Commit Graph
74 Commits
Author SHA1 Message Date
Benoit Socias 567e5b58d5 [IMP] base, tools, web_editor, *: use original image if size increases
*: web_tour, website

When no transformation is applied on an image, changing the quality
sometimes increases its storage size.

This commit makes sure that the original image remains used if only the
image quality is modified and if this makes its storage size bigger.

Fixes #61619
task-2835144

closes odoo/odoo#103398

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2023-07-19 13:12:51 +02:00
Benoit Socias 706e696e3d [IMP] base, tools: compute webp image size
This commit introduces the computation of the image size from a webp
binary source without relying on PIL.

This is needed by eCommerce to determine which image to fetch when using
the zoom functionality on the product page.

task-2774352

Part-of: odoo/odoo#85494
2023-07-15 05:10:47 +02:00
Benoit Socias 4095539765 [IMP] base, web: upload a JPEG too when uploading a WEBP in backend
The library used to generate PDFs does not support the WEBP image
format. For those images to be included in reports, they need to be
converted. For security reasons, this conversion cannot be done on the
server, therefore it was decided to keep an already converted copy of
such images.

This commit converts uploaded WEBP images to JPEG and uploads them both
so that the report generation can use the JPEG instead.
This commit also pre-generates the resized version of images - and JPEG
versions of each of them.

task-2774352

Part-of: odoo/odoo#85494
2023-07-15 05:10:46 +02:00
Benoit Socias d1292a96a6 [IMP] base,*: support image/webp image format
*: mail, mrp, test_website, web, web_editor

Before this commit '.webp' images could not be used in odoo.

After this commit '.webp' images can be uploaded to odoo.
- can be used in image field
- can be used in HTML field image
- can be used in mails and website
- can be transformed (shape mask, filter effect, crop, rotate, resize,
  adjust quality)

task-2774352

Part-of: odoo/odoo#85494
2023-07-15 05:10:45 +02:00
Sanket Brahmbhatt 2d70761dca [FIX] base,tools: raise usererror instead of a valueerror
This issue is generated when the user uploads an image of more than
50.0 million pixels, so error would be generated. But, currently it raises a
`ValueError` which results in traceback. So, we replace it with
`UserError` so the user has an idea about Image size or pixel being excessive.

closes odoo/odoo#121396

Sentry: - 4075426049
X-original-commit: ac2a3966cb035f112bf6aebb1244dc8d67831d1a
Signed-off-by: Rémy Voet <ryv@odoo.com>
2023-05-15 13:59:31 +02:00
Julien (jula) 0a267b3336 [FIX] tools: x_studio image field size
__Current behavior before PR:__
The size of an image field is guessed using the field name. For instance, an image field with `field_name = "XXXX_123"` is resized to 123 pixels when fetched.
This is can be an issue if a user creates an image field using studio in a form view.
If the user sets the label of the field as "Image 1", the technical name will become `x_studio_image_1`. Therefore, the image field will be resized to 1 pixel width.

__Description of the fix:__
Refactor the `image_guess_size_from_field_name` method to return `(0, 0)` when the field name starts with `x_studio_`.

__Steps to reproduce the issue:__
1. Open a form view (of any model)
2. Open studio
3. Add an image field with label "Image 1" (notice the technical name becomes in `x_studio_image_1` in debug mode)
4. Close studio
5. Upload an image on the created field
6. Save... The image is resized to 1 pixel width

opw-3242084
opw-3249632
opw-3253133

closes odoo/odoo#118960

X-original-commit: 3318f0e67da40983f52595aba933d8c8fd0f5cc5
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-04-24 16:57:44 +02:00
jard@odoo.com d65f3e64b2 [FIX] tools.image: Allow conversion of P to JPEG
While upgrade of a customer database, A P-type image
was being converted to JPEG image. It didn't allow to save
as direct conversion from P-type(palette) to JPEG. So, fix
covers conversion of such corner cases to first convert it
to RGB and then RGB can convert it to desired output format
opw-3043418

closes odoo/odoo#107300

X-original-commit: d0db7a14dec7ee6a983ede3bf7b968675f83979d
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-12-06 17:12:02 +01:00
Krzysztof Magusiak 167cf8fff8 [FIX] tools.image: Update IMAGE_MAX_RESOLUTION
New phones go up to 48MP (Samsung Galaxy A22).
Also the error message was saying 4.5 instead of 45.

opw-3020614, opw-3020502

Close #104424

closes odoo/odoo#104546

X-original-commit: 8b19107c69c648dbfba2a9304c04f0f55aac4b46
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-11-02 09:45:40 +01:00
Xavier Morel e75f2989b4 [FIX] core, web: Pillow 9.1 deprecations
Pillow 9.1 deprecates most if not all toplevel Image constants:
https://pillow.readthedocs.io/en/stable/releasenotes/9.1.0.html#constants

These constants have been moved to thematic enum classes (e.g. all the
resampling constants in `PIL.Image.Resampling`).

