Commit Graph
40 Commits
Author SHA1 Message Date
Christophe Simonis 2bc6ea1b37 [MERGE] forward port branch 11.0 up to 02ee3fd88e 2018-05-23 19:33:40 +02:00
Christophe Simonis 02ee3fd88e [MERGE] forward port branch saas-15 up to 1b81f1a5c9 2018-05-23 18:36:28 +02:00
Christophe Simonis 373a1c1128 [MERGE] forward port branch 10.0 up to 682ae1cc64 2018-05-23 18:30:36 +02:00
David 682ae1cc64 [FIX] website_form: set meta field
Before this commit, if you enable website_form_enable_metadata, that
will crash with a "KeyError: 'meta'"

This commit closes #24848
2018-05-23 09:16:32 +02:00
Christophe Simonis 4aa5ec3fa5 [MERGE] forward port branch 11.0 up to d67b410dfc 2018-03-07 18:46:38 +01:00
Christophe Simonis d67b410dfc [MERGE] forward port branch saas-15 up to cb87388d72 2018-03-07 17:42:02 +01:00
Christophe Matthieu 108d22ecdf [FIX] website_form: public user can send attachment
Issue:
An additional information page is part of our shop process to allow
additional information to be submitted. If this form is left blank,
then selecting the next button allows the process to continue.
However, if data is added to the form the form freezes and the process
will not continue when 'next' is selected.

Why:
Public user can not read the field 'model' of 'ir.model' (to save the
attachments)

opw-1818592
2018-03-06 09:26:34 +01:00
Thibault Delavallée 1fbc29a641 [MOV] base: move ir_* models into models/ 2017-11-27 11:15:03 +01:00
Deep Patel eb9d7f8b6f [IMP] website_form: name of submitted attachments
In case of custom field 'upload file', the attachement
name will be the technical name of the input tag of the
form (aka 'attachments'). It is more user friendly to have
the name of the uploaded file.
2017-10-25 15:24:53 +02:00
Xavier Morel fccbe4ff4f [FIX] website_form: custom field thing blows up in P3
Custory reading seems to denote that field names are probably already
text in the normal case, and thus should not need decoding? It only
blows up in a tour so...
2017-09-14 12:21:26 +02:00
Olivier Dony 695716efb0 [FIX] P3: remove pycompat.{keys,items,values} helpers
Now that we're closer to switching to P3 for good, these helpers have
outlived their usefulness, and mostly add noise.

All remaining dict.iter*() or dict.view*() must be converted to the
normal keys(), values() or items() calls.

Whenever the result is likely to be used for more than the scope of a
loop, or when the dict needs to be modified during iteration, the calls
must be wrapped in a ``list()``, to protect the new P3 semantics.
Those cases are very exceptional.

Also removed some dead code or improved the API to remove unnecessary
conversions.
2017-08-20 23:25:54 +02:00
Olivier Dony 5f4db9df66 [MERGE] Forward-port saas-16 up to 5afe894f44 2017-05-16 18:23:15 +02:00
Olivier Dony 5afe894f44 [MERGE] Forward-port saas-15 up to 878fbc75ff 2017-05-16 17:09:45 +02:00
Olivier Dony 9b3ca1af23 [MERGE] Forward-port 10.0 up to 1545995b39 2017-05-16 12:12:30 +02:00
xmo-odoo fffaf735f5 [FIX] P3: list -> iterable builtins (#16811)
In Python 3:

* various builtins and dict methods were changed to return
  view/iterable objects rather than lists
* and the separate Python 2 view/iterable builtins and methods were
  removed altogether

This is problematic when using these items as list (which the happens
repeatedly in Odoo), but more viciously when iterating *multiple times*
over them (which also happens, which I've messed up multiple times while
writing this, and which is a pain to debug even when you've just created
the issue).

Convert all code using these to semantics-matching cross-version
helper functions to get the LCD behaviour between P2 and P3, and
forbid the builtins via lint.

issue #8530
2017-05-10 09:39:55 +02:00
Thibault Delavallée 16884487e7 [FIX] website_form: do not subscribe administrator to all records from website form
As administrator is used to create all records from website form he is
also put into followers. This creates a lot of unnecessary notifications
and/or emails depending on the system configuration.

Using the magic context key this behavior is modified. Administrator
will not follow every records created through the website form anymore.
2017-05-09 09:31:11 +02:00
Xavier Morel 3979f6802e [#8530] convert exception handlers to except..as syntax
Futurize fixers:
* lib2to3.fixes.fix_except
2017-04-11 14:53:29 +02:00
Christophe Simonis 45045bb7a1 [MERGE] forward port branch saas-15 up to c8f01e3b62 2017-03-17 18:06:16 +01:00
Denis Vermylen 9995deda86 [FIX] website_sale: fix extra-step
truly fix 328a5a7ea3
sudo() was applied at the wrong step.

mea culpa
2017-03-15 10:44:52 +01:00
Jeremy Kersten 9edaf9fdf0 [IMP] website_form, website_hr_recruitment: improve thankyou page
Improve thank page after the application to a job.
Stop duplicate Magic field, using global fields
Add helper method on website to retreive the last created record
2017-03-10 18:20:11 +01:00
Raphael Collet 4a18d5744e [FIX] base: restrict read access to ir.model and ir.model.fields to employees 2017-01-20 10:05:10 +01:00
Raphael Collet 3649b7f359 [FIX] base: access rights of ir.model and ir.model.fields
This partially reverts commits 5d746d0ac6 and
73de86c768.

The tightening of access rights was too strong: regular users need to be able
to read models and fields (to create an email templace, for instance.)

