Commit Graph
30 Commits
Author SHA1 Message Date
Julien Castiaux da8def8e41 [IMP] core, web: Delegate delivery of static files
Rationnals
----------

Web servers can serve some resources (e.g. static files) right away
without any interaction with the web application. The network model of
most web servers makes them capable of handling thousands of
simultaneous requests when it comes to intensive IO operations such as
streaming data from a file. The network model of Odoo is different: it
is capable of a lot of processing power but can only serve a handful of
requests at a time, i.e. Odoo (with some help from postgres) is
optimized for CPU operations, not IO.

Some users don't configure their web server, they use a basic
configuration that relay all requests to Odoo. The result is that many
Odoo HTTP Workers can be busy streaming static files instead of
processing other requests. This can lead to a worker starvation, i.e.
all workers are busy streaming files and cannot process new requests.

X-Sendfile
----------

In this work, we add the support for the [X-Sendfile] header family,
they are multiples http headers that can be used by the web application
to communicate with the web server in order to delegate the delivery of
files stored on the file system. Odoo still receives the request but it
does no more stream the file content from within its HTTP worker,
instead it skips the response body altogether and sets the `X-Sendfile`
special header with the path of the file on the filesystem. The web
server intercepts that special header, open the file and stream it.

Using those headers, we can use the best of both the web application and
the web server. The web application is still responsible to locate the
resource and verify the access rights, the web server is still
responsible of streaming the content.

Using X-Sendfile is opt-in via the `--x-sendfile` CLI flag. We set both
`X-Sendfile` (apache) and `X-Accel-Redirect` (nginx). If you are using
apache, make sure `mod_xsendfile` is enabled. If you are using NGINX
you have to add the following location block:

    location /web/filestore {  # custom path, hardcoded within Odoo
        # Prevent access from the outside world, i.e. makes this
        # route only accessible via X-Accel. MANDATORY!!!
        internal;

        # Give access to the filestore using this server's
        # permissions. Odoo is in charge of verifying the access
        # rights.
        alias /path/to/odoo/data-dir/filestore;
    }

The Odoo [deployment documentation] has been updated accordingly.

[X-Sendfile]: https://www.nginx.com/resources/wiki/start/topics/examples/xsendfile/
[deployment documentation]: https://www.odoo.com/documentation/master/administration/install/deploy.html#serving-static-files-and-attachments

Changes to the API
------------------

To benefit most from X-Sendfile, all APIs related to streaming content
over HTTP has to be adapted. They are: (1) `request._serve_static`,
(2) `ir.http._serve_fallback`, (3) `/web/content` and (4) `/web/image`.

Each used it own way to deliver content: (1) `_serve_static` was using
`send_file` (flask's send_file that as been vendored with odoo 10
years ago and not maintenained since then), (2) _serve_fallback was
handcrafting a `werkzeug.wrappers.Response`, (3) /web/content-image were
using the "binary server" `ir.http.binary_content` API.

I has been decided to remove all 3 APIs and to merge the code inside of
the new `http.Stream` object and the `ir.binary` helper model.

A Stream wraps what is going to be sent to the browser, it can be a path
to a file on the locale filesystem, a blob of raw data or an URL to an
external resource. The Stream also holds various metadata that are
mainly used for caching. The preferred way to create a Stream is via one
of its three factories so that all the metadata are set. The factories
are: `from_path`, `from_attachment` and `from_binary_field`. A stream
instance exposes a single method `get_response()` used to create the
corresponding HTTP response object out of the stream.

Inside of `ir.http` were a few methods that were not related to the http
routing and formed what was called the "binary server". All those
methods have been removed and the feature have been refactored inside of
the new `ir.binary` model. The removed methods are:

- `_xmlid_to_obj`
- `_get_record_and_check`
- `_binary_ir_attachment_redirect_content`
- `_binary_record_content`
- `_binary_set_headers`
- `binary_content`
- `_response_by_status`
- `_get_content_common`
- `_content_image`
- `_content_image_get_response`
- `_placeholder_image_get_response`

The new `ir.binary` abstract model exposes the following utilities:

**`_find_record`**

Find an attachment or a record with a binary-field out of an xmlid or
out of a pair record-model/record-id. Check the access rights and the
access token.

**`_get_stream_from`**

Create a Stream from an attachment or a record with a binary-field.

**`_get_image_stream_from`**

Same as `_get_stream_from` but adapted for images. It sets a sensible
ETag on the stream and has image resizing support.

**`_placeholder`**

Get the image placeholder blob.