This triggers warnings in Odoo, and the removal delay is quite short
(slated for Pillow 10, release planned mid 2023). Pillow 9.1 is also
already in Debian Bookworm (current testing).

Fix by shimming at the import level: if the enums are available import
them into the local namespace, otherwise alias `PIL.Image` itself as
to the enum.

closes odoo/odoo#96799

X-original-commit: 7be04d31bad078681ef0a2919234c11840a2e8e2
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-07-28 02:40:23 +02:00
Victor Feyens 24f9af3fd0 [IMP] *: remove Trailing newlines (C0305)
Part-of: odoo/odoo#86332
2022-04-27 07:51:23 +02:00
Fabien Pinckaers 6b87526048 [IMP] Speed Imp: remove unnecessary base64 encode & decode
Avoid to base64 encode, then decode to process assets and images for a ~25% speed improvement.
Change image processing tool to work on images, rather than base64 encoded strings.

Performance is ~25% faster on assets & images:

  /web/assets/...frontend.min.css:    13ms to 7ms,  base64 enc/dec: 2 -> 0
  /web/image/XML_ID:                  10ms to 8ms,  base64 enc/dec: 3 -> 0
  /web/image/res.users/2/avatar_128:  40ms to 20ms, base64 enc/dec: 6 -> 2

closes odoo/odoo#82851

Related: odoo/enterprise#23537
Signed-off-by: Fabien Pinckaers <fp@odoo.com>
2022-01-22 11:51:42 +00:00
Xavier Morel bdc9d9d369 [FIX] core; base: lots of docstrings
* add configuration for `flake8[flake8-rst-docstring]`
* enable docstring-related checks
* fix invalid docstrings in odoo's core & `base`
* fix a few more bits (mostly missing or incorrect `:param:` info
  fields) are out of scope for the lint but my editor catches

closes odoo/odoo#74604

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2021-12-09 14:36:58 +00:00
Jeremy Kersten 300954d8c4 [IMP] base: auto resize attachment to 1080p
After some analyze on a lot of customer databases, seems like most of the time
their are performance probleme, and big store, it is due to  a lot of big file
uploaded without reason. E.g. barcode, photo, ... a small one will be enough.

Now, we decided (in stable) to auto resize these pictures to 1920x1920px
by default and compress it with a quality of 80 when the source is bigger.

You can bypass this behaviour in your specific use case,
using a context key: 'image_no_postprocess' set to True.

You can disable the resize (and quality implicitely)
using an icp: 'base.image_autoresize_max_px' set to '0'.

You can change the default resize (1920x1920) format using an icp:
'base.image_autoresize_max_px' set to '<width>x<height>' (e.g. '1024x768')

You can change the default quality (80) using an icp:
'base.image_autoresize_quality' with a value between 0 and 100 where 0 skip it.

You can change the type of file that will be post process using icp:
'base.image_autoresize_extensions' (subtype of the mimetype comma separated).

Api of image has not be changed in this commit, only refactored to allow to
work with image directly without the need to encode/Decode in base64 the raw.

We decide to keep 1920x1920 by default instead of 1080p to avoid to resize
portrait picture in 1080px and stay consistent with field image_1920 that
return a 1920px image for width or height whatever the orientation.

+ fix some lint diff for ci style in master

closes odoo/odoo#78556

X-original-commit: d9ce0507960f247e1187baf7bd8399f90be237aa
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-10-22 17:34:29 +00:00
luz paz c9e29e5917 [FIX] *: correct typos
Various user facing an non-user-facing typos
Found via `codespell`

Closes odoo/odoo#65648

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-02-19 13:20:48 +00:00
Christophe Monniez 2529447428 [FIX] tools: prevent call to pillow exif_transpose image method
In a previous fix [0], the call to exif_transpose was kept to allow
rotation of images format different than `JPEG`.

