Commit Graph
643 Commits
Author SHA1 Message Date
Simon Genin (ges) feef532b41 [REF] web, stock: refactor report client code
This commit converts the report code to the new framework.

Since the module stock still has code that extends the old
"ReportClientAction", the old report code is put inside this module.
It can be then naturally removed once the module is fully converted.

closes odoo/odoo#97390

Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2022-09-02 20:10:53 +02:00
Rémy Voet (ryv) ef35a33300 [FIX] web: never cache the CSRF token
"website.layout" inherit of "portal.frontend_layout" which inherit of
"web.layout" which contains the creation of the CSRF token.
Add because "website.layout" add a t-cache key, the CSRF token is under
this cache key. But the CSRF token should be always generated,
then add t-nocache on CSRF token t-set.

Part-of: odoo/odoo#95755
2022-08-10 14:43:07 +02:00
Younn Olivier cd2a649b8b [FIX] web, mass_mailing, website: remove frontend debug icon
After [1] moved the website edition in the backend, we feel that the
code required to make the additional debug icon in the footer of the
frontend still work is not worth it.

Before this commit, on a website page, it was not working: clicking on
it from the WebsitePreview client action would only remove the debug
mode of the frontend, and the backend would keep it.
The user can now leave the debug mode from the debug menu systray item
and we consider that leaving debug mode as a visitor (from the
frontend) is not a feature worth keeping.

[1]: https://github.com/odoo/odoo/commit/31cc10b91dc7762e23b4bde9b945be0c4ce3fe3b

task-2687506

closes odoo/odoo#95499

Related: odoo/upgrade#3721
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2022-07-29 15:53:12 +02:00
Abdelouahab (abla) d86ed180a6 [FIX] web : fix bg for bold document layout
To reproduce
============

on settings -> document layout -> choose Bold with blank background.
print a document (quotation for example) that has at least 2 pages.
the second page of the document has a background.

Purpose
=======

the issue is caused by the condition :
https://github.com/odoo/odoo/blob/0436709f33e57479bd6d62c2e0a2de74743cbaa4/addons/web/views/report_templates.xml#L403
where we don't take into account the case where no background is set.

Specification
=============

to solve the issue the condition was corrected

opw-2888650

closes odoo/odoo#96528

X-original-commit: bf2ce0aa0c7d45c90d7ff104d5af5f99b29d59ae
Signed-off-by: Simon Genin (ges@odoo) <ges@odoo.com>
2022-07-22 16:22:02 +02:00
Romeo Fragomeli 1fcd098af5 [REF] *: BS5: migration
Automated change made by a lot of RegEx to change all think that is
possible to automate.

https://getbootstrap.com/docs/5.1/migration

Task ID: 2766483

Part-of: odoo/odoo#95450
2022-07-07 13:30:24 +02:00
Romeo Fragomeli 903e72d0ac [REF] *: BS5: various
Refs:
https://getbootstrap.com/docs/5.1/migration

Task ID: 2766483

Part-of: odoo/odoo#95450
2022-07-07 13:30:20 +02:00
Romeo Fragomeli 9ea1351334 [REF] *: BS5: Migrate forms and inputs
- BS5 uses native inputs instead of pseudo-element for some
  input like checkbox, radio, ...
  in BS5 input checkbox don't have "virtual visual" checkbox anymore
  (::before), so we remove the relative's rules

- removed `.custom-control` class

- `form-switch` use a new layout system in BS5 we adapt the code to
  match the Bootstrap approach (inline SVG).

- In tests, we don't check the exact value of the background as it
  change in community/enterprise, and it's difficult to check the value
  of an SVG.

- Overflow in progressbar is now hidden.
  -> we had to restore it.

- In BS5 margins in forms/inputs has been changed
  -> we had to restore it (e.g. 'mb-3')

- .form-group, .form-row, .form-inline
> Dropped form-specific layout classes for our grid system.
> Use our grid and utilities instead of .form-group, .form-row,
> or .form-inline.

- .input-group-append and .input-group-prepend
> Dropped .input-group-append and .input-group-prepend.
> You can now just add buttons and .input-group-text as direct
> children of the input groups.

Ref:
[1] https://getbootstrap.com/docs/5.1/migration/#forms

Task ID: 2766483

Part-of: odoo/odoo#95450
2022-07-07 13:30:18 +02:00
Gorash ae3354b306 [FIX] web, *: debug icon consistency according to the mode and the url
*: website

X-original-commit: 0cd55d90121cd5bcebdf4c7b0212910ef44a9d85
Part-of: odoo/odoo#95222
2022-07-06 17:10:17 +02:00
Julien Mougenot 315718ea66 [FIX] web: Remove CSS comment parsed as rule
A CSS comment in webclient_templates was written as a JS comment and
appeared as an invalid CSS rule in the devtools. This commit converts
that comment to use the proper syntax.

closes odoo/odoo#94925

Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2022-06-30 18:52:13 +02:00
Florian Charlier b5f3433adc [IMP] auth_signup,portal,web: welcome external users w/o portal
When portal is not installed and `auth_signup.invitation_scope` is "b2c",
visitors can create an account, leading to a blank page. Still, accounts can be
required for several use cases in apps that do not require portal (such as
survey).

