Now, slug uses seo_name if field exists before to fallback on display_name.
It allow to have a custom url without change the product name already used in
backend e.g. or just because you want add some keywords for seo.
task-2291676
closesodoo/odoo#54152
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
It was deleted in 11.0 as it was not used anymore. Now, it is
reintroduce as it is a nice utility function for some external app or
fixes. Here, it is use so that /website/add and /website/add/<path> work
as a controller POST with a CSRF token.
task-2241766
render, render_template, load, activity_schedule_with_view,
get_website_pages should all be private:
It should not be possible to render an aribtrary template only with
its name or id
Still need to render some qweb views from js so the method
render_template is kept public.
This explains why the website editor still need read access on
ir.ui.view as we want to allow any snippet to be rendered.
The method fields_view_get should be the only way to retrieve the view
content. This method is executed in a super-user context.
To avoid retrieving views for a model a user does not have access to
(as it may reveal some informations like name of fields), add a
verification of 'read' rights before retrieving the view content.
Execute _postprocess_access_rights with sudo(False) as this method is
used to evaluate which buttons should be displayed.
Remove the su flag to avoid misleading the user and displaying a
button they won't be able to use.
Retrieving the database id from an view key is not considered as a
sensitive information and get_view_id and viewref can be left as a
public methods.
Add missing sudo when needed
Change _handle_visibility in website to avoid increasing the query
count: Checking the visibility (to fail most of the time) to retry in
sudo was making unecessary queries.
Some apps, once installed, automatically create a menuitem in website.
What complexify the UI and create useless menu withtout plusvalue.
It is not because you install livechat to make support online, that you want
a link in your menu to show stats e.g.
Now we remove the default menu created, and help user to find it when he create
a link. The autocomplete suggest most of the main App's controllers
task-2189613
closesodoo/odoo#49081
Related: odoo/enterprise#9733
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Toggle method defined on ir.ui.view does the same job of toggle_active that
is the generic one available on all models.
Task ID 2170708
Community PR odoo/odoo#46563
Also remove all t-fields from footers to have only static contents in
footers. For social links, a controller is added so that a "static url"
/website/social/xxx always redirect to the correct set URL for the given
xxx social network.
Part of https://github.com/odoo/odoo/pull/38950
task-2087641
Co-authored-by: qsm-odoo <qsm@odoo.com>
This commit introduce multiple improvements regarding social image:
- (perf) Don't read ir.attachment through `social_default_image` when it is
not needed. Use a stored boolean to know if the field should be accessed.
This will remove one SQL query in attachment for public user.
- Show website logo, not the company logo since we now have a different logo
for website.
- Don't show images lower than 200 width or 200 height px. Logo will be
shown regardless of his size.
- Don't show website logo if there is a website social_default_image.
Indeed, the spec was to prevent showing logo and social_default_image if
they are the same image. Technically, this is hard to identify as they
could be the same image uploaded with different resolutions (media dialog),
especially if one of those was uploaded through the backend and one from
the frontend.
It is most likely we will never correctly identify duplicate as they won't
be exactly the same.
For this reason, it makes more sense to hide the website logo if the
social_default_image is set. It avoids every issues while it makes sense
since you won't want to use the logo over the social_default_image. If you
really want to, you could reupload it through the SEO media dialog.
closesodoo/odoo#47848
Related: odoo/upgrade#1012
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Co-authored-by: Romain Derie <rde@odoo.com>
Co-authored-by: Jeremy Kersten <jke@odoo.com>
If we are rendering a page, the menus will most likely be rendered as well.
Note that even in a 403 case when the page is found but is not visible, the
menus will also be shown on the 403 page.
Fetching the menus before accessing the requested page will prefetch that page
as well in one go if that page is in the menus, without any costs for the pages
not in the menus.
There is a tradeoff for 'non-layout' pages, which only occurs in advanced
technical cases:
1. Create a page with specific extension as name suffix (page.css) in which
case the page will be bootstraped accordingly, without call to layout.
2. Remove the call to layout in HTML editor or backend
3. Remove the call to submenus template in HTML editor or backend
For those cases, the menus will be prefetched for no reason.
Note that homepage '/' is rendered through a controller, same logic is applied
there.
task-2211013
This route was public by mistake, probably introduced to test during
ddf32f4 but no reason to make it public, public user has not the write
access on models anyway.
Courtesy of Swapnesh Shah
closesodoo/odoo#44915
X-original-commit: 66ac96b25aa4cf2b074f6c06b57ed8be72d6d647
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
* web_editor, theme_bootswatch
Instead of having an entirely dedicated system for theme options in a
third tab of the left panel, those theme options are now simple snippet
options. See the customizeWebsite generic method.
This allows to make any option available in the third tab or on any
meaningful element like the header or the footer. This also allows to
take advantage of all the features of the left panel: dependencies,
visibility update, etc.
Note: same as before, those changes do apply the color/size/layout
immediately on the website, even if not saved. Changing that behavior
is complex and might be the job of another task.
Part of https://github.com/odoo/odoo/pull/41166
task-2088298
Previously, theme customization was done through a modal dialog in the
website module, this was not very user friendly since the rest of the
customization for the website design was done from edit mode, meaning
the user had to exit edit mode to customize things such as theme colors
or fonts. It was also rather confusing to have these seemingly related
things in completely unrelated places.
This commit moves all of the options that used to be in the theme
customization modal into a new tab in the editor's left panel.
This commit is mainly just about rendering the old modal as a third left
panel content. See next commit for deeper changes.
Note: same as before, those changes do apply the color/size/layout
immediately on the website, even if not saved. Changing that behavior
is complex and might be the job of another task.
Part of https://github.com/odoo/odoo/pull/41166
task-2088298
In 0.15 accessing werkzeug.urls functions directly through werkzeug
is deprecated, the shortcut will be removed in the eventual werkzeug
1.0.
Fix existing uses of these shortcuts. Also cleanup some imports when
they're not far from a werkzeug* import being altered.
Before this commit, the `url_code` field value was stored in the cookie instead
of the `code` field.
This was making the language selector in the frontend to not change the lang
correctly when trying to access the website default lang, ONLY for the lang
having an `url_code` different than its `code` value (typically the case for
principal languages).
Step to reproduce:
- Add `fi_FI` as main lang on website
- Visit frontend and change lang to `Suomi`, it won't change
This behavior was only related to the language switcher. It did not affect
dispatching (if correct lang in url) and nearest lang finder.
Fixes#41522closesodoo/odoo#41728
X-original-commit: b62b2828552abb38c8adc74c69cb427c3fd98605
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Avoid redirect from /favicon.ico to /<lang>/facivon.ico at each request
closesodoo/odoo#40535
X-original-commit: 94bcbc92e5e5a6fd3de7267e3c01f8c11fb045f4
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
From now, you need to explicitely add sitemap=True if you want your controller
into the sitemap.
It's the default value, but if you forgot it, it will raise a Warning on runbot.
It will avoid wrong controller in sitemap and duplicate (empty) content.
From now, if your model contains a field website_id, the modelConverter for
sitemap will automatically add the domain:
"[('website_id', 'in', (False, current_website_id))]"
It avoid redundant declaration and ugly url in redirect/rewrite view.
Migration: need to remove it from url_from in website.rewrite
task-2065018
closesodoo/odoo#39427
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
You need to provide a small part of the code, because to avoid fraud, google
make several request to be sure that you don't allow all codes :)
So the 'WPS' solution was dropped, now we take the first request from google
that match the part provided, as the good one, and refuse all others requests.
task-2086915
closesodoo/odoo#39186
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
.. and first menu is a container with # as url.
There is a particular case where the / url would loop endlessly.
1. Unpublished the homepage /
2. Edit the menu so the first menu is a container. There is a hint telling you
a container menu should have its URL set to `#` as a good practice.
3. This will lead to endless loop for public user as the code will check if the
homepage can be accessed. Since it is unpublished, it will then fallback on
the first menu which is not '/' and redirect to it.
Sadly, the code was not expecting `#` to be handled as `/`.
opw-2081969
closesodoo/odoo#38234
X-original-commit: cff11bdb66f1dda41cf333a28b67df7ef20a3de9
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
After this commit, you will be able (in technical mode) to update the url for
the python controllers.
Eg.
You can now rename /shop in /garden and /shop/product/ in /garden/vegetable/
Most of urls will be replaced at fly in the renderd qweb, with the function
url_for but all old urls will keep available. So if you access url /shop you
will be automatically redirected to /garden (308 Permanent Redirect).
As for cdn and other post-process of att, the automatically replacement in the
rendered qweb is only done when you will be not website editor. But the new
dispatch of URL will be applied in all cases.
For developper, since it is Permanent Redirect, don't forget to clear cache or
open chrome debug tool (with option 'Disable cache while DevTools is Open) to
see your lasts changes.
closesodoo/odoo#36555
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Before this commit, 'Go to website' in website module dashboard might not
redirect to the correct website.
