Commit Graph
163 Commits
Author SHA1 Message Date
Antoine Guenet 8e0f1e08ac [IMP] web_editor: reduce the timeout for chatgpt calls
The timeout for calls to the OLG API in the editor was set to 300
seconds, which is far too long for a chatbot. This reduces it to 30s.

closes odoo/odoo#141135

Signed-off-by: Nicolas Bayet (nby) <nby@odoo.com>
2023-11-06 12:32:04 +00:00
Antoine GuenetandLou 386a2fdebf [ADD] web_editor: create/transform content with a LLM
This commit implements a dialog for content generation using ChatGPT,
which can be opened via the Powerbox or via a button in the toolbar.

If text is selected, the dialog opens in "alternatives" mode. In this
mode, five alternative versions of the selected text are generated. The
user can choose one and it will be inserted in lieu of the selection.
Five buttons can be used to guide the AI to make the content longer,
shorter, more professional, more friendly, or more persuasive. Clicking
any of these buttons will restart the generation process with the new
parameters.

If no text is selected, the dialog opens in "prompt" mode. In this mode,
the dialog contains a textarea in which the user can input a prompt
which is then used to generate content. The user can then exchange with
the AI back and forth until the content is satisfactory. Any of the AI's
responses can be inserted into the document by clicking its "Insert"
button.

When content is inserted into the document, a green frame is shown
around it for two seconds, to make it clear to the user that something
has been inserted and where.

If an error occurs, it is inserted in the dialog like other responses
but in red and it can't be inserted into the document.

Please find the PR of the IAP part (Odoo Language Generator) here :
https://github.com/odoo/iap-apps/pull/703

task-3383324

closes odoo/odoo#137064

Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
Co-authored-by: Antoine Guenet (age) <age@odoo.com>
Co-authored-by: Lou (loha) <loha@odoo.com>
2023-10-20 11:22:06 +00:00
Martin Trigaux 22ab49e343 [IMP] *: use file_path and file_open
Replace all the calls to get_resource_path to the better file_path or
directly use file_open when not needed

Doing both a get_resource_path and file_open means checking twice that
the file exists.
Doing a simple path concatenation before a file_open is safe.
If given to another method (e.g. etree.parse), calling file_path is
the prefered method.

Note that get_resource_path used to return False when the file does
not exists while file_path/file_open raises a FileNotFoundException

closes odoo/odoo#135607

Related: odoo/upgrade#5187
Related: odoo/enterprise#47475
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-10-06 14:33:43 +00:00
Benoit Socias 262a05931c [FIX] web_editor: replace extension of webp converted images
This commit replaces the `.jpg`, `.jpeg` or `.png` extension of uploaded
images to `.webp` when the image is converted to webp.

task-3460171

closes odoo/odoo#137022

X-original-commit: 77624c9eafc7f21a2ec5edcd3d56ee76e646fc38
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2023-09-29 09:21:55 +00:00
Nicolas Bayet 1d70293093 [REF] web_editor: move handle_history_divergence in tools.py
As `handle_history_divergence` is not used in the controllers, it makes
no sense to have it in `controllers/main.py`.

task-3217965

closes odoo/odoo#136277

Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
2023-09-27 14:57:13 +00:00
Nicolas Bayet 1eb32c94b4 [REM] web_editor: remove route /web_editor/ensure_common_history
As the route is not used anymore, remove it.

task-3217965

Part-of: odoo/odoo#136277
2023-09-27 14:57:13 +00:00
Nicolas Bayet 2d05f703d7 [FIX] web_editor: strengthen collab stale detection & recovery
Before this commit, the stale document detection was imprecise and
incomplete.

The stale document could happen in different scenario:
1)  Client B save when client A is disconnected (therefore client A
    should be notified that the document is stale upon reconnection):

    - For that scenario, the code had a heuristic to detect if the
    internet connection disconnected and reconnected but was imprecise
    as the browser api is not 100% reliable on all browser and
    platforms. That made the code under-checking or over-checking with
    the server.

2)  The user has not yet focused on the element and before this
    commit, the stale document was not detected.

3) If there is a partition in the peer to peer network and a member of
   another partition that save, all other partition will not be aware
   that they are working on a stale document.

4) The stale document happen before 2 peers could be fully connected.

For any of those scenarios, if a stale document was not detected and
the user tried to save changes, only then, a popup would inform that
the version was stale. And if the user closed the tab thinking the
document would automatically save, the change would not be saved
(without warning).

This commit:
1) improve detection of stale document
To detect the document this commit add a message in the odoo bus.bus
for the channel of the record for each write. That will ensure the
message to be received as soon as a user is connected to odoo.

2) improve recovery from stale document
Before this commit, the recovery was only made from the server.

As a detection is now direct (rather than delayed by the previous
heuristic), a document could be detected stale before receiving a step
that would not make it stale. Therefore, we cannot just reset from the
server as a recovery mechanism.

To recover, this commit first tries to reset from missing steps from
all peers. If unsuccessful, it will tries to reset from a snapshot. If
unsuccessful, it will reset from the server.

3) add a mechanism for aborting requests
To prevent unexpected concurrency behavior, this commit add a mechanism
to abort requests.

