Commit Graph
332 Commits
Author SHA1 Message Date
Odoo Translation Bot e6a92e523f [I18N] Update translation terms from Transifex 2015-12-27 01:25:25 +01:00
Odoo Translation Bot 5254e31a46 [I18N] Update translation terms from Transifex 2015-12-13 01:27:04 +01:00
Odoo Translation Bot 8e7417ffa6 [I18N] Update translation terms from Transifex 2015-12-06 01:28:23 +01:00
Odoo Translation Bot 3180f80bf9 [I18N] Update translation terms from Transifex 2015-11-22 01:30:36 +01:00
Odoo Translation Bot 3d7ae73305 [I18N] Update translation terms from Transifex 2015-11-15 01:35:06 +01:00
Odoo Translation Bot 14799a9006 [I18N] Update translation terms from Transifex 2015-11-08 01:32:40 +01:00
Odoo Translation Bot e3287faee6 [I18N] Update translation terms from Transifex 2015-11-01 01:32:05 +01:00
Odoo Translation Bot 265b789e38 [I18N] Update translation terms from Transifex 2015-10-25 01:34:24 +02:00
Odoo Translation Bot 7592d85b1f [I18N] Update translation terms from Transifex 2015-10-18 01:35:07 +02:00
Jérome Maes 22631a152a [FIX] mail, website_mail : special controller for message author avatar
Previous commit (3304b31938) was not performant enough for AL, so got special autorization to make a particular controller for mail.message author avatar. Avatar of message is avaiblable if current user has 'read' access right to the document. Otherwise the default avatar is one white pixel.
2015-10-06 09:43:46 +02:00
Jérome Maes 3304b31938 [FIX] im_livechat, website_mail : message author avatar visible
To display author avatar to public user, using the /web/image url with res.partner returns the placeholder since public doesn't have access. Using the url on mail.message will display the avatar according to the access right defined on res_model/res_id of mail.message. However this executes mush query to fetch the avatar image (1 per message, against 1 per partner).

Maybe this wasn't a bug, but since it is a regression, this deserves to be fixed ...
2015-10-01 12:41:18 +02:00
Christophe Simonis 7636b510a2 [ADD] *: CSRF protection in forms and routes
* make CSRF protection the default on all non-SAFE methods
  note: there currently is no way to call a CSRF-protected endpoint
  without a form-encoded entity-body as that's the only place we get the
  CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
  generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
  the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
  the purpose of a CSRF token in the database manager screens.
  There is no request database to obtain the
  secret and generate a CSRF token.
2015-10-01 01:36:50 +02:00
Martin Trigaux e0eaaee2db [I18N] add l10n_sa and pos_cache terms + reexport
One last export before v9!
2015-09-29 14:40:59 +02:00
Jérome Maes 6bba311d8c [FIX] website_mail : force login to post comment
Transform POST param into GET param when redirecting to login page can cause security issues. Now, instead of displaying textarea (even if public user) and the redirect to login page keeping written comment, we display the login button with a redirection to the page to comment.
The redirection happen before commenting, avoiding to remenber param such comment text, rating, ...

To post a comment, the user must:
- be connected
- have a token
- or have a sha_sign
2015-09-25 16:03:49 +02:00
Jérome Maes c436c56148 Revert "[FIX] website_mail, website_sale : redirect to login page to post comment"
This reverts commit 7974bf5441.
2015-09-25 16:03:40 +02:00
Jérome Maes 7974bf5441 [FIX] website_mail, website_sale : redirect to login page to post comment
Add 'force_display' param for the frontend chatter to allow public user to see the textarea. When submitting his comment, he will be redirect to login page (like it was before generic chatter) in both mode (json and post mode). This required changing the error handeling of json mode : when a login is required, the user switch to post mode to allow http redirect, keeping its submitted params (rating, comment, ...).
2015-09-23 13:06:25 +02:00
Jérome Maes 6ed93f1770 [FIX] website_mail : prevent posting empty comment 2015-09-23 13:05:41 +02:00
Martin Trigaux 1a48daa4ce [I18N] export source terms 2015-09-21 11:46:35 +02:00
Jérome Maes f6ec21b450 [FIX] website_mail : css author avatar class, make the same in js and qweb template 2015-09-18 15:30:52 +02:00
Martin Trigaux 2e8996ce0b [I18N] add missing translations
Fetching was stopped at sale, because reasons
2015-09-15 09:30:37 +02:00
Martin Trigaux 1348fee217 [I18N] all: regenerate .pot and pull .po
How great is it to get Odoo (almost) 9.0 (almost) translated?