Testing
-------

It is possible to test the web server configuration using the
`test_http` module. Install the module then run the unittest using the
`webserver` test-tag. By default it attempts to connect to a web-server
running on `http://localhost:80`, you can change this URL by setting the
`WEB_SERVER_URL` environment variable.

    odoo-bin -i test_http --stop-after-init
    WEB_SERVER_URL='http://localhost:80' odoo-bin --test-tags webserver --stop-after-init

closes odoo/odoo#88134

Task: 2801675
Related: odoo/documentation#2083
Related: odoo/enterprise#26191
Signed-off-by: Julien Castiaux <juc@odoo.com>
2022-06-01 02:53:59 +02:00
root 41b5d4306e [IMP] purchase: create hook to override searchbar sortings
With this commit we can now call a hook when we want to modify the code for this route.
Before this commit the only way to modify/extend this would be by taking over a big part of the code.

closes odoo/odoo#84905

Signed-off-by: Arnold Moyaux <arm@odoo.com>
2022-02-18 15:30:47 +00:00
Fabien Pinckaers 6b87526048 [IMP] Speed Imp: remove unnecessary base64 encode & decode
Avoid to base64 encode, then decode to process assets and images for a ~25% speed improvement.
Change image processing tool to work on images, rather than base64 encoded strings.

Performance is ~25% faster on assets & images:

  /web/assets/...frontend.min.css:    13ms to 7ms,  base64 enc/dec: 2 -> 0
  /web/image/XML_ID:                  10ms to 8ms,  base64 enc/dec: 3 -> 0
  /web/image/res.users/2/avatar_128:  40ms to 20ms, base64 enc/dec: 6 -> 2

closes odoo/odoo#82851

Related: odoo/enterprise#23537
Signed-off-by: Fabien Pinckaers <fp@odoo.com>
2022-01-22 11:51:42 +00:00
Louis Wicket (wil) 80d74e7ee0 [IMP] mail, web, *: add support for guest users
* = crm_livechat, hr, hr_holidays, im_livechat, mail_bot, purchase, sms,
    snailmail, survey, test_discuss_full, test_mail, web_editor, website,
    website_livechat

 - Create new model `mail.guest` for guests.
 - Rewrite some RPCs to target routes rather than model methods so that
   guests are able to use them.
 - Patch JS and python models to support guests.
 - Create a stand-alone page and boot the channel in it.

task-2494829

closes odoo/odoo#75496

Related: odoo/enterprise#20417
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2021-09-02 00:43:34 +00:00
JF Aubert b71a62b515 [IMP] purchase: Purchase order portal view
Show the purchase orders which are in state "RFQ sent" on the portal
using two separate blocks (Requests for Quotation & Purchase Orders)
as done in Sales (Quotations & Sales Orders)

closes odoo/odoo#61035

Task: 2035476
Signed-off-by: William Henrotin <Whenrow@users.noreply.github.com>
2021-04-07 13:49:46 +00:00
Achraf (abz) a07fc355aa [FIX] purchase: Display the right logo in portal with multicompany
What are the steps to reproduce your issue ?

    1. Create two companies on a multi-company database without Website installed.
        For this use case, install Purchase
    2. Configure two distinct logos per company
    3. Create a Purchase Order with the second company.
    4. Send PO from second company over as email.
    5. Check recipient email (or mailhog for Runbot) for the email
    6. Find that while the PDF report reflects second company's logo,
        the header navigation bar in the client email when clicking "View Request
        for Quotation" reflects company_id=1's logo.

What is currently happening ?

    The displayed logo is not the correct one.

What are you expecting to happen ?

    Display the right logo.

Why is this happening ?

    Because when rendering the view. The value of 'res_company' declared in the context has as value the id of the default company of the user

How to fix the bug ?

    Specify the current company.

opw-2380274

closes odoo/odoo#62066

X-original-commit: 044bca5e64451d86c6f7c9dbb919c0c319a37bd5
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
Signed-off-by: Achraf <abz-odoo@users.noreply.github.com>
2020-11-20 09:19:58 +00:00
Nicolas Martinelli 691c14c070 [FIX] account, purchase, sale: portal access error
- Install account / purchase / sale
- Ceate an internal user without any access rights
- Go to `/my`

A 500 error is raised because of an AccessError.

When the user has no access rights to any of the mentioned applications,
the `search` call returns an AccessError.

