Commit Graph
98 Commits
Author SHA1 Message Date
Julien Castiaux 4174b330f7 [FIX] http_routing: /r russian vs /r link tracker
Install website_links, create a link e.g. to http://example.com, install
the russian language and translate the default website. Access the short
link you created before-hand, 404 website page not found.

Accessing a website starting with /r is ambiguous, is /r the
link-tracker controller or is /r a russian lang alias (nearest lang
algorithm)? The controller should be prioritary to the lang alias.

This restore the behavior as it was before the httpocalyse.

closes odoo/odoo#99555

X-original-commit: e8a1b4c0cdffb38e48ca980205a61c75c564dee8
Signed-off-by: Jérémy Kersten <jke@odoo.com>
Signed-off-by: Julien Castiaux <juc@odoo.com>
2022-09-05 20:13:17 +02:00
Julien CastiauxandRomain Derie fd5c6a861c [FIX] http_routing: missing 301/302 on access err
Install website and website_hr_recruitment, open /web with ?debug=1, go
to website > configuration > redirect, create a temporary (302)
redirection from `/jobs/detail/experienced-developer-4` to `/404`. Open
the `/jobs/detail/experienced-developer-4` as admin and unpublish the
page. Open the same URL via private browsing (so that you are not
connected), you get the default 403 - Forbidden page, you were not
redirected to the 404 - Not Found page.

Custom 301 (permanent) and 302 (temporary) redirections are fallback
redirections when the requested page does not exist or is not accessible
to the current user. The HTTPocalypse broke the later case, it was not
checking for existing redirection upon access error.

The use case is the one supported with [1] where people want/need to
display something better than a 403 when they unpublish a record like a
job position for instance (most of the requested cases on opw).
Indeed:
- People have link to that record/job everywhere on the internet
- The job position / record is no more relevant, and people need to
  unpublish it
- People don't want to delete it (or can't sometimes due to record
  relations)
- People don't want visitors to land on a 403, mainly because it is a
  non customizable advanced/technical page (it displays a technical
  message including the record name etc)
- Their need is to either land a their customizable friendly 404 or
  sometimes on another record to promote it.

[1]: https://github.com/odoo/odoo/commit/3b9cd536607b1631dd375ab2e5cc94eb814a6e9b

closes odoo/odoo#93981

X-original-commit: eb7eecec976570ae3301c17a04adc9c110d5b14a
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Signed-off-by: Julien Castiaux <juc@odoo.com>
Co-authored-by: Romain Derie <rde@odoo.com>
2022-06-18 00:50:34 +02:00
Denis Ledoux bfdd54e815 [FIX] http_routing: support invalid ipv6 URL
opw-2870792

closes odoo/odoo#93138

X-original-commit: 4e052a387885890d9b0950fae825624b7f7a3f2b
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2022-06-08 19:00:20 +02:00
Gorash 391eb18eb2 [IMP] website: slug method also works with lazy values
Before this commit, the behavior is broken if using lazy values, the
condition using isinstance does not work. It's best to use the slug as
if given the correct value. Indeed, in odoo, we don't have any other
object having `id` as attributes in addition to `seo_name` or
`display_name` and not being a recordset and whose slug we want.
If there is an error, it is imperative that we provided a tuple (from
read).

Part-of: odoo/odoo#88276
2022-06-03 16:40:38 +02:00
Julien Castiaux 04e972660b [IMP] core: don't save visitor default session
Every request comes with a session, a dictionary that is persisted on
the filesystem and that saves various information such as the user
cart on the ecommerce.

When a user simply visits the website, a default session is created and
saved on disk, this bloats the filestore with many sessions. Creating
the session on-the-fly is cheaper than loading it from the filesystem.
With this work the default session is not saved on disk anymore unless
explicitly asked via `session.touch()`.

An exception to the statement "creating the session on-the-fly is
cheaper" is geoip, the ip geolocalization is not cheap. In this work,
geoip have been moved from http_routing/request.session.geoip to a
lazy property core/request.geoip. When requested the info is persisted
on the session. Like other keys from the default session, geoip will not
be persisted unless there is non-default stuff in the session.

Because the CSRF-TOKEN is based on the session-id, it is important the
session-id stays the same across multiples requests even when the
session is not persisted on disk. Even when a session is not persisted
on disk, the session-id cookie is still set so that the next session
created on-the-fly uses the same session-id.

Technical note regarding the session, it has been decided to drop the
session-snapshot protocol and to reintroduce a "modified" flag. It has
been decided not to use werkzeug's session (which natively comes with a
"modified" flag) and to keep our own session object. We decided to
extend MutableMapping instead of dict; using MutableMapping we only
have to override __setitem__ and __detitem__; using dict we would had to
override update()/pop()/... too.