We here add a landing page for users that created an account but have no
requested redirections and cannot be redirected to a customer portal either.

auth_signup_uninvited is also updated in model to be consistent with config
data.

Tests are added to check this behavior.

Task-2762102

Part-of: odoo/odoo#85703
2022-06-14 09:35:57 +02:00
Gorash b0a2a41d78 [IMP] all/website: using lazy values and t-cache in templates
Using lazy values allows you to not do query when the content is not
displayed or if it is already cached. Adding `t-cache` only reduces
render time, but combining it with lazy values saves browses, computes
and query.
Thus for the `/shop` page the page is displayed in 60ms (before: 250ms).

Part-of: odoo/odoo#88276
2022-06-03 16:40:40 +02:00
Camille Spiritus e8776485b4 [IMP] account: align delivery and recipient adresses on invoices
Since 15.2, when creating an invoice containing both a recipient address and an invoice address, the addresses would both appear on the left, one after the other.

This made reading difficult and the invoice unclear.

Furthermore, the company address wasn't present by default on the invoice : it was only there if a layout had previously been selected.

This PR:
- reverts the behaviour of the company address, i.e. it appears even if no layout is (yet) selected ;
- aligns the delivery and the recipient address on each side of the page when necessary, while not changing the outcome if a single address is given.

Also displays a "title" above the addresses when necessary to make things clearer.

task-2809240

related : https://github.com/odoo/enterprise/pull/27240

closes odoo/odoo#91487

X-original-commit: 1e745256fabbec4d6979180d8f792c99be463509
Related: odoo/enterprise#27383
Signed-off-by: Florian Gilbert <flg@odoo.com>
2022-05-17 16:03:16 +02:00
Abdelouahab (abla) 873b7b8a82 [FIX] l10n_ch : fix body style in swissqr_report
To reproduce
============

- Create a company with a complete Swiss address (street, city, zip and country).
- Install the l10n_ch modules and install the Swiss plan comptable in the Settings of the Accounting app.
- Go to Accounting > Configuration > Settings > Activate the "QR codes" > Save
- Go to Accounting > Configuration > Journals > Choose the journal for the invoices > In "Advanced settings" verify that the communication type is "Based on invoice" and the communication standard is "Switzerland"
- Go to Accounting > Configuration > Journals > Select your bank journal(s) > Verify that you have set up your bank account number and the name of the bank
- Go to the Contact app > Configuration > Bank Accounts > Choose the one you use for the QR-bills > Edit > In "ISR Client Identification Number" refer a client number and make sure account type is 'IBAN' > Save.
- Verify that you have a complete address on the contact form of the customer (street, city, zip and country).
- create multiple invoices for this client
- try to print QR-bill for these invoices at once -> and assert error is raised

Purpose
=======

the `assert len(outlines_pages) == len(res_ids)` fails because the generated pdf
contains only a single invoice.

this issue is caused by the line `<script>document.body.className += " l10n_ch_qr";</script>` in `swissqr_report.xml`,
when `wkhtmltopdf` generates the pdf from html, it doesn't wait for all javascript to finish before rendering the page,
which lead to not execute the script `<script>document.body.className += " l10n_ch_qr";</script>` for some pages then the final pdf
is missing some pages.

Specification
=============

To solve the issue we removed the javascript block `<script>document.body.className += " l10n_ch_qr";</script>` from the template
and move it to python, by setting the body style when generating the html.

opw-2772396

closes odoo/odoo#89835

X-original-commit: a669b4c5f78aa18b87f5adcfc5acca3ce0a76040
Signed-off-by: abla001 <abla@odoo.com>
2022-04-27 18:38:10 +02:00
+2 6d13271aac [REF] web: adapt code to owl 2
Owl 2 changelog: https://github.com/odoo/owl/blob/a9f29c4caad4f32d06be1ec4780572825781cd9b/CHANGELOG.md

Part-of: odoo/odoo#80156
Co-authored-by: Aaron Bohy <aab@odoo.com>
Co-authored-by: Bruno Boi <boi@odoo.com>
Co-authored-by: Géry Debongnie <ged@odoo.com>
Co-authored-by: Samuel Degueldre <sad@odoo.com>
Co-authored-by: Mathieu Duckerts-Antoine <dam@odoo.com>
Co-authored-by: Simon Genin (ges) <ges@odoo.com>
Co-authored-by: Francois (fge) <fge@odoo.com>
Co-authored-by: Michael Mattiello (mcm) <mcm@odoo.com>
Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: luvi <luvi@odoo.com>
Co-authored-by: Lucas Perais (lpe) <lpe@odoo.com>
Co-authored-by: Jorge Pinna Puissant <jpp@odoo.com>
2022-02-10 07:46:12 +00:00
stefanorigano (SRI) 0f64e506f2 [MOV] web, * : move font-awesome library in an editable location
This commit "forks" fontAwesome into `src/libs` in order to allow
further customization.
Part of v16 overall restyle (task-2704984).

