we write on each record the value, whatever the current value.
Now we check if it is necessary to avoid useless fork.

The first change on header was slowly.

closes odoo/odoo#62119

X-original-commit: e18c43d217be89b35213236038e72bc8298061a0
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-11-20 16:56:54 +00:00
Olivier Dony d16343a41d [FIX] website: adapt /website/action to v14 perms
As of v14 and #53335 (6c97a6d), access to `ir.actions*` models has been
restricted to admins, except in specific context such as via the
`/web/action/load` route.

This commit updates the `/website/action/` route to follow that logic,
and allow custom server actions to be exposed as "custom controllers".

The principle is that the action is located in a sudo environment, but
executed using the request environment. Access will only be permitted if
the model of the action is writable for the current user, or if any
action "groups" are set and the user belongs to one of them
(cfr f0d37c384b for that part).

closes odoo/odoo#62009

X-original-commit: ddf4c705ae0b83761495cd6a00d34463fa252043
Signed-off-by: Toufik Benjaa (tbe) <tbe@odoo.com>
2020-11-19 11:50:31 +00:00
Jeremy Kersten 71f42e274d [FIX] website: favicon use STATIC_CACHE_LONG that is a real year
365 * 24 * 60 is not a year, but year/60 ;)
While we fix it, it is the good time to change and use the dedicated
http.STATIC_CACHE_LONG that exists for it.

closes odoo/odoo#60807

X-original-commit: bb4d5bebaf926cbdf6f8842cd1ca0e5850523bf5
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-10-27 10:22:56 +00:00
Jeremy Kersten 550d2935bd [IMP] website: support generic website for dynamic snippet filters
Made the website_id non mandatory on website snippet filters and adapted
the fetching route so that it interprets an unspecified website_id as
the filter being available on any website.

Before this commit website snippet filters had to be limited to one
single website.

After this commit website snippet filters can be made available on all
websites by setting their website_id to no value (this is the new
default of the pre-defined filters).

https://github.com/odoo/odoo/pull/59831
task-2355369

closes odoo/odoo#59831

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-10-13 13:09:45 +00:00
David Beguin 4c9e39cfbd [FIX] website: get visitor tz directly from cookie
Since tz is now (from 6eb4762fee) added to the client cookie,
visitor timezone can directly be set when creating the visitor, using the
request.

Jstz can be removed as even for module in ENT that used this lib,
we can get the timezone using Intl lib instead.

This will also reduce the number of request made only to get visitor's
timezone.

This commit reverts part of 17e8402523
Linked ENT PR: 12963

Task ID: 2333825

closes odoo/odoo#59501

X-original-commit: 3d9a2de3575777c87327691319d89f9de6b8eada
Related: odoo/enterprise#13918
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2020-10-08 11:45:39 +00:00
Romain Derie 49dfe5e329 [FIX] website: prevent /web/become route to crash
Since 9f82605df1, any call to `_login_redirect()` without previously going
through `web_login()` method would crash, as `login_success` is set there.

In this case, it was:
Dispatch -> web_login -> redirect (new dispatch) -> _login_redirect()

task-2340941

closes odoo/odoo#57881

X-original-commit: 448fcb3c702c3346ca5af922bbf457231a7330f5
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-09-16 15:35:02 +00:00
Jeremy Kersten a019479d14 [FIX] website: check website_published exists before use
closes odoo/odoo#56786

X-original-commit: d23899b3c4ea91e4ac80163764c97cb9591d889c
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-08-31 09:17:10 +00:00
Laurent Stukkens (LTU) 0e7640b5f2 [IMP] website, website_sale: add dynamic snippets
* Implement new snippets that allow the user to choose a filter
  and a template.
  Three snippets have been created:
  - Dynamic Snippet: Displays the data in a grid format
  - Dynamic Carousel: Displays the date in a carousel
  - Dynamic Products: Let the user pick a product category and
                      displays the products in a carousel

task-2276740
PR #53175

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-08-18 17:40:25 +00:00
Xavier MorelandOlivier Dony a9a6509713 [ADD] auth_totp
New module for supporting two-factor authentication via time-base
one-time-password (TOTP).

Users (including portal users) can choose to enable two-factor auth in
their user account settings, by scanning a QR code and adding it to an
authenticator app, such as Google Auth, 1Password, etc.

When two-factor is enabled, password-based non-interactive RPC is only
possible by using API keys.