Clean .tx/config file
Regenerate .pot files
Fetch current translations from Transifex (10% completion)
2015-09-14 17:53:37 +02:00
Martin Trigaux 613286b0e8 [I18N] export application terms of all modules
Now that most refactoring has been merged

It is better to have red a great work of another culture in translation than never to have read it at all.
― Henry Gratton Doyle
2015-09-07 17:21:58 +02:00
Damien Bouvy 37c62282a2 [FIX] website_mail: if there is a partner linked to the user, let him write
Who's the idiot who coded this stupi... Oh. Right. Never mind.
2015-08-31 21:56:18 +02:00
Thibault Delavallée 01ab75f597 [IMP] mail: notification emails with button
Notification emails have been redesigned. They notably include buttons
allowing to perform some action directly from the email.

The notification creation and sending has been partially rewritten
and improved. The purpose is to lessen the number of rendering to perform
when sending emails to recipients. Recipients are first categorized into
groups. Basic groups are partners and users. The notification template
is then rendered twice, one for followers and one for not-followers. In most
cases there will be few rendering to perform. Through inheritance it
is possible to further categorize users. For example HR users / officers
that have approve / refuse buttons in their email.

A custom data structure is used to store data about buttons and actions.
URLs, follow / unfollow are added in the structure and used in the
template to render the email for a given group.

New routes are added in mail. Those allow to perform some action, like
going to a form in create mode, following / unfollowing, executing a method,
sending a signal for a workflow. Those routes are for users only and rely
on classic access rights.

A generic route for viewing records is added. It replaces the old redirect
action. According to some specific action given by the already-existing
get_access_action, the record will be visible for everybody (forum, blog)
or restricted (going on the Inbox / login / form view, according to access
rights).

The next commit will add the various inherits necessary to add the actions
in the main addons.
2015-08-28 17:30:42 +02:00
Christophe Simonis edeceba7df [MERGE] forward port of branch saas-6 up to 7a768a4
Due to `sale` rewrite (94716a3f14),
the commit 503820acb6 has been partially
ignored (in sale.order.line) and will be rewritten later using new-api.
2015-08-28 15:07:16 +02:00
Jérome Maes 9cc25d1c38 [IMP] website_mail : widgetize the Frontend Chatter. Prepare to include rating feature with posting mail.message 2015-08-27 09:36:35 +02:00
Denis Ledoux af07b2a075 [MERGE] forward port of branch 8.0 up to 42ecf5e 2015-08-26 14:05:17 +02:00
Martin Trigaux 6c51a80aa4 [I18N] export application terms of all modules 2015-08-25 12:01:38 +02:00
Martin Trigaux 1f57c9a5a6 [FIX] website_mail: do not reveal full email address in contact name
When subscribing a document, a partner is created based on the email address.
Instead of using the email address as the name (which is a bit too spammer
friendly), only keep the first part of the email address as a name.

Following discussion https://www.odoo.com/groups/59/13640169
2015-08-25 10:02:00 +02:00
Goffin Simon 256978195b [FIX] website_mail: action_edit_html
Introduced by 9abf7a2010
When clicking on the many2one edition button of the field "email_registration_id"  in the
"event.event" view form, the return action id was not available in the action.

closes #8147
opw:647698
2015-08-24 09:11:00 +02:00
Christophe Matthieu 6baf611df1 [IMP] web: create generic controller '/web/content' and '/web/image'
Replace deprecate controllers like /web/binary/image, /web/binary/saveas...
Use ETag for all content with 'unique' option to cache the content if the content is never changed.
2015-08-21 22:06:52 +02:00
Thibault Delavallée e6f038a821 [REF] mail: mail_thread: followers update
Followers can now be partners or channels. Partners following a document
will receive needaction, as previously. However people can follow documents
through channels. Members of a channel are able to listen to a stream
of messages using the channel. Those messages do not create needaction
messages. It is therefore possible to follow documents without receiving
too much notifications. For interesting documents subscribing with its
partner will create notification.

message_follower_ids fields is udpated. It is now a many2many to
mail.followers, not to res.partner anymore. A subscription can be either
a partner (partner_id) or a channel (channel_id).

Some access rules have been updated accordingly.
2015-08-21 12:11:56 +02:00
Yannick Tivisse 0decfd94d1 [IMP] __openerp.py__ files : remove all occurence of authors and website
where it was 'Odoo SA', 'OpenERP SA', 'OpenERP s.a.', 'OpenERP SA', 'OpenERP'
      or 'http(s)://openerp.com' or 'http(s)://www.odoo.com'
2015-08-20 16:15:59 +02:00
Odoo Translation Bot 4fcc756ef9 [I18N] Update translation terms from Transifex 2015-08-09 02:00:12 +02:00
Goffin Simon 982f713236 [FIX] website_mail: clean_for_save
Removing hidden tags could remove useful tags in the DOM
such as "br".

opw:646185
2015-08-07 16:22:05 +02:00
Damien Bouvy ad081b0da1 [IMP] website_mail: