* = bus, crm_livechat, hr, mail_bot, test_discuss_full, test_mail,
website_livechat
Now that livechat uses guest, we can write proper ACL for channel and
channel member to check if the current user/guest is a member.
This allows removing most sudo in code and to simplify search domains.
Remaining sudo in discuss folder have been reviewed and commented.
task-3394829
closesodoo/odoo#138330
Related: odoo/upgrade#5295
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Improve link preview code
* remove useless code indirections;
* improve performance of link creation, cleanly support batch-creation (could
lead to 98+5 URLs to the same domain creation within default 10 seconds
instead of 98+1 but we feel it's ok);
* name methods according to ORM;
* use tools for html empty;
Also cleanup link preview tests: concatenate tests when possible, improve
setup, use real-life scenarios (using 'message_post' notably), remove useless
data creation.
Task-3557985 (Mail: Message cleanup (shortcode, link))
Prepares Task-36879 (Mail: Support MultiCompany Aliases)
Part-of: odoo/odoo#138938
Since [1], live chat visitors are using the mail guest system for
authentication. With this change, visitors are allowed to reach the
attachment upload routes (even if nothing allows it in the frontend
for now). This commit restricts attachment upload for guest and portal
users with the `allow_visitor_upload` field that can be toggled.
At the same time, this commit enables file upload when authorized
on the frontend and for cross origin live chats.
[1]: odoo#129770
task-3332628
closesodoo/odoo#137574
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Relational data in server formatter are:
- for one relation: None/false or object
- for many relations: list of objects or list of commands
The commands were:
- 'insert': to add a new item in a relational field
- 'unlink': to remove an item from a relational field
- 'insert-and-unlink': to remove an item from a relational field
- 'clear': to remove all items from relational field
There was a slight nuance between 'unlink' and 'insert-and-unlink'
at some point, but it becomes irrelevant with current code of model.
The name of the commands were hard to grasp what they actually mean
for the many relations.
This commit improves it by renaming 'insert' by 'ADD' and the 2
'unlink' commands by 'DELETE'. This makes it more apparent that
the data in 'ADD' refers to data of record to add in the relation,
while 'DELETE' refers to data of record to delete from the relation.
The 'clear' has been replaced by `False` value instead of a command.
Part-of: odoo/odoo#136308
This commit introduces a new message action to download
all files of the message, when the message contains more
than a single attachment.
This commit also do not show the delete icon on a file
when it's linked to a message without any text content, and
there's only 1 file attached to this message.
This is because deleting message and deleting the file means
basically the same, as deleting the attachment would mean the
message is empty, and empty messages are considered deleted.
We only show "Delete" of the message for clarity.
Task-3340653
closesodoo/odoo#132164
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
In this commit, we moved all features related to the PWA and the PWA
itself to the community.
This includes:
* PWA
* Web Push Notification
* VCARD
Note from original commits:
===========================
PWA (part 1)
------------
This commit adds a ServiceWorker to complement the WebManifest to
complete the setup of the backend as a Progressive Web App.
More precisely, it adds the route, registration and the most basic
ServiceWorker to allow the backend to be recognized as an installable
PWA.
References:
- https://web.dev/install-criteria/
- https://developer.mozilla.org/en-US/docs/Web/Progressive_web_apps/Installable_PWAs
- https://developer.mozilla.org/en-US/docs/Web/API/Service_Worker_API/Using_Service_Workers
Task ID: 3063485
PWA (part 2)
------------
This commit adds a WebManifest as a first step toward setuping the
backend as a Progressive Web App.
In a nutshell:
- the web app's name is configurable through a config parameter
(available in the Settings, in debug); defaulting to "Odoo".
- the web app's icon has been revamped to accommodate the required sizes;
also its design matches the one from the Android app.
- "theme-color" is used to color part of the browser/system UI to match
Enterprise brand color; also supports the dark mode.
References:
- https://web.dev/learn/pwa/web-app-manifest/
- https://web.dev/install-criteria/
- https://developer.mozilla.org/en-US/docs/Web/Manifest
Task ID: 3063485
PWA shortcuts
-------------
The main goal of this commit is like we did inside the `Android Odoo
Mobile App`, allowing users to have some Odoo application shortcuts.
We added the following apps in the key `shortcuts` on `web.manifest` in
these orders: `Discuss`, `CRM`, `Project`, `To-Do` (old `Notes`).