It would just redirect to `/` (href) without forcing the website selected in
the dashboard.
task-2063252
Closes#36390closesodoo/odoo#37359
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
In order to be able to send push notifications using recipients timezone,
the visitor timezone is now stored in DB.
The visitor timezone is only updated once, when found_visitor_timezone
cannot be found in localstorage. Once the timezone is updated,
found_visitor_timezone is added to localstorage.
Task ID : 1936643
PR #34973
With this commit it is now possible to change the lang displayed in the URL.
Eg, you could use `/fr` instead of `/fr_BE`, or even a fancier `/french`.
Task-32838
Courtesy of pla@odoo.comclosesodoo/odoo#35135
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Before this commit, user would be redirect to / instead of /my after signup.
That error was detected with task-1829827 which has a tour ensuring user is
correctly redirected to /my after signup on the checkout summary after payment.
Since 0229ef4c4a, the `web_login()` super call order has been changed when
called from the `/web/signup` route.
See the commit for more details but basically, before the fix, it went only
through:
1. web.web_login
2. portal._login_redirect
Where now, it goes through:
1. website.web_login
2. auth_signup.web_login
3. web.web_login
4.portal._login_redirect
Thus, portal._login_redirect is not returning `/my` as redirect anymore.
Indeed, website.web_login will ignore its super() and force redirect to `/`
With this commit, website's user are redirected to /my as expected.
Side effect: website's user will also be redirected to /my on login instead of
`/`, which is also prefered.
closesodoo/odoo#33865
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
The goal is to be coherent with the user property.
Actually, company_id and company_ids on the environment are no fields.
Calling env.company_id returns a browse record, not an id.
When opening the pdf at the end of an order Chrome tries to load
/favicon.ico which returns 404 before this patch. We provide the
favicon from the current website.
closesodoo/odoo#33746
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
* theme_bootswatch, theme_default, website_theme_install
This commit makes use of the new 'auto' widget for font selection:
instead of enabling a template which will enable a scss file which sets
a font variable to a specific value... we directly allow to do a scss
custo which sets that value.
The code in charge of resetting font customizations on theme switching
is also moved and refactored here in website (instead of being specific
to each theme).
Part of https://github.com/odoo/odoo/pull/33442
task-1974659
Co-authored-by: qsm-odoo <qsm@odoo.com>
* base
Before this commit, if an option was customized thanks to the customize
dialog, the page was not reloaded, only the new scss <link/> elements
were retrieved and replaced in the DOM.
There were two problems with this:
- The <script/> and <style/> tags were also retrieved for no reason (as
the whole result of t-call-assets was returned)
- This made use of a deprecated ir.qweb method that we want to remove
(see https://github.com/odoo/odoo/pull/33432)
This commit removes the use of the deprecated method by improving the
system: only the <link/>'s new URLs are returned on customization.
closesodoo/odoo#34040
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Purpose
=======
Allow the user to select the allowed companies for which he wants to see records
on top of selecting his current company.
It is confusing for users to see the records from the company he is connected to
and the records of the children companies.
Instead of using the hierarchy of companies to access records across companies,
the user can now select (from his set of allowed companies) the companies for
which he wants to access records.
/!\ This means that the user will interact with records from company A when in
company B.
Example: a SO has been created and confirmed in A. When in B, I create the
invoice from it.
Specifications
==============
1/ Deprecate the parent/children hierarchy on the res.company model. The fields are
kept on the res.company model to ensure the retro-compatibility, but won't be used
accross the standard code anymore. The only functional usage for this mechanism
was to allow to see records from several companies by creating a virtual parent
company, which will be possible with the new mechanism.
2/ By default, a user will only see the records of the company he is connected
to (or records without a company). (It is still editable by the user if needed).
For that, put this information in the user context, to allow having different
configurations on different browser tabs. Instead of having domains like
['|',
('company_id', '=', False),
('company_id', 'child_of', user.company_id.id)]
you'll have something like
['|',
('company_id', '=', False),
('company_id', 'in', company_ids)]
Note that the 'company_ids' is a value that is passed in the evaluation
context on the record rule, as we already have user, or time.
company_ids is a list of the ids of all the enabled companies in the
user's context.
