Commit Graph
84 Commits
Author SHA1 Message Date
Romain Derie c593e7d598 [FIX] website_mail: avoid sending too many RPCs
Before this commit, a JS widget would be instanciated for every `.js_follow` on
the page.
Every widget would then perform a RPC to know if the object was followed.
That would be an issue if there was too many `.js_follow` on the DOM.
Eg: on the forum tag page (/forum/1/tag), there might be unlimited tags. This
    is where the biggest issue is ATM, on Odoo.com we have over 5500 tags,
    which performs 5500 RPC.

Your browser will most of the time just crash.

This commit improves that behavior by sending only one RPC to get the tags info
in once.
With 5000 tags, there was 5000 RPCs, now there will only be one for the tags.
Also, each RPC were doing 8 requests each, so this will bring requests from
40.000 to 80.

Fixes #45576

closes odoo/odoo#46278

Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2020-02-27 16:54:25 +00:00
15c934a1ab [IMP] (website_)mail: improve routes and management of mail followers
Purpose of this commit is to improve model of followers, notably management
code and its use in routes. Indeed it is quite an old model and code had
to be cleaned a bit to improve code readability and maintenance.

In this commit we

  * remove unnecessary code examples in gamification about followers: using
    that model as example of code for goals is probably not a good idea as it
    is technical;
  * rewrite routes called by JS are simplified to better match JS
    implementation;
  * introduce computed fields to fetch related partner or channel name,
    email (partner only) and active status;

LINKS

Task 1933771
Task 2078313

closes odoo/odoo#39808

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Co-authored-by: Remy Voet <ryv@odoo.com>
Co-authored-by: jgi-odoo <jgi@odoo.com>
Co-authored-by: Xavier-Do <xdo@odoo.com>
2020-01-21 16:40:06 +00:00
Romain Derie b703d3b0c7 [FIX] website_mail(_channel): don't use self.env in controller
Without this, it will crash since self.env does not exists in a controller.
Using request will still crash later since `check_followers` does not exists.

Introduced with 957c99abd5

Found while working on task-2152191

closes odoo/odoo#42509

X-original-commit: 70e4a716feda7acb7385a98ac51ab40dabc3f50e
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2019-12-30 16:09:25 +00:00
Richard Mathot e25ea9e665 [FIX] website_mail: prevent crash
`self` is a controller, not a model, thus we use the request to get the
environment.

opw-2160614

closes odoo/odoo#42350

X-original-commit: ac456d8d12bfc26addb3f097aa5552176f6fb765
Signed-off-by: Richard Mathot (rim) <rim@openerp.com>
2019-12-24 15:39:03 +00:00
David Beguin 957c99abd5 [REF] mail, various : make message_partner_info_from_emails from mail.thread private
Purpose: make some methods from mail.thread mixin private and update their
naming if necessary. Some methods prepare data for business flows and deal
with internal information. Public methods should either use of give some
access to those methods. Computation itself should be keps internal.

In this commit we put message_partner_info_from_emails as private. As it is
used in discuss JS we define a controller that controls access to this method.
It explicitly checks for related document access rule and rights before
calling the private method.

Some addons are updated accordingly to the method change.

Related to task ID 1911679
Linked to PR #29483
2019-05-13 15:18:40 +00:00
Christophe Simonis 017ee5eab3 [MERGE] forward port branch saas-17 up to 877e709871 2017-08-24 13:17:53 +02:00
Xavier Morel 481a00dc4b [FIX] P3: hash/hmac payload must be bytes 2017-08-20 23:25:54 +02:00
Jérome Maes 3cfd64f63f [MOV] portal,website_mail: move chatter frontend to portal
This split responsiblilies :
- portal provides basic chatter for portal document, and
website documents (slides, blog, ...).
- website_mail provides comments moderation (unpublished mail
message)
- website_rating integrate rating when posting comments
2017-08-16 14:56:40 +02:00
Jérome Maes 548126f1f6 [IMP] website_mail: use access right rather then hardcoded domain 2017-06-30 11:07:01 +02:00
Jérome Maes d79678fdd5 [IMP] website_mail: make the frontend chatter lazy
Message are now fetched and display using javascript
to optimize performance.
Also the chatter is completely rewrite : add pager,
filter possiblity, ...

This commit is mainly technical: posting feature does
not change. Only the display with pager is new.
The goal is also to prepare frontend chatter for a
better integration with rating widget.

The mail.thread mixin is extended to manage the field
website_message_ids (display all messages that can be
seen on frontend by user (employee or not).

