Emails are now send once by recipient. If there is a partner_id, use it as
recipient using the correct recipient_ids field, not partner_ids (not the
same meaning, recipients for emails use recipient_ids). Use the email_to
if there is no partner_id. Indeed this method is called with partner_id
and email being the same recipient.
Also added auto delete to generated emails. As partner_ids is not used anymore
the mails are not considered as notifications and stay in the mail_mail table.
There is no need to stock those emails.
When sharing a survey, a mail.mail is created but the attachment were lost.
This is due to a missing command (6, _, ids) when creating records in
attachment_ids field (many2many).
Fixes#9364, opw 656742
* make CSRF protection the default on all non-SAFE methods
note: there currently is no way to call a CSRF-protected endpoint
without a form-encoded entity-body as that's the only place we get the
CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
the purpose of a CSRF token in the database manager screens.
There is no request database to obtain the
secret and generate a CSRF token.
How great is it to get Odoo (almost) 9.0 (almost) translated?
Clean .tx/config file
Regenerate .pot files
Fetch current translations from Transifex (10% completion)
Now that most refactoring has been merged
It is better to have red a great work of another culture in translation than never to have read it at all.
― Henry Gratton Doyle
Main changes :
- mail.notification model is removed. People do not receive notifications
anymore. Instead two ways of following documents exist
- using a channel; messages will be displayed on the channel itself
in a near future commit
- following with its partner; messages will all be considered as
needaction, using a new m2m table. People should receive less
needaction messages by following less records by themselves.
There is no more read / unread state anymore. Instead only needaction
messages are considered. Todo (Favorites) messages still exist, and are
stores on a new m2m table instead of using decorated notifciations.
- the main filter for documents is not message_unread anymore, but
message_needaction. A lot of views and filters have been updated
accordingly.
- the vote feature has been removed