Task: 2789035
Part-of: odoo/odoo#86015
2022-04-05 14:13:54 +02:00
Julien Castiaux 5ced646b3f [FIX] auth_signup: impossible to login
Install auth_signup, go to /web/login, 500 Internal Server Error.

auth_signup extends the /web/login template and in this extension calls
`keep_query()` which has been wrongly moved from base to http_routing in
commit 880954ebfc. Here, we restored `keep_query()` in the base module
but moved in ir_qweb.

closes odoo/odoo#87491

Related: odoo/enterprise#25754
Signed-off-by: Julien Castiaux <juc@odoo.com>
2022-03-30 17:35:06 +02:00
Gorash 880954ebfc [IMP] *: remove _render from ir.ui.view and simplify report
There were inconsistencies in the calls to `_render`.
* the view context could contain information that misled developers.
Indeed, the context and value of the view are not supposed to be found
in the rendering. Thus by calling `ir.qweb` with the name of the
template, we ensure that there is no unwanted information and in
addition the cache key is that of the name of the template which saves
a query.
* the context used for rendering was modified by a method on
`ir.ui.view`, except this is not information used by this model. There
is now a `_prepare_environment` method residing on `ir.qweb`. This
method allows to modify the value dictionary as well as the context in
which the rendering will be done. This preparation of the data as well
as my security check is done only once per rendering. This also saves
some queries
* Freeze options for rendering were inconsistent. It could be that
options on which rendering depends were not part of the cache key. Thus,
depending on the user who generated the generation of the rendering
function, there was or was not information in the template. For example
for automatic branding. This is no longer possible, because it is the
context that is used. The options serving as a cache key are only
recorded for information (for the profiling system for example). A
simplification of the `ir.qweb.field` models could be made.

The report rendering and call `ir.qweb` instead of `ir.ui.view`.

Part-of: odoo/odoo#85110
2022-03-29 10:56:15 +02:00
Gorash a327b2ec8a [IMP] http_routing: display UserError from Qweb error
Part-of: odoo/odoo#85110
2022-03-29 10:56:15 +02:00
Julien Castiaux 8639f9b257 [FIX] website: restore debug mode in website pages
Install website, create a custom web page, we'll call it page_1. Ensure
you are not in debug mode (go to /web/health?debug=0 to disable it).
Open the web page enabling the debug-mode /page_1?debug=1, the page
opens but the debug mode is disabled.

Because web pages are served using another routing mechanism than
controlers we have to ensure we load the debug query-string in those
mechanisms too.

closes odoo/odoo#85340

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2022-02-28 13:53:09 +00:00
Julien Castiaux 06cc322e7e [REF] core: HTTPocalypse (13) http_routing/website
This commit is the 13th commit of a comprehensive refactor of our HTTP
framework. See odoo/odoo#78857 for complete historic, discussions and
rationnals.

Here be dragons.

First and foremost, `http_routing` is a technical module that aim to
provide the minimum viable compatibility code between portal and
website. Its primary job is to take care of the lang inserted in the
path of URLs, e.g. `en` in `/en/my_blog`. Both when routing a request
with a lang in the URL and when rendering templates with multilang
support.

Next to `http_routing` is website, the module used by customers to
create pretty web page accessible online. Website uses a different
routing logic than the backend, webpages are **not** registered in the
routing map of werkzeug but instead delivered by website dedicated
code. It means that **all** request targeting a website page thrown at
the werkzeug router **fail** with a HTTP 404 error. The reality is that
website abuses the fallback mechanism (`_serve_fallback`) to deliver
its pages.

Using `_serve_fallback` as the standard way to deliver pages is broken
by design. It is the least crappy way to deliver content as long as
website page don't have a dedicated path prefix. Using a path prefix
(e.g. `p` in `/p/fr/mon_blog`) it would have been possible to route the
request to a dedicated endpoint using the same router as the backend and
with no change to the HTTP dispatching code. Sadly, the business does
not want such prefix so we have to stick with a broken design.

It is broken because prior to serving a page, website needs to setup A
LOT of stuff on the system. It needs to ensure a proper user is set on
the environment, it needs to setup the GeoIP database, it also needs
to determine the lang the user requested the page and it also needs to
save multiple attributes on the request objet itself (`is_frontend`,
`is_frontend_multilang`, `routing_iteration`, `website`, `lang`,
`rerouting` and `website_routing`). Since `base/ir.http@_match()` will
fail, everything must be set either prior to calling this method or in
`website/ir.http@_serve_fallback`.

---

The original implementation was overriding the `_dispatch` method which
was responsible to call the four `_match()`, `_authenticate()`,
`_postprocess_args` and finally `WebRequest._dispatch()`. The override
was very special, here is an attempt to explain it:

1) try to match an endpoint using the backend router, 404-errors are
   ignored.
2) include the geoip stuff.
3) authenticate using the `auth` @route argument if an endpoint matched
   in (1), otherwise authenticate with the public user.
4) if not endpoint matched or if a frontend endpoint matched in (1):
  a) call `_add_dispatch_parameters` which sets many arguments on the
     `request` object, including the lang found in the request cookies
  b) try to extract a lang from the URL: abort with a redirection when
     the lang is missing or wrong, remove the lang from the request
     path when it is set (updating both `request.lang` and the cookie).
5) return the result of `super()._dispatch()`

Note that `_serve_fallback()` is called during `super()._dispatch()`
when the path still does not route to an endpoint. Thanks to the
`_dispatch` overrides in http_routing and website, it is garanteed that
the system is setup prior to calling `_serve_fallback`.

---

Because it is now `http.py@Request._serve_ir_http()` that is responsible
of calling the four`_match()`, `_authenticate()`, `_pre_dispatch` and
finally `_(http|json)_dispatch()` it is no more possible to override it
to take over the dispatching to perform the http_routing/website magic.
The prior implementation can not work with the new design thus is has
been refactored too.

To render a website page, there must be a user configured on the
environment (not None) and the various special attributes must be set on
the request object. The special `lang` attribute is popped from the
request path but backend endpoints must be delivered in priority.

Using the new design, it has been decided to override the `_match`
method to implement the lang-in-path logic, to override both
`_pre_dispatch` and `_serve_fallback` to call `_add_dispatch_parameters`
which have been renamed `_frontend_pre_dispatch` and to also grant the
public user in the `_serve_fallback` override.

The `_handle_error` override in website has similar needs, the function
is called upon error (4xx/5xx) in order to render a pretty
website-looking page. Because such error can occurs as early as in
`_match()` (page not found and no fallback), when nothing has been setup
yet, website is yet again responsible for setuping everything: request,
orm, frontend.

Many other small improvement are not described here. Hopefully the added
comments in the source code are enought.

PR: odoo#78857
Task: 2571224
2022-02-24 13:30:50 +00:00
Wolfgang Taferner c099709b85 [FIX] http_routing: mitigate key does not exist in context for lang
closes odoo/odoo#84478

X-original-commit: bdde46dad4d5886a8423bfaa0cac316784c7d382
Signed-off-by: Olivier Dony <odo@odoo.com>
2022-02-14 19:25:02 +00:00
Gorash e830953570 [IMP] IrQweb: refactoring and add technical documentation
Major changes:
- Remove some of the recursively when compiling
- Compile attributes became a directive
- Compile options became a directive
- `t-field` compilation now uses the same logic as `t-out`
- Simplification of ``t-if`` directive compilation
- Improved handling of errors wrapped by QWebException
- Constants defined outside the class

    Odoo
     ┗━► _render (returns MarkupSafe)
        ┗━► _compile (returns function)                                        ◄━━━━━━━━━━┓
           ┗━► _compile_node (returns code string array)                       ◄━━━━━━━━┓ ┃
              ┃  (skip the current node if found t-qweb-skip)                           ┃ ┃
              ┃  (add technical directives: t-tag-open, t-tag-close, t-inner-content)   ┃ ┃
              ┃                                                                         ┃ ┃
              ┣━► _directives_eval_order (defined directive order)                      ┃ ┃
              ┣━► _compile_directives (loop)    Consume all remaining directives ◄━━━┓  ┃ ┃
              ┃  ┃                              (e.g.: to change the indentation)    ┃  ┃ ┃
              ┃  ┣━► _compile_directive                                              ┃  ┃ ┃
              ┃  ┃    ┗━► t-if            ━━► _compile_directive_if                 ━┫  ┃ ┃
              ┃  ┃    ┗━► t-foreach       ━━► _compile_directive_foreach            ━┛  ┃ ┃
              ┃  ┃    ┗━► t-inner-content ━━► _compile_directive_inner_content ◄━━━━━┓ ━┛ ┃
              ┃  ┃    ┗━► t-options       ━━► _compile_directive_options             ┃    ┃
              ┃  ┃    ┗━► t-call          ━━► _compile_directive_call               ━┫ ━━━┛
              ┃  ┃    ┗━► t-att           ━━► _compile_directive_att                 ┃
              ┃  ┃    ┗━► t-tag-open      ━━► _compile_directive_open          ◄━━┓  ┃
              ┃  ┃    ┗━► t-tag-close     ━━► _compile_directive_close         ◄━━┫  ┃
              ┃  ┃    ┗━► t-out           ━━► _compile_directive_out             ━┛ ━┫ ◄━━┓
              ┃  ┃    ┗━► t-field         ━━► _compile_directive_field               ┃   ━┫
              ┃  ┃    ┗━► t-esc           ━━► _compile_directive_esc                 ┃   ━┛
              ┃  ┃    ┗━► t-*             ━━► ...                                    ┃
              ┃  ┃                                                                   ┃
              ┗━━┻━► _compile_static_node                                           ━┛

closes odoo/odoo#81024

Related: odoo/enterprise#22942
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2022-02-03 08:09:31 +00:00
Gorash 9ce5bc8881 [IMP] IrQweb: merge Qweb engine file qweb.py and ir_qweb.py
QWeb is the primary templating engine used by Odoo. It is an XML
templating engine and used mostly to generate XML, HTML fragments and
pages.