Links:
- https://w3c.github.io/manifest/#shortcuts-member
- https://developer.mozilla.org/en-US/docs/Web/Manifest/shortcuts
Task ID: 3123607
Offline mode
------------
This commit introduces a way to notify the user that he's "offline"
(aka. cannot reach its Odoo server) and that Odoo doesn't work in a
graceful way in this circumstance.
To do so, the Service-Worker will return the response of the
´web/offline´ route, which is cached at its setup.
Note: this screen is only show when launched while "offline" and fails
to load the requested page. It does not "interrupt" the WebClient to
show this screen when the connection drops off (cf. not a replacement
for the existing notification).
Task ID: 3203639
WebPush
-------
WebPush allows sending data to the user browser/app(PWA) even when
tab/app is closed. Web push is a "constant" link between the
ServiceWorker of browser/app and a WebPush server.
Note that each browser has its own custom WebPush server.
e.g.:
Chrome: https://fcm.googleapis.com/
Firefox: https://updates.push.services.mozilla.com/
Safari: https://web.push.apple.com/
Edge: https://wns2-ln2p.notify.windows.com/
WebPush introduces some cryptographic notion to ensure some the
reliability of the data sent:
VAPID: "Voluntary Application Server Identification" is the standard
used to generate the public and the private to sign the message
between the browser and the WebPush server
JWT: "JSON Web Token" is the standard used to sign the payload to the
WebPush server
ECE: "Encrypted Content-Encoding" is the standard used by WebPush to
encrypt the data of the payload to avoid sending RAW data
outside trusted network.
Simplified steps how to WebPush works:
The Javascript code of a web page subscribes to the WebPush server
(using the VAPID key generated at mail_entreprise install).
The WebPush server replay with a subscription (and some other info
like the unique URL endpoint per subscription where to send a
notification)
The application (odoo-bin in our case) sends a post request to the
WebPush server using the specific URL endpoint of the user (using JWT
and ECE).
The WebPush server sends back to the browser the encrypted payload.
The browser decrypts the payload and sends it to the ServiceWorker
linked to the subscription.
Here is a Sequence diagram of all interactions to process a web push
notification.
In Odoo, we use WebPush to send Notification to the user.
This commit aims to have a parity with the Android/iOS Mobile App at
the notification level.
Notes:
There are some ways to encrypt (ECE) the message for WebPush:
AESGCM128: this is a draft
AESGCM: very well documented
AES128GCM: RFC8188 Standard encoding
We implement only the RFC one as it is the only one implemented in all
major updated browsers (Chrome, Firefox, Safari, Edge, ...)
You need to allow the desktop "Notification" and "Push" inside your
browser. For iOS Devices, it only works on iOS 16.4+ and it's requiring
Odoo to first be added to the Home Screen. It's delivered silently,
meaning no sound, vibration, haptics or screen wake.
Note:
Notifications are sent directly if there are less than five
notifications, otherwise we use a cron triggered immediately.
Also, we have changed the value of the "QueryCount" as mail_enterprise
executes a new query to search the devices associated with the partner.
We have added a "try/except" for any Exception before the
push_to_end_point method as we want to avoid blocking a normal flow
just for a not mandatory push notification if something happens during
the push to the endpoint.
See: odoo/enterprise@d0ae70103d
Links:
https://www.rfc-editor.org/rfc/rfc8030https://www.rfc-editor.org/rfc/rfc8188https://www.rfc-editor.org/rfc/rfc8291https://www.rfc-editor.org/rfc/rfc8292https://w3c.github.io/push-api/index.htmlhttps://autopush.readthedocs.io/en/latest/http.htmlhttps://web.dev/push-notifications-web-push-protocol/https://github.com/web-push-libs/encrypted-content-encodinghttps://github.com/web-push-libs/pywebpushhttps://github.com/web-push-libs/vapidhttps://caniuse.com/push-api
Task ID: 3123678
VCARD
-----
In the process of replacing the native methods exposed in the mobile
apps, this commit implements the download of a vCard containing a
partner's information.
By using this standard format, both regular web users and mobile ones
are now able to save the partner's details to use them with their usual
address book software.
On a mobile device, the actual import of those informations is delegated
to the operating system.
