- When rendering a website page, exceptions might happens.
If so, an error page is displayed, to do so we create
a new psyscopg cursor to read the view in database and render it.
But if the current (failed) transaction was holding a lock, the new
cursor might have to wait for this lock to be released further
down the line. However, this will only happen after the
request is done (and in fact it won't happen). As a result, the
current thread/worker is frozen until its timeout is reached.
So rolling back the transaction will release any potential lock
and, since we are in a case where an exception was raised, the
transaction shouldn't be committed in the first place.
closesodoo/odoo#44085
X-original-commit: 7a61c89da5ccaed983275eb5f4986475ebf8b48d
Signed-off-by: Toufik Benjaa (tbe) <tbe@odoo.com>
Without demo data, for the odoo-master transifex project
closesodoo/odoo#41935
X-original-commit: dab7670b73506fb3a835695ee3bd735e0c5e5c2b
Related: odoo/enterprise#7287
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
This commit fixes 2 issues, both coming from a misbehavior in
`get_nearest_lang()`:
1. Anyone could reach the website in a lang available in backend but not in
frontend. Eg, french is activated but not a website lang, going to `/fr`
would show the page in french.
2. As a logged in user coming from backend in a lang not available in frontend
(has request.lang set to that lang), the website would show a 500 error page
since it would not filter out the current request lang.
Both these issues are fixed here by ensuring langs are filtered out if they do
not belong to the frontend (website langs).
Step to reproduce (bug 1):
- Install french in backend lang (not on website)
- Visit `127.0.0.X/fr_FR`, the frontend will be displayed in french even if
it not a lang available in frontend.
Step to reproduce (bug 2):
- Install french on frontend and remove english from frontend
- Navigate to the backend /web
- Navigate to frontend, it will crash
Fixes#40572 and fixes#40078closesodoo/odoo#41146
X-original-commit: 4bfba037fbbf34c178abd532f7bf52b94ae40b27
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Old heuristic is not more True:
Force to check method to POST. Odoo uses methods : ['POST'] and ['GET', 'POST']
We have some controller that only allow 'GET' method, so we need to check GET
also when we try to know if an url is multilang or not.
This commit fix case where a controller '/test' only allow GET and you were in
another language that the default, in this case, the rendered url in qweb was
/get instead of /<lang>/get.
Closes#37223closesodoo/odoo#40519
X-original-commit: c7650106f8588083be12812600a6c94ba703fd6f
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Reproduce the issue
- Install eCommerce & Sales
- Create a quotation
- Preview
- Switch to french on the website page
- Click on "Signer & Payer"
There is a lot of things not translated.
Cause
On the website, the route `/website/translations` is called.
The route calls a method `_get_translation_frontend_modules_domain`
which teturn a domain to list the domain adding web-translations and
dynamic resources that may be used frontend views.
The missing translations are in the web module and the module is not
loaded by the method.
This commit adds the `web` module to the domain and a missing
translation for the portal module
OPW-2120397
closesodoo/odoo#41072
X-original-commit: 50c2ecbc9ef0e446af0a1d4010ec1d923aa41bec
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
A customer reported a problem when he deleted a language on the
website app.
In some cases, if you go on the odoo's generated website as a public
user let's imagine the following url: website.com/en_GB
The lang is saved in a cookie and sent to the context.
If you delete the language from the website languages (without
deactivating it) and you go on website.com as a public user,
the method will try to use the context or the cookie value which is
'en_GB' and it crashes.
This commit makes sure that the language is available
OPW-2129580
closesodoo/odoo#41007
X-original-commit: f3e9ca13f60ced0ec61cea0d13da45b2569da14e
Signed-off-by: Jason Van Malder <jasonvanmalder@users.noreply.github.com>
A nicer 404 layout was introduced with e9106f8f98 but the specs got changed
just after it was merged.
It has been decided to make the 404 fully editable (before, everything was
fully editable except the popular page div).
