Commit Graph
27 Commits
Author SHA1 Message Date
Samuel Degueldre 74e23b2e2b [IMP] Prevent reverse tabnabbing in plaintext2html, linkify, _makeLink
These functions convert plain text links into clickable hyperlinks.
These open in new tabs but did not have the "noreferrer noopener" rel
attributes, which made them susceptible to reverse tabnabbing.

A lot of attack vectors were available to unregistered, uninvited
anonymous users and presented a significant phishing threat (such as
posting links in the instant-chat, through a mail-alias, in a forum post
or in a twitter post) and leading the operator to believe he had been
disconnected from odoo in the original tab, prompting them to enter
their credentials.

while these three places will add the noreferrer and noopener attributes
on the anchor tags generated by them, there are still many places that
create hyperlinks without the use of these functions, although most of
them are static links, they still represent a transitive security
vulnerability to the linked sites.

There are also a few modules and widgets that roll out their own links
or open new tabs unsafely using window.open(), these will need to be
patched separately.

closes odoo/odoo#37591

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2019-10-01 08:24:59 +00:00
qsm-odoo 4895b452c1 [FIX] website_twitter: restore twitter animation in edit mode
Animations (now public widgets) are now disabled by default in edit
mode. It is opt-in. That one should have been enabled and was left
disabled by mistake.

task-2070930

closes odoo/odoo#36807

Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2019-09-12 16:40:59 +00:00
4721de57df [REF] website_twitter: adapt code after jQuery update
Part of task 1896658

Co-authored-by: Aaron Bohy <aab@odoo.com>
Co-authored-by: Christophe Matthieu <chm@odoo.com>
Co-authored-by: Mathieu Duckerts-Antoine <dam@odoo.com>
Co-authored-by: David Monjoie <dmo@odoo.com>
Co-authored-by: Martin Geubelle <mge@odoo.com>
Co-authored-by: svs-odoo <svs@odoo.com>
Co-authored-by: Vincent Schippefilt <vsc@odoo.com>
2019-03-06 20:07:17 +01:00
qsm-odoo a80775ce3c [REF] website, *: stop using 'animation' confusing name
* web, website_blog, website_sale, website_twitter

Before this PR, all website widgets were named 'Animation'. Now that
they are 'Public Widgets', we can at last stop using the confusing
'animation' name.

Part of https://github.com/odoo/odoo/pull/29442
task-1932066
2019-02-26 17:09:23 +00:00
qsm-odoo d946b7a85d [REF] website, *: use public widgets instead of website animations
* website_blog, website_crm_partner_assign, website_event,
  website_event_track, website_form, website_forum, website_links,
  website_mail, website_mail_channel, website_mass_mailing,
  website_sale, website_sale_comparison, website_sale_delivery,
  website_sale_stock, website_sale_wishlist, website_slides,
  website_twitter

While using the 'Animation' class of website instead of the frontend
'Widget' class leads to the same behaviors, this refactoring is done for
two reasons:
- Stop using the confusing 'Animation' name for non-animated behaviors
- Instantiation of 'Widget' is slightly faster than 'Animation'

Part of https://github.com/odoo/odoo/pull/29442
task-1932066
2019-02-26 17:09:23 +00:00
stefanorigano 1d9208c4fa [REF] *: improve app icons, add SVG version
- Uniform colors and design
- Replace duplicated icons (eg. sale / sale_management)
- Improve misleading icons (eg. POS)
- Add icons for new apps

Add SVG versions to lossless future editing and print/marketing use.

task-54681
2018-08-09 15:46:06 +02:00
qsm-odoo 7f10b55a50 [REF] *: BS4, adapt display classes
The system completely changed. I also had to adapt classes to new
screen breakpoints.