task-2745275

Part-of: odoo/odoo#83501
2022-02-08 12:05:54 +00:00
Fabien Pinckaers 8ae4d92a58 [IMP] base: remove postprocessing of rendered pages
First step to stream QWeb templates: removing the two post
processing operations applied on rendered templates. This
should slightly speed up the rendering of every page.

1/ Don't remove empty lines after rendering, but fix the root
cause of: view inheritancies and QWeb compilation that don't
add extra empty lines.

2/ handle page break in the two reports that uses it, rather
than processing every view produced.

closes odoo/odoo#82244

Related: odoo/enterprise#23328
Signed-off-by: Fabien Pinckaers <fp@odoo.com>
2022-01-10 19:28:29 +00:00
thcl-odoo 5b854f7f5f [FIX] web: match downloaded pdf with preview
Current behavior :
PDF Preview in document layout settings doesn't match the downloaded one (colors of div with the total and the columns displayed)

Steps to reproduce :
- Go to Settings
- 'Configure Document Layout' under Companies
- Set layout to Boxed
- Change the colors
- Download the PDF Preview

Reason :
- The columns for the unit price and taxes had the 'd-none' class so they weren't visible when printing the pdf preview. To keep coherence, if we see them in the preview we must see them in the pdf.
- Colors, especially the total div with a 'Boxed' layout, weren't taken into account for some elements in the preview. This is due to a character sanitized in the CSS, specifically '>' which becomes '&gt;' for the '.row > div > table' selector.

OPW-2716089

closes odoo/odoo#81932

X-original-commit: 158c0ae425b3be446d81c3a6f4387b2d9426d10e
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
Signed-off-by: Claude Thibault (thcl) <thcl@odoo.com>
2021-12-28 09:47:25 +00:00
Yannick Tivisse c2f450a7ad [FIX] web: Fix access right issues on external layout prining
Purpose
=======

If the user doesn't have access to ir.ui.view (aka no admin or
website access rights), printing a report with a configured
external layout will lead to a traceback, as it's forbidden
for the use to read on the field "key" on the related ir.ui.view.

As we only want to retrieve the view key, this is safe to use
sudo at that point.

closes odoo/odoo#80528

Taskid: 2701251
X-original-commit: 3891ab34740a86a5e795b9fbcb3fb998d705985e
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2021-11-29 14:08:52 +00:00
Nicolas Bayet 4813f42997 [IMP] mail,*: replace jinja with qweb
Jinja as a templating engine was problematic in differents respect:
- introduce external dependency to Odoo (less controll)
- add another templating mechanism in the stack
- specific feature in qweb cannot be reused
- difficulty in rendering easily editable templates
- more knowledge required with no betterment

By replacing jinja with qweb we can now build tools to edit a qweb
that will work with the previously jinja encoded document
(essentially `mail.template` records).

There is a catch however. Some email fields (eg. email_to) used jinja
syntax for rendering dynamic variables (ie. ${object.something} and
${object.something_that_should_not_be_escaped | safe}).

We still want user to use dynamic variables for some char fields (eg.
subject, from, to, ...). We made a new rendering engine called
"inline_template" that will render an expression enclosed by `{{` and
`}}`.

To be able to edit the templates from the backend interface, a
plugin to the Odoo editor has been made for seamlessly edit the
document.

This qweb plugin includes:
- make dynamic variables (eg. `<t t-out="variable"/>`) not editable
  (for preventing the user to shoot himself in the foot)
- group and hide related logical branching (ie. t-if, t-elif, and t-else)
  in order to see only one at once
- a floating select input to switch visibility of a particular logical
  branching

Task-27033

X-original-commit: odoo/odoo@68182baff4
Part-of: odoo/odoo#77377
2021-09-28 23:42:54 +00:00
Lucas Perais (lpe) 56dda82a5f [REF] web, *: legacy: lazy loading of legacy reporting views
Since commit 0134495ba5 the reporting
views pivot, graph, cohort are written in full new framework.

Some applications still need the legacy ones, so this commit just implements
the lazy loading of those views.

In stock, report_stock_forecasted has been adapted in order to avoid having
a GraphView override: we now modify the canvas' height in pure JS.