To create new XML template, please see :doc:`QWeb Templates documentation
<https://www.odoo.com/documentation/15.0/developer/reference/frontend/qweb.html>`

In **input** you have an XML template giving the corresponding input
etree. Each etree input nodes are used to generate a python function.
This fonction is called and will give the XML **output**.
The ``_compile`` method is responsible to generate the function from the
etree, that function is a python generator that yield one output line at a
time. This generator is consumed by ``_render``. The generated function is
orm cached.

In the graphic below you can see theresume of the call of the methods
performed in the IrQweb class.

    Odoo
     ┗━► _render (returns MarkupSafe)
        ┗━► _compile (returns function)                                        ◄━━━━━━━━━┓
           ┗━► _compile_node (returns code string array)                       ◄━━━━━━━┓ ┃
              ┃  (add technical directives: t-inner-content, t-tag)                    ┃ ┃
              ┣━► _directives_eval_order (defined directive order)                     ┃ ┃
              ┃                                                                        ┃ ┃
              ┣━► _compile_directives                              (recursive) ◄━━━━┓  ┃ ┃
              ┃  ┣━► _compile_directive                                             ┃  ┃ ┃
              ┃  ┃    ┗━► t-if            ━━► _compile_directive_if                ━┫  ┃ ┃
              ┃  ┃    ┗━► t-foreach       ━━► _compile_directive_foreach           ━┫  ┃ ┃
              ┃  ┃    ┗━► t-*             ━━► ...                                  ━┛  ┃ ┃
              ┃  ┃    ┗━► t-inner-content ━━► _compile_directive_inner_content ◄━━━━┓ ━┛ ┃
              ┃  ┃    ┗━► t-tag           ━━► _compile_directive_tag               ━┫    ┃
              ┃  ┃    ┗━► t-call          ━━► _compile_directive_call              ━┫ ━━━┛
              ┃  ┃    ┗━► t-out           ━━► _compile_directive_out           ◄━┓ ━┫
              ┃  ┃    ┗━► t-field         ━━► _compile_directive_field          ━┛  ┃
              ┃  ┃                                                                  ┃
              ┗━━┻━► _compile_static_node                                          ━┛

Part-of: odoo/odoo#81024
2022-02-03 08:09:31 +00:00
Nicolas Lempereur 4e24115a31 [FIX] http_routing: redirect no double query_string
Reproduction:

- have 308 redirection from /shop to /boutique and refresh routes
- go in incognito on /boutique?order=name+asc (don't go on
  /boutique first, or restart odoo to clear ORM cache)
- select a sorting option eg. price

=> we are redirected to /boutique?order=name+asc?order=list_price+asc
and this error is shown:

Invalid "order" specified (is_published desc, name asc?order=list_price
 asc, id desc).

This is happening because url_rewrite is keeping current query string
(see ir.http()._slug_matching) and caching it. So if the first call
caches:

  url_rewrite('/boutique') => /boutique?order=name+asc

all other url_rewrite('/boutique') calls will give you
/boutique?order=name+asc even if the query string has changed.

In addition to that, url_for may append query_string to url_rewrite
return value, so you may get a double query_string such as:

?order=name+asc?order=list_price+asc

which causes the error.

In this fix, we restore the removal of query string that was removed in
3beb4545c4.

opw-2702036

X-original-commit: 5dcf6e91fed769f4ab22ac63d3e5078cdd352e86
Part-of: odoo/odoo#82099
2022-01-04 10:26:16 +00:00
Fabio Barbero a66cdf3f7f [IMP] link_tracker, http_routing: ignore requests from social bots for link tracker
Purpose
=======
Avoid counting requests from social bots (twitter, facebook, linkedin...)
when tracking a link.

Specifications
=============
Social media platforms have a specific user agent in the HTTP headers that
can be used to detect them and to not increment the click count in that case.

Task-2578902

closes odoo/odoo#78806

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-12-14 09:11:15 +00:00
Jeremy Kersten 5945e8e4e3 [FIX] http_routing: don't remove trailing / during redirect
Before this commit, since we promote the use of route without trailing / for
best SEO (fee0113), we remove the trailing / during a redirect to avoid an
extra request.

Unfortunately, it will break some route with trailing / in case of multi lang.

So we remove this optimization, it will increase potentially number of http
request before to get the final url, but it will allow to continue to support
trailing slash in v15.

This commit partially revert the commit ae35117

closes odoo/odoo#80191

X-original-commit: 84d2f5b57ccf3dbcefebdbc795ab1872bc1504b9
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-11-22 16:27:09 +00:00
Xavier Morel b51b094c2b [IMP] http: avoid cycle on request 2021-01-26 09:05:35 +01:00
Jeremy Kersten 914fe1085e [FIX] http_routing: avoid extra redirect on logout in multi lang
context:
Connected in /fr on a website with /en as default lang.