hidden/hide -> d-none
show -> d-block
hidden-xs -> d-none d-md-(block/inline/...)
hidden-sm -> d-md-none d-lg-(block/inline/...)
hidden-md -> d-lg-none d-xl-(block/inline/...)
hidden-lg -> d-xl-none
visible-xs-* -> d-* d-md-none
visible-sm-* -> d-none d-md-* d-lg-none
visible-md-* -> d-none d-lg-* d-xl-none
visible-lg-* -> d-none d-xl-*
hidden-print -> d-print-none
visible-print-* -> d-none d-print-*
...
and all possible combination of those had to be handled too.
2018-07-27 12:36:54 +02:00
kujiu f90cf060a3 [FIX] Syntax of icons (#25577)
Description of the issue/feature this PR addresses:

Accessibility improvements forbids the use of the syntax
`<i class="fa fa-check"/> Some text`
to create a labelled icon. But, by this, some fonts are changed.

Desired behavior after PR is merged:
The old syntax can be used.
2018-07-04 09:55:52 +02:00
kujiu 9de1bc0eef [IMP] Improve compatibility with screen readers (accessibility) (#24574)
Today, Odoo is really tricky to use without seeing the screen, it must be improved to be usable.

This PR forbid to use labels without a "for" attribute, add some title, rule and aria attributes in HTML. With that, Odoo will be fully usable with a screen reader.


* [IMP] Labels must have a for attribute. Improve accessibility.
* [IMP] Better error message when trying to read a missing cached value
* [FIX] Add some aria-label and title attributes for screen readers.
* [FIX] Template name is not included in the error message in case of SyntaxError in QWeb
* [FIX] Improve the Tour failed at step error message to be more explicit.
* [IMP] Add aria-labels
* [FIX] Add missing aria-label on failing test
* [IMP] aria-hidden means hidden. Fix all bad aria-hidden and hide aria-hidden for all.
* [IMP] Color names on kanban views and many2many tags
* [IMP] Add some checks on views for accessibility.
* [IMP] Add `alt` attribute on `img` tags.
* [IMP] Add aria-label and title on non-described icons
* [IMP] Add button role to widgets with btn class
* [IMP] Translate aria and formatted attributes.
* [IMP] Remove wrong aria-labelledby
* [IMP] Add menu role on dropdowns
* [IMP] Buttons must be focusable
* [IMP] Add aria attributes on progress bars
* [IMP] Improve accessibility of basic widgets
* [IMP] Change main layout to more semantic tags
* [IMP] Add menuitem role when missing
* [IMP] Remove wrong role='presentation'
* [IMP] Improve accessibility of tab panels
* [IMP] Add aria-invalid on invalid fields
* [IMP] Add aria-sort on ordered columns
* [IMP] Add role on alerts
* [IMP] Use dialog role, header, main and footer tags for modals
* [IMP] Add labels on o_status
* [IMP] Improve accessibility of kanban view with feeds and articles
* [IMP] Add alerts in case of new messages
* [IMP] Add widget, navigation or img role to aria-labelled items
2018-06-22 21:22:21 +02:00
qsm-odoo b04dec4025 [REF] *: rename all LESS files to SCSS
This is a simple renaming without adaptation.
2018-04-18 15:59:15 +02:00
qsm-odoo 0a31cb9b4a [IMP] website, *: improve 'animation' API
* web_editor, website_twitter

- There can now be multiple animation widget on the same element
- Animation are destroyed before saving the editor (allows to not be
  forced to do that destruction / code duplication in many cleanForSave)
- .data('snippet-view') is definitely dead
2017-11-09 09:49:36 +01:00
qsm-odoo f1f3a8c76a [REF] website_twitter: better adaptation to websitepocalypse
+ Some layout fixes
+ Controllers routes renaming
+ SASS -> LESS

Note: animations and layout could be further improved but the goal of
this commit was to refresh the code to master's new conventions.
2017-10-18 13:33:23 +02:00
qsm-odoo a3f899c395 [FIX] website(_twitter): properly stop snippet animations
The `stop` method of snippet animations was renamed to `destroy` (as
animations are now extensions of standard `Widget` class).
2017-09-30 14:33:05 +02:00
qsm-odoo 2972976962 [REF] web_editor, website, *: complete refactoring
* mass_mailing, payment, point_of_sale, portal, survey, web, web_tour,
  website_blog, website_crm_partner_assign, website_event,
  website_event_questions, website_form, website_forum, website_gengo,
  website_hr_recruitment, website_links, website_mail,
  website_mail_channel, website_mass_mailing, website_quote,
  website_sale, website_sale_options, website_slides, website_twitter

This commit reviews the whole "JS side" of the web_editor and website
apps. This is a first step to be able to improve them with new and
better functionnalities; this commit is not supposed to change any
visual behavior.