References:
- https://datatracker.ietf.org/doc/html/rfc6350
- https://en.wikipedia.org/wiki/VCard
- https://github.com/eventable/vobject#vcards
Task ID: 2583916
===========
End of note
===========
Task ID: 3478014
closesodoo/odoo#133560
Related: odoo/enterprise#46530
Related: odoo/upgrade#5086
Signed-off-by: Adrien Dieudonné (adr) <adr@odoo.com>
Co-authored-by: Romeo Fragomeli <rfr@odoo.com>
Co-authored-by: Romain Estievenart <res@odoo.com>
Co-authored-by: Pierre Paridans <app@odoo.com>
Before this commit, when a message had many link previews,
deleting all of them required to delete one by one.
This commit improves this aspect by showing a "Delete All"
button in the dialog to delete all link previews at once.
task-3488054
closesodoo/odoo#134301
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
This PR adds a panel to consult all attachments of a discuss channel
easily.
task-3476444
closesodoo/odoo#132784
Signed-off-by: Matthieu Stockbauer (tsm) <tsm@odoo.com>
This PR adds the `add_guest_to_context` decorator in order to provide a generic
way to extract the guest from a request. It will be used to unified guest
extraction from cookie/param based on its provenance (external livechat/public
page).
This is better than the `pre_dispatch` method since it can be applied to
specific routes instead of adding this logic to every request.
part of task-3332628
closesodoo/odoo#130052
Signed-off-by: Matthieu Stockbauer (tsm) <tsm@odoo.com>
With this commit, users can send voice messages in channels and chat.
There's a new button in composer to record audio from the microphone,
up to 1 minute clip duration. This adds a voice attachment with its
dedicated voice player that shows waveforms and allows playback.
To ensure compatibility in all supported browsers, we choose to
encode voice recording with `audio/mp3` thanks to lib `lamejs`.
Task-3240168
closesodoo/odoo#117036
Related: odoo/enterprise#45482
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
This PR prepares the ground for the one introducing guests
for livechat visitors. Since our SameSite cookie policy
is Lax, the cookie won't be send on unsafe cross site
requests thus another mechanism will be introduced to
retrieve the guest.
This PR abstracts the way the guest is retrieved in order
to ease this transition as much as possible by overriding
the `ir_http._pre_dispatch` method in order to inject the
guest in the context if any.
part of task-3332628
closesodoo/odoo#129039
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Before this PR, suggested recipients without partner where not
checked and needed to be manually created. This is prone to mistakes
when sending an email to the suggested recipient.
This PR checks all the suggested recipients by default and create
the missing partners when a message is posted, and when full composer
is open. That way, there's far less risk to not send the email to
suggested recipient, and instead the user should manually uncheck
to not send the email.
closesodoo/odoo#128647
X-original-commit: 258b2420676fb1a0d7e834ab79f6bf1ec0f73254
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Livechat override of `_message_update_content` accesses `self` channel
but it was not called with the guest env, leading to access error.
Part-of: odoo/odoo#128290
The `/mail/message/post` route wrongly prevent serialization
errors by suppressing any `OperationalError` when writing
on a canned response. This is wrong since the `write` method
does not issue any SQL.
In order to properly prevent serialization errors, the request
is now done with the `SKIP LOCKED` clause.
This is better since the error does not occur, hence:
- No rollback needed
- No need to mute the sql logger
- No need to suppress any exception
closesodoo/odoo#127761
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Since https://github.com/odoo/odoo/pull/126713, deleting a message
would crash as the `mail/message/update_content` route is called without
passing the `partner_ids` parameter.
This commit fixes the issue by making the parameter optional.
closesodoo/odoo#127284
X-original-commit: 34abd3dc1d159962a376b248134d0cd4977f3dcb
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
This commit adds a GIF picker in discuss
app. GIF feature makes use of Tenor GIF API [1].
To enable GIF picker in discuss, you must provide
a Tenor GIF API key in the General Settings.
Then the GIF picker is visible in all channels
(chat window and discuss app), next to the emoji picker
button.
[1] https://tenor.com/gifapi/documentation
task-2365705
closesodoo/odoo#116060
Related: odoo/enterprise#41959
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Co-authored-by: Brieuc-brd <brd@odoo.com>
Before this commit, when editing a message, it was not possible
to add new mentions.
This commit adds the support to add new mentions when editing the
message.
Note that mentions added from editing message won't notify them:
it's only at creation of message that mentioned users are notified.
task-3329714
closesodoo/odoo#126888
X-original-commit: 1fe935d273142064784b9ecff2fff1c34e91064f
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
This PR make add a last used date to the canned responses
in order to know whether they are still usefull or not.
part of task-3332872
closesodoo/odoo#125909
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
In [1] the order by `id ASC` has been removed from the
`_message_fetch` method. This is wrong since we want
to load the messages coming DIRECTLY after the given
id thus, this order is required.