Before this commit,
  /web/session/logout?redirect=/
  /
  /fr_FR/
  /fr_FR

Now
  /web/session/logout?redirect=/
  /fr_FR

Part 1 -> to say that we are in multilang context and use url_lang.
   multilang=False to avoid /web/session -> /fr/web/session
   website=True to have url_lang done in the request.redirect.
Part 2 -> to remove the trailing '/' that will be only useful for '/'

closes odoo/odoo#76290

X-original-commit: ae35117ee1e019c3c0c333f291478825a5722706
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-09-10 08:49:13 +00:00
Jeremy Kersten b290bceada [FIX] http_routing: is_frontend can be unset on request
AttributeError: 'HttpRequest' object has no attribute 'is_frontend'

e.g.: when we call request.redirect in ensure_db(), before that the _dispatch
method check if it is a is_frontend route or not.

closes odoo/odoo#73759

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-15 10:27:57 +00:00
Jeremy Kersten 478068c829 [IMP] *: always use Odoo Response
This branch adds request.redirect on all requests.
In case of a front end request, we do an url_for to the location.

We removed redirect_with_hash that was only for retro compatibility

local_redirect has been renamed to redirect_query, and param keep_hash has been
removed and moved.

Default code for redirect is 303 now instead of 302.

Now redirect and redirect_query make local redirect by default, you need to
pass local=False to make external redirect.

All werkeug.utils.redirect has been replaced by request.redirect.

Http.redirect now use an http.Response type, and it become easy to add an
override like 'set_cookies' e.g.

Dispatch of a website.page return an http.response too, so we first need to
check if it is a cached version before to check if it is an Odoo Response.

Migrate your code:

http.redirect -> request.redirect(location, code, local)
http.local_redirect -> request.redirect_query(location, query, code, local)
http.redirect_with_hash -> request.redirect

Courtesy of odony for help and review ;)

closes odoo/odoo#72599

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-08 07:00:06 +00:00
Jeremy Kersten 1bf9367c6f [FIX] http_routing: fix url_for with querystring
before this commit

url_for('/fr?a=b') -> /fr/fr?a=b because /fr?a=b not in ['fr', 'en']

Now we split query string before to check that first path is a lang
2021-07-07 13:45:51 +00:00
Romain Derie 119d9437e0 [IMP] http_routing: remove trailing / for homepage with language
Before this commit, `/fr_BE/` and `/fr_BE` would both be served without one
being redirected to the other.
That would be considered as duplicate content, as 2 different URLs would be
serving the same content.

opw-2505818
opw-2513575
Community: https://github.com/odoo/odoo/pull/71065
Enterprise: https://github.com/odoo/enterprise/pull/18615
2021-06-03 12:06:07 +00:00
Jeremy Kersten 3e238439f2 [FIX] http_routing: url_rewrite return now a tuple
Fix of refactoring 91b9dce

closes odoo/odoo#66927

X-original-commit: 03a318ff36949c80008ae35b4c744272c9986b9e
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-02-26 14:03:30 +00:00
Jeremy Kersten 2ecc538d51 [FIX] website: handle RequestUID case in slug
Before this commit, a 308 on a route with a modelconverter for a model
that have a seo_name field will crash with an exception:
Cannot iterate on RequestUID

Another simplest solution was to use a with_user(SUPERUSER_ID) but in this case
it bypass the security set and display the name of the record even if not yet
published.

How to reproduce:

Create a 308 from /shop/<product> to /mag/<product>
Unpublish product 10
Try to access /shop/product-10

You have an unmanaged '500 internal error"
because slug_matching -> build -> to_url -> slug with a record with Requestuid
as env._uid.

X-original-commit: 4ac2cab96655a3c5e673b0a04be5599dba507850
2021-02-01 14:51:19 +00:00
Jeremy Kersten 4a88d09632 [FIX] website: fix url_for when no qs
Before this commit, old url was not rewrited in case you don't have any query
string.

X-original-commit: 959774b18283abe0c5a5c5ca0d379a1dda1d7a36
2021-02-01 14:51:19 +00:00
Jeremy Kersten 91b9dced64 [IMP] website: merge cache of is_multilang_url with url_rewrite
Fwd-port of 6e87ee0

closes odoo/odoo#64916

X-original-commit: 6e987e6f7f5e6422bb1d04ea8764ab298446ffb0
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2021-01-22 12:07:04 +00:00
Jeremy Kersten 62c208f8e7 [FIX] website: don't try to convert static url in multilang
Same for all /web/ urls that are no multilang

X-original-commit: 476978a1530469d7d93678aa5c0131d9b1fa767c
2021-01-22 12:07:03 +00:00
Adrian Torres b7017e58cc [FIX] *: adapt business code to function-redefined error
This commit adapts the business code in which
class/module/function/method redefinition took place so that it no
longer happens and the pylint test passes.
2020-10-16 12:56:52 +00:00
Xavier Morel 9e27956aa9 [FIX] core: handle cors preflight with custom auth
Odoo provides basic handling of CORS preflight requests: if an
endpoint is marked as `cors=<truthy value>` then it'll automatically
reply allowing the request.