When fetching or posting message, a check is done to see
if we need to do it as sudo(). website_mail implement posting
messages with token or sha_in (using in website_quote).
The same verification is now done when fetching messages, via
'_special_access_object' method.
2017-06-30 11:06:32 +02:00
Olivier Dony 5dd2cc8e63 [MERGE] Forward-port saas-14 up to b9e2207267 2017-06-01 00:37:30 +02:00
Olivier Dony 7e44444878 [MERGE] Forward-port saas-11 up to 156e9d0016 2017-05-31 20:09:51 +02:00
Olivier Dony 156e9d0016 [MERGE] Forward-port 9.0 up to 75e03c0f76 2017-05-31 19:28:20 +02:00
Antonio Espinosa a0ff74b78d [FIX] website_mail: do not propagate csrf_token to message_post method
Indeed through portal users can post a message. Form used in order to
do so include a csrf token. However this one should not be propagated
to message_post because it is not a mail_message model field.
This creates unnecessary warnings.

Closes #13956 .
2017-05-29 13:57:10 +02:00
Olivier Dony 3979a4f4c6 [REM] website_mail: remove sha_in based message_post
The _message_post_helper() method historically allowed
passing a `sha_in` signature to let an unauthenticated
user post a message on a record.

This option is unused and an alternative is preferred:
passing a `token` value that matches the value of a
given field of the record.

In light of the increasingly grim future of SHA-1
as a cryptographic hash function, we consider it
better to entirely remove this specific option.

It has been unused for a while, and a simple
alternative exists.

As a temporary measure, the feature was also
deactivated in 10.0 at 2cffcfd860
2017-02-25 04:05:26 +01:00
Olivier Dony 2cffcfd860 [FIX] website_mail: disable sha_in based message_post
The _message_post_helper() method historically allowed
passing a `sha_in` signature to let an unauthenticated
user post a message on a record.

This option is unused and an alternative is preferred:
passing a `token` value that matches the value of a
given field of the record.

In light of the increasingly grim future of SHA-1
as a cryptographic hash function, we consider it
better to entirely remove this specific option.

It has been unused for a while, and a simple
alternative exists.

The `object_shasign` method itself will be dropped
in master.
2017-02-25 02:10:36 +01:00
Raphael Collet ffdafd3f8a [REM] most uses of _model (useless in most cases) 2016-08-16 09:55:46 +02:00
Keyur Gajjar 30f48eb6b6 [MIG] website_mail: code migration to new api
No functional changes, only rewrite the code with
the api.v8 which more pythonic and smooth.
2016-04-13 11:20:53 +02:00
Jeremy Kersten 28e2dcf043 [FIX] website_payment, website_mail: fix route declaration typo
Missing s of method for allowed methods.
2016-01-28 14:00:26 +01:00
Jérome Maes 22631a152a [FIX] mail, website_mail : special controller for message author avatar
Previous commit (3304b31938) was not performant enough for AL, so got special autorization to make a particular controller for mail.message author avatar. Avatar of message is avaiblable if current user has 'read' access right to the document. Otherwise the default avatar is one white pixel.
2015-10-06 09:43:46 +02:00
Jérome Maes c436c56148 Revert "[FIX] website_mail, website_sale : redirect to login page to post comment"
This reverts commit 7974bf5441.
2015-09-25 16:03:40 +02:00
Jérome Maes 7974bf5441 [FIX] website_mail, website_sale : redirect to login page to post comment
Add 'force_display' param for the frontend chatter to allow public user to see the textarea. When submitting his comment, he will be redirect to login page (like it was before generic chatter) in both mode (json and post mode). This required changing the error handeling of json mode : when a login is required, the user switch to post mode to allow http redirect, keeping its submitted params (rating, comment, ...).
2015-09-23 13:06:25 +02:00
Jérome Maes 6ed93f1770 [FIX] website_mail : prevent posting empty comment 2015-09-23 13:05:41 +02:00
Damien Bouvy 37c62282a2 [FIX] website_mail: if there is a partner linked to the user, let him write
Who's the idiot who coded this stupi... Oh. Right. Never mind.
2015-08-31 21:56:18 +02:00
Thibault Delavallée 01ab75f597 [IMP] mail: notification emails with button
Notification emails have been redesigned. They notably include buttons
allowing to perform some action directly from the email.