4) a framework for testing the collaboration of the wysiwyg
As it could be quite tedious and error prone to manually tests
concurrency issues related to the wysiwyg, this commit add a framework
for testing the collaboration of the wysiwyg and test the detection
and recovery of stale document.

task-3217965

Part-of: odoo/odoo#136277
2023-09-27 14:57:13 +00:00
Julien Banken 95e6d0199b [FIX] web_editor: video selector component adjustments for Knowledge
This commit will apply the following changes:
1. Introduce a new `VideoIframe` component for the `VideoSelector`
   component. With that change, one can easily mock the `VideoIframe`
   component in a tour and replace the iframe of the video with
   alternative content. It will then be possible to test the whole video
   integration flow with a tour without relying on Third-Party services.
2. Enhance the Python video parser to include the video id and the video
   parameters of the url being parsed. These new information will be
   used for the new video behavior of Knowledge.
3. Call the callback function notifying that the video url has changed
   when the textarea is emptied (see: `selectMedia`).
4. Authorize non-internal users to call the /web_editor/video_url/data
   route. This will ensure that portal users will be able to integrate
   videos in their Knowledge articles.
5. Apply some minor UI and UX adjustments:
   - The label next to the toggle buttons will now be properly aligned.
   - The textarea to input the video url will be automatically focused.

task-3297215

closes odoo/odoo#127452

Related: odoo/enterprise#40683
Signed-off-by: Damien Abeloos (abd) <abd@odoo.com>
2023-09-13 15:34:27 +00:00
bve-odoo 66dcfc9bcb [FIX] web_editor: better error message when missing filename field
closes #112101

Signed-off-by: Rémy Voet <ryv@odoo.com>
2023-06-09 12:58:02 +00:00
Louis Wicket (wil) 537b0ce712 [REM] base, *: remove binary_field_real_user from context
Formerly, using sudo() on a record had the effect of replacing the
current user with the superuser. But sometimes, knowing who the "real
user" was was necessary, so we needed to store it somewhere. This is
basically why the key `binary_field_real_user` was introduced in the
context: to keep track of who the user was before switching to sudo
mode.

Since 1e6c3bec2c, however, switching to
sudo mode no longer changes the current user; meaning that the
`binary_field_real_user` is no longer necessary.

This commit removes the remaining occurrences of the now useless
`binary_field_real_user` from the code.

* = hr, portal, web_editor

closes odoo/odoo#92032

Enterprise: https://github.com/odoo/enterprise/pull/27649
Related: odoo/enterprise#27649
Signed-off-by: Louis Wicket (wil) <wil@odoo.com>
2023-08-16 10:23:49 +02:00
Maitri Patel b66c88df12 [FIX] web_editor: handle none value for description field
If a user gets the 'description' field None, then traceback will appear.

https://github.com/odoo/odoo/blob/907aba0f54f65788c78c1370a573fbe9b69be8c5/addons/web_editor/controllers/main.py#L50

Error: 'TypeError: expected string or bytes-like object'

Sentry-4319373991

closes odoo/odoo#131943

X-original-commit: d00a1fd4b3dbed7b55a32ce6bbd659b56dd06de2
Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
2023-08-14 19:28:58 +02:00
Xavier-Do 595aa24843 [IMP] registry: multiple ormcache
One of the main issue with ormcache is that the invalidation clears
everything, meaning that some value, slow to compute but with a long
lifetime, can be removed from the cache because an easy to invalidate
value is cleared, like after writting or creating a product has an
example.

Most example in the code will try to invalidate the cache of the models
doing something like `env['ir.qweb'].clear_caches()` but it is
finally equivalent to `env.registry.clear_cache()`, and cross worker.

The idea is to have multiple cache, maybe with specific sizes for a
specific purpose.

Having one per model is maybe a bad idea because it will be difficult
to size the LRU correcly, and it is too dynamic. Checking invalidation
may be expensive.

The proposed solution is closed allow a limited number of named caches,
using onse sequence per cache. This is actually close to the
cache_longterm.

We want to discourage using a specific cache for one use case in
the buisness code. Adding a cache shouldn't be something easy, doable
in stable.

Note that we could also change the invalisation mecanism using an
insert only table. We an check the sequence of this table, but also
fetch all invalidation messages.
Another possible improvement, especially if we have more than x cache is
to have a global sequence, checking signaling would mean to check the
main sequence, and only the other ones if the main one changed.

Note that this poc is inspired from the long term cache but not all
use case where applie yet.

Part-of: odoo/odoo#119813
2023-07-18 11:42:26 +02:00
Xavier-Do a0c1f41780 [IMP] base, website: small refactoring
Mainly to simplify website overrides and general api

Part-of: odoo/odoo#119813
2023-07-18 11:42:25 +02:00
Benoit Socias 0ba3617f9d [IMP] base, web_editor: precompute and use resized webp on upload
`libwebp` cannot be used to perform resize operations on webp images on
the server.

This commit uploads all resizes of webp images whenever a webp image is
uploaded:
- resized to any smaller size in 1024, 512, 256 & 128,
- each size converted to jpg as well to be usable in `wkhtmltopdf`.

When an Image field requires `_imageProcessing` to resize a webp image,
it retrieves the pre-resized image instead of running through the
Pillow toolbox.

Pre-converted images are stored as `ir.attachment`s with:
- `res_model` = ir.attachment
- `res_id` = id of transformed attachment
  i.e. id of original size webp for resized images
       id of webp for jpeg-converted images
- `description` = "format: image/jpeg" for jpeg conversions,
                  "resize: [size]" for resized images.

task-2774352

Part-of: odoo/odoo#85494
2023-07-15 05:10:46 +02:00
Benoit Socias c035d0003d [IMP] web_editor: upload a JPEG too when uploading a WEBP
The library used to generate PDFs does not support the WEBP image
format. For those images to be included in reports, they need to be
converted. For security reasons, this conversion cannot be done on the
server, therefore it was decided to keep an already converted copy of
such images.

This commit converts uploaded WEBP images to JPEG and uploads them both
so that the report generation can use the JPEG instead.

task-2774352

Part-of: odoo/odoo#85494
2023-07-15 05:10:45 +02:00
Xavier-Do ca8dc2d9b4 [IMP] base, website: small refactoring
Mainly to simplify website overrides and general api

closes odoo/odoo#121376

Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2023-06-10 11:14:12 +02:00
Xavier-Do 6d5d234f15 [IMP] base: better ormcache management
1. move cache to _get_asset_paths

The `_get_asset_content` cache has many cache key that are related to a
posprocessing of the `_get_asset_paths` result, the heavy part of this
method. Moving the cache to _get_asset_content will have the benefit
to create less duplicates entries in the ormcache as well as less cache
miss.