We prevent the access error and return 0 as a fallback.

opw-2367559

closes odoo/odoo#60849

X-original-commit: 54ef98c613219aba3bda41817f7767261b8092d2
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
2020-10-27 15:36:48 +00:00
Adrian Torres b7017e58cc [FIX] *: adapt business code to function-redefined error
This commit adapts the business code in which
class/module/function/method redefinition took place so that it no
longer happens and the pylint test passes.
2020-10-16 12:56:52 +00:00
Victor Feyens 2da7bc2adb [REM] portal, *: remove archive_groups dead code
PURPOSE

Clean code and be and more performance oriented.

SPECIFICATIONS

Various portal pages hold references to archive_groups. It was a summary
of customer documents for portal, containing a count of all documents split
by model.

Currently its computation is not used. Indeed archive_groups is displayed
only in 'my_details' page that does not hold any document-based reference
or code call. Other calls to archive_groups are dead code as the result is
not used. Since 13.0 it is even not computed on standard pages to speedup
their load (as it was not used).

It is not used anymore and its computation and references can be removed
safely, especially with v14 in mind for which we want to remove dead code
to maintain.

Followup of odoo/odoo#55228

LINKS

Task ID-2329081
PR odoo/odoo#55800
PR #12368

closes odoo/odoo#56859

X-original-commit: e75086000ee4317b2ad2994db5d906fbcbd5081f
Related: odoo/enterprise#12830
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2020-09-01 10:30:32 +00:00
Rémy Voet (ryv) 8d62eacfff [FIX] *stock*, mrp: fix effective_date
- Avoid to truncate the hour/min/sec in the computation of the
effective date which is related to the `date_done`
of the first incoming picking.
- With manufacturing in 3-step (pbm_sam), the store picking
had a source document == "New". It was the case because
the `_get_move_finished_values` was call before the create
and the name is set only on create.
To fix this issue, during the `create` set the origin of all move.
- To avoid to maintain old views unused,
remove unused view of stock move.
- The computation of the products_availability json is too expensive
to be in tree view (2.5 times long with it) of picking.
It will be hard to optimize because the half the time
is due to _get_report_lines method - already in batch (on 80 records).
- Review buttons of the replenishment list to be more Odooer.
- In some cases the delay alert date was wrongly compute:
  - If we new dest_move_ids of a existant move, the delay alert date
    won't be compute.
  - If the state (to done) and the date are save in same write call
    the alert date of next move won't be reset.
To avoids these issues, refactor the alert date to be a compute stored
fields.
- To avoid any confusion between date expected in the replenishement
(in date) and the purchase order receipt date (datetime),
we put the receipt date at the middle of the day.
Also  On-Time Delivery Rate computation counts
only when date are bigger effective date trunced to date.
Also used the timezone of the company by default (if not user timezone)

task-2246665

closes odoo/odoo#55379

Related: odoo/upgrade#1586
Related: odoo/enterprise#12309
Signed-off-by: Arnold Moyaux <amoyaux@users.noreply.github.com>
2020-08-18 07:48:27 +00:00
Jeremy Kersten 73b4e9b1b6 [IMP] portal,*: /my counter async
Before this commit, the time to compute all counters was making the rendering
of the portal page slow.

Now the count is done in rpc after the loading of the page.

Now you can decide which part you want to show on the portal, and only compute
for these one.

It is not because you have purchase installed for your internal process, that
it means that your supplier use your portal and it avoid the computation for
all end users.

We parallelize the counters in arbitrary 3 rpcs.

closes odoo/odoo#55999

Related: odoo/enterprise#12456
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-08-17 15:59:03 +00:00
Victor Feyens 71f3fa991c [IMP] *: disable unused archive_groups feature in portal
The archive groups feature allows the user to have fast access to
records of a given month, under its details information.

But since the details section isn't shown anymore on portal sub-pages,
the feature is computed for nothing on (most) pages.
Removing this computation avoids a read_group call on portal subpages
(multiple potential queries).

This commit disables the feature until a total removal in master.
my_details is only truthy on the /my/account portal page, where no
archive_groups is given anyway (and the value is set to True only in the
rendered tempate itself).

X-original-commit: 40c57fafdd5651a522891ab68affe38933ea5202
2020-08-03 07:23:30 +00:00
Victor Feyens 34fb9f3159 [IMP] portal,*: do not compute record counts for portal subpages.
The record counts are only useful for the badges displayed in /my &
/my/home.
By avoiding those counts on subpages, we gain a lot of useless queries,
improving the loading speed of those sub-pages.