*However* this is performed in `HttpRequest.dispatch` (likely in order
to correctly handle the nodb case), which means it's executed after
the auth handler has run... which means custom auth handlers will be
called on preflight requests.

This is a problem because they are missing relevant
information (e.g. which endpoint they're invoked for), plus having to
deal with preflight requests in every custom auth handler is annoying,
and simply allowing preflights could cause issues if the decision
diverges between the auth handler and the automatic
handling.

To fix this issue, extract the preflight *decision* into a separate
method so we get the same decision-making process everywhere, and in
case of CORS preflight set the auth to none to limit the eventual
capacity for nuisance in the span between the bypassed auth and the
automated preflight handling.

Also change the signature of IrHttp._authenticate so it's clearer if a
callsite was forgotten somehow (and this makes for less changes and
duplication at the callsites).

closes odoo/odoo#56029

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-08-19 13:41:24 +00:00
704bcc5527 [IMP] portal, *: move language switcher to portal
*: base, http_routing, website

Make the language switcher available on portal without website
installed.

Part of https://github.com/odoo/odoo/pull/55300
task-2203383

Co-authored-by: Jeremy Kersten <jke@odoo.com>
Co-authored-by: qsm-odoo <qsm@odoo.com>
2020-08-14 17:40:58 +00:00
Jeremy Kersten 3beb4545c4 [IMP] http_routing: add cache on rewrite computation
Before this commit each url was processed each time, now with have a cache
with the path (withtout query string) as key on each worker.
It reduces drastically the time of the rewrite check on hot. (~10x)

closes odoo/odoo#54690

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-07-22 07:25:00 +00:00
Jeremy Kersten 30e4873a2f [IMP] website: allow to have custom slug
Now, slug uses seo_name if field exists before to fallback on display_name.

It allow to have a custom url without change the product name already used in
backend e.g. or just because you want add some keywords for seo.

task-2291676
2020-07-07 13:11:57 +00:00
Martin Trigaux d9287caf94 [IMP] *: convert to private methods
render, render_template, load, activity_schedule_with_view,
get_website_pages should all be private:
It should not be possible to render an aribtrary template only with
its name or id

Still need to render some qweb views from js so the method
render_template is kept public.
This explains why the website editor still need read access on
ir.ui.view as we want to allow any snippet to be rendered.
2020-05-14 13:59:10 +02:00
alt-odoo d3ffc3248c [FIX] http_routing: small fixup due to commit 423402f1e5
Method _get_exception_code_values can return None value for code. We should avoid
getting a KeyError in HTTP_STATUS_CODES in this case.

closes odoo/odoo#50160

X-original-commit: ea138667d55b535d8ec51f86fd649e28d704ac76
Signed-off-by: Alex Tuyls <alt-odoo@users.noreply.github.com>
2020-04-24 14:30:17 +00:00
Julien Castiaux ab4000fb3c [REF] base: Remove deprecated exceptions and osv
TL;DR: remember `osv` and `except_orm` ? You can forget about them.

* Deprecated `except_orm` dropped.
* `UserError` elevated as super type of all user-related
  errors.
* Unused `DeferredException` dropped.
* Unused `QWebException` dropped (real one is in `qweb.py`).
* `MailDeliveryException` made a python exception.
* `name` legacy exception attribute made an alias of the python standard
  `args[0]` attribute and deprecated.
* `value` legacy exception attribute dropped.
* `exception_type` RPC error response key dropped.
* Deprecated `osv` module dropped.
* `--osv-memory-age-limit` cli option made an alias of
  `--transient-age-limit` and deprecated.

The `odoo.exceptions.Warning` have long been a deprecated alias to
`UserError`. It is going to be removed in a future version but first we
explicitly deprecate it with a warning.

The `odoo.exceptions.DeferredException` was a very old internal
exception, it has been removed without deprecation notice as it is never
raised.

The `odoo.exceptions.except_orm` has been a deprecated exception type
with deprecation warning for 5 years, it has been removed in favor of
UserError which becomes the super class of all user-related errors.

The `odoo.base.models.ir_mail_server.MailDeliveryException` was
inheriting `except_orm`. As it is not related to a user error but is
more of a problem an admin much take care of, the exception has been
made a Python error.

The `exception_type` JSON key in RPC error responses was holding an
hardcoded value derived from the exception type. Its usage has been
dropped in favor of the `name` JSON key that holds the precise exception
name. Again as it was hardly used in the source code (beside the crash
manager) it has been dropped without deprecation warning.

Since we are here trying to clean odoo custom exceptions, we are also
deprecating the `name` exception attribute in favor of the more standard
`args[0]` attribute.

The `name` (along with `value`) were two attributes used to raise
`except_orm` exceptions before the introduction of `UserError`,
`AccessError` and related exceptions. The `name` attribute, at the time,
was holding the exception type/title. Nowadays it contains the error
message. The `value` attribute, at the time, was holding the error
message. Nowadays it is no more used.

The `osv` module contains very old deprecated aliases. There is no
simple way to log a deprecation warning for osv, osv_memory and
osv_abstract but as they have not been in use for ages, they have been
removed too. To be consistent, the `--osv-memory-age-limit` cli option
has been made a deprecated alias to the `--transient-age-limit`.

closes odoo/odoo#45723

Task: 2187728
Related: odoo/enterprise#9162
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2020-04-08 08:41:17 +00:00
Jeremy Kersten 26c4de2f18 [IMP] http_routing: use cached code from lang
In case of short controller that don't use qweb template, we don't need
anyhting else that this url code that don't change frequently.

It make only sense for model like lang, website, ... that will not change
frequently. And are called on each call by the dispatcher.

In case of a website page, we will btw browse lang later, but in case of
small controller like /favicon.ico, or page without qweb, ... we can just
use the same from last query.
2020-03-26 18:12:47 +00:00
Jeremy Kersten 9430dd1287 [FIX] website: perf - use lang cache in url for.
Before this commit, url_lang (= url_for) will make query to find the lang_code
but we alrady have this info in ormcache with get_available method.

So instead to rebrowse (search query) the lang, we use a new method that will
try to find it in cache if possible before to make the query.

The gain on each page is n-1 (where n is # lang installed)
Because the switcher of languages do an url_for for each lang available.

Related to #47257
task-2211013

X-original-commit: 2cecbe356ce283e15fb0bbd0a6e9aa4735af520e
2020-03-19 15:37:47 +00:00
Jeremy Kersten 4c40393490 [FIX] website: perf - translation - avoid query to find what we know
Before this commit, each module override _get_translation_frontend_modules_domain
from ir.http to add its own translation in website if needed and that module
is not starting by website_. Updating the domain from the super() call.
Since we know in most of the case the name, it is useless to do a:
   select name from module where name = 'name1' or name = 'name2'...

Now we support a new override of _get_translation_frontend_modules_name that will
allow to add the known module name directly in the list instead to make a search.

In case nobody override _get_translation_frontend_modules_domain, we don't need to
make an extra rpc to find the module.

Related to #47257
task-2211013

X-original-commit: 0dc54814161ab55c34dd2242f65dea23d19fdfca
2020-03-19 15:37:47 +00:00
Jeremy Kersten c2142a34f7 [FIX] website: perf - cache the compute hash for translation
Before this commit, we compute the hash on each request, to know if we need to
download the file from the frontend or if we can use cache.

Now we store the hash computed in cache. The cache will be invalidated when we
touch one of these translations (openerp-web in the comments) or when you
install a new lang (already the case).

+ avoid to use read on a record, since it will not use the cache from record.

Related to #47257
task-2211013

X-original-commit: d5aaecbc51de19ef1d8d9988b691177fc73a4b86
2020-03-19 15:37:47 +00:00
Xavier Morel de590816d8 [FIX] *: deprecated access to url_ utilities through werkzeug root
In 0.15 accessing werkzeug.urls functions directly through werkzeug
is deprecated, the shortcut will be removed in the eventual werkzeug
1.0.

Fix existing uses of these shortcuts. Also cleanup some imports when
they're not far from a werkzeug* import being altered.
2020-02-04 12:42:35 +00:00
Toufik Ben Jaa b22ba61c80 [FIX] website: rollback transaction before creating new one
- When rendering a website page, exceptions might happens.
    If so, an error page is displayed, to do so we create
    a new psyscopg cursor to read the view in database and render it.

    But if the current (failed) transaction was holding a lock, the new
    cursor might have to wait for this lock to be released further
    down the line. However, this will only happen after the
    request is done (and in fact it won't happen). As a result, the
    current thread/worker is frozen until its timeout is reached.

    So rolling back the transaction will release any potential lock
    and, since we are in a case where an exception was raised, the
    transaction shouldn't be committed in the first place.

closes odoo/odoo#44085

X-original-commit: 7a61c89da5ccaed983275eb5f4986475ebf8b48d
Signed-off-by: Toufik Benjaa (tbe) <tbe@odoo.com>
2020-01-28 11:13:55 +00:00
Romain Derie 9b3de32478 [FIX] http_routing, website: fix frontend lang in http dispatcher
This commit fixes 2 issues, both coming from a misbehavior in
`get_nearest_lang()`:
1. Anyone could reach the website in a lang available in backend but not in
   frontend. Eg, french is activated but not a website lang, going to `/fr`
   would show the page in french.
2. As a logged in user coming from backend in a lang not available in frontend
   (has request.lang set to that lang), the website would show a 500 error page
   since it would not filter out the current request lang.

Both these issues are fixed here by ensuring langs are filtered out if they do
not belong to the frontend (website langs).

Step to reproduce (bug 1):
  - Install french in backend lang (not on website)
  - Visit `127.0.0.X/fr_FR`, the frontend will be displayed in french even if
    it not a lang available in frontend.

