* make CSRF protection the default on all non-SAFE methods
note: there currently is no way to call a CSRF-protected endpoint
without a form-encoded entity-body as that's the only place we get the
CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
the purpose of a CSRF token in the database manager screens.
There is no request database to obtain the
secret and generate a CSRF token.
- dates are editable even in confirm state. Only events in done states are
not editable.
- the print badge button is actually a button to edit badges, so let us udpate
the name
Indeed the type field has been renamed to event_type_id. However some code
was still relying on the type and type_count names, instead of event_type_id
and event_type_id_count.
How great is it to get Odoo (almost) 9.0 (almost) translated?
Clean .tx/config file
Regenerate .pot files
Fetch current translations from Transifex (10% completion)
Now that most refactoring has been merged
It is better to have red a great work of another culture in translation than never to have read it at all.
― Henry Gratton Doyle
Among others small improvements :
- [event] remove automatic logging of new registrations on event; for big events
it produces only noise
- [event_sale] fix product creation from event management; better display of
address and date of the event
- [website_event_track] add a cancel state on the track model. The stat button
on the event shows only not-canceled state. Also added some tips.
Field show_menu generates three menus Introduction, Location and Register on the
page of the event on the website.
Generating new menus requires the Technical Features groups so checking this box
would produce and error on non-technical users.
Moreover these menus are hardcoded, making it less useful and may produce
unexpected behaviour (replaces previous menus).
Hide the menus to non-technical users and add help message explaining the
effect of the field.
Fixes#7099
When clicking on the publish/unpublish button in a form view, if the
user does not belong to the `base.group_website_publisher` group,
fallback to a simple toggling behavior.
Now there should be only one button box per page, and the name should be
"button_box".
Conflicts:
addons/crm/crm_tip_data.xml
addons/event/event_tip_data.xml
addons/fleet/fleet_view.xml
addons/hr/hr_view.xml
addons/hr_recruitment/hr_recruitment_view.xml
addons/project/project_tip_data.xml
addons/purchase/purchase_tip_data.xml
addons/sale_crm/sale_crm_view.xml
addons/website_quote/views/website_quotation_backend.xml
openerp/addons/base/res/res_partner_view.xml
Conflicts:
addons/account_reports/views/partner_view.xml
Conflicts:
addons/claim_from_delivery/claim_delivery_view.xml
addons/stock/stock_view.xml
- Preserved explicit 3rd-party copyright notices
- Explicit boilerplate should not be necessary - copyright law applies
automatically in all countries thanks to Berne Convention + WTO rules,
and a reference to the applicable license is clear enough.
Now,
- event contains the HTML badge fields and the report (and report templates) to print badges
- event_sale add the ticket type on badges
- website_event allow the edition of badge throught website editor.
When the editor will be available in backend, event will be allow to edit badge report, so the action should be moved from website_Event to event module.
This commit impact crm, website, website_sale and web_planner modules because it
- add planner for website and website_sale
- improve planner notebook by setting texterea and input size to 100% and using col-md-* class
- split js code into common part (used in backend and frontend) and backend part (only for backend)
- adapt some tour, since every page will have the planner modal in its DOM, the tour selectors msut be more accurate
- introduce some style fixes and adaptations
- ...
- email is now required when buying tickets, to avois having subscription
that we cannot email with event information
- 'not yet started' message should be linked to the event state, not to the
fact that the event has tickets or not. A confirmed event without configured
tickets is just displayed on the website, but not set as unconfigured.