- Differentiate between the Community and Enterprise editions
in the version number. By adding this attribute on the global
odoo JS object in the web client bootstrap controller /web,
we can differentiate between versions easily on the client
side without extra RPC calls.
- Remove a couple of version-related RPC calls in case
the global version info is present in the JS environment
- Update "About" panel to display the edition info
- This commit also reverts 07fe5afc87
which implemented the idea in a more limited way.
Closes#9625
* add CSRF token as core.csrf_token
* add CSRF tokens to client-generated and/or JS-submitted forms
* remove broken "compatibility" mode of web.ajax.post
/cc @dmo-odoo I've no idea how that was supposed to work, from looking
things up all modern browsers seem to support FormData, and old IEs
which don't don't support fallbacks either and would require
submitting an actual form as fallback so...
* make CSRF protection the default on all non-SAFE methods
note: there currently is no way to call a CSRF-protected endpoint
without a form-encoded entity-body as that's the only place we get the
CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
the purpose of a CSRF token in the database manager screens.
There is no request database to obtain the
secret and generate a CSRF token.
Move the widget_x2many tour to web and call it from test_new_api as it needs
to be overrided for the new design, and it requires models and data from
test_new_api.
Clean other unnecessary stuff from web_tests, and thus remove the addon.
- fix html and css layout using only pure bootstrap
- replace db selection by a link to the database selector
- reorder templates
- remove unused templates
If the module barcodes is installed, a BarcodeEvents singleton is
automatically instanciated. It listens to keypresses and, when a
sequence of keys represents a barcode, it broadcasts a 'barcode_scanned'
event on core.bus containing the barcode string.
boot.js log:
* ``Missing dependencies``:
These modules do not appear in the page. It is possible that the JavaScript
file is not in the page or that the module name is wrong
* ``Failed modules``:
A javascript error is detected
* ``Rejected modules``:
The module returns a rejected deferred. It (and its dependent modules) is not
loaded.
* ``Rejected linked modules``:
Modules who depend on a rejected module
* ``Non loaded modules``:
Modules who depend on a missing or a failed module
* select2 was linked in both backend and frontend (by web and website)
* select2-bootstrap was in website and linked only in frontend but it
is in fact needed in backend too
+ Remove useless link of the lib by other modules
Icons in web client main menu were added as a side effect of changes in
enterprise. The problem was that the template for the menu added the
icon in it exists, which is never what we want anyway.
When a user tries to log into a postgresql database with no view web.login (this
happens if the database is not an odoo database or using a previous version of
odoo), the rendering failed, producing a 500 error (with no detail for the user)
Instead, redirect to the database selector with an informative message.
Fixes#3443
The database selector page is a jinja template with no access to database
required so should be able to be displayed on any database.
Future improvement could verify the version of base module for even more precise
verification before login (but need to make sure it's always accurate).
Implement a new way of dealing with barcode events. This was necessary
because the old way of dealing with input coming from barcode devices
did not stop keyevents. This lead to all kinds of issues (eg. barcode
reader output being inserted as tender in a paymentline).
This new class inserts itself so that it handles all keyevents before
everything else. This means that it has authority on what keypress
events pass and which ones do not. It differentiates between 'real'
keyboard input and input coming from devices by buffering events. When a
certain amount of events come in fast enough, it is handled as a barcode
and a 'barcode_scanned' event is emitted on core.bus. When buffered
events are decided to not be a barcode, they are recreated and
redispatched.
- Several Modules have been splitted into several apps
Examples :
Human Resources : Splitted into Leaves, Recruitment, Expenses, Appraisals, Timesheets, Employees, Payroll
Marketing : Mass Mailing, Events, ...
Messaging : Chat, Agenda, Notes, Address Book, ...
- Generally, the related reports have been moved in the apps, as last menu
- Also, configuration menu (no_one group) have been moved into a config root menu
exception made for the warehouse and lunch modules
- Configuration for typical frontend modules have been moved into the website settings
Related modules : Ecommerce, blog, slides, forum
- When they are present, menus like 'product' or 'customers' have been moved
ex : Customers in Sales menu, Product in POS menu
- A lot of sequences and xmlids have been added or modified in this commit
- List of apps :
1 Chat : Inbox, Channels
2 Agenda : Calendar
3 Notes
4 Address Book : The view contact is still laying in the mail module (1 app => 2 icons)
5 eCommerce : Still to define : Config + Orders Analysis + Shipping + incoming Amazon module
6 Sales : Dashboard (Sales Team Kanban), CRM, Sales (note that they are splitted into 2 submenus)
Assignation, After-Sales (Invoicing and Services), Reports
7 Point of Sale : Dashboard (POS status), Orders, Reports
8 Project : Dashboard (Project Kanban), Search (all tasks, issues), Incoming Forecasts module, Reports
Project.issue.version feature has been removed completely
9 Members : Dashboard (Members Kanban), Report, Config
10 Timesheets : Time Tracking, Approvals, Reports
11 Purchase : Purchase, Control (Products and Bills)
12 Warehouse : Dashboard (Warehouse Kanban), Operations, Inventory Control, Schedulers, Configuration
13 Manufacturing : Same menu structure
14 Mass Mailing : Mailings, Campaigns, Reports
15 Events : Events, Reports
16 Lead Automation : Campaigns, Reports
17 Surveys : Surveys, Reports
18 Human Resources : Dashboard (Departments Kanban), Employees, Contracts, Engagement (Gamification)
19 Recruitment : Job Positions, Applications, Resumes & Letters, Reports
20 Expenses : Expenses, Approvals, Reports
21 Leaves : My Leaves, Approvals, Reports
22 Appraisals : Appraisals, Interview, Reports --> Will probably be modified by the incoming refactoring
23 Payroll : Current Menu
24 Lunch : My Lunch, Manager, Configuration
25 Accounting : Same menus currently, waiting the new accounting to be merged
26 Fleet : Current menu
27 Sign : Incoming docusign module
28 No root menuitem with this sequence
29 Attendance : Attendance, Reports
Sign in/out by project feature has been removed completely
30 Link Tracker (group_no_one) : Link Tracker, UTMs
New view added : URL Shortner, which is the frontend view embedded in backend
31 Versionning : Website domain, Versions, Experiments
32 Slides (group_no_one) : Channels, Categories, Slides, Tags
33 No root menu item with this sequence
34 Livechat : Channels, History, Reports
35 Dashboards : My Boards, Configuration
36 App Store : Local Modules, Apps, Updates
Last Settings : Incoming Dashboard Settings, Sales, ...., Website Settings
General Pattern for all modules' settings :
| Module_name
|-- Settings : General Config view (checkbox screen)
|-- Record setting 1
|-- ...
|-- Record setting n
Example for Sale module
| Sales
|-- Settings : Checkbox screen
|-- Quotations
|---- Quotation Templates
|---- Report Layout Categories
|---- Contract Template
|---- Invoice Type
|-- Contract
|---- Deduplicate Contacts
|-- Delivery
|---- Delivery Methods
|---- Delivery Pricelist