Co-authored-by: Olivier Dony <odo@odoo.com>
2020-08-14 23:06:24 +00:00
Xavier Morel 9f82605df1 [FIX] portal, website: login redirection
* migrate website to overriding web_login less (still needed to flag it
  as website-enabled) and use _login_redirect for its login redirection
  override needs
* modify portal and website to not replace / shortcut the redirection
  workflow, so it's possible to override those properly if / as
  necessary
2020-08-14 23:03:27 +00:00
Thanh Dodeurandqsm-odoo 59d46b51b1 [MOV] website: move google map snippet from themes to community
Improve the base code and adapt to new website features as well.

Part of https://github.com/odoo/odoo/pull/49101
task-2091396

Co-authored-by: qsm-odoo <qsm@odoo.com>
2020-07-28 07:45:40 +00:00
Jeremy Kersten c387ec19b4 [IMP] website: allow to have custom slug Ux
Now, slug uses seo_name if field exists before to fallback on display_name.

It allow to have a custom url without change the product name already used in
backend e.g. or just because you want add some keywords for seo.

task-2291676

closes odoo/odoo#54152

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-07-07 13:11:57 +00:00
DramixDw 714f0aa07f [IMP] website: reintroduce a way to post from js
It was deleted in 11.0 as it was not used anymore. Now, it is
reintroduce as it is a nice utility function for some external app or
fixes. Here, it is use so that /website/add and /website/add/<path> work
as a controller POST with a CSRF token.

task-2241766
2020-05-29 13:59:15 +00:00
Martin Trigaux d879300944 [REM] website: remove lazy template call
Was making a render_template on an arbitrary template
Does not seem to be used anymore
2020-05-14 13:59:10 +02:00
Martin Trigaux d9287caf94 [IMP] *: convert to private methods
render, render_template, load, activity_schedule_with_view,
get_website_pages should all be private:
It should not be possible to render an aribtrary template only with
its name or id

Still need to render some qweb views from js so the method
render_template is kept public.
This explains why the website editor still need read access on
ir.ui.view as we want to allow any snippet to be rendered.
2020-05-14 13:59:10 +02:00
Martin Trigaux 56a8c9e431 [FIX] *: add sudo when accessing views
The method fields_view_get should be the only way to retrieve the view
content. This method is executed in a super-user context.

To avoid retrieving views for a model a user does not have access to
(as it may reveal some informations like name of fields), add a
verification of 'read' rights before retrieving the view content.

Execute _postprocess_access_rights with sudo(False) as this method is
used to evaluate which buttons should be displayed.
Remove the su flag to avoid misleading the user and displaying a
button they won't be able to use.

Retrieving the database id from an view key is not considered as a
sensitive information and get_view_id and viewref can be left as a
public methods.

Add missing sudo when needed

Change _handle_visibility in website to avoid increasing the query
count: Checking the visibility (to fail most of the time) to retry in
sudo was making unecessary queries.
2020-05-14 13:59:10 +02:00
DramixDw 9b9829416b [IMP] website: simplify website menu
Some apps, once installed, automatically create a menuitem in website.
What complexify the UI and create useless menu withtout plusvalue.

It is not because you install livechat to make support online, that you want
a link in your menu to show stats e.g.

Now we remove the default menu created, and help user to find it when he create
a link. The autocomplete suggest most of the main App's controllers

task-2189613

closes odoo/odoo#49081

Related: odoo/enterprise#9733
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-05-01 07:59:07 +00:00
Thibault Delavallée 318f02b8e8 [REF] base: replace toggle method by already-existing toggle_active for ir.ui.view
Toggle method defined on ir.ui.view does the same job of toggle_active that
is the generic one available on all models.

Task ID 2170708
Community PR odoo/odoo#46563
2020-04-03 12:59:28 +00:00
Benjamin Vrayandqsm-odoo 5ba817c453 [IMP] website: add templates for footer
Also remove all t-fields from footers to have only static contents in
footers. For social links, a controller is added so that a "static url"
/website/social/xxx always redirect to the correct set URL for the given
xxx social network.