To simplify even further, the css and js parameters are removed since
they only filter the output of get_paths, the heavy part of globing the
file will be done before that. Anyway, they are both true when called
from _get_asset_content, and the only other call, in
`_get_related_bundle` don't really need to filter them since it is not
a critical part regarding performance, and the funtional result will
stay the same.

The initial orm cache key was using `_get_template_cache_keys`, a little
overkill and possibly creating duplicates entries again. The only
context key needed is website_id for `_get_related_assets`.

Note that it is not really enough, the orm cache key should actually
contain `request.session.get('force_website_id')` as well has
`request.httprequest.host`. This will be addressed latter since a nicer
solution would be to have website_id as a unique parameter computed
earlier.

2. better _get_asset_paths cache key

The orm cache key was simplified in previous point but there is still
one concern, the website_id depends on more parameters than that:
- request.session.get('force_website_id')
- request.httprequest.host
- existing websites

The idea here is to call `get_current_website` instead of using all
parameters that could define the webiste.

In the same spirit of `_get_template_cache_keys` `_assets_path_params`
can be overriden to give extra params that are usefull to list assets
path. Those params are computed before entering the method
`_get_asset_paths`. This may latter put at a higher level latter, in
get_asset_node, to simplify the _generate_asset_nodes_cache key.

3. better assets_node caches key

The main purpose of this part is to improve ormcache containing assets
nodes. The ormcache key contains
- to much context key
- missing session/host/env info
- unwanted boolean options.
- keys leading to the same cache value

The main goal being to reduce the size of the cache keys, decrease the
number of cache entries and improve the cache hit.
This will also make the behaviour more coherent and hopefully less bug
prone because of mismatch in parameters.

The main reason of the orm cache is the slowness of the validation of
the assets. This includes:
- listing files (dedicated orm cache)
- computing version

The cache key was depending on
- `debug`
The only relevant value for debug is "contains assets"
We dont need to differ between debug='', debug='1', debug='test',
and 'debug=assets', 'debug=tests,assets', ...
- `defer_load`, `lazy_load`, `media`
Those values are only useful to generate html node, a leightweight
operations that does not really needs to be in cache. `media` was also
used in the generation but it looks useless if we have the media on the
node. THIS NEEDS TO BE VALIDATED but in any case, since media is not
used to generate the url, it doesn't make sence to use it in the
generation.
The main idea to remove them from the ormcache key is simply to generate
the nodes outide the ormcached values.
-`async_load`
This one is similar to `defer_load` and `lazy_load` but it looks like
it wasn't used anymore. This was simply removed
- context.get('lang')
The only information needed is the direction, rtl or ltr. This means
en and fr languages, despite sharing the same css assets, will duplicate
the ormcache entries.
-`_get_template_cache_keys`
Only the lang and webiste where really relevant in this flow. Other
keys are actually useless in this flow.

Some information used in the generation where not in the orm cache key
- `self.env.user.lang` if there is no lang in the context
- `request.session.get('force_website_id')`
- `request.httprequest.host`
- ...

The proposed solution is to:
- extract any informùation needed from thecontext, request, environment
before entering the ormcache, reduce it to the minimal possible set of
values needed
```
    rtl = self.env['res.lang']._lang_get_direction(self.env.context.get('lang') or self.env.user.lang) == 'rtl'
    assets_params = self.env['ir.asset']._get_assets_params()  # website_id
    debug_assets = debug and 'assets' in debug
```

and remove a leightweight part of the logic

```
    def _get_asset_nodes(self, bundle, css=True, js=True, debug=False, defer_load=False, lazy_load=False, media=None):
        links = self._get_asset_links(bundle, css=css, js=js, debug=debug)
        return self._links_to_nodes(links, defer_load=defer_load, lazy_load=lazy_load, media=media)
```

Where _get_asset_links is the cached part, and _links_to_nodes is the
lightweight part generating the nodes based on the `defer_load`, ....

Additionnal notes:
- data-asset-version and data-asset-bundle are removed from the node
since they don't seem to be used anymore since 65d70acdbf
- async_load is removed since there is no occurence of this in the code.
- a small hack is still needed to pass javascript content instead of
links, this is only to manage css compile error and will hopefully be
removed in the future.
- a context key is still in use to generate the bundle, the
`commit_assetsbundle` but it has no impact on content and will hopefully
be removed in the future.

4. Add test for ormcache hit/miss

In this context, hit/miss is about having the same cache key for the
same result. This test demonstrates the current state, were entries are
create in the ormcache only if the key is really different and will lead
to a different result.

5. remove cache invalidation

This cache invalidation is quite agressive since everytime an
assetbundle is updated, all workers will clear their cache.

The concerned cache by this clear_cache is `_generate_asset_nodes_cache`
throug `_get_asset_nodes`.

The cache is ignored, both in dev=xml and debug=assets.

This clear cache was made conditionnal in 553ea82f81 but this does
not solve an issue we can have in production.

Lets imagine a clean solution
- all sources are updated
- all workers are restarted.

The orm caches are all empty, but since the sources
changed, all bundles will be recomputed. This means that every bundle
updated in database with save_attachement will invalidate the cache of
all workers. Rendering a pdf report of any kind using a specific bundle
will invalidate all cache. Starting a debug=assets for the first time
will invalidate all cache, even if the cache is not used in this case.

But for a regenerated bundle we would expect the ormcache to be:
- empty (did not generate the same bundle yet)
- have the same value (concurrent generation of the same bundle)

Having a different value would mean that the bundle was generated with
another version of the sources. In this case it is maybe even better not
to invalidate the cache since it could lead to an invalidation war
between two workers.

The only case where invalidating this cache is useful is when a bundle
changes, Usually if an ir_asset is created, modified, ...

There is still another rare but possible possibility to have a 404 if
the transaction is rollbacked after populating the assets node cache.
In this case, we only need to clear the cache locally in case of
rollback.