After a small test, it appeared that the call would crash if the image
in another format had the same `LensInfo` tag.
So it's safer to not call this method at all.

With this commit, the rotation tag is retrieved disregarding the file
format by using the `getexif` method if available, falling back to the
private method for Pillow < 6 support.

As a bonus, a test is also added with a small embedded `JPEG` image,
crafted with an `Orientation` exif tag and, for reference,  the
`LensInfo`tag that caused so much trouble.

The fix referenced in [0] was not forward-ported as it was only moving
the code the is completely removed in the present.

[0] b83c48d5c48954193

closes odoo/odoo#65823

X-original-commit: bfd3f857b44f31f8077182d10cab869f42076464
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2021-02-09 14:51:36 +00:00
Martin Trigaux ba244cef01 [IMP] *: replace to new _() syntax
Using a few regex like
\((_\(.*%s.*)(\) % )([\w\[\]][\w .\[\]\(\)'"]*)\)
($1, $3))

Old syntax is still compatible but starts the migration to the new
syntax that catches error.
2020-06-18 13:03:34 +02:00
Sébastien Theys 3c3f0753da [FIX] tools, base: fix orientation of image with EXIF orientation tag
Before this commit, some images would display incorrectly orientated.

This typically happens for images taken from a non-standard orientation
by some phones or other devices that are able to report orientation.

The specified transposition is applied to the image before all other
operations, because all of them expect the image to be in its final
orientation, which is the case only when the first row of pixels is the top
of the image and the first column of pixels is the left of the image.

Moreover the EXIF tags will not be kept when the image is later saved, so
the transposition has to be done to ensure the final image is correctly
orientated.

closes odoo/odoo#38717

X-original-commit: 0f8e132ec0495fcdfa0a47d5b9c98a2f6f10c7d8
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2019-10-14 13:03:03 +00:00
RomainLibert 85eeaccf06 [FIX] tools: use user friendly message in case of error
closes odoo/odoo#37058

Signed-off-by: Nans Lefebvre (len) <len@odoo.com>
2019-09-18 10:14:12 +00:00
fw-bot c8d09167fd [FIX] tools: crop & resize image crashes
- When trying to access an image that need to be resized and cropped,
  the code could crashes.

  This is due to the fact that PIL expect to work with integer for
  sizes, but in some cases we provide floats

closes odoo/odoo#37442

Signed-off-by: Toufik Benjaa (tbe) <tbe@odoo.com>
2019-09-25 15:12:46 +00:00
Sébastien Theys 67e3924bfe [IMP] tools, product, website_sale: rename image_variant_max
Follow up of 58a2ffa26f

Variant specific field `image_raw_original` was meant to be renamed to
`image_variant_1920` instead of `image_variant_max` to follow the same naming
convention as the other fields (having the pixel number in the name).

closes odoo/odoo#35493

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-08-06 12:29:13 +00:00
Sébastien Theys b77bbd01f8 [FIX] tools: fix condition of image_process quick return
Follow up of 344614b54a

If base64_source is falsy, we don't need to check the other parameters.

closes odoo/odoo#35489

Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2019-08-06 12:16:18 +00:00
Sébastien Theys 45e3be94c0 [IMP] tools, base: removed unused image helpers
PR: #34925
2019-08-02 16:47:58 +00:00
Sébastien Theys 1b85ab93ec [IMP] base, product, website_sale: move image zoom out of mixin
This field is not necessary on most models so move it to the few places where it
is needed to avoid computing it and storing it everywhere.

PR: #34925
2019-08-02 16:47:58 +00:00
Sébastien Theys 58a2ffa26f [IMP] *: rename image fields
image_original => image_1920 (now resized to 1920)
image_big => image_1024
image_large => image_256
image_medium => image_128
image_small  => image_64
image replaced by image_1920 (when writing) or by image_1024 (when displaying
	what was previously the big size)

+ add new intermediate format:
image_512

PR: #34925
2019-08-02 16:47:58 +00:00
Julien MougenotandLucas Perais ed18095127 [IMP] base: Configure document layout
The onboarding modal for setting up the few base fields of a company
has now been moved to a wizard
It is accessible from the general settings, but also in the onboarding
section of sale and account modules.