The notification creation and sending has been partially rewritten
and improved. The purpose is to lessen the number of rendering to perform
when sending emails to recipients. Recipients are first categorized into
groups. Basic groups are partners and users. The notification template
is then rendered twice, one for followers and one for not-followers. In most
cases there will be few rendering to perform. Through inheritance it
is possible to further categorize users. For example HR users / officers
that have approve / refuse buttons in their email.

A custom data structure is used to store data about buttons and actions.
URLs, follow / unfollow are added in the structure and used in the
template to render the email for a given group.

New routes are added in mail. Those allow to perform some action, like
going to a form in create mode, following / unfollowing, executing a method,
sending a signal for a workflow. Those routes are for users only and rely
on classic access rights.

A generic route for viewing records is added. It replaces the old redirect
action. According to some specific action given by the already-existing
get_access_action, the record will be visible for everybody (forum, blog)
or restricted (going on the Inbox / login / form view, according to access
rights).

The next commit will add the various inherits necessary to add the actions
in the main addons.
2015-08-28 17:30:42 +02:00
Christophe Simonis edeceba7df [MERGE] forward port of branch saas-6 up to 7a768a4
Due to `sale` rewrite (94716a3f14),
the commit 503820acb6 has been partially
ignored (in sale.order.line) and will be rewritten later using new-api.
2015-08-28 15:07:16 +02:00
Jérome Maes 9cc25d1c38 [IMP] website_mail : widgetize the Frontend Chatter. Prepare to include rating feature with posting mail.message 2015-08-27 09:36:35 +02:00
Martin Trigaux 1f57c9a5a6 [FIX] website_mail: do not reveal full email address in contact name
When subscribing a document, a partner is created based on the email address.
Instead of using the email address as the name (which is a bit too spammer
friendly), only keep the first part of the email address as a name.

Following discussion https://www.odoo.com/groups/59/13640169
2015-08-25 10:02:00 +02:00
Thibault Delavallée e6f038a821 [REF] mail: mail_thread: followers update
Followers can now be partners or channels. Partners following a document
will receive needaction, as previously. However people can follow documents
through channels. Members of a channel are able to listen to a stream
of messages using the channel. Those messages do not create needaction
messages. It is therefore possible to follow documents without receiving
too much notifications. For interesting documents subscribing with its
partner will create notification.

message_follower_ids fields is udpated. It is now a many2many to
mail.followers, not to res.partner anymore. A subscription can be either
a partner (partner_id) or a channel (channel_id).

Some access rules have been updated accordingly.
2015-08-21 12:11:56 +02:00
Damien Bouvy ad081b0da1 [IMP] website_mail: generic chatter implementation
A new generic chatter template is available in website_mail
This template allows access rights escalation when some kind of token or uuid
is available on the model or if you use the object_shasign function in the
main controller of website_maill to generate a cryptographic signature to allow
commenting on any object.

To use this chatter, you need to make a t-call to website_maill.thread in your
template after having set the following variables:
- chatter_object: the browserecord of the mail_thread object (mandatory)
- token: if you use a token system  (optional)
- token_field: name of the field that stores the token on your object  (optional)
- sha_in: if you use a shasign to allow public comment  (optional)
- nosubscribe: set False if you want the partner to be set as follower of the object  (optional)
- message_type, subtype: see message_post in mail_thread.py
2015-08-07 01:47:06 +02:00
Olivier Dony 0bd4545348 [LEGAL] Use global LICENSE/COPYRIGHT files, remove boilerplate text
- Preserved explicit 3rd-party copyright notices
- Explicit boilerplate should not be necessary - copyright law applies
  automatically in all countries thanks to Berne Convention + WTO rules,
  and a reference to the applicable license is clear enough.
2015-06-02 03:16:04 +02:00
Christophe Simonis adf07a9490 [MERGE] forward port of branch saas-4 up to 5087612 2014-06-19 16:13:35 +02:00
Thibault Delavallée b07b8a5b1f [FIX] website_mail: restored follow JS code that was wrongly merged with the mail group follow snippet. Now both widget animation exists, the second being more complex and therefore requiring a different animation. 2014-06-19 09:33:36 +02:00
Olivier Dony e276ac33f6 [MERGE] Forward-port saas-4 up to bf135ad 2014-05-28 17:45:31 +02:00
Thibault Delavallée 0c89ca0f8f [FIX] website_mail, websit_mail_group: moved discussion group snippet to the right module; it should not be available when the mailing list archives module is not installed. Also fixed get_alias_info route to be mail_group specific and to avoid allowing people to browse the database. 2014-05-28 11:12:33 +02:00
Thibault Delavallée 02018563b3 [FIX] website_mail: fixed is_follower controller, that could leak data about records.
Added instead a controller to get alias data. This controller is called by the
discussion group snippet to have the info about the alias.
2014-05-28 09:59:31 +02:00
Olivier Dony 04211015fc [MERGE] Forward-port of latest saas-4 fixes, up to 0452851 2014-05-27 20:49:49 +02:00
Thibault Delavallée ef2c068ec3 [IMP] website_mail: improved snippet to subscribe to a mail.group.
Main modifications :
- layout: input - button when not following, links (email - archives - unsubscribe) when following
- when adding your email, update all other subscribe snippets input in the page to avoid havign to re-type it
- management of fields of the record to subscribe to, used to have access to the alias of the group
2014-05-27 08:54:37 +02:00
chm@openerp.com f299180399 [FIX] website_mail: request.website.user_id.id
bzr revid: chm@openerp.com-20140502092659-1gwsx6lmgmtcf80q
2014-05-02 11:26:59 +02:00
Thibault Delavallée b484da7e73 [FIX] [IMP] website_mail: improved and fixed the 'subscribe button'.
This button is used to perform a 'message_subscribe' or 'message_unsubscribe' on some
documents. It is notably used to add a 'Subscribe' button in some pages that subscribe
the user to a mailing list (aka mail.group).
This branch fixes some subscribe/unsubscribe issues, better manages the public user,
use the session to remember whether a public user has subscribe to a mailing list,
and uses already-existing code to manage partners.