Part-of: odoo/odoo#121376
2023-06-10 11:14:11 +02:00
Robin Lejeune (role) 3f80451100 [FIX] web_editor: fix flipped SVG shapes on Firefox
On Firefox only: some SVG shapes either disappear when flipped or are
not properly flipped.
This is due to the way Firefox parses SVGs and the way Odoo applies
transformations on them. It happens when the main `<svg>` contains other
nested `<svg>`, and the flip transformation is applied to each of them,
causing unexpected behaviors.
When the parent contains a direct `<svg>` child and both of them are
then applied a transformation, the whole shape disappears. When the
parent contains some `<svg>` inside a `<defs>`, and the children are
then included with `<use>`, each element is flipped individually, which
means the flip is not processed as we would expect.
This commit makes sure the flip is only applied to the main `<svg>`.

Steps to reproduce:
(A) >= 14.0:
- On Firefox, drag & drop the image-text snippet
- Add a background shape and choose "Origins 07"
- Flip it: it isn't flipped

(B) >= 15.2:
- On Firefox, drag & drop any block snippet
- Add a background shape and choose "Float 13"
- Flip it: the shape is hidden

task-3264851

closes odoo/odoo#123175

X-original-commit: 784b4dd1a7c0a75d301466a83a2894418ff8eaa2
Signed-off-by: Bojabza Soukéina (sobo) <sobo@odoo.com>
2023-06-01 10:25:30 +02:00
Preksha Chouhan feff1fc79f [FIX] web_editor: convert color opacity to be compatible with PIL Image color
ValueError 'unknown colour specifier' occurs when we access
export_icon_to_png(). This error occurs when we change the colour of an
icon in the mailing template, because the value of alpha (opacity) in 'rgba'
is in the range of 0 to 1, but PIL Image support colour opacity range 0 to 255.

This commit converts the opacity value range (0 to 1) to a range (0 to 255)
compatible with the PIL image library when the colour specifier is 'rgba'.

sentry - 3933353285

closes odoo/odoo#121696

X-original-commit: 7e4be89f6c0b2f8b82a207030e8a8cb20d72664f
Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
2023-05-19 10:18:53 +02:00
bve-odoo 6c2b889a28 [FIX] *: prevent warnings on runbot and sentry noisy tracebacks
As we have a team dedicated to work on analysing tracebacks
with sentry, and to takedown all tracebacks occuring on the saas,
we do an effort to avoid unecessary warnings and tracebacks
for both sentry and the runbot.

closes odoo/odoo#112101

Signed-off-by: Rémy Voet <ryv@odoo.com>
2023-02-27 17:45:35 +01:00
Jeremy Kersten 81a875fcaa [FIX] web_editor: adapt color of svg support rgba with space
Before this commit, we only support rgba(xxx,yyy,zzz,v.www)
Now we support also rgba(xxx, yyy, zzz, v.www)

How to reproduce:
Edit theme color secondary, chose a color with transparency.
Go to a 404 page and the pinky will be not loaded.

closes odoo/odoo#114486

X-original-commit: e418c912509999e44bcfc5325f3df6844af9bfe6
Signed-off-by: Jérémy Kersten <jke@odoo.com>
2023-03-19 15:49:04 +01:00
Nicolas Bayet d42a1736ca [FIX] web_edior: prevent fix ensure_no_history_divergence crash
When record does not contain any value for a field being checked by
`ensure_no_history_divergence`, prevent the check as there is no version
to check againts.

task-3196592

closes odoo/odoo#113767

X-original-commit: 7e32b645b28164038e13393867a79672d69e4d17
Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
2023-02-27 17:08:02 +01:00
Achraf (abz) a1d73fef7f [FIX] web_editor: Change logger.error to logger.warning
we don't necessarily need an error type logger here, a warning is enough.
In addition, it is reported on sentry because we receive all error type logs.

sentry-3931144637

closes odoo/odoo#113765

X-original-commit: 358a85103476d25ea507f210d0fae4eef9853669
Signed-off-by: Achraf <abz@odoo.com>
2023-02-27 17:07:59 +01:00
David MonjoieandOlivier Dony db295685ad [FIX] web_editor: better history divergence regexp
Using a lazy `?` quantifier lead to poor matching performances and
was not needed technically.

Using `*` instead of `+` lead to a lot of false positives when trying
to write records with an empty value for `data-last-history-steps`.

It is currently unclear how to reach such a case but in the meantime
it is better to allow people to write the record as such rather than
being completely locked with no possibility of saving.

closes odoo/odoo#113540

X-original-commit: 0a370758972e6a0c399471f9982f3898da92ef68
Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
Co-authored-by: Olivier Dony <odo@openerp.com>
2023-02-24 10:06:27 +01:00
Benoit Socias fb9efde4f3 [FIX] *: replace werkzeug's Response by odoo's Response
*: base, http_routing, mass_mailing, web, web_editor, website_slides

In some situations `werkzeug.wrappers.Response` are used instead of
`odoo.http.Reponse` that extends it.
This is a problem because since [1] the calls to `set_cookie` expect it
to accept the `cookie_type` parameter, which is not the case in the base
werkzeug implementation.

This commit replaces the `werkzeug.wrappers.Response` by
`odoo.http.Response`.