The following company settings are editable with that wizard:

- Set report **layout**:
The user can chose the overall look of the report. The current choices
are : *Standard* (default), *Background*, *Boxed* and *Clean*.

- Set company **logo**:
Changes the company logo.

- Set report **colors**:
The user can set the primary and secondary colors of the report through
a newly added widget allowing to pick a custom color.
When changing the **logo**, colors are automatically set to its most dominant
colors.
> A "Reset colors" button also triggers the color calculation.

- Set report **font**:
Changes the overall font of the report. Only Google Fonts are used
for enhanced compatibility.

- Company **tagline**, also called "header"
- **Footer**
- **Paper format**
- Report **preview**:
A mockup of a final report
Automatically updates when changing **layout**, **logo**, **colors** or **font**

Co-authored by: Julien Mougenot <jum@odoo.com>

closes odoo/odoo#33863

Signed-off-by: VincentSchippefilt <VincentSchippefilt@users.noreply.github.com>


Co-authored-by: Lucas Perais <lpe@odoo.com>
2019-07-29 08:29:26 +00:00
Sébastien Theys 344614b54a [IMP] base, product: optimize image compute when image is not set
All of those fields `__get__` and method calls have a cost, it is small but when
done for many records it adds up, so they are better not done.

When creating 1000 products without image, this compute takes:

47ms +/- 1ms before the commit
37ms +/- 1ms after the commit

That's around 20% less.

Part of task-1918881

closes odoo/odoo#34294

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-06-21 11:09:50 +00:00
Christophe Simonis 71a50a2214 [MERGE] forward port branch saas-12.3 up to 409679866b 2019-06-06 11:54:35 +02:00
Christophe Simonis cfe0523714 [MERGE] forward port branch 12.0 up to 8f21148e1a 2019-05-31 14:37:38 +02:00
Sébastien Theys 76cf2ae82a [IMP] web_editor, *: improve media dialog attachment upload
* = web_unsplash, website

Remove iframe upload and replace it with a proper RPC. The route is now only
accepting one file at a time, which makes it easier to maintain, and allows to
process the first file as soon as it is ready, instead of having to wait on
everything.

Also fix a bug where a document could not be uploaded because it would try to
parse it as an image.

Remove filter after search result from the JS and add the corresponding
conditions in the domain to avoid processing and returning unnecessary records.

If multiple attachments exist with the same URL, now display them all to avoid
confusion.

Compute all the necessary values in the python model instead of in the JS.

Allow SVG in the widget (the server already accepted them before).

Disable multiple image upload when not in multiImages mode.

task-1930726
PR: #31208
2019-06-04 22:14:13 +02:00
Sébastien Theys 86d304fdb0 [IMP] tools: prevent unnecessary image processing
Both for performance and to avoid reducing the quality of an image in unexpected
situations.

- avoid applying useless operations in the first place
- do not count an operation if it had no effect
- allow quality 0 as a safe default that does not forcefully re-save the image

PR: #31208
2019-06-04 22:14:13 +02:00
Sébastien Theys 08cda70147 [FIX] tools: fix support for multi-frame GIF images
Before this commit, only the first frame would be saved.

PR: #31208
2019-06-04 22:14:13 +02:00
Sébastien Theys f58668ccb5 [FIX] tools: fix image processing of palette PNG with alpha channel
Since b0ff033d69

To reproduce this issue: give to the processing method a PNG with transparency
and which is already encoded in palette mode.

In 12.0 such image could be `addons/payment/static/img/codensa_easy_credit.png`.

In earlier versions of Pillow, adding an alpha channel to such image would have
no effect, but since version 6.0.0 they raise an exception when that happens.

The PNG spec forbids the use of a full alpha channel with palette-based images
according to http://www.libpng.org/pub/png/book/chapter08.html#png.ch08.div.5.2

task-1998639

closes odoo/odoo#33628

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-05-24 12:23:09 +00:00
Sébastien Theys 822b05d1da [IMP] tools: limit image quality to 95
Values above 95 do not increase the quality but they disable optimizations that
increase the file size unnecessarily.

See `quality` parameter at
https://pillow.readthedocs.io/en/4.0.x/handbook/image-file-formats.html#jpeg

Part of task-1930726

closes odoo/odoo#33507

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-05-20 13:54:34 +00:00
Sébastien Theys d445f46806 [FIX] *: convert image route size param to int and use named param
* = tools, base, web, website_profile, website_slides

Before this commit it was impossible to pass those parameters in the URL because
they were received as string but expected as int.