In order to solve this issue, this commit ensures the
order of the messages returned by the `_message_fetch`
method is always in descending order as it was done
implicitly before [2].
[1]: https://github.com/odoo/odoo/pull/123664
[2]: https://github.com/odoo/odoo/pull/116666
task-3349175
closesodoo/odoo#124169
X-original-commit: 074a5fea5a7f08c7018620cb9b2b956b3a871344
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Signed-off-by: Didier Debondt (did) <did@odoo.com>
Since [1] the pyhton discuss tests have been splitted into a
subfolder. They are wrongly immported and cannot be run at the
moment. This commit solves this issue.
[1]: https://github.com/odoo/odoo/pull/120062closesodoo/odoo#124114
X-original-commit: b796704408d0511af2c310fde5964003dc25190e
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Before this revision, when you pass `context` in the arguments
of a JSON routes, this one gets automatically injected
in the environment context.
This is not the case for regular HTTP routes.
It makes sense to propagate the context for the JSONRPC protocol,
JSON routes used by the backend, such as `call_kw`,
but it doesn't make sense to pass this context automatically
for any other kind of routes, such as front-end routes
or routes used by custom Javascript widgets.
This change brings a more unified behavior for routes
of types HTTP and JSON.
In addition, most developers were not aware of this "feautre",
that passing `context` in the arguments of a JSON route leaded
to the injection of this context in the environment context.
This is actually reflected by the diff size this changes required,
only a dozens of routes needed to be adapted, to manually
add the context in their route arguments and to inject it
in their environment context.
closesodoo/odoo#121726
X-original-commit: a7a5655631e6d5b05fd2ba3d0c80617aae6d9cfe
Related: odoo/enterprise#41229
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
1. Display avatar in top bar next to channel name and description.
2. Edit icon appears on hover.
3. Clicking on the Edit icon opens file browser to upload a new avatar.
4. Certain file types are allowed.
5. Avatar can only be changed for group chat by any member of the channel.
6. For channel it can be done with admin rights.
7. Disable uploading text from file uploader in this case.
Also show avatar of channel/chat conversation in chat window.
Author avatar in message list no longer shown im status.
Chat window header color matches new systray color.
task-2684679
[FIX] mail: make chat window header match systray color
Part-of: odoo/odoo#117357
Allow partner to unfollow a document from a follow up email of that document
through an unsubscribe URL in the email even if not connected.
It works for internal user for follow up on any document and for any partner on
follow up of document tagged as authorizing being unfollowed by any partner (
slide.channel and slide.slide).
Technical note:
The unfollow block is rendered in mail_thread and updated for each recipient in
mail_mail. We don't render it in mail_mail because we don't have the language
of the message at that point.
Depending on the partner and the related document, the unfollow block is:
- either removed if the user cannot unfollow the document (for example if it
doesn't follow it)
- or updated with partner and document information + a security token
Task-3061864
Part-of: odoo/odoo#107978
Allow users to unfollow easily document from the inbox for which he/she doesn't
want to be notified anymore.
When hovering on a follow up message with a related document followed by the
user, the interface displays an action to unfollow it that allows the user to
remove himself/herself as follower of the document. As a result of performing
that action a toast is displayed as a feedback.
Technical note:
The unfollow link is displayed on a message.canUnfollow is true which check
that the thread related to the message is followed by the user.
In order to know if the user follows the record related to the message, we now
transmit with each message the id of the follower table that link the user to
the related record if it follows it. This allows to insert the follower on
client side so that the unfollow action can use the standard mechaism already
developed to unfollow a record.
Unfortunately, that information coudn't be added in the already public method
message_format of mail message because that method is not always called on the
user retreiving the message but also by the one posting message. We didn't want
also to include all followers in the formated message so we rely on additional
method that add that information per partner.
To support unfollowing a document in the inbox no matter the current company,
we have modified message_unsubscribe in mail_thread to allow internal user to
unsubscribe themself without checking any rights. Indeed, some document have
record rule that prevents reading it if the user is not in the right company
(ex. crm.lead) and then was preventing the user to unfollow the document using
that method.
Task-3061864
Part-of: odoo/odoo#107978
By this commit, If a user edits the message body or changes
the message attachments, the edited label in the blob,
shows the last edit Info.