[1]: https://github.com/odoo/odoo/commit/2cbda6c98ee947cea1d06c09880eee8c758304a8

closes odoo/odoo#112827

X-original-commit: 28da08292b7028575e628c5ad846fc05d30498f2
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
2023-02-16 09:01:07 +01:00
Nicolas Bayet 9731e9be6d [FIX] web_editor,project,note: ensure same history
This commit add a mechanism to ensure that someone could never save
changes from an history that diverge (in case there is a partition in
the RTC network or a person A was disconnected while another person B
saved changes that were not transmitted to person A).

task-3002163

closes odoo/odoo#112099

Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
2023-02-09 10:49:00 +01:00
Nicolas Bayet 82d9e8bf9f [FIX] web_editor: write with string in update_checklist
Before this commit, when the user tried to update a checklist, there
was a traceback in `handle_history_divergence` because the `value` is a
byte sequence instead of a string.

opw-3158660
task-3165844

closes odoo/odoo#112112

X-original-commit: e3900dfe51cb294ad139395cb402c9f13dd067c5
Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
2023-02-07 16:38:42 +01:00
Benoit Socias 3bbce756c6 [IMP] website, web_editor, *: save dropped images as attachments
*: mass_mailing

When images are dropped from outside the browser into a website page
text paragraph, they are stored as an inline base64-encoded source.

This commit marks those images to be saved as attachments when it
happens in website. The save happens upon page save similarly to what is
done when images are transformed.
This commit also applies this behavior for pasted images.

task-2928495

closes odoo/odoo#98801

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2022-12-23 19:19:06 +01:00
Romain Derie 7442fb7161 [IMP] web_editor: consolidate both supported image mimetype lists
Before this commit and since commit [1] which introduced
`SUPPORTED_IMAGE_EXTENSIONS` on top of the existing
`SUPPORTED_IMAGE_MIMETYPES` there would be 2 lists which were holding
related values which a strong link between the two: one was holding the
image extensions while the other was holding the images mimetypes.

It was a bad idea as it was not robust and no relation between the two.

It's an issue as some WIP code was then trying to retrieve the extension
based on a given mimetype which was not possible to do in a reliable
way:
```py
ext = SUPPORTED_IMAGE_EXTENSIONS[SUPPORTED_IMAGE_MIMETYPES.index(mimetype)]
```

The chance is then taken to merge those 2 lists in a single dict that
will strengthen the link between the mimetype and its related extension.

[1]: https://github.com/odoo/odoo/commit/9dab9ffce297dcfc89f0ec7efc4c8f8b43104220

Part-of: odoo/odoo#98801
2022-12-23 19:19:06 +01:00
qsm-odooandJulien Castiaux 0e8e5d4c0a [FIX] web_editor: restore shape on default images in themes
Website themes make customizations to the default snippets. In
particular, some are applying shapes on default images. To do that, the
customization is not applied on the image directly but by changing its
src to a special web_editor route in charge of automatically adding the
shape on whatever default image the configurator chose for this snippet.

Typically, in a snippet with an image whose src is:

/web/image/website.my_snippet_default_image

The src is replaced by the theme with:

/web_editor/image_shape/website.my_snippet_default_image/website/some_shape.svg

That controller/route crashed since [1], making those images blank
areas in pages generated by the configurator. Indeed, the image from
the filestore was accessed via `file_open` which only allows reading
inside the addons_paths.

[1]: https://github.com/odoo/odoo/commit/da8def8e410de68256ba4ab09ebf7a8b699355ac

closes odoo/odoo#105421

X-original-commit: d536e0a23cf0aa06c3ee13fb2c105e83201434e0
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
Co-authored-by: Julien Castiaux <juc@odoo.com>
2022-11-09 15:04:03 +01:00
Romain Derie ab2adbdc72 [FIX] web_editor, *: allow internal user to upload unsplash image
* web_unsplash, website_forum

With [1], the access errors when a portal user were using the media
dialog got fixed. It also came with the unsplash capability for portal
user in the media dialog.

Still, there was a remaining problematic point: an internal user can't
upload an unsplash image in the backend through the media dialog. It
doesn't really make sense for an internal user to have less right than
the portal user.

This commit corrects that part.

Note that only unsplash images were problematic, not regular uploaded
image as the difference was that unsplash images attachment are saved
with an `url` property, which was triggering due to [2].

Finally, it was chosen to make that "bypass" more robust and opt in, so
forum and unsplash are allowing their use cases to go through, it's not
done in a generic way anymore.

Also fixing a small issue about the res_id not being sent when editing a
forum post, because it was assuming that the URL would end with the ID
which is not the case when you edit your answer.

[1]: https://github.com/odoo/odoo/commit/e10493711879c7f0cc8832db3f1936c622ea605c
[2]: https://github.com/odoo/odoo/commit/bfffe39f1376a56226572295b945a2cc73ba50ce

task-3007844

closes odoo/odoo#103138

Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2022-10-12 10:34:58 +02:00
Benoit Socias 37d8810235 [FIX] web_editor: filter ACE views that do not belong to page
When the ACE editor was introduced in [1], it relied on the already
existing `_views_get` to obtain the list of views that could be edited.

When the `mode` of `ir.ui.view` was introduced in [2], no mechanism was
introduced in `_views_get` to avoid fetching primary views that have
nothing in common with the current view.

This commit adds a parameter to `_views_get` to request the
exclusion of unrelated primary views.
Since even before it appeared in [3], `_views_get` relies on the
following approach:
- consider the top-most parent of the `t-call`ed views
- consider the views that inherit it
I.e.: reach each node of each view hierarchy tree by starting from its
root.

Because this starts from the top-most parent, simply preventing the
call to each primary child view is wrong, because any child on the
parent path must be considered - be it primary or not.
We therefore introduced a `skipped` list that keeps track of those
"later to be processed" views - so that the filtering of primary
children does not remove them.

[1]: https://github.com/odoo/odoo/commit/7c45e5976e6caf3d7b9eb508f728062704232261
[2]: https://github.com/odoo/odoo/commit/434be479f97a32987d0817bf329183fc2bbe3bf5
[3]: https://github.com/odoo/odoo/commit/bff6e04e9536d7b80916987eb123de98b1b689b1

task-2898555

closes odoo/odoo#100625

X-original-commit: 34ac97ce96019573a6a0af968d9c90b9d0d89ae8
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2022-09-21 02:26:01 +02:00
Gorash 5410b7c238 [IMP] base/web: XML templates are added into the asset bundles.
XML files are now declared in python module manifests. During the qweb
't-call-asset' directive, assetbundle will fetch the declared xml files,
apply the inheritance (t-inherit) and create a javascript service (for
eg: 'web.assets_backend.bundle.xml') which is added at the end of the
*.js mimifier file.