The opportunity is also taken to properly use named parameters when calling
`image_process`.

closes odoo/odoo#33506

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-05-21 10:34:40 +00:00
Sébastien Theys 66cd46d202 [IMP] tools: move image process into chainable methods
This allows to more easily customize each method, and it gives more flexibility
regarding which operations to apply and in which order.

task-1958000
PR: #31811
2019-04-29 13:45:34 +00:00
Sébastien Theys f159ba8f31 [IMP] tools,website: correctly handle favicon and .ico files
Previously the image that we uploaded as a favicon of the website was not
resized, so it could be extremely excessive in size and resolution, and it also
was not guaranteed to be a square.

Now we always resize it appropriately and save it as an ICO file.

The default favicon is now applied to all websites instead of only the first.

task-1958000
PR: #31811
2019-04-29 13:45:34 +00:00
Sébastien Theys 425f197f16 [IMP] tools,base,*: remove intermediary image functions
* = hr, im_livechat, mail, payment, purchase, web, web_editor, web_unsplash,
	website_profile, website_slides

Since the merge of all image tools into one function, the intermediary functions
are not needed anymore.

task-1958000
PR: #31811
2019-04-29 13:45:34 +00:00
Sébastien Theys e479138558 [IMP] tools,base: merge all image tools
Make the image tools more consistent and easier to maintain by having a single
function handling all the cases, instead of several functions doing more or less
the same thing with obscure differences.

Also introduce a new function to guess the size based on a field name, to be
used in the following commit.

task-1958000
PR: #31811
2019-04-29 13:45:03 +00:00
Sébastien Theys 4c61ee7b7d [IMP] tools,base: remove ratio from image crop
Following commit: 6801baa662

Crop is always used when we know the target size. Therefore there is no point
to pass a ratio argument. However size is required now.

Also "center" is always used, so make it the default type.

task-1958000
PR: #31811
2019-04-29 13:45:03 +00:00
Sébastien Theys d870877967 [IMP] tools,base,web,website_*: keep image ratio on resize
* = website_partner, website_profile, website_sale, website_slides

Before
======

Since commit: 2e3848b394

The images that are resized have additional borders if the target ratio is
different than the image ratio. Those borders are transparent if the image
format supports it, and are white otherwise.

With that current solution, if the background where the image is displayed is
another color than white, it is looking really bad.

Moreover, most images are stored resized like this, so it is not even possible
to decide if it should have borders or not depending on the context, the
original image and ratio is forever lost.

It is also inconsistent because if the image is already smaller than the target
size then it doesn't include borders. In that case it keeps the original ratio
instead of the target ratio. So it isn't even guaranteed that the target
ratio is going to be respected.

After
=====

This commit will solve all of those problems by always keeping the ratio of the
original image.

This implies the views should be taking care of adding borders when necessary.

task-1958000
PR: #31811
2019-04-29 13:45:03 +00:00
Sébastien Theys 433d007075 [IMP] tools,web_editor,web_unsplash: improve image optimize for web
This commit introduces the possibility to resize and to select the quality when
optimizing an image for web.

This will be used by the media dialog in a future commit.

The arbitrary resolution limit of 42e6 has been increased to 45e6 to fit some
of the biggest images we might get from Unsplash, and this value has been moved
into a variable so it can be customized.

The mimetype computation has been moved after the image processing because in a
next commit the operation could return the image in a different format than what
was originally given. Eg. BMP -> PNG, or unsupported format -> JPEG.

task-1958000
PR: #31811
2019-04-29 13:45:03 +00:00
Sébastien Theys 8269f85513 [IMP] tools: remove the "ghost border fix" from image tools
We can't reproduce the issue it was trying to solve.

task-1958000
PR: #31811
2019-04-29 13:45:03 +00:00
Sébastien Theys d61e9d940f [IMP] tools: rename the image filter ANTIALIAS to LANCZOS
This is the new name since Pillow 2.7.0.

task-1958000
PR: #31811
2019-04-29 13:45:03 +00:00
Sébastien Theys d303518841 [IMP] tools,base: remove image encoding parameter
The image tools were accepting an encoding parameter but it was never used.
Indeed the given images are always encoded in base64.