*: board, stock

closes odoo/odoo#76931

Related: odoo/enterprise#21054
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2021-09-22 12:22:46 +00:00
Benjamin Vray 81f0f0840c [IMP] website_sale, *: review prices to be more realistic
*: product, purchase, purchase_stock, sale, sale_stock, web

PR-69971

task-2501400

closes odoo/odoo#69971

Related: odoo/enterprise#19974
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-30 10:39:44 +00:00
Leonardo Pavan Rocha f33f305807 [FIX] web: fixes reports not scrolling
task-2355704 introduced a bug which prevented scrolling in reports, instead of only in report preview.
This PR fixes this bug.

task-2586245

closes odoo/odoo#73496

Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2021-07-09 12:59:09 +00:00
Kevin Baptiste 86aa7b78aa [IMP] *: introduce data-hotkey on form and modal views
Define `data-hotkey` on most used action buttons.

For the modals, the following keys are dedicated for "special"
actions:
 - Alt+G: add
 - Alt+V: save
 - Alt+Z: cancel

closes odoo/odoo#73275

Taskid: 2588233
Related: odoo/enterprise#19464
Signed-off-by: Kevin Baptiste <kba@odoo.com>
2021-07-15 08:39:49 +00:00
Jorge Pinna Puissant 54e9527ec2 [IMP] web, *: read session information from a module
* google_recaptcha, mail, partner_autocomplete, point_of_sale, website

Now, to read session information, the module "@web/session" must be
imported. Not that, there is also the user service with all the user
information.

closes odoo/odoo#73201

Related: odoo/enterprise#19434
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2021-07-08 14:13:39 +00:00
Romain Tartière bac1f99312 [FIX] web: Adjust label#for to match input#id
The #for attribute of the LABEL tag should match the #id of the INPUT
tag, not it's #name.

This regression was introduced in a171694644

closes odoo/odoo#73052

X-original-commit: 979c9d71aee4b1bb6c8798bdfdbf69ac8af3fa69
Signed-off-by: Romain Tartière <romain@vittoriaconseil.com>
Signed-off-by: Simon Genin (ges@odoo) <ges@odoo.com>
2021-07-01 09:05:16 +00:00
Leonardo Pavan Rocha bc40795c56 [IMP] base: base layout designer improvements
This commit implements improvements in the layout designer, such as addition of a new custom background, adds custom report footer and company details.

task-2355704

closes odoo/odoo#66860

Related: odoo/upgrade#2275
Signed-off-by: Arnaud Joset <arj-odoo@users.noreply.github.com>
2021-06-25 10:33:31 +00:00
Samuel Degueldre ee3804fdf5 [IMP] web: prefetch translations to speed up webclient startup
closes odoo-dev/odoo#901

Signed-off-by: Géry Debongnie (ged) <ged@openerp.com>
2021-06-18 21:31:29 +02:00
+1 0573acae23 [REF] web: rewrite the webclient in OWL (phase 1)
This commit is the first phase of the conversion of the web/ JS
codebase to the owl framework. The impact of this commit is two-fold.

First, it rewrites the framework part of web with a new system of
services and registries. Services allow to execute code (e.g. do rpcs,
setup things) before launching the application. They can also expose
an API to be used by other parts of the application (e.g. a notification
service would expose a function to display notifications). Services are
often a good extension point for external modules that want to execute
code at webclient startup. Registries offer another way to extend the
application. They provide well designed extension points to add
elements/behaviors from the outside (for instance, to add a systray item,
an error handler...).

Second, this commit initiates the conversion of the webclient to owl
with a top-down approach, around those notions of services and registries.
The root of the web application is now an owl application. Among others,
the WebClient, ActionManager, Navbar, UserMenu, DebugManager, Dialogs,
services (e.g. notification, ajax...) have been converted to the new
framework/architecture.

Legacy views and client actions are still supported (and used). They
will be converted in the next months, and at some point, the support
will be dropped.

Co-authored-by: Aaron Bohy <aab@odoo.com>
Co-authored-by: Bruno Boi <boi@odoo.com>
Co-authored-by: Géry Debongnie <ged@odoo.com>
Co-authored-by: Samuel Degueldre <sad@odoo.com>
Co-authored-by: Mathieu Duckerts-Antoine <dam@odoo.com>
Co-authored-by: Simon Genin (ges) <ges@odoo.com>
Co-authored-by: Francois (fge) <fge@odoo.com>
Co-authored-by: Michael Mattiello (mcm) <mcm@odoo.com>
Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Lucas Perais (lpe) <lpe@odoo.com>
Co-authored-by: Jorge Pinna Puissant <jpp@odoo.com>
2021-06-18 21:31:27 +02:00
dht-odoo 1ef6fd9098 [IMP] web, {base}_setup: improves field type from text to html
Replace text fields to html fields as we have our own 'OdooEditor'.
Indeed, it gives more options to users in the way they format their
content without weighting too much on the UI
(tools appear on demand and not by default).

