Chrome recently changed their SameSite policy default value from None to Lax,
the session is no more shared between the webpage and the iframe.
As a result, the csrf check systematically fails.
After this commit, the csrf_token check is only made when you have a session.
In case you are using your form in an iframe on another site, with the new
cookies policy, your cookies with the session_id (linked to the csrf token)
is not sent to the server and the check csrf always fails.
Since the purpose of the csrf is to prevent another website to submit a form
with your 'authenticated account', we can consider that if you are not logged
and so have no session_id, it is no critical and we can ignore the csrf check.
opw-2330286
closesodoo/odoo#58050
X-original-commit: 9a0c9f3192bc7043add89446cbe6c2650499a654
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
When we send dates with website_form, if the language of the website is
eg. in arabic we will send moment.js arabic dates that can't be parsed
by the server.
This also happens with norwegian and any language which doesn't use
ascii numbers or textual format of month or days (and possibly RTL
language).
With this changeset, if we detect we are in a use case where this matter
(an existing field and a date format that will fail) the date will be sent
as odoo server format.
Expected change:
- what worked still work with or without server restart
- what didn't work works after server restart
- special case such as "english" with custom format in res.language
containing textual month might now not work with code update without
server restart (probability of this is low).
opw-2326882
closes#57042closesodoo/odoo#57217
Note: the saas-13.5 version always force isoformat for existing fields
X-original-commit: f50f32ea656df62d16f0aeba1247fc3b2d394e5d
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
This is a slow operation and string join is significantly faster
https://stackoverflow.com/a/3055541/1398110
This can make a noticable difference when processing a long form
Courtesy of Nils Hamerlinck
closesodoo/odoo#52664
X-original-commit: 87a2702fdabdcfeb774ddfb9db2e28bdd5595f9a
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
* = base_setup, website_form, website_sale, website_crm,
crm_iap_lead_website, website_hr_recruitment, website_mass_mailing
Integrate reCaptchaV3 on website_form submit and website_mass_mailing
subscription.
You can now use ReCaptchaV3 to add reCaptcha verification in any module
using google_recaptcha.
Also added a better error management on the form with custom messages.
task-2217980
closesodoo/odoo#48466
Related: odoo/enterprise#9649
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Issue
- Set outgoing mail server
- Install Online Ticket Submission
- Publish an Helpdesk Team
- Log out
- Create a ticket from the helpdesk form
The user who created the ticket is "Public User"
He has no email address, so the mail is not sent
Cause
insert_record method in website_form/main.py uses .sudo()
In v12 => sudo replaces the user in env by the superuser => ok
In v13 => sudo adds a flag "su" and does not replace the user in env
Solution
Add a with_user(SUPERUSER_ID) to the create method's call in
insert_record
OPW-2196668
closesodoo/odoo#46835
X-original-commit: 761ae16634b14bec7be522666bb2163490566ecc
Signed-off-by: Jason Van Malder (jvm) <jvm@odoo.com>
With this change, a binary field in a website form works when
website_crm_phone_validation (website_crm in 13.0) is installed.
The module website_crm_phone_validation would call `extract_data` method
to do some things, but when extract_data was called a second time to
really save data, the FileStorage werkzeug object would already consumed
and files would erroneously appear as empty.
opw-2191873
closesodoo/odoo#46241
X-original-commit: a168fe23cc6d9b817b44c189822952a1ee98d81d
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
When a binary field is added to studio, the system will try to write the
name to {binary_field_name}_filename: this works if the field was
created with studio but could not work eg. if just a binary field is
created manually.
opw-2191873
closes#45994closesodoo/odoo#46164
X-original-commit: 13b65d878d5240f07b279045e30d53915d176a61
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
This commit fixes the following points:
- While dropping a form builder, the default action is now set to
'Send an email' instead of first available action.
- Titles of the forms which previously were readonly, are now editable.
- When sending an email, the 'reply-to' address is now set from the
email field provided in the form, instead of the catchall mail.
- Hitting 'Send' button for 'Send an email' option now immediately
sends the mail instead of putting it in the queue.
task-2082970
closesodoo/odoo#42515
X-original-commit: 7ada68cc91fde1b6eff151549808a20e85cb5bf7
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
Issue
- Install CRM & Website
- Edit the website contact form
- Add "Expected revenue" field
Traceback
Cause
Monetary fields are not handled by the form builder
Solution
Add the monetary field in the form builder core
OPW-2150986
closesodoo/odoo#41558
X-original-commit: 6c27c3abf4907e1faac670ea8ef006992ec96063
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
If the name of a file input field is 'x_binary_input', before
commit 9be29371abcdfe57b1738484c5057ad81e76b00d (opw 2092653),
self.form_fields would have names of the form 'x_binary_input[i]'.