In order to do this, the 404 template can't have inherited views, which brings
the following changes:
1. Remove every main website module xpath view adding their most popular page
2. Remove the xpath view in portal to add popular page part (was not needed
in http_routing/web). It has been decided that having `Home` ('/' url) even
without portal and/or website is not a big deal.
Those changes allow the 404 template to be written in a single view without any
inherited views.
The 404 will be the same for backend only databases, portal and website.
task-1966460
closesodoo/odoo#40637
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
This commit introduces a nicer 404 page, which is basically the same layout as
the one used on Odoo.com.
Also, the 404 is now fully customizable, blocks can be drag'd & drop'd.
task-1966460
closesodoo/odoo#38901
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Initial b6ed34e1 idea was to ensure that we always have
_rewrite_len and _routing_map defined. Unfortunately, this
is not correct since class attribute defined dynamically
are actually added in registry, and recomputed on each install.
More than that, the call si shared between multiple database
meaning that routing_map cache may be shared between multiple
database whcich is not correct.
After b6ed34e1, when installing discuss on a fresh database without
demo, all discuss routes will be unknown since None is already in
_routing_map and thus routing_map is not recomputed.
When routing_map is on the model class, in registry,
a new install will reset the class, remove the _routing_map attribute,
which will fix the problem.
Task #2117275closesodoo/odoo#39640
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
Now, you can define a Visibility mode between:
Public (All poeple)
Connected (Portal or Employee)
Restricted Group (Has this group or is Employee)
With Password (Know password or is Employee)
Internal Users (Is Employee)
It is a 'fair' feature, but without really warranty that the content is
really unreadable via others methods, ...
It is more for frontend display, that real secret. Dont use this like
a keychain ;)
We only catch the visibility on the main view and not the t-call inside.
Even if it should work on controller too, it is only display now on the
page property menu. (Or on the view directly in backend)
task-2091365
A 404 will take 3 to 5 seconds to be resolved and execute +- 1900 query, to return
a rendered page which is quite expensive, especially when multiple missing images
are rendered in a view.
Catching static route and marking them as not frontend will help to avoid to handle miss
on static resources. In this case server returns a standard 404.
This commit also fix a iframe src in order to avoid a 404 on
/web/(test )/report/html/some_report (thx to aab-odoo)
X-original-commit: 818d0cb59fbae78d0edf06318082981f318e4db7
This reverts commit 08108486d5.
+ Fix the url that add a useless ending / and so a useless redirection.
There are no problem of mixed content or anything else, if you configure nginx
and launch your server in proxy-mode as specified into the documentation.
closesodoo/odoo#38196
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
In case you have a controller website=True without website installed, the
request.redirect() use url_for which one uses request.website_routing on the
request, without that it has been set by the website dispatcher.
closesodoo/odoo#38191
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
* = portal, website, test_website, account, sms
Portal an Survey error pages were ugly default pages.
Now the error pages will be the same as the website ones.
Also fixing single module builds tests
task-2059969
closesodoo/odoo#35535
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
After this commit, you will be able (in technical mode) to update the url for
the python controllers.
Eg.
You can now rename /shop in /garden and /shop/product/ in /garden/vegetable/
Most of urls will be replaced at fly in the renderd qweb, with the function
url_for but all old urls will keep available. So if you access url /shop you
will be automatically redirected to /garden (308 Permanent Redirect).
As for cdn and other post-process of att, the automatically replacement in the
rendered qweb is only done when you will be not website editor. But the new
dispatch of URL will be applied in all cases.
For developper, since it is Permanent Redirect, don't forget to clear cache or
open chrome debug tool (with option 'Disable cache while DevTools is Open) to
see your lasts changes.
closesodoo/odoo#36555
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
When accessing an URL, there is some computation to check if you try to access
a lang. Part of this job is to get the closest language available.