The main goal was to achieve a structure similar to the backend one.
Now, the frontend side also has a root widget (like the WebClient)
and all other widgets are attached to it one way or another. This allows
the benefits of using the 'trigger_up' functionnality for example.

As RPC are now mainly done with the `this._rpc` functionnality (being
possible thanks to the parent hierarchy), the frontend will also be
possible to test thanks to QUnit in a future update (besides the "text"
editor side which still requires a refactoring to be able to do that).

---

Here are some of the changes:

(-) conventions and documentation

The code has been updated to follow JS conventions and a lot of code has
been commented (around +2000 lines of comment). This also means that
lots of functions have been renamed to use camelCase or simply to make
their name understandable.
See https://github.com/odoo/odoo/wiki/Javascript-coding-guidelines.

(-) deprecated: web_editor.base

The "web_editor.base" module has been split and does not force the
modules which require it to wait for DOM ready anymore. This was indeed
slowing loading times, but also prevented to use some modules in some
contexts (see the LESS editor use in web_studio which is the subject of
another task).
Now the "editor context" can be got thanks to the "web_editor.context"
JS module with its "get" function.
The "web_editor.base" module should probably not be used anymore (see
its code and recent updates).

(-) new: web.dom_ready

If a JS module should wait for the DOM to be ready to be executed, a
new JS module has been created: "web.dom_ready". This should always
be used in a module which only want to instantiate stuff. Do not
extend (or worst, include) classes after DOM ready.

(-) website.website

The "website.website" module has been split. "website.website" does not
return anything useful anymore, it just initialize some miscellaneous
stuff, without waiting for the DOM to be ready. You might want to check
"website.utils", "website.content.compatibility" or `WebsiteRoot`. Also
`website.form` has been deleted (use `this._rpc`), so has been
`website.error`. `website.prompt` will be removed in a future update to
be replaced by `Dialog.prompt`.

(-) widgets are great

Many classes which were not widgets are now widgets. This allows them to
use the 'events', the 'xmlDependencies' and the 'this._rpc' features for
example. Here are some of the main ones:

- Snippet options: these were classes with a `$el` for the menu element
    and `$target` for the customized element. This is still the case
    but following standard `Widget` structure (one exception: using
    `this.$(...)` searches in the `$target` as before this update).

- Snippet animations: instead of class instances with a `$target`
    element which can be `start` and `stop`, these are now standard
    widgets which can be `start` and `destroy`. `this.$target` is
    an alias to `this.$el` for ease of compatibility.

- Snippet editors: instead of class instances in charge of an editor
    overlay, these are now widgets. Each "child" snippet editor is
    properly attached as a "child", which allows editors to communicate
    and to be properly destroyed.

(-) root widgets and website navbar

The frontend is different of the backend. In the backend, the page has
an empty <body/> element and all the components are instantiated from
parent to children (i.e. the `WebClient` is instantiated and is in
charge of instantiating the `ControlPanel`, etc). The frontend cannot
work like that on page loadings as they are way more frequent than in
the backend and we do not want them to flicker. A frontend page is
loaded as a <body/> element which already contains the website navbar
and its menus and the whole content page. JS code has to be "attached"
to these existing elements. This is possible thanks to the `RootWidget`
instances and the specialized `WebsiteRoot`, `IframeRoot` and
`WebsiteNavbar` (see code for details).