Task-2664848
closesodoo/odoo#117896
Related: odoo/enterprise#40208
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
As a bonus, add cross-tab update for current user in chatter.
Part of task-3265211
closesodoo/odoo#120018
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Before this PR, link previews where not updated when a user was editing a
message.
This clear the current link previews and reprocess the updated message.
closesodoo/odoo#119917
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
The opportunity is taken to clean the methods to make the override
actually possible.
Part of task-3265211
closesodoo/odoo#119942
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
This commit focuses on removing all references to discuss.channel from
controllers of mail module.
In preparation of splitting discuss and mail modules.
Part of task-3265211
closesodoo/odoo#119523
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
This commit focuses on removing all references to discuss.channel from
code located in /models of mail module.
In preparation of splitting discuss and mail modules.
Part of task-3265211
closesodoo/odoo#119413
Signed-off-by: Debondt Didier (did) <did@odoo.com>
It is only used there.
In preparation of splitting discuss and mail modules.
Part of task-3265211
closesodoo/odoo#119306
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
It is only used there.
In preparation of splitting discuss and mail modules.
Part of task-3265211
closesodoo/odoo#119302
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
* = bus, calendar, crm_livechat, hr, hr_holidays, im_livechat, mail_bot,
mass_mailing, privacy_lookup, test_discuss_full, test_mail,
test_mail_full, website_crm_livechat, website_livechat, base
In preparation of splitting discuss and mail modules.
Part of task-3265211
closesodoo/odoo#118354
Related: odoo/upgrade#4553
Related: odoo/enterprise#39661
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
When using message_post, the body format must be explicitly specified.
If html is expected, a Markup object should be used.
If text is given, the content will be escaped.
Before this PR:
message_post was unaware if the content of a message was HTML or
text. This lead to multiple situation where the content was
incorrectly considered as HTML and led to display errors.
In
self.message_post(body="Hello %s!" % self.name)
if the name contained HTML, it would be evaluated.
In
self.message_post(body="Contact Raoul <raoul@caramail.be>")
the email would not be displayed as considered as unknown HTML and
discarded by the sanitizer
Now each call must explict the type of content.
Use the escape() helper to properly combine Markup and translations.
It would also be acceptable to use Markup() to wrap a static
translation but escape is better as one can not guarantee the content
of a translation.
closesodoo/odoo#111850
Related: odoo/documentation#3612
Related: odoo/enterprise#36728
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
With this commit, messages can be pinned on a channel and
chat conversation. There's a new menu listing all pinned
messages on a conversation, and we can jump to these messages
in the current conversation.
As this feature incentives to see older messages, this commit
also adds a "Jump to Present" button when looking at old messages.
closesodoo/odoo#116666
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Adapt code of message fetch so that fetching of
(needaction) messages are controlled in a way to
keep continuous sequence of messages at all time.
This code design solves the "holes" problem in a message
list by not allowing holes. This fixes many scenario that
generated these holes, resulting in unfetchable messages.
Example of such a scenario:
- post 40 messages
- post a new message that is reply of the oldest message
- page reload and scroll up until load more
=> 10 messages are missing in-between replied message and
following message (that should have been 11 messages apart)
This code also prepares for allowing jumps in a conversation.
Part-of: odoo/odoo#116666
Since [1], the `temporary_id` of a message is passed to the
`message_post` route in order to renconciliate the temporary
message on the client side and the real message created by the
server.
This led to crashes when sending message on the chatter because
this parameter was not allowed as a `_notify_thread` parameter.
Since this parameter is highly specific and isn't linked to any
business/model code, this parameter is now passed via the context
thus solving this issue.
[1]: https://github.com/odoo/odoo/pull/116085closesodoo/odoo#116333
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
This commit removes the "new message" separator when posting a
message on a channel.
At the same time, this commit solves an issue that caused messages
to flicker when the message came from the bus before the answer of
the rpc.
In order to do so:
- messages are marked as read immediately after
`message_post` for the member of user that posted it.
- a temporary id is passed to `message_post` in order
to reconcialiate temporary/server messages.
task-3232911
closesodoo/odoo#116085
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Before this commit:
Portal users are not able to join RTC Calls in Discuss.
After this commit:
Portal users are able to join RTC Calls.
Task-3050534
closesodoo/odoo#115963
X-original-commit: 0bfd2625fb89b93494c9df1aad9b7390723f1aa7
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>