`image_colorize` was the only method not taking base64 directly, so it has been
modified for consistency. This allows to change the code in partner to not
base64 decode the image in some case just to be base64 encode it again after.

`crop_image` and `limited_image_resize` have been slightly refactored to account
for this change, but in this commit their behavior was kept.

task-1958000
PR: #31811
2019-04-29 13:45:03 +00:00
Sébastien Theys 413c63556f [IMP] tools,base,web: improve image tools
Add support for a 256*256 image, to be used in the following commit.

Define sizes in named variables instead of being hard-coded in several places in
the code.

Allow parameters `preserve_aspect_ratio` and `upper_limit` to be passed from
the different helper methods.

Factorize the code inside `image_resize_images` to make it easier to read.

Add new function to compute whether the size of an image is above a given size.

task-34045
PR: #30656
2019-02-14 16:03:09 +00:00
Thanh Dodeur a86b726a27 [FIX] base: fixes http redirection
The 7d85ab1eac refactor of 'ir.http' introduced changes in `web/image` that
caused the route to no longer return early (to avoid data processing steps)
in the case of redirection and that caused `binary_content` to not set the
mimetype of the `ir.attachment` when it was an URL.

This commit fixes those issues, allowing `web/image` to redirect properly.

closes odoo/odoo#30777
2019-02-04 10:16:12 +00:00
7d85ab1eac [REF] base, *: refactor binary_content
*: tools, web, website, website_forum, mail, im_livechat

This commit refactors ir_http to make it more readable
and flexible.

Move the resize function of web/image to odoo.tools

Co-authored-by: XavierDo <xdo@odoo.com>
Co-authored-by: Antony Lesuisse <al@openerp.com>

closes: #28563
task: #1908896
2018-12-06 19:09:33 +00:00
Adrian Torres 52f5528cfb [REF] *: replace deprecated pycompat helpers for builtins
This commit replaces calls to pycompat helpers that were intended for
python 2 <-> python 3 interoperability for python 3 builtins, as python
2 is no longer officially supported by Odoo.

This includes:
    * calls to imap/izip/ifilter replaced by map/zip/filter
    * uses of text_type replaced by str
    * uses of unichr replaced by chr
    * calls to implements_to_string, implements_iterator removed
    * string_types and integer_types replaced by str, int respectively
    * calls to to_native replaced by calls to to_text

This is done in preparation to the removal of these deprecated helpers
in the following commit.
2018-11-29 09:28:17 +00:00
Pedro M. Baeza 1ad4d42f0b [ADD] *: replace hardcoded data URIs with helper
- Add a method for generating an image data URI, and expose it in QWeb context

- Fix reports, website templates or mail templates with data hardcoded
  data URIs, to use the helper (Python cases), or the existing
  kanban_image helper (for JS cases)

This will gracefully handle SVG support in addition to classical image
formats.

Closes #26635
2018-10-03 17:48:14 +02:00
Pedro M. Baeza 1be50fdeaf [ADD] *: support SVG images
Introduce official support for SVG files in the framework, including the
following parts:

1. When client-side SVG images are uploaded, the content is displayed until
you save using data URI scheme according RFC 2397 [1]. This scheme requires
to specify content format. Using hardcoded "image/png" works for all images
types except SVG.
Type-sniffing is done using "magic byte" detection via the first base64
encode byte, so that the proper data URI scheme can be used.
This should not cause SVG-related security problems as the file is
displayed through `<img>` tag, which does not allow SVG scripting [2].

2. Make /web/image controller compatible with SVG

3. Add support for SVG files for company logo, which uses a dedicated
controller.

4. Resizing of SVG files is a no-op, as it makes little sense for a
vector-based format. We also want to avoid micro-alterations to the SVG
document (in "natural" viewport parameters) as we would store multiple
copies of the files in the filestore.

5. Because SVG files are inherently dangerous, upload of SVG files is
restricted to administrators, either by blocking it directly before
saving it in the database (binary fields with attachment=False), or by
neutering them to text/plain mimetype (for binary fields with
attachment=True)

6. Add tests for the SVG upload cases and for the non-admin uploads.

[1] https://tools.ietf.org/html/rfc2397
[2] https://www.w3.org/wiki/SVG_Security

Closes #26635
2018-10-03 17:48:01 +02:00