X-original-commit: 79c8384f1bcbcdede030e187008319a70c664571
2020-08-03 07:23:29 +00:00
yhu-odoo 0d3d26aca1 [IMP] purchase(_stock): portal update scheduled date
1. Show only date not datetime on update portal. When update the
scheduled date, set it to be the last minute of that date.
2. Send updated date immediately when user pick a date.
3. If an activity for update the date already exist, update the
note instead of creating a new one.

Task #2265912
PR 52809
2020-06-29 13:27:17 +00:00
yhu-odoo 181c7d82e3 [IMP] purchase: send reminder mail to vendor
1. automatically send a reminder mail to vendor to confirm the receipt
date. If confirmed, (confirmed by vendor) will be added next to the
receipt date. If not, vendor can update the date on the portal website.
An warning activity will be set for the purchase representative for this
update.

2. Vendor can also comfirm recieption of the PO when we 'send PO by mail'.
If confirm, (confirmed by vendor) will be added next to the confirmation
date. An filter is added in the PO search view to show all unconfirmed
PO.

Task 2230811
PR #49921

Signed-off-by: Simon Lejeune (sle) <sle@openerp.com>
2020-05-27 08:20:17 +00:00
Ravi Singh 9bfce9a999 [IMP] purchase: revamp of purchase order view inside portal.
In this commit- we have changed purchase order view(portal side) and included
sidebar and chatter just like so view.

task-2124829
Closes #48402
2020-04-16 06:21:51 +00:00
David Beguin 307f51ab85 [IMP] web: split _content_image with get response sub method
This commit splits the _content_image method to allow to call the
get response part individually.

This is needed because _content_image call binary_content using current user
access. But in some cases, we need to render a binary content even if the user
does not have access to the target model (typically for public users).

The binary_content is gotten in sudo mode where needed and the result can be
given to the _content_image_get_response.

This will avoid code duplication where the sudo use case is met.

Usage :
This commit prepare the redesign of survey. This _content_image_get_response
method will be called to grant access of background image even for public
users. Other modules will use this new method like elearning (website_slides)
to display karma ranking, etc.

Task ID: '2150291'
PR #43237
2020-01-17 10:25:20 +00:00
laa 9cfb6c05a4 [FIX] Portal : missing url args
on the portal:
- in Timesheets, when search something, the text of the search must remain displayed
- in Tasks, when search something, the text of the search must remain displayed
- in Purchase Orders, "Sort By" and "Filter By" selectors shouldn't change when going to next page
- in Timesheets, the "Group By" selector shouldn't change when going to next page

closes odoo/odoo#40278

Related: odoo/enterprise#6787
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-11-28 15:39:03 +00:00
Yannick Tivisse 26e32dac34 [IMP] portal: Partial revert of #37312
Purpose
=======

This fix makes no sense because it exposes some private data to
portal users. Fortunately it was only introduced in the master branch.

closes odoo/odoo#40710

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-11-22 14:45:22 +00:00
Yannick Tivisse 89cbc25a34 [FIX] purchase: Allow internal users to see their own orders 2019-11-05 16:18:10 +01:00
Sébastien Theys 425f197f16 [IMP] tools,base,*: remove intermediary image functions
* = hr, im_livechat, mail, payment, purchase, web, web_editor, web_unsplash,
	website_profile, website_slides

Since the merge of all image tools into one function, the intermediary functions
are not needed anymore.

task-1958000
PR: #31811
2019-04-29 13:45:34 +00:00
Toufik Ben Jaa e8b5ef5b5e [FIX] purchase: crash on portal when no product image
- Since commit https://github.com/odoo/odoo/commit/8108a60dc38432243bef4f934784b119c77cf91d the purchase order crashes if a
  `purchase.order.line` product has no image.

  This is due to the fact that we pass a boolean value (False) to the
  function `image_data_uri` on the template `purchase.portal_my_purchase_order`
  which crashes.

closes odoo/odoo#29137
2018-11-29 11:24:16 +00:00
Julien (juc) Castiaux 8108a60dc3 [FIX] purchase: access forbidden for product image on order line
When a user accesses a PO through the portal thanks to an access token
(without being connected), the product image on each order line is
rendered using the image placeholder with a size of 48x48.

This raises a 403 Forbidden at image retrieval since the access token is
not passed as a parameter. This commit corrects that behavior by sending
the resized image along with the rendering of the template instead of an
url.