After this commit, they are of the form 'x_binary_input[i][j]'.
When calling extract_data, field_name would then be 'x_binary_input[i]'
instead of 'x_binary_input'. Therefore, the file would be considered as orphan
instead of being attached to x_binary_input.
We thus change the split so that it always returns 'x_binary_input'.
opw 2122624
closesodoo/odoo#41135
X-original-commit: 21ed2b971f66879fa3fa53dbd2c349ab39fa3fdb
Signed-off-by: fah-odoo <fah-odoo@users.noreply.github.com>
Coming from the sudo() modification. The mail.message is created in sudo,
but the user is still the public user, who doesn't have a email address,
leading to an raised error.
Using studio, add a file field on a form. Using the web form builder,
append that field on a form. Upload a file, `x_field_filename` is left
empty thus the filename is lost.
opw-2028071
closesodoo/odoo#34491
Signed-off-by: Julien Castiaux <Julien00859@users.noreply.github.com>
This commit removes the field `datas_fname` from `ir.attachment` as
it was unnecessary and most of the time the duplicate of `name` or
`url`.
Task #1909865closesodoo/odoo#32976
Signed-off-by: Martin Geubelle (mge) <mge@openerp.com>
There was a code that on:
- a form that sent a mail
- with a custom file field
would set the file as attachments, but the code was dead because of a
typo in `if` statement order.
opw-1906883
closes#28525
Issue:
An additional information page is part of our shop process to allow
additional information to be submitted. If this form is left blank,
then selecting the next button allows the process to continue.
However, if data is added to the form the form freezes and the process
will not continue when 'next' is selected.
Why:
Public user can not read the field 'model' of 'ir.model' (to save the
attachments)
opw-1818592
In case of custom field 'upload file', the attachement
name will be the technical name of the input tag of the
form (aka 'attachments'). It is more user friendly to have
the name of the uploaded file.
Custory reading seems to denote that field names are probably already
text in the normal case, and thus should not need decoding? It only
blows up in a tour so...
Now that we're closer to switching to P3 for good, these helpers have
outlived their usefulness, and mostly add noise.
All remaining dict.iter*() or dict.view*() must be converted to the
normal keys(), values() or items() calls.
Whenever the result is likely to be used for more than the scope of a
loop, or when the dict needs to be modified during iteration, the calls
must be wrapped in a ``list()``, to protect the new P3 semantics.
Those cases are very exceptional.
Also removed some dead code or improved the API to remove unnecessary
conversions.
In Python 3:
* various builtins and dict methods were changed to return
view/iterable objects rather than lists
* and the separate Python 2 view/iterable builtins and methods were
removed altogether
This is problematic when using these items as list (which the happens
repeatedly in Odoo), but more viciously when iterating *multiple times*
over them (which also happens, which I've messed up multiple times while
writing this, and which is a pain to debug even when you've just created
the issue).
Convert all code using these to semantics-matching cross-version
helper functions to get the LCD behaviour between P2 and P3, and
forbid the builtins via lint.
issue #8530
As administrator is used to create all records from website form he is
also put into followers. This creates a lot of unnecessary notifications
and/or emails depending on the system configuration.
Using the magic context key this behavior is modified. Administrator
will not follow every records created through the website form anymore.
Improve thank page after the application to a job.
Stop duplicate Magic field, using global fields
Add helper method on website to retreive the last created record
This partially reverts commits 5d746d0ac6 and
73de86c768.
The tightening of access rights was too strong: regular users need to be able
to read models and fields (to create an email templace, for instance.)
[FIX] ir_values: in `get_actions`, exclude field `code`
Remove unrestricted "read" access. To make code internally using `ir.model`
work, add a private method `_get` on `ir.model` to retrieve the record
corresponding to a model name, without access rights issue.
Change signature of method `get_authorized_fields` to make it use a model name
instead of a model id. This removes the necessity of a search on `ir.model`.
The form builder offers the possibility to add a "Custom File Upload"
field. When the user clicks on "Send", an error occurs ("An error has
occured, the form has not been sent.").
This is because we try to send a mail linked to "mail.mail", which
doesn't make sense.
The case was actually taken into account in the code, there was just an
oversight in the code.
opw-684040