The `binay_image` and `content_disposition` are moved
from the web controller to the `ir.http` model,
to be able to override these methods.
This makes possible to browse the records images as sudo
when the record is published on the website.
e.g. to see the partner images on the website `/partners` page
from the `website_crm_partner_assign` module.
opw-659244
The method that set `geoip` in the session, `_geoip_resolve`,
is called just before `self._authenticate`, which logout the user
when the session is invalid, and therefore reset the session.
Therefore, `geoip` could not be in the session in that place.
This isn't that bad, as, at the next request, the `geoip` will be
correctly set in the session.
During the analysis of this issue, we observed that the reset
of the session is actually not saved, because the save
of this session is done in `Root.get_response`, through the call
`self.session_store.save(httprequest.session)`,
but `Root.get_response` is not called in `Root.dispatch` in case
of HTTPException (500 internal server error in this case).
This might need to be changed, to do the session save with a finally
in this `Root.dispatch` method, so the above bug could have been
resolved with a simple refresh (which would have re-defined the
`geoip` in the session).
opw-650416
- remove useless cache clear_prefix
- add a route cache attribute when used it will save the rendered page into the
ormcache for the specified time, this is only enabled if the user is public
and reponse code is 200
- enable it on /page controller for 5min
Improves aea358ca67 and avoid spurious
redirects for URLs that do not match a controller but do not
have a valid language.
When the URL does not match any controller, the language
matcher tried to strip the leading path component, treating
it as a language code. For example:
/fr_BE/page/homepage
would not match any route, so it would be rerouted internally
as /page/homepage, after setting `request.lang` to fr_BE.
This breaks the magical 404 handler that allows ir.attachment
entries to be mapped to static URLs. Due to the internal rerouting,
the mapping of e.g. /website_mycompany/static/src/image/logo.png
would be rerouted to /static/src/image/logo.png and not match
the mapped URL anymore.
Now the stripping of the path component will only occur if
that path component matches an installed language code.
The consequence is that URLs containing uninstalled language codes
will now lead to 404 errors - an acceptable trade-off (e.g.
when an older version of the website is still indexed by a search
engine)
Redirect odoo.com/page//contactus ==> odoo.com/page/contactus
(only for get method)
Apache don't redirect but search for route with only one slash...
For SEO optimization, Odoo force a redirect permanently
The extra auth blows an environment and causes an extra query
of ``website`` before calling the controller.
The preceding two SQL queries likely can't be avoided: one uses uid1 to fetch
the current website's public user in order to set it, the other one
fetches the current website using the user set beforehand
Detect most of bots/crawlers to avoid auto redirect. Most bots fetch
with lang en_US, so even if default website lang was not in en_US,
googlebot was redirected to en_US page.
Now we keep also the language selected by user into a cookie.
If cookie exists but lang not in url, we redirect the user into
his preferred language.
Manage special case to allow to change the lang in url to set the
default lang at fly in url and set the cookie...
Many routes are not specified as multilang=False but should be.
With the auto redirection, we need to update these routes to avoid
useless redirects !
The implementation of ormcache does not work on methods that take a context
parameter. Because of the decorator decorator, the arguments of the call are
passed positionally to the method ormcache.lookup, and positional arguments
are used in the cache key.
The fix consists in removing the context parameter from the faulty methods,
either directly, or by caching a private method called by the public method.
Commit 540b753bf8 introduced
support for resources stored as ir.attachment records in
asset bundles too.
This is specifically useful for customizations.
However the HTTP route for reaching those resources
when they are *not* in a bundle was originally created
in the `website` module (as a special handling for
404 requests)
This means that these dynamic resources would only
be partially supported when `website` is not installed,
causing various problems:
- missing resources in debug mode where bundles are skipped
- errors when trying to define new client-side Qweb templates
via XML resources - which are loaded with a direct request
- ...
This commit moves back the supporting code to the web module.
The `mimetype` column is not present in ir.attachment without
the `website` module, but sniffing it based on the attachment
name works fine at serving time too.
Closes#6002