3/ Out of the generic improvements brought by this task, this will illustrate
issues that could exist since several versions. For example, it should not be
possible to create a scrap order for the company A with a package of the company
B, or it should not be possible to create an invoice on the company A with
payment terms from the company B. Before the version 12.0, it was easy to
encounter this kind of issues as the admin was the SUPERUSER_ID. A positive side
effect of the fact that the SUPERUSER_ID has become an inactive user was to
make it more difficult to introduce mismatch on the records, but haven't solved
the issue, as it was still possible to do it with parent companies
configuration. Some of these issues have been fixed in this commit, but all the
business flows should be re-tested to check if an ir.rule should be introduced
(eg: a multi company rule for stock.quand.package), if the company of a record
is correctly transfered to another record created from the first record (eg:
From a SO, create an invoice and a payment, the company of the sales order
should be transfered on the invoice and the payment, even if the company of the
sales order is A and I'm logged into the company B with the company A enabled.
4/ Currently, if I click on a button on a notification email (example 'View
Task'), I face a traceback if I'm not logged into the company of the record.
Now, if you click on a button and if you have access to the record, the correct
company will be automatically set.
5/ If I display a kanban view with several records from several companies (and
an image), all the images should be displayed.
6/ Currently if you copy paste an url, this will crash if you're not in the
correct company. This won't be fixed because it's quite impossible to do it in
a clean way. This task brings a workaround. Copy/Paste -> Traceback -> Log into
the correct company, re-copy/paste -> Ok.
7/ 2 property methods have been added on the environment to retrieve the company
on which the user is logged in and the companies the user enabled, on a specific
tab.
That way, when creating a record, instead of doing
default=lambda self: self.env.user.company_id
do
default=lambda self: self.env.company_id
On the other hand, to retrieve the enabled companies, do
companies = self.env.company_ids
8/ Modify the Company Switcher widget to allow to log into another company
WITHOUT writing on the res.users (and thus bringing cache invalidation issues
and so on). Also allow to enable several companies and see records from several
companies, and independantly of the other browser's tabs.
9/ When focusing on a tab, save the current company configuration on the local
storage. That way, when doing 'CTRL+T' or a middle click, the context is
propagated to the new tab.
10/ Improve the error message in case of multi company access errors. Now, when
the user is in debug mode, display the related names of the records and the name
of the user who brings the issue.
11/ Remove the context erasing when writing on a res.users
This is probably coming from the migration to new API of the base module.
The context was not propagated at this moment, which was a common mistake at
that time. When migrating the module, probably by using the 'black box' method,
as the context was not propagated, it was erased on the new version. This is
now an issue because the context (i.e. the enabled companies) was erased when
writing on a res.users, leading to tracebacks.
See: https://github.com/odoo/odoo/commit/7eab8e26d3d46c53f4be924d6a34e80a66e74960#diff-4c2e738ee8f64f11806c889ea097b5e7R624
12/ Fix the crash manager on redirect warnings. The issue is the following
- Create an invoice on a company without a configured CoA.
- Set a partner
- On the onchange_partner_id, a redirect warning is raised to propose you
to configure a CoA
- Click on 'Go to the configuration panel'
- A generic warning says something like 'Do you want to discard your changes?'
- Click on yes, the page refreshes, but not on the redirect action.
Now, set correctly the action on the hash, and reload instead. The breadcrumb is
lost for example, but you reach the correct action at least.
13/ Introduce a res.group to enable/disable the multi company per tab
feature.
14/ To help the users to know which tab is in which company, add the
possibility to have a favicon per company. When creating a company,
the classical 'O' icon is colored by default in a random color.
15/ Remove the company switcher on the frontend. This was mainly there
to allow a user to swicth to the company linked to the website.
This behavior is now transparent to the user. If the website A is
activated, then the company set on the context is the company of the
website.
16/ Deprecated the _company_default_get method on the res.company
model. Remove the method _get_company on the res.users model.
17/ Add 'allowed_company_ids' and 'current_company_id' on the pyeval
context. You can now use those variables on domains in the views to
access directly to the activated company.ies on the current tab.
TaskID: 1960971
closesodoo/odoo#32341
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
Reset view feature code still had remains of initial release (Odoo 9.0).
At that point all the view tree was returned, not only the broken view.
Since it has been fixed in 12.0 and refactored in saas-12.3 with this PR, it
now only takes the broken view as argument, handling multiple views has no
sense anymore.
Thus, this commit remove the (unused) multiple view compatibility.
This commit also add a test to test the refactoring or this feature.
Coming from #32009 (task-1943001)
- Store previous arch to be able to reset it (soft reset)
- Add the possibility to reset from file if possible (hard reset)
- Adapt frontend reset page to these new fields
- `arch_fs` hack to check if view was modified got moved to new field
`arch_updated` as we now need to keep track of the `arch_fs` to reset a
broken view.
Closes#32009 (task-1943001)