bzr revid: tde@openerp.com-20140319113129-qd2bok52hvf1ybiu
2014-03-19 12:31:29 +01:00
chm@openerp.com 3624a3beb2 [IMP] website_mail: refactor follow button; add partner_id in session for public user
bzr revid: chm@openerp.com-20140318101505-4yivw8h5oujyhm9b
2014-03-18 11:15:05 +01:00
chm@openerp.com 73446943f5 [FIX] website snippet: clean_for_save; display email in subscribe snippet
bzr revid: chm@openerp.com-20140306134746-oi0p580c3s3t2a24
2014-03-06 14:47:46 +01:00
chm@openerp.com 58a5f90758 [IMP] website: dynamic website_mail snippet with js
bzr revid: chm@openerp.com-20140306130240-cpsd5mssziuvrpf8
2014-03-06 14:02:40 +01:00
Fabien Meghazi 14bb6060d7 [REM] Removed @website.route() decorator
Need trunk-website-al Rev#5151

bzr revid: fme@openerp.com-20140120153733-ve3dn2kwvha7n3yl
2014-01-20 16:37:33 +01:00
Christophe Matthieu f927506bfc [FIX] website_mail: follow/subscribe button
bzr revid: chm@openerp.com-20140113110542-jkb13xfiy3tno50n
2014-01-13 12:05:42 +01:00
Fabien Pinckaers ed7623fc45 [IMP] Performance improvement: improved cache with context, better get_object
bzr revid: fp@tinyerp.com-20131130154659-uqis34x2cemmocly
2013-11-30 16:46:59 +01:00
Christophe Matthieu 84e24d62b5 [IMP] add website_hr_recruitment
Module for jobs displayed on the website.
The public user can apply or follow the jobs.

little fixes in website_mail

bzr revid: chm@openerp.com-20131002115603-ikgipps88vbf69ef
2013-10-02 13:56:03 +02:00
Thibault Delavallée 726cda367e [FIX] website and all derived addons: fixed imports broken when moving
website.py to models/ directory in website (revision 9491 revid:xmo@openerp.com-20130930145358-qh7xdicgg21prsk4).

bzr revid: tde@openerp.com-20131001085739-hoczgpqrv2nrr6lb
2013-10-01 10:57:39 +02:00
Thibault Delavallée 857f255d95 [IMP] website_mail, website_blog: improved follow / unfollow (always display email, more visible)
bzr revid: tde@openerp.com-20130930143357-0r61uikrf8nx92fg
2013-09-30 16:33:57 +02:00
Thibault Delavallée b34f746c36 [ADD] website_mail: added templates, js and css to have a generic follow button.
Based on the same principle as publish, there is now a generic button to follow
or unfollow objects in openerp. This should replace all custom instance of
subscription in other addons.

bzr revid: tde@openerp.com-20130923095909-4p5aiswlwy14g32k
2013-09-23 11:59:09 +02:00