Commit Graph
15 Commits
Author SHA1 Message Date
Pierre Masereel 234590f3db [IMP] base_import_module: add industry modules availability
We now have the possbility to publish modules that only contains XML on
apps.odoo.com and we want to display in the apps of the database to ease
the installation.

TASK-3186716

closes odoo/odoo#140245

Signed-off-by: Pierre Masereel (pim) <pim@odoo.com>
2023-11-02 16:57:50 +00:00
Julien Castiaux f04b90b6e8 [REF] core: HTTPocalypse (12) web ir.http & login
This commit is the 12th commit of a comprehensive refactor of our HTTP
framework. See odoo/odoo#78857 for complete historic, discussions and
rationnals.

The web module is twofold, on one side there are many controllers: /,
/web, /web/login, /web/database/selector, /web/dataset/call_kw, etc, on
the other side there is `session_info`: the method responsible to create
the web client's environ.

This module is kinda an exception as it is (with base) a server wide
module. In the case of the HTTP framework, it means that the controllers
of web are always accessible, i.e. going to / or /web/login will never
return a 404 Not Found even if the user is not connected to a database.

This is both a blessing and a curse. It is a blessing because the
controllers are always accessible it means that a new users can freely
access those routes. It is a curse because *any* user can access them,
even user who don't have a session yet thus who are not connected to a
database yet. From a developer standpoint, we have to put extra care to
correct serve users with and without a database. An example is the
/web/login route, the login/password pair is stored in a database,
without database it is impossible to validate a user login but users can
still access this route without db.

To solve this problem, there is the `ensure_db` function. This function
attempts to find a database using various sources (?db= query-string,
session db, mono db) and to save it on the user session. In case no db
is found, the user is redirected to the database selector. In a way,
this function grants a database to the user in a seamingly experience.
In a way, this function brings a welcome differentiation between
`auth='none'` with a database and `auth='none'` without a database. Such
differentiation only matters for the server wide modules as "regular"
module controllers are only accessible via the ir.http routing map, i.e.
it is not possible to declare a nodb controller outside of server wide
modules.

An important changement is the `session.authenticate` method, before it
was possible to call the method when the cursor was not yet initialized,
authenticate would open a cursor against the given database, setup a
registry and an environment and ultimately save everything on the
current request. Because the cursor is now greedily created, it is no
more possible to update the request environment when authenticating on
another database.

PR: odoo#78857
Task: 2571224
2022-02-24 13:30:50 +00:00
Martin Trigaux ba244cef01 [IMP] *: replace to new _() syntax
Using a few regex like
\((_\(.*%s.*)(\) % )([\w\[\]][\w .\[\]\(\)'"]*)\)
($1, $3))

Old syntax is still compatible but starts the migration to the new
syntax that catches error.
2020-06-18 13:03:34 +02:00
Nicolas Martinelli 79d29c51df [FIX] base_import_module, cli: deploy
The use of the `deploy` command always fails because of an incorrect
CSRF token since commit 9bae56acd4. Indeed, the latter
re-introduces the session rotation, i.e. the session ID is changed at
authentication.

Practically, what happens server-side is:
- authentication
- generate CSRF token
- create the response with the token and a change of session ID

At this point, the token generated is not correct anymore since it is
based on the 'old' session ID. Therefore, when it is reused at
uploading, an error is raised.

It is actually possible to simplify the process by performing the
authentication and the file upload in a single request. There is indeed
no real use of extracting the authentication, since the request is then
only used to upload the module.

opw-1902863

closes odoo/odoo#28653
2018-11-14 09:40:17 +00:00
xmo-odoo b4429c2a91 [FIX] Various P3-related import changes
* LDAP import: python-ldap is not python3-compatible, pyldap is

  Warning: only supported from debian Stretch (current testing)?
  https://packages.debian.org/search?searchon=names&keywords=pyldap

* implicitly relative imports
* imports of moved or removed stdlib modules

issue #8530
2017-04-28 09:06:53 +02:00
Xavier Morel 3979f6802e [#8530] convert exception handlers to except..as syntax
Futurize fixers:
* lib2to3.fixes.fix_except
2017-04-11 14:53:29 +02:00
Mohammed Shekha 870f2ff893 [MIG] base_import_module: Migrated to new API 2016-07-13 12:46:50 +02:00
Xavier Morel 045b9019ef [FIX] base_import_module: CSRF handling
* disabled CSRF protection for login route
* return CSRF token from login and retransmit it during module upload

``deploy`` only sends CSRF token if given one by authenticate so that
the command can be used for non-updated modules.

Closes #9488
2016-01-12 19:05:43 +01:00
Xavier Morel e80f1152c7 [ADD] convenience res_users._is_admin
Checks that the provided user (or user in the provided dataset):

* is the superadmin
* or is a member of group_erp_manager

There are a number of hand-rolled "is_admin" checks in the codebase some
of which are fairly gnarly. The shortcut provides a single point of
contact, avoids forgetting about cases (e.g. SUPERUSER_ID) and is
relatively convenient when checking a user which is not the "current"
user.

closes #8146
2015-08-20 09:42:06 +02:00
Fabien Meghazi c1e6e70870 Added --force to odoo deploy
Will force --init mode even if module is already installed
2014-06-11 09:55:17 +02:00
tpa-odoo 8fa3a17c39 [IMP] improved code to show import result in wizard and improved typo 2014-05-22 17:09:52 +05:30
tpa-odoo 41147025b8 [ADD] add wizard to import zipped module 2014-05-22 15:51:51 +05:30
Fabien Meghazi e49b8f5ae3 [FIX] /login is not webservice friendly, base_import_module uses it's own
Exceptions in /base_import_module/* will generate 500 pages with a short message

bzr revid: fme@openerp.com-20140326215709-esc4zkpfp8uzuww1
2014-03-26 22:57:09 +01:00
Fabien Meghazi 62a5632aec [IMP] Use requests for http requests. python does not provide multipart encoding
bzr revid: fme@openerp.com-20140326150842-h33yuiwsnrm8gmbk
2014-03-26 16:08:42 +01:00
Fabien Meghazi 40fdb08a7d [WIP] base_import_module
bzr revid: fme@openerp.com-20140319085343-zkee3rmqc9dzpa7h
2014-03-19 09:53:43 +01:00