In this commit we replace report_footer and report_header field of
"base.document.layout, res.config.settings" model as
they are related fields of res.company models field
report_footer, report_header.

Task Id: 2499504

X-original-commit: 4c474d0d2055efe81fdc21502aa5957fe80af7ef
2021-06-07 05:21:40 +00:00
Xavier-Do 4c4a740e0a [IMP] web, base: add option to profile dispatch
The profiling tools can be useful to profile a test of some execution
point but this is not convenient to identify a problem on a running
instance.

With this commit, an option available in the debug menu allows to add a
flag on the user sessions to enable profiling of all requests. Each
request will be saved in a different 'ir.profile' entry, but will be
grouped under the same session.

The profiling can be activated on all sessions, even for a public user,
but only if profiling is enabled on the database globally.

This commits also adds a speedscope view to visualize saved results in
the web client.

closes odoo/odoo#66590

Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2021-06-02 11:46:28 +00:00
Younn Olivier 507408e8e1 [FIX] web, website: display default company name on frontend layout
Before, the "Company name" placeholder was hardcoded in the frontend
layout template, and the user had to change it with his company name
from the website view, which was not user-friendly if the website module
was not installed.

Now, by default, the frontend layout template displays the user's
company name. If the website module is installed, it is editable.

task-2468472

closes odoo/odoo#71176

X-original-commit: 059804be90021559debee6f930462594a3ca8a97
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2021-05-21 16:56:11 +00:00
Simon Genin (ges) ecfe85db84 [REF] web: static/src/(img|fonts) => static/(img|fonts) 2021-04-29 07:34:40 +00:00
Xavier Morel a671b744b8 [FIX] *: raw -> out of mail values 2021-04-29 05:34:20 +00:00
Xavier Morel c6f744d7c3 [FIX] web: raw -> out of footer thing
Done this way so `_message` can be overridden with custom
markup. Should now work properly ootb: `final_message` should be a
`Markup` from qweb rendering, if `_message` also is such, the merge
should happen without further escaping of either value.

Note: needed to convert the str.__mod__ call to a concatenation as
otherwise the markupness information is lost. That's probably a
recurring issue.
2021-04-29 05:34:20 +00:00
Xavier Morel 9fadd925cb [FIX] reporting: fix rendering during PDF printing
The process of making HTML reports palatable to wkhtmltopdf is a bit
involved, including various renderings intersperded with
processing. This means bits of HTML are created, which are
processed (via lxml) before being fed into further templates.

On step 3, the previously processed bits need to be marked as Markup
lest they be escaped again and lead to... odd results.

Also explicitly provide encoding for one case where it's not entirely
necessary but can't hurt.

Also un-escape <base> in report templates, it seems completely
unnecessary. And try to move it to the correct location to the extent
that that's possible: per-spec, it should be in the head, not outside
the document entirely.
2021-04-29 05:34:20 +00:00
Xavier Morel 996cb85c27 [FIX] *: mass replace known t-raws by t-out
* QWeb bodies should be markup-safe so `0` should always be
  markup-safe.
* `head` is qweb-rendered so the same.
* The `json` pseudo-module in qweb templates is `json.scriptsafe`,
  which should be markup-safe.
2021-04-29 05:34:20 +00:00
Xavier Morel 01875541b1 [CHG] core, web: deprecate t-raw
Add a big fat warning when the qweb compiler finds a `t-raw`.

`t-esc` should now be used everywhere, the use-case for `t-raw` should
be handled by converting the corresponding values to `Markup`
objects. Even though it's convenient, this constructor *should never
be made available in the qweb rendering context* (maybe that should be
checked for explicitely?).

Replace `werkzeug.escape` by `markupsafe.escape` in
`odoo.tools.html_escape`, this means the output of `html_escape` is
markup-safe.

Updated qweb to work correctly with escaping and `Markup`, amongst
other things QWeb bodies should be markup-safe internally (so that a
`t-set` value can be fed into a `t-esc`). See at the bottom for the
attributes handling as it's a bit complicated.

`to_text` needed updating: `markupsafe.Markup` is a subclass of `str`,
but `str` is not a passthrough for strings. So `Markup` instances
going through would be converted to normal `str`, losing their safety
flag. Since qweb internally uses `to_text` on pretty much
everything (in order to handle None / False), this would then cause
almost every `Markup` to get mistakenly double-escaped.

Also mark a bunch of APIs as markup-safe by default

* html_sanitize output.
* HTML fields content, sanitization is applied on intake (so stripped
  by the trip through the database) and if the field is unsanitised
  the injection is very much intentional, probably. Note: this
  includes automatically decoding bytes as a number of default values
  & computes yield bytes, which Markup will happily accept... by
  repr-ing them which is useless. This is hard to notice without `-b`.
* Script-safe json, it's rather the point (though it uses a
  non-standard escaping scheme).
* Note that `nl2br`, kinda: it should work correctly whether or not
  the input is markup-safe, this means we should not need to escape
  values fed to `nl2br`, but it doesn't hurt either.