When the debug mode is activated, comments are added in the template
indicating which file the template comes from as well as the
inheritances applied to it.

****

JavaScript:

assets.js (module @web/core/assets) takes care of loading libraries,
javascripts and styles.
`loadJS(url)` (loads the javascript and returns a resolved promise when
the templates are also loaded via the '*.bundle.xml' service)
`loadCSS(url)` (loads the style a resolved promise when the file is
loaded)
`loadXML(xml, app=assets.defaultApp)` (load template into
application/owl, used by the `*.bundle.xml` services)
`getBundle(bundleName)` (get the bundle descriptor)
`loadBundle(desc)` (load the files and bundle from a descriptor)

templates (XML element content all owl templates)

A new `ready(serviceName)` method on boot.js lets you know when a
service is loaded are the require.

The xmlDependencies attribute no longer exists.

Python:

The xmls taken into account by assetbundle.py, applying `t-inherit`
inheritances and adding an `name_of_the_bundle.bundle.xml` service in
the generated JavaScript file.

****

Every manifest changes is into the next commit, except 'web_tour' in
this current commit as example.

Part-of: odoo/odoo#95500
2022-09-14 20:25:01 +02:00
tsm-odoo de6de48deb [IMP] bus, *: adapt server to use websocket instead of longpolling
*: hr_presence, web_editor.

This commit is part of the websocket integration in Odoo.
It focuses on adapting the bus to support websockets:
   - last notification id is now kept on the server
   - channel list is built by overriding the `_build_bus_channel_list`
     method of the `ir_websocket` model instead of overriding the `_poll`
     method of the bus controller.
   - The bus presence was updated during polls, since there is no more poll,
     bus presence update will be the responsability of the client.
   - The `/websocket/peek_notifications`, `/websocket/update_bus_presence`
     routes will be available so that odoo sh can access notifications/update presence
      from http requests.
   - /longpolling routes are now prefixed with /bus thus won't be redirected to the
     gevent worker anymore except for `/longpolling/health` which is the
     health check route of the gevent server.

Since websocket now handle incoming messages, a way to manage authentication
have been introduced :
    - The session is retrieved from the HTTP handshake.
    - When a websocket message comes/leaves the session is retrieved
      on the file system so that we're sure it still exists and that
      it is up to date.
    - The session is checked
    - If no session is found on the file system or `check_session`
      fails, the websocket connection is closed with the `SESSION_EXPIRED`
      close code (which is a custom close code: 4001).
    - Note that websocket connections are closed every `KEEP_ALIVE_TIMEOUT`
      seconds to ensure no websocket connection will stay open if the user
      clears its cookies.
    - Note that a wsrequest object is available when processing incoming
      messages. It is similar to the http request and contains various
      useful informations (session, env, ...).

Part-of: odoo/odoo#75510
2022-08-23 17:55:10 +02:00
Romain DerieandMerlin e104937118 [FIX] web_editor, web_unsplash, *: allow portal user to upload images
* website_forum

Portal users cannot insert images in the WYSIWYG, eg in a forum post.

Steps to reproduce:
- Install website_forum
- Connect as portal
- Go to the forum and create a new post
- Type '/image' and try to insert an image
- An Access Error is raised preventing the portal user from inserting an
image

History:
- It was possible in version earlier than 15.0 before the new editor, as
  it was using a base64 inplace image upload to bypass the access rights
  and avoid creating an attachment.
- It was broken in 15.0 with the new editor which doesn't have such a
  mechanism. The image upload was then disabled for those users in 15.0
  with [1] to avoid that bad UX with those errors/tracebacks.
- It was decided to implement a clean solution in master and see from
  there was will be done with 15.0 (as being able to upload an image on
  a forum seems quite critical).

Solution here in master to be able to use the media dialog:
- First issue, about opening the media dialog:
  It fetches attachments, which is raising some access errors. We now
  catch the error silently and return an empty list.
- Second issue, about upload an image (and thus creating an attachment):
  We now create attachments with sudo to allow access to portal users,
  but only if he has write access on the model.

[1]: https://github.com/odoo/odoo/commit/e453d4c119a69f285d9a014babe485492bbe9c40

opw-2648770
task-2811325

closes odoo/odoo#82612

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Co-authored-by: Merlin (megu) <megu@odoo.com>
2022-07-08 14:33:43 +02:00
Antoine Guenet ae7110f44e [IMP] web_editor: add route for Odoo Editor tests
Loading assets for Odoo Editor's tests was a problematic matter since
some were in the lib folder while others were in src. This solves that
issue by finally creating a route for these tests, like web has one for
QUnit tests.

Part-of: odoo/odoo#94516
2022-07-04 18:53:07 +02:00
Benoit Socias 3fd430bf8e [FIX] web_editor: restore finding attachment image info
Since [1] the attachments are not found by `get_image_info` anymore
because the search based on the id only does not specify the model.
Because of this the mimetype of uploaded images is not put in the DOM
image's dataset. This lack of mimetype prevents the Shape, Filter, Width
and Quality image options from being used.

This commit defaults the model to `ir.attachment`.

Steps to reproduce:
- Drop a "Text - Image" snippet.
- Replace the image by uploading one.
=> The Shape, Filter, Width & Quality options did not appear anymore.

[1]: https://github.com/odoo/odoo/commit/da8def8e410de68256ba4ab09ebf7a8b699355ac

task-2883695

closes odoo/odoo#94288

X-original-commit: 99fda1024ff7d809f13523acd13770c02a49d1e1
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2022-06-22 14:28:56 +02:00
Florian Charlier dae28c4b46 [IMP] base: add _is_internal method to res.users
No method was readily available to know if a user is `internal` (has
group `base.group_user`), which was inconsistent with other base groups.