For instance, you could try to get `/fr_BE/..` and it would redirect to
`/fr_FR/..` if french is installed but not belgian french.
There is a known issue when loading files/assets from a module starting by the
same letter than a lang, in debug assets.
Only reported case was `hr_XXX` modules which would be redirected to `hr_HR`
lang (croatian).
So, the issue would only occur when:
1. Debug assets is enabled
2. hr_HR lang is activated
3. only hr_XX modules would be impacted
But since 269aa59411, the issue would appear even if `hr_HR` was not activated.
This commit restore the issue to its minimal case, when `hr_HR` lang is
activated.
closesodoo/odoo#37494
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
SHA-1 is a cryptographic hash function that have weaknesses known since
2005, it has been deprecated by the NIST [1] about 10 years ago in 2011
and Google [2] have been able to perform a collision attack in 2017.
We use SHA-1 in order to generate unique URL for resources that can be
cached by the browser: assets bundle, translations, qweb templates and
qweb images.
Although practical attacks still requires quite a lot of computational
resources, it is time to upgrade SHA-1 to SHA-2.
We have selected the SHA-512/256 variant of the SHA-2 algorithm as
replacement for SHA-1 for the following reasons:
* On 64 bits platform, SHA-512 is the fastest SHA-2 variant, it is only
~1.5x slower than SHA-1. [3]
* Keeping only the 256 foremost bits protects against both collision
attacks and length extension attacks.
* The hexadecimal digest is only 24 chars longer than SHA-1 which is
nice to have somewhat short URLs.
We have not used SHA-3 because:
* At the moment of writing, it is too slow (~3x slower than SHA-1) [3]
* It is not guaranteed to be available with the Python 3.5 `hashlib`
module.
* One of the author of SHA-3 is Belgian.
[1] https://csrc.nist.gov/projects/hash-functions/nist-policy-on-hash-functions
[2] https://shattered.io/
[3] http://bench.cr.yp.to/results-hash.html
[4] http://www.commitstrip.com/en/2017/02/27/the-sha-1-alternative/
The canonical tag is important for SEO, indeed it prevents search engines from
indexing duplicate content.
Reasoning
=========
The choice has been made to create the canonical tag automatically depending on
the request path, ignoring the query string, and manually prefixing the
appropriate domain and language code.
Indeed creating it manually for each resource would create a lot of code and
potential mistakes.
It is more dangerous to do it the generic way, but after investigation it
appears that it is an acceptable trade-off since the vast majority of our routes
are well built and already ready for this:
- using query string only for minor features that do not change the main content
- having the models, the ids, the pager and other important features in the path
Override
========
It is still possible to override the default behavior by passing
`canonical_params` manually to the view or to the different methods.
This is done for `/event` because the only way to display Past Events is to add
`date=old`.
Languages
=========
Fix an issue where it was possible for a bot to be on the URL without language
code but to use a language that is not the default language.
Adapt hreflang, because it:
- must only be present on canonical pages
- must always lead to canonical pages
- should not be set if there is no alternate language
Misc
====
task-1958075
closes#12532
Inspired by OCA module `website_canonical_url` courtesy of Jairo Llopis.
closesodoo/odoo#35852
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Co-authored-by: Jairo Llopis <jairo.llopis@tecnativa.com>
Co-authored-by: Sébastien Theys <seb@odoo.com>
With this commit it is now possible to change the lang displayed in the URL.
Eg, you could use `/fr` instead of `/fr_BE`, or even a fancier `/french`.
Task-32838
Courtesy of pla@odoo.comclosesodoo/odoo#35135
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
get_installed and _lang_get_id are both ormcached and correctly check
the context
Retrieving a res.lang from a code is a frequent action that can be
achieved with _lang_get (cf previous commit).