Part of https://github.com/odoo/odoo/pull/38950
task-2087641

Co-authored-by: qsm-odoo <qsm@odoo.com>
2020-03-31 18:16:08 +00:00
Romain DerieandJeremy Kersten 30f4f610bf [IMP] website: improvement regarding social image
This commit introduce multiple improvements regarding social image:
  - (perf) Don't read ir.attachment through `social_default_image` when it is
    not needed. Use a stored boolean to know if the field should be accessed.
    This will remove one SQL query in attachment for public user.
  - Show website logo, not the company logo since we now have a different logo
    for website.
  - Don't show images lower than 200 width or 200 height px. Logo will be
    shown regardless of his size.
  - Don't show website logo if there is a website social_default_image.
    Indeed, the spec was to prevent showing logo and social_default_image if
    they are the same image. Technically, this is hard to identify as they
    could be the same image uploaded with different resolutions (media dialog),
    especially if one of those was uploaded through the backend and one from
    the frontend.
    It is most likely we will never correctly identify duplicate as they won't
    be exactly the same.
    For this reason, it makes more sense to hide the website logo if the
    social_default_image is set. It avoids every issues while it makes sense
    since you won't want to use the logo over the social_default_image. If you
    really want to, you could reupload it through the SEO media dialog.

closes odoo/odoo#47848

Related: odoo/upgrade#1012
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Co-authored-by: Romain Derie <rde@odoo.com>
Co-authored-by: Jeremy Kersten <jke@odoo.com>
2020-03-30 16:06:13 +00:00
Jeremy Kersten a65d27cce9 [IMP] website: perf - favicon.ico cached for 1 year
Note that this route is only used when no icon is set in DOM, such as accessing
a PDF after an order.

task-2211013
2020-03-26 18:12:47 +00:00
Romain Derie 2c09e00a64 [IMP] website: perf - prefetch menus when serving a page
If we are rendering a page, the menus will most likely be rendered as well.
Note that even in a 403 case when the page is found but is not visible, the
menus will also be shown on the 403 page.

Fetching the menus before accessing the requested page will prefetch that page
as well in one go if that page is in the menus, without any costs for the pages
not in the menus.

There is a tradeoff for 'non-layout' pages, which only occurs in advanced
technical cases:
1. Create a page with specific extension as name suffix (page.css) in which
   case the page will be bootstraped accordingly, without call to layout.
2. Remove the call to layout in HTML editor or backend
3. Remove the call to submenus template in HTML editor or backend
For those cases, the menus will be prefetched for no reason.

Note that homepage '/' is rendered through a controller, same logic is applied
there.

task-2211013
2020-03-26 18:12:47 +00:00
Martin Trigaux 40667755b1 [FIX] website: restrict access to route
This route was public by mistake, probably introduced to test during
ddf32f4 but no reason to make it public, public user has not the write
access on models anyway.

Courtesy of Swapnesh Shah

closes odoo/odoo#44915

X-original-commit: 66ac96b25aa4cf2b074f6c06b57ed8be72d6d647
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-02-07 19:51:09 +00:00
qsm-odoo 6fb4ed44a0 [IMP] website, *: make theme custo options act as simple snippet options
* web_editor, theme_bootswatch

Instead of having an entirely dedicated system for theme options in a
third tab of the left panel, those theme options are now simple snippet
options. See the customizeWebsite generic method.

This allows to make any option available in the third tab or on any
meaningful element like the header or the footer. This also allows to
take advantage of all the features of the left panel: dependencies,
visibility update, etc.

Note: same as before, those changes do apply the color/size/layout
immediately on the website, even if not saved. Changing that behavior
is complex and might be the job of another task.

Part of https://github.com/odoo/odoo/pull/41166
task-2088298
2020-02-05 23:49:53 +00:00
Samuel Degueldre 3bb666c226 [REF] website, web_editor: move theme customization to edit mode
Previously, theme customization was done through a modal dialog in the
website module, this was not very user friendly since the rest of the
customization for the website design was done from edit mode, meaning
the user had to exit edit mode to customize things such as theme colors
or fonts. It was also rather confusing to have these seemingly related
things in completely unrelated places.

This commit moves all of the options that used to be in the theme
customization modal into a new tab in the editor's left panel.

This commit is mainly just about rendering the old modal as a third left
panel content. See next commit for deeper changes.

Note: same as before, those changes do apply the color/size/layout
immediately on the website, even if not saved. Changing that behavior
is complex and might be the job of another task.

Part of https://github.com/odoo/odoo/pull/41166
task-2088298
2020-02-05 23:49:53 +00:00