_is_internal is now used in the codebase where it is clear that
`.has_group('base.group_user')` is called on a single record.

Part-of: odoo/odoo#85703
2022-06-14 09:35:57 +02:00
Julien Castiaux da8def8e41 [IMP] core, web: Delegate delivery of static files
Rationnals
----------

Web servers can serve some resources (e.g. static files) right away
without any interaction with the web application. The network model of
most web servers makes them capable of handling thousands of
simultaneous requests when it comes to intensive IO operations such as
streaming data from a file. The network model of Odoo is different: it
is capable of a lot of processing power but can only serve a handful of
requests at a time, i.e. Odoo (with some help from postgres) is
optimized for CPU operations, not IO.

Some users don't configure their web server, they use a basic
configuration that relay all requests to Odoo. The result is that many
Odoo HTTP Workers can be busy streaming static files instead of
processing other requests. This can lead to a worker starvation, i.e.
all workers are busy streaming files and cannot process new requests.

X-Sendfile
----------

In this work, we add the support for the [X-Sendfile] header family,
they are multiples http headers that can be used by the web application
to communicate with the web server in order to delegate the delivery of
files stored on the file system. Odoo still receives the request but it
does no more stream the file content from within its HTTP worker,
instead it skips the response body altogether and sets the `X-Sendfile`
special header with the path of the file on the filesystem. The web
server intercepts that special header, open the file and stream it.

Using those headers, we can use the best of both the web application and
the web server. The web application is still responsible to locate the
resource and verify the access rights, the web server is still
responsible of streaming the content.

Using X-Sendfile is opt-in via the `--x-sendfile` CLI flag. We set both
`X-Sendfile` (apache) and `X-Accel-Redirect` (nginx). If you are using
apache, make sure `mod_xsendfile` is enabled. If you are using NGINX
you have to add the following location block:

    location /web/filestore {  # custom path, hardcoded within Odoo
        # Prevent access from the outside world, i.e. makes this
        # route only accessible via X-Accel. MANDATORY!!!
        internal;

        # Give access to the filestore using this server's
        # permissions. Odoo is in charge of verifying the access
        # rights.
        alias /path/to/odoo/data-dir/filestore;
    }

The Odoo [deployment documentation] has been updated accordingly.

[X-Sendfile]: https://www.nginx.com/resources/wiki/start/topics/examples/xsendfile/
[deployment documentation]: https://www.odoo.com/documentation/master/administration/install/deploy.html#serving-static-files-and-attachments

Changes to the API
------------------

To benefit most from X-Sendfile, all APIs related to streaming content
over HTTP has to be adapted. They are: (1) `request._serve_static`,
(2) `ir.http._serve_fallback`, (3) `/web/content` and (4) `/web/image`.

Each used it own way to deliver content: (1) `_serve_static` was using
`send_file` (flask's send_file that as been vendored with odoo 10
years ago and not maintenained since then), (2) _serve_fallback was
handcrafting a `werkzeug.wrappers.Response`, (3) /web/content-image were
using the "binary server" `ir.http.binary_content` API.

I has been decided to remove all 3 APIs and to merge the code inside of
the new `http.Stream` object and the `ir.binary` helper model.

A Stream wraps what is going to be sent to the browser, it can be a path
to a file on the locale filesystem, a blob of raw data or an URL to an
external resource. The Stream also holds various metadata that are
mainly used for caching. The preferred way to create a Stream is via one
of its three factories so that all the metadata are set. The factories
are: `from_path`, `from_attachment` and `from_binary_field`. A stream
instance exposes a single method `get_response()` used to create the
corresponding HTTP response object out of the stream.

Inside of `ir.http` were a few methods that were not related to the http
routing and formed what was called the "binary server". All those
methods have been removed and the feature have been refactored inside of
the new `ir.binary` model. The removed methods are:

- `_xmlid_to_obj`
- `_get_record_and_check`
- `_binary_ir_attachment_redirect_content`
- `_binary_record_content`
- `_binary_set_headers`
- `binary_content`
- `_response_by_status`
- `_get_content_common`
- `_content_image`
- `_content_image_get_response`
- `_placeholder_image_get_response`

The new `ir.binary` abstract model exposes the following utilities:

**`_find_record`**

Find an attachment or a record with a binary-field out of an xmlid or
out of a pair record-model/record-id. Check the access rights and the
access token.

**`_get_stream_from`**

Create a Stream from an attachment or a record with a binary-field.

**`_get_image_stream_from`**

Same as `_get_stream_from` but adapted for images. It sets a sensible
ETag on the stream and has image resizing support.

**`_placeholder`**

Get the image placeholder blob.

Testing
-------

It is possible to test the web server configuration using the
`test_http` module. Install the module then run the unittest using the
`webserver` test-tag. By default it attempts to connect to a web-server
running on `http://localhost:80`, you can change this URL by setting the
`WEB_SERVER_URL` environment variable.

    odoo-bin -i test_http --stop-after-init
    WEB_SERVER_URL='http://localhost:80' odoo-bin --test-tags webserver --stop-after-init

closes odoo/odoo#88134

Task: 2801675
Related: odoo/documentation#2083
Related: odoo/enterprise#26191
Signed-off-by: Julien Castiaux <juc@odoo.com>
2022-06-01 02:53:59 +02:00
Xavier Morel 7bce4c19f3 [IMP] web_editor: cleanup channels regex
Model pattern was too permissive, separator is the literal `.`
character, not any random thing.

Also remove unnecessary bracket expression, it's unnecessary when
matching a single item.

OPW-2836106

closes odoo/odoo#90107

X-original-commit: 320cdb4e85cb86915fa25cfda8f17e0a372e765e
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Signed-off-by: Raphael Collet <rco@odoo.com>
2022-05-03 13:31:03 +02:00
Benoit Socias a042851853 [FIX] web_editor: fallback on URL search when shape not found from slug
Since [1] illustration shapes are only obtained from their slug. Before
they were obtained from their URL.