[FIX] ir_values: in `get_actions`, exclude field `code`
2017-01-17 16:15:26 +01:00
Raphael Collet 5d746d0ac6 [IMP] base, *: tighten ir.model access rights
Remove unrestricted "read" access.  To make code internally using `ir.model`
work, add a private method `_get` on `ir.model` to retrieve the record
corresponding to a model name, without access rights issue.

Change signature of method `get_authorized_fields` to make it use a model name
instead of a model id.  This removes the necessity of a search on `ir.model`.
2017-01-03 16:52:49 +01:00
Christophe Simonis 235ed4b2c1 [MERGE] forward port branch saas-12 up to 9ad5f26 2016-08-20 18:08:19 +02:00
Christophe Simonis 9ad5f26b3f [MERGE] forward port branch saas-11 up to 3a2147d 2016-08-20 17:18:31 +02:00
Christophe Simonis bc1a0a32ca [MERGE] forward port branch 9.0 up to 58cbcba 2016-08-19 16:59:29 +02:00
Nicolas Martinelli 19e556b34f [FIX] website_form: traceback when sending an attachment
The form builder offers the possibility to add a "Custom File Upload"
field. When the user clicks on "Send", an error occurs ("An error has
occured, the form has not been sent.").

This is because we try to send a mail linked to "mail.mail", which
doesn't make sense.

The case was actually taken into account in the code, there was just an
oversight in the code.

opw-684040
2016-08-17 14:52:10 +02:00
Thibault Delavallée c8a313d51e [IMP] various: use odoo for imports instead of openerp and update class names 2016-08-10 15:48:07 +02:00
Christophe Simonis 5a3a06f26f [MERGE] forward port of branch saas-11 up to d4d09df 2016-07-04 13:16:34 +02:00
Denis Ledoux bc2a06c019 [FIX] http, website_form: preserve form input values order
By default, werkzeug doesn't preserve the order
of the parameters sent to routes.

As stated in the werkzeug documentation:
```
parameter_storage_class

the class to use for args and form.
The default is an ImmutableMultiDict which supports multiple values per key.
alternatively it makes sense to use an ImmutableOrderedMultiDict
which preserves order or a ImmutableDict which is the fastest
but only remembers the last key.
It is also possible to use mutable structures, but this is not recommended.

New in version 0.6.

```

For some of our use cases, it makes sense to keep the order
of the route parameters.

e.g. In the website builder, when building a form
with a bunch of inputs values that will be concatened
in a lead note, the user expects the answer to be displayed
in the same order than the form inputs.

This change is seen as a bit risky as it could lead to
performances issues in the http routes processing, and this
is the reason we do not merge this in stable 9.0 at the moment.

If needed, it could be back ported later to 9.0, after
several weeks/months of testing in this release(saas-10 atm).

opw-677508
2016-06-30 10:45:55 +02:00
Christophe Matthieu 7ede9bcb2d [IMP] base ir.qweb: compile template (and use ast) to improve rendering speed
* The compiled templates are cached per user, lang, inherit context values
* ir.ui.fields: attributes method return an dict, and record_to_html return only the content value of the field
* all rendered text use build_text and all attributes use build_attribute
* t-esc-options is removed and replace by format_value method
* AssetsBundle receive the list files and remains
2016-06-14 09:46:25 +02:00
Olivier Dony ee804e1d32 [MERGE] Forward-port 9.0 up to 74d8cbc190 2016-04-21 18:05:14 +02:00
Denis Ledoux d57623023b [FIX] website_form: handle date & datetime
Adding date & datetime inputs in the website
form builder couldn't work, because
the posted values for these input
types were not treated at all,
and they were not in the format
the date/datetime were stored in database.

opw-672674
2016-04-20 16:19:25 +02:00
Martin Trigaux 34348ebf8d [FIX] typo, English 2015-12-22 11:58:47 +01:00
Xavier Morel e3a2448ebe [ADD] form builder whitelisting: ACL check
Only users who can edit the website's structure should be allowed to
whitelist fields.
2015-11-30 16:39:13 +01:00
Xavier Morel 2afb5b43ef [IMP] form builder fields blacklisting
* blacklist all fields by default
* don't use blacklist in get_authorized_fields which is called to see if
  a field can be added to a form, instead only use it afterwards to see
  if the field can be written to by the formbuilder. That way
  formbuilder can whitelist fields which are actually added to forms
  on-demand resulting in a more secure interaction
2015-11-30 16:39:13 +01:00
Nicolas Lempereur 6f02ba9cbf [IMP] website_form: don't remove newline
In some instance, the mail content of a sent form would only be text
formatted. This could lead to a message with no newline, thus making it
illegible.

This fix has to be ugly since body_html field of a mail.mail is of type
text.
2015-11-18 11:41:25 +01:00
Nicolas Lempereur a4cfe7f6ec [FIX] website_form: be consistent when concatenating string
In the form builder, custom field name could contain special char but
the get key values are of the type str whilst the value are in unicode
type.

Thus when concatenating them, one should be converted so they are
uniform and don't lead to an encoding error.

opw-656745
2015-11-18 10:49:24 +01:00
David Monjoie d210744ef0 [IMP] website_form: various improvements
- Fixed the module name and category in manifest
- Fixed website_form_blacklisted being ignored
- Unauthorized readonly and magic fields
- Reset the form on successfull submit
- Added missing date field
- Added date and datetime validation
2015-09-15 14:00:36 +02:00
David Monjoie a77f5cf42f [ADD] website_form: generic form controller
Contains a new ajax post function that comes from mdo's
original code and that I was not able to get rid of.
2015-08-26 16:01:19 +02:00