Using _lang_get ensure the active_test in the context is correct and
is not poluted with another context propagation issue.
odoo/odoo#35490 discussion is an example of bad context propagation
closesodoo/odoo#35504
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
cache_hashes was introduced at 8a28cc22fd to reduce the number of reload
The cache is correctly reseted when the translations content changed but did
not contain all the translation-related parameters that are, however, stored
in the session_info
This commit fixes two bugs:
Language parameters invalidation:
1. Access the webclient in a specific language
2. Modify the language parameters (e.g. thousands separator)
3. Refresh the page
--> webclient is still using old language parameters (from cache)
No translation flag after installing a language:
1. Load a database in English in mono-language
2. Load a second language
3. Access a record with a translated field
--> translation button not present on translated field (multi_lang is still
false in cache value)
To fix it, this commit adds all the information that are returns by the
/web/webclient/translations call to make sure the hash represent the reality
closesodoo/odoo#34266
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
* http_routing, portal, rating, survey, website, website_survey,
website_slides_survey
Before this commit, the final base layout of website was a fully
overridden layout of the one in portal, which was somehow a duplicated
one of the login one in web, which... so lots of duplicated code.
This commit is a first step towards a better organization:
1) The web app defines a frontend layout (to include base frontend
assets), with a base company logo as header.
2) The portal app modifies that layout in place to include the base
header, footer, ... It also uses a primary extension of it for
portal pages.
The survey app simply uses the above layout instead of defining its
own (by primary extension to include its own assets for its own
pages)
Same goes for the rating app and pages.
3) The website app modifies that layout in place to include the UI
assets, to add website UI, ... This allows to create frontend apps
which do not depend on website, with a non duplicated layout that
will be automatically adapted if website is ever installed (this
therefore allows to get rid of website_survey definitely)
This commit also fixes the session info system and the translation URL
on the frontend side to not require to redefine the whole session_info
for portal, website, ... Now the frontend session_info is defined in web
and http_routing extends it to add translation informations, then
website extends it again to add its own elements (not to redefine them
all as before). Note: before, http_routing defined the translation route
but only portal was adding it in its layout...
This is an adaptation of the work that was done with commit
https://github.com/odoo/odoo/commit/99821fdcf89aa66ac9561a972c6823135ebf65c0
Note 1: Many frontend but non-website apps (not only survey / rating)
could probably use this too but this would be the topic of another task.
Note 2: survey currently depends on http_routing but does not add itself
in the list of frontend apps to translate, it probably should.
Note 3: web_editor does currently not depend on http_routing but does
add itself in the list of frontend apps to translate, it thus uses a
function it does not really depend on... to check after its work-in-
progress refactoring.
task-1961045
closesodoo/odoo#33825
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
Generate a unique URL for translations and cache them forever in the
browser. This reduces the number of requests, in exchange for computing
the hash of the translations when the session object is added to the page
Reintroduces 5324284f5 that was reverted because in the case of an URL
like /payment_stripe/static/src/js/stripe.js directly inside a QWeb
template, we would possibly get:
/fr_FR/payment_stripe/static/src/js/stripe.js
Which is not accepted by werkzeug SharedDataMiddleware we use to serve
static data in /{module_name}/static/ directories.
Added test without changeset failed with:
- test_process_att_no_request_lang: <AssertionError>
line: self._test_att('/en_US/', {'href': '/'})
wrong result: {'href': '/en_US/'}
- test_process_att_with_request_lang: <AssertionError>
line: self._test_att('/', {'href': '/fr_FR/'})
wrong result: {'href': '/'}
- test_process_att_matching_cdn_and_lang: <AssertionError>
line: self._test_att('/en_US/a', {'href': 'http://test.cdn/a'})
wrong result: {'href': 'http://test.cdn/en_US/a'}
- test_process_att_no_route: <AssertionError>
line: self._test_att('/my-page', {'href': '/fr_FR/my-page'})
wrong result: {'href': '/my-page'}
- test_process_att_url_crap: <IndexError: list index out of range>
line: request.httprequest.app._log_call[-1],
opw-1922051
closes#32095
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>