After this commit the old behavior is restored as a fallback in case the
illustration shape cannot be found from its slug.
This is needed to allow importing shapes into the system from data
files.

[1]: https://github.com/odoo/odoo/commit/bde8abcfeb57c74438943e44215a7c8cb822329f

task-2793073

closes odoo/odoo#86858

X-original-commit: 91f2a989ddd7961f92a377b1bf74cc741dcbd3d0
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2022-03-22 13:36:56 +01:00
Benoit Socias e9e1864153 [FIX] web_editor: decode base64 of uploaded non-image documents
Since [1] non-image documents uploaded in web editor were stored as
received in base64 without being decoded.
This led to downloading them as they were stored in base64.

After this commit uploaded documents are base64-decoded before being
stored.

Steps to reproduce:
- edit a web page
- drop a "Text - Image" snippet
- replace the image
- upload a document (PDF, TXT...)
- save page
- download document
=> received document was base64-encoded

[1]: https://github.com/odoo/odoo/commit/6b8752604898bf2b583b7f5334e35f6a1583595e

task-2782269

closes odoo/odoo#86812

X-original-commit: b0218b8ff50c7cea2a018d20a62e63510bfdd01e
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2022-03-21 17:57:01 +01:00
qsm-odoo 1ab7210ae3 [REF] web_editor, website: review the web_editor.assets model
- Three controllers were actually useless as the relevant public methods
  of the web_editor.assets can be called directly via RPC in the related
  usecases.

- Review the web_editor.assets model methods organization in the model
  declaration.

closes odoo/odoo#85392

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2022-02-28 12:56:05 +00:00
Julien Castiaux c0647b5c52 [REF] core: HTTPocalypse (14) changes all addons
This commit is the 14th commit of a comprehensive refactor of our HTTP
framework. See odoo/odoo#78857 for complete historic, discussions and
rationnals.

* `request.uid = x` => `request.update_env(user=x)`.
* `request.context = x` => `request.update_env(context=x)`.
* `request.context = dict(request.context, x=y)`
   => `request.update_context(x=y)`.
* `request.cr = None` => `request.cr.close()`.
* `http.mono_db()` => `request.db`.
* `http.dispatch_rpc()` => `service.dispatch_rpc()`.
* `@service.model.check` => `service.model.retrying()`.
* `request.endpoint`
   => `env['ir.http']._match(request.httprequest.path)[0].endpoint`.
* `request.routing_iteration `=> `removed`.
* `request.jsonrequest` => `request.dispatcher.jsonrequest`.

Note that `request.params` is now set much later in the process. If you
are in a situation where you values from the query string or the
http body you can use `request.get_http_params()`.

Note that using the new `request.future_response`, it is possible to
add headers and cookies on the response object before the response
object is initialized. Please note that headers/cookies saved on
the future response will NOT be injected in case of error.

PR: odoo#78857
Task: 2571224
2022-02-24 13:30:51 +00:00
Antoine Guenet bf61c9a36a [FIX] web_editor: properly convert fonts to images
export_icon_to_png sometimes failed because PIL's getbbox returned None.
This fixes it by not using a default color of (0, 0, 0, 0) when creating
the image but using the actual color of the image instead.
Also, the size of the image was wrong because of using the default size
when width and height are defined.

task-2761098

closes odoo/odoo#84638

X-original-commit: efcb432f4c459b2d2d819c3aed7d63d53fc93809
Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
Signed-off-by: Antoine Guenet <age@odoo.com>
2022-02-15 14:55:05 +00:00
stefanorigano (SRI) 0f64e506f2 [MOV] web, * : move font-awesome library in an editable location
This commit "forks" fontAwesome into `src/libs` in order to allow
further customization.
Part of v16 overall restyle (task-2704984).

task-2745275

Part-of: odoo/odoo#83501
2022-02-08 12:05:54 +00:00
Antoine Guenet fcc220c336 [FIX] web_editor: prevent cropping fonts->images on apply padding
When fonts with a round border were converted to images, the dimensions
often ended up slightly off, and most visibly a little bit cropped by
the border.

Note that this also removes the "alpha" argument of the font_to_img
route since it wasn't used anywhere and transparency is not supported in
emails anyway.

Part-of: odoo/odoo#83233
2022-01-24 15:09:26 +00:00
Fabien Pinckaers 6b87526048 [IMP] Speed Imp: remove unnecessary base64 encode & decode
Avoid to base64 encode, then decode to process assets and images for a ~25% speed improvement.
Change image processing tool to work on images, rather than base64 encoded strings.

Performance is ~25% faster on assets & images:

  /web/assets/...frontend.min.css:    13ms to 7ms,  base64 enc/dec: 2 -> 0
  /web/image/XML_ID:                  10ms to 8ms,  base64 enc/dec: 3 -> 0
  /web/image/res.users/2/avatar_128:  40ms to 20ms, base64 enc/dec: 6 -> 2

closes odoo/odoo#82851

Related: odoo/enterprise#23537
Signed-off-by: Fabien Pinckaers <fp@odoo.com>
2022-01-22 11:51:42 +00:00
Antoine Guenet 2093aefbe8 [FIX] web_editor: remove check ids in tests
The random ids of checklists and stars are preserved in the dom, which
is needed for their readonly check features to work. However, it
complicates testing. This systematically removes these ids in tests.
It also removes the ids when they are not needed anymore (the node is
not a checklist anymore for instance).

closes odoo/odoo#83137

Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
2022-01-21 15:04:09 +00:00
Antoine Guenet d6688ca759 [ADD] web_editor: allow rating with stars in readonly fields
Similar to checklists, this allows the user to click the powerbox stars
widget even in readonly mode, so as to change a rating without going in
edit mode.

task-2575449

Part-of: odoo/odoo#81920
2022-01-14 10:21:30 +00:00