Update some qweb field serialisations to mark their output as
markup-safe when necessary (e.g. monetary, barcode,
contact). Otherwise either using proper escaping internally or doing
nothing should do the trick.

Also update qweb to return markup-safe bytes: we want qweb to return
markup-safe contents as a common use-case is to render something with
one template, and inject its content in an other one (with Python code
inbetween, as `t-call` works a bit differently and does not go through
the external rendering interface).

However qweb returns `bytes` while `Markup` extends `str`. After a
quick experiment with changing qweb rendering to return `str` (rather
unmitigated failure I fear), it looks like the safest tack is to add a
somewhat similar bytes-based type, which decodes to a `Markup` but
keeps to bytes semantics.

For debugging and convenience reasons, MarkupSafeBytes does *not*
stringify and raises an error instead (`__repr__` works fine). This is
to avoid implicit stringifications which do the wrong thing (namely
create a string `"b'foo'"`).

Also add some configuration around BytesWarning (which still has to be
enabled at the interpreter level via `-b`, there's no way to enable it
programmatically smh), and monkeypatch `showwarning` to show warning
tracebacks, as it's common for warnings to be triggered in the bowels
of the application, and hard to relate to business logic without the
complete traceback.

`t-out`
=======

`t-esc` is a bit confusing for the new behaviour of "maybe escape
maybe not", so add a `t-out` alias with the same behaviour.

Unlike `t-raw`, `t-esc` is only soft-deprecated for now: there are
thousands of instances, so editing all the templates is not
great. Eventually we'll add a `ci/style` to prevent addition of new
ones, and eventually we might do a bulk-replace and hard-deprecate.

Attributes handling
===================

There are a few issues with respect to attributes. The first issue is
that markup-safe content is not necessarily attributes-safe
e.g. markup-safe content can contain unescaped `<` or double-quotes
while attributes can not. So we must forcefully escape the input, even
if it's supposedly markup-safe already.

This causes a problem for script-safe JSON: it's markup-safe but
really does its own thing. So instead of escaping it up-front and
wrapping it in Markup, make script-safe JSON its own type which
applies JSON-escaping *during the `__html__` call.

This way if a script-safe JSON object goes through `markupsafe.escape`
we'll apply script-safe escaping, otherwise it'll be treated as a
regular strings and eventually escaped the normal way.

A second issue was the processing of format-valued
attributes (`t-attf`): literal segments should always be markup-safe,
while non-literal may or may not be. This turns out to be an issue if
the non-literal segment *is* markup-safe: in that case when the
literal and non-literal segments get concatenated the literal segments
will get escaped, then attributes serialization will escape
them *again* leading to doubly-escaped content in attributes.

The most visible instance of this was the `snippet_options` template,
specifically:

    <t t-set="so_content_addition_selector" t-translation="off">blockquote, ...</t>
    <div id="so_content_addition"
        t-att-data-selector="so_content_addition_selector"
        t-attf-data-drop-near="p, h1, h2, h3, .row > div > img, #{so_content_addition_selector}"
        data-drop-in=".content, nav"/>

Here `so_content_addition_selector` is a qweb body therefore
markup-safe, When concatenated with the literal part of
`t-atff-data-drop-near` it would cause the HTML-escaping of that
yielding a new Markup object. Normal attributes processing would then
strip the markup flag (using `str()`) and escape it again, leading to
doubly-escaped literals.

The original hack around was to unescape() `Markup` content before
stringifying it and escaping it again, in the attribute serialization
method (`_append_attributes`).

That's pretty disgusting, after some more consideration & testing it
looks like a much better and safer fix is to ensure the
expression (non-literal) segments of format strings always result in
`str`, never `Markup`, which is easy enough: just all `str()` on the
output of strexpr. We could also have concatenated all the bits using
`''.join` instead of repeated concatenation (`+`).

Also add a check on the type of the format string for safety, I think
it should always be a proper str and the bytes thing is only when
running in py2 (where lxml uses bytestrings as a space optimization
for ascii-only values) but it should not hurt too much to perform a
single typecheck assertion on the value... instead of performing one
per literal segment.

Note: we may need to implement unescape anyway, because it's still
possible to get double-escaping with the current scheme: given an
explicitly escape-ed `foo` and `t-att-foo="foo"`, `foo` will be
re-escaped.

fixup! [CHG] core, web: deprecate t-raw
2021-04-29 05:34:19 +00:00
oco-odoo 7d678cc7f4 [IMP] account: introduce foreign VAT fiscal positions
Such fiscal positions define an alternate VAT for a specific region. When foreign_vat is set, a country must be set on the fiscal position; it'll be used to know for which tax report the fiscal position must be available as an alternate VAT (in the tax report; see enterprise branch). Note that it is possible to defined several foreign VATs for the same country, as long as they belong to different states within that country.