Step to reproduce (bug 2):
  - Install french on frontend and remove english from frontend
  - Navigate to the backend /web
  - Navigate to frontend, it will crash

Fixes #40572 and fixes #40078

closes odoo/odoo#41146

X-original-commit: 4bfba037fbbf34c178abd532f7bf52b94ae40b27
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-12-02 08:31:26 +00:00
Jeremy Kersten dc77f67cad [FIX] website: match get/post in is_multilang_url
Old heuristic is not more True:
Force to check method to POST. Odoo uses methods : ['POST'] and ['GET', 'POST']

We have some controller that only allow 'GET' method, so we need to check GET
also when we try to know if an url is multilang or not.

This commit fix case where a controller '/test' only allow GET and you were in
another language that the default, in this case, the rendered url in qweb was
/get instead of /<lang>/get.

Closes #37223

closes odoo/odoo#40519

X-original-commit: c7650106f8588083be12812600a6c94ba703fd6f
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-11-26 14:35:46 +00:00
Jason Van Malder 16e6907efa [FIX] http_routing, portal: fix web translations not loaded
Reproduce the issue

    - Install eCommerce & Sales
    - Create a quotation
    - Preview
    - Switch to french on the website page
    - Click on "Signer & Payer"

    There is a lot of things not translated.

Cause

    On the website, the route `/website/translations` is called.
    The route calls a method `_get_translation_frontend_modules_domain`
    which teturn a domain to list the domain adding web-translations and
    dynamic resources that may be used frontend views.

    The missing translations are in the web module and the module is not
    loaded by the method.

This commit adds the `web` module to the domain and a missing
translation for the portal module

OPW-2120397

closes odoo/odoo#41072

X-original-commit: 50c2ecbc9ef0e446af0a1d4010ec1d923aa41bec
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2019-11-28 15:22:41 +00:00
jvm-odoo dc771b1a5c [FIX] http_routing: fix context language used when not available
A customer reported a problem when he deleted a language on the
website app.

In some cases, if you go on the odoo's generated website as a public
user let's imagine the following url: website.com/en_GB

The lang is saved in a cookie and sent to the context.

If you delete the language from the website languages (without
deactivating it) and you go on website.com as a public user,
the method will try to use the context or the cookie value which is
'en_GB' and it crashes.

This commit makes sure that the language is available

OPW-2129580

closes odoo/odoo#41007

X-original-commit: f3e9ca13f60ced0ec61cea0d13da45b2569da14e
Signed-off-by: Jason Van Malder <jasonvanmalder@users.noreply.github.com>
2019-11-27 12:14:21 +00:00
Xavier-Do fe0da16a24 [FIX] http_routing: revert b6ed34e1 and check _rewrite_len
Initial b6ed34e1 idea was to ensure that we always have
_rewrite_len and _routing_map defined. Unfortunately, this
is not correct since class attribute defined dynamically
are actually added in registry, and recomputed on each install.
More than that, the call si shared between multiple database
meaning that routing_map cache may be shared between multiple
database whcich is not correct.

After b6ed34e1, when installing discuss on a fresh database without
demo, all discuss routes will be unknown since None is already in
_routing_map and thus routing_map is not recomputed.

When routing_map is on the model class, in registry,
a new install will reset the class, remove the _routing_map attribute,
which will fix the problem.

Task #2117275

closes odoo/odoo#39640

Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2019-10-31 13:56:19 +00:00
Jeremy Kersten e239934abe [FIX] website: allow to modify the visibility of a page
Now, you can define a Visibility mode between:
    Public (All poeple)
    Connected (Portal or Employee)
    Restricted Group (Has this group or is Employee)
    With Password (Know password or is Employee)
    Internal Users (Is Employee)

It is a 'fair' feature, but without really warranty that the content is
really unreadable via others methods, ...

It is more for frontend display, that real secret. Dont use this like
a keychain ;)

We only catch the visibility on the main view and not the t-call inside.

Even if it should work on controller too, it is only display now on the
page property menu. (Or on the view directly in backend)

task-2091365
2019-10-29 16:04:47 +00:00
Xavier-Do d65fcfecb6 [FIX] web: avoid expensive 404 during js tests
A 404 will take 3 to 5 seconds to be resolved and execute +- 1900 query, to return
a rendered page which is quite expensive, especially when multiple missing images
are rendered in a view.

Catching static route and marking them as not frontend will help to avoid to handle miss
on static resources. In this case server returns a standard 404.

This commit also fix a iframe src in order to avoid a 404 on
/web/(test )/report/html/some_report (thx to aab-odoo)

X-original-commit: 818d0cb59fbae78d0edf06318082981f318e4db7
2019-10-17 17:10:06 +00:00
Christophe Simonis 97842368ef [FIX] http_routing: avoid using deprecated methods
Oversight of previous forward-port.
2019-10-09 02:39:09 +02:00
Christophe Simonis d74b451805 [MERGE] forward port branch 13.0 up to f4105eb9c7 2019-10-09 02:08:17 +02:00