Another solution could be to generalize the access token check to any
model in:
https://github.com/odoo/odoo/blob/12.0/odoo/addons/base/models/ir_http.py#L303-L311

But this seems overkill regarding this specific error.

opw-1902741

closes odoo/odoo#28479
2018-11-08 07:37:23 +00:00
Nicolas Martinelli 0530b36a2d [FIX] purchase: matching domain
The domain used for the `purchase_count` variable should be in line with
the domain used to retrieve the PO list at
https://github.com/odoo/odoo/blob/68dafa0620fb8e36c9a1a58da0668bede2c3699b/addons/purchase/controllers/portal.py#L50

opw-1894625

closes odoo/odoo#28096
2018-10-24 09:11:50 +00:00
Sébastien Theys 82a46db2de [FIX] portal,sale,sale_management: raise if no document
Before this commit, the method _document_check_access would succeed if it was called with a non-existing id.

Now it will raise a MissingError.

PR: none
Task: none
2018-08-17 10:40:07 +02:00
David Beguin 9434f7b64e [REF] Portal Controller : Remove domain from account and purchase
The list of visible records are anyway based on access_rights.
State has been removed from the domain.
If the portal must be customized for a model,
access rights / rules can be added to do so.

Task ID : 30985
2018-08-03 15:20:42 +02:00
Mitali Patel 84f528bcff [IMP] Portal - Share link : Easily share the url of a document
Purpose
=======
- Quickly share the url to someone else (a client, a colleague,...)
- Ensure that the recipient can access at least
  the portal view of the shared record.
- Typically used when a client cannot retrieve the mail to access his order.
  The share link can be used in this case.

Specifications
==============
For any object inheriting form portal.mixin:
    - Add a button SHARE (not visible in edit mode)
    - When clicking on this button, a popup opens with :
        - A warning message for tasks and projects only (see below)
        - the link (like in gmail) that can be copied
        - Recipients
        - mail composer (with preselected template) ==> see below
        - button [Send Link] [Copy Link] Discard
        - After sharing document, put internal note like
          "Document shared to xyz,...." with template message
    - Anyone with the link, even anonymous user (not logged in) can have access
      to the document with the access token provided in the url.

Impacted models:
    - account.invoice (Community)
    - project.project (Community)
    - project.task (Community)
    - purchase.order (Community)
    - sale.order (Community)
    - helpdesk.ticket (Enterprise)

Warning messages and access rules:
    Allowed :
        - SO canceled or draft will be accessible with the link
          with access_token
        - If the customer account is B2B (signup not enabled), the recipient
          will anyway see the document as the user specifically wants the
          recipient to see the document.
    Restrictions :
        - For Project and Task, if the privacy is not public, then, there is a
          contradiction between the access_token mechanism
          and the privacy of the document.
        - A warning message will be displayed in the share wizard to inform the
          user if the document cannot be visible by the recipients and to
          ask him to set the privacy to 'Visible by following customer'.
          The send button will, in that case, be hidden.
        - To avoid to block the share for a new project, default privacy value
          is now set to 'Visible by followong customer'

Technical implementation
========================
- Move the access_token mechanism (field + methods + mail controller)
  to the portal.mixin to be able to use it in a generic way for each object
  inheriting the portal.mixin
- Generalise a part of the _*model*_get_page_view_values method
  into a single one in portal
- Generalize the _*model*_check_access into the portal controller of the
  portal module
- Remove the init_column + default value for the access_token
  > old records have an access_token,
  > new one won't but it will be generated on demand via the get_access_token
  Done for performance reasons
- Add share button into action menu separately. + kanban view context menu
  (except for task and project where button not in action menu but 'simple'
  button for task and project because other modules already provide action
  to send documents by email, which is not the case for project and task.)
- Add a sign_token used to authentify the recipient in the portal view chatter,
  if any. The message will be posted as if the user was logged in.
- Set the _get_share_url as private for security reason
- Add a redirect parameter to _get_share_url to get
    If false : The direct portal view url
    If True : The redirect url (mail/view/?)
- Cleaning up unnecessary code

- Bug fix :
    - Before, if user was not logged and record had partner_id,
      if partner id was null, post message was done as admin.
      Now, the post message is done as public user.
    - If the user had an uid but had no access_token, he could be able
      to gain the access token of the record.
      check_access_rights was missing in the get_access_action.

Task ID : 30985
Closes #25629
2018-08-03 15:20:42 +02:00
Christophe Simonis f02ed9ab9a [MERGE] forward port branch saas-16 up to 0af13af5de 2018-01-02 16:54:38 +01:00
Christophe Simonis 017ee5eab3 [MERGE] forward port branch saas-17 up to 877e709871 2017-08-24 13:17:53 +02:00
Thibault Delavallée bcada50bc5 [MOV] (website_portal_)purchase: move customer portal to purchase 2017-08-21 13:54:08 +02:00