Note that this new feature is only for FOREIGN stuff; so, when you have to submit a tax report in different regions than yours. For example if you have a Belgian accounting, have French customers, and have a French VAT in addition to your Belgian VAT, to submit a tax report in France. For domestic operations, simply use your the vat field of your company, just like before.

[IMP] account: add country_id on taxes and filter them on invoices

The invoices now compute the country from which they should accept the taxes: it's either the one defined by fiscal_position_id.country_id (if fiscal_position_id is a foreign VAT fiscal position, i.e. it defines a foreign_vat value), or the company's account_fiscal_country_id.

Taxes from other countries are filtered from the view; we don't want them to be available there. There is also a constraint ensuring that. Same goes for tax repartition lines and tags from other countries.

We don't want to mix taxes, tags and foreign VAT fiscal positions from different countries, as it would break the tax report in enterprise. Doing this ensures the tax report can efficiently discriminate the move lines between the different regions whose report they have to appear in.

[IMP] account: add country_id to account.chart.template

This is done so that the taxes are created in the right country, and the fiscal country is initialized in a consistent way when instantiating the CoA on the company.

[IMP] account: print foreign VAT on invoice instead of company VAT if one is defined

[IMP] web: allow forcing company vat on document templates

This is done to allow the use of foreign vat fiscal position on invoices: in that case, we don't want to use the company VAT, but the value of fiscal_position_id.foreign_vat. So, when such a value exists, the invoice simply set the force_vat variable to the right value.

[IMP] base_vat: also validate VAT of foreign VAT fiscal positions

We generalize the code formerly only done for res.partner so that the foreign_vat field of account.fiscal.position can be checked in the same way.
2021-04-01 12:09:20 +00:00
Julien MougenotandSimon Genin 03641610c2 [REF] *: convert all modules to new asset system
Conversion of all modules to the new manifest assets declaration.

Part of task: 2352566

Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Simon Genin <ges@odoo.com>
2021-03-31 13:57:18 +02:00
8cc066173d [IMP] *: Improve assets management
This commit changes the way assets are declared in Odoo modules.

Before: assets were declared in template files. Template bundles were
generated from primary templates, so technically any qweb template could
have been called as an asset bundle, with the 't-call-assets' directive.

Being standard qweb templates, they had access to standard HTML tags
(script, link, with or without raw scripts or style definition), qweb
directives (t-call, t-raw, etc.) and could be inherited by other
templates.

Now: assets are defined in the module's manifest and generated by the
't-call-assets' directive.

More information on the new system can be found on the updated user
documentation (see the "JavaScript Reference" section).

Task: 2352566

Co-authored-by: Bruno Boi <boi@odoo.com>
Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Lucas Perais <lpe@odoo.com>
Co-authored-by: Mathieu Duckerts-Antoine <dam@odoo.com>
Co-authored-by: Raphael Collet <rco@odoo.com>
Co-authored-by: Simon Genin <ges@odoo.com>
2021-03-31 13:57:17 +02:00
Julien MougenotandSimon Genin ebe86f5ca5 [REF] web,*: Flatten _assets_helpers
Before this commit, the asset bundle "_assets_helpers" was the only
bundle using a "t-raw" directive to insert assets in between other asset
calls.

Now _assets_helpers only contains the assets called before the t-raw
directive, and the second part (1 file actually) has been added after
every call of the bundle.

This has been done to improve consistency in asset bundles declarations
by reducing them to the simplest possible templates.

Part of task: 2352566

Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Simon Genin <ges@odoo.com>
2021-03-31 13:57:17 +02:00
Aaron Bohy aa07146421 [IMP] web: boot.js: throw even if not in debug
Before this commit, when a module wasn't correctly defined (e.g.
wrong format for dependencies, wrong format for module name, name
already defined...), an error was thrown but only in debug mode.
In non debug mode, the problem was simply ignored, which is wrong.

An example of harmful consequence would be the following: if
someone defines a new test file and uses an already used module
name, he won't be notified of his mistake unless he runs the suite
in debug mode. If he doesn't, the runbot won't detect it either as
it runs tests in non debug mode. It would then lead to one of the
two test suites not being executed.