(-) lazy loading

No more (or at least a lot less) XML/JS has to be loaded on page
loading, thanks to the use of the `Widget.xmlDependencies` feature.
XML which have to be lazy loaded is loaded only on related Widget
instantiation if necessary, which allows to execute a lot of JS code
before the DOM is ready and to start many widgets on DOM ready (not
later). A visual benefit of this is clicking on the 'edit' button as
soon as it is possible: before this commit, this was sometimes not
doing anything as event handlers were not binded yet.

Still a possible exception: loading the session and locales. This may
be asynchronous stuff which is still required before widget
instantiations but this will be the subject of another task.

(-) deprecated code and code location

More than reviewing code and organizing it, many apparent dead code was
removed. More importantly, mislocated code was put in the right app.
This is the case for snippet animations which is a concept for website
apps but was defined in the web_editor app, or some translation concepts
which were part of website but should have been part of web_editor.

---

There are probably more things to say about this commit but I will let
the comments speak for those.
2017-08-16 11:04:14 +02:00
Kishan Gajjar aaeef14903 [IMP] web_editor, website(_*): show all snippets even if module is not installed
* mail_channel, mass_mailing, twitter, event

- t-install attribute holds the technical name of the module that
  needs to be install to use a particular snippet.

- Disable the drag & drop feature for these dummy snippets.

- Move some images to website module.

- Installed snippets display at the top of the list.

- Hide not-installed module snippets if user don't have rights to install module.
2017-07-04 10:54:20 +02:00
Jainik Patel a4d7540ed9 [ADD] various: add missing icons for website apps 2016-08-18 16:45:38 +02:00
qsm-odoo 4005cf025e [FIX] website_twitter: stop JS code crash if no tweet
Prevent the JS to crash when a well-configured twitter account with
no tweet in it is used with the website twitter snippet.
2016-07-18 11:26:04 +02:00
Christophe Matthieu 9665882fba [IMP] web_editor: adapt css, js and xml to use web_editor 2015-07-10 17:00:12 +02:00
Jérome Maes 06dfb4baef [FIX] website_twitter : loading the twitter js template with the correct deferred to aovoid timeout and crash. 2015-03-24 13:49:35 +01:00
Géry Debongnie 4fdf74fe21 [IMP] web+addons: improvement to module system
The module system needs to know the dependencies of a given module
before executing the function.  This is why the dependencies were
defined once in an array, and then were described one more times in the
call to require.

But a trick can simplify this: the boot function can parse the string
representation of the module and extract the calls to require from it.
It is more work for the processor, but it leads to simpler module
definitions.
2015-03-18 09:23:37 +01:00
Géry Debongnie 59a4706dd9 [REF] website_twitter: update to the new module system 2015-03-18 09:23:37 +01:00
Martin Trigaux 07ccd6c1c7 [IMP] website_twitter: remove debugger 2015-01-16 17:14:23 +01:00
Christophe Simonis c825d0552d [MERGE] forward port of branch saas-3 up to ec27773 2014-11-05 21:46:42 +01:00
Olivier Dony e133e5fc36 [FIX] website_twitter: display setup/debug info only for website editors, not visitors 2014-09-22 14:54:10 +02:00
Denis Ledoux 1d77697a5d [FIX] website_twitter: IE does not accept twitter date format
Datetime like Tue Jul 13 23:18:36 +0000 2010 is not accepted by IE and return "Invalid date".
Therefore, We parse the date to a format known by IE (and other browsers)
Trick took from http://stackoverflow.com/questions/3243546/problem-with-javascript-date-function-in-ie-7-returns-nan
2014-08-18 13:13:56 +02:00
Olivier Dony 66484dbbc8 [FIX] website_twitter: use HTTPS profile URLs to be safe on HTTPS websites 2014-05-15 17:08:29 +02:00
Barad Mahendra 0152bea512 [MERGE] [ADD] website_twitter: add twitter scroller snippet
bzr revid: odo@openerp.com-20140410174622-j2waid38nk3fqitt
2014-04-10 19:46:22 +02:00