Fun fact: a lazy loaded file was actually loaded twice, but we were
only notified in debug mode. With this change, it made the test
suite fail all the time, no matter the mode. We simply removed the
file from the page source, and let the first test needing it lazy
load it.

closes odoo/odoo#66918

Signed-off-by: Géry Debongnie (ged) <ged@openerp.com>
2021-03-30 08:57:35 +00:00
yograj tandelandMohammed Shekha ef62df2bfd [IMP] web: consider FieldDependencies given on custom widget
With this commit we support adding FieldDependencies on custom widget, consider
FieldDependencies given on custom widget and add it to fieldInfo so that when
modal does calls to server to fetch data it consider those fields while reading

this will let us to design custom widget which may have some other fields in
dependency, say for example weekly recurrence widget which uses sun, mon etc.
fields, so with this we can fetch data of those dependent fields without adding
it to view.

task-2335399

closes odoo/odoo#60277

Related: odoo/upgrade#2021
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
Co-authored-by: Mohammed Shekha <msh@odoo.com>
2021-03-26 12:25:44 +00:00
YOGRAJ TANDELandMohammed Shekha 7da9c296eb [ADD] calendar,lunch,web: weekly recurrent widget
with this commit we adding weekly recurrent widget, currently proeject and
calendar shows boolean for each day vertically but with this widget we displays
week days and its boolean horizontally.

Here widget will display first day as per language's week_start field, also we
adds FieldDependencies on custom widget and consider those FieldDependencies
while processing view node in basic_view.js

We add support of registry to contain owl custom widgets and add support
of rendering owl custom widgets.

Also with this commit we removes fields like sun, mon, tue etc. from view and
instead use "web_weekly_recurrence" custom widget to display boolean for each
week day.

Co-authored-by: Mohammed Shekha <msh@odoo.com>
2021-03-26 12:25:44 +00:00
Mohammed ShekhaandAaron Bohy 877ef5552b [IMP] web: add support of owl custom widget
add support of <widget> tag for owl, In order to prepare the future,
we want to convert everything in Owl, in future widgets generated by
<widget> tag will also be converted to owl.

with this commit we support widget to instantiate using ComponentWrapper.

task-2337692

Co-authored-by: Aaron Bohy <aab@odoo.com>
2021-03-26 12:25:44 +00:00
Oussama MESSAOUDI afce9559ac [FIX] website_forum, *: refit the forum biography popover
*: web

task-2276974

closes odoo/odoo#67902

X-original-commit: 1207b99b73f5906209499cb2935b750faecd756d
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2021-03-15 19:20:48 +00:00
Michael Mattiello (mcm)andged-odoo 7086488064 [REF] web, *: remove patchMixin + imp utils.patch
* hr, hr_holidays, im_livechat, mail, snailmail, website,
  website_livechat

This commit removes `patchMixin` and improve `utils.patch`.
`utils.patch` now supports native classes and has a new parameter
used to patch class members.

`utils.patch` is now used everywhere `patchMixin` was and it must
be used to patch classes.

closes odoo/odoo#65967

Related: odoo/enterprise#16278
Signed-off-by: Géry Debongnie (ged) <ged@openerp.com>
Co-authored-by: ged-odoo <ged@odoo.com>
2021-02-26 10:39:21 +00:00
Géry Debongnie e2b85d4613 [REF] web: move error handling code to other file 2021-02-25 14:30:33 +00:00
Romeo Fragomeli d85f5ddeac [FIX] web: client report action mounted called twice
Before this commit, the 'mounted' method of the ControlPanel in
the client report action  was called twice.

It happened because the client report action updated the ControlPanel
before being actually mounted, so mounted was called once when the
traceability report was mounted, and once when the update was applied.

Ideally, this should not be an issue (this isn't an issue with owl).
However, in Odoo, we mix layers of Owl Components and legacy
widgets. In these situations, the above scenario isn't properly
handled (and can't be).

As a consequence, in mobile (enterprise), it crashed because an
handler bound in mounted (thus twice) was only unbound once.

This commit avoids the issue as the update was actually useless.

Steps to reproduces (Mobile):
* Go to Inventory (Stock)
* Open the "burger menu"
* Select "Products" -> "Products"
* Select one product in the list
* Click on the "Forecasted" ("stat button")
* Select one "SO line" (sale order) to go to the form view
* Go back to the previous view using breadcrumb
* Optional: Go to another app if the screen can't scroll (e.g. go to Sales)
* Scroll the view => Bug

closes odoo/odoo#66497

X-original-commit: d3854dbf7a6e0c0f9ac00c11716908bc175808d7
Related: odoo/enterprise#16507
Signed-off-by: Adrien Dieudonné (adr) <adr@odoo.com>
2021-02-18 16:46:57 +00:00
Géry Debongnie 2716828f25 [IMP] web: display better tracebacks in debug=assets
The recent change in the way debug=assets works (which now bundles all
files in a bundle instead of serving them statically) had a negative
impact on the stacktrace displayed in the error dialog in debug=assets:
it now display the bundle/linenumber instead of the actual file/line
number.

This is not a huge deal, most of the time, because the errors displayed
in the console display the correct information, and the debugging
process should work as before.  But it can certainly be annoying in some
cases.

With this commit, we use the Stacktrace.js library to dynamically fetch
the sourcemaps and to decorate the displayed information with the
correct file and line numbers.

closes odoo/odoo#66318

Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2021-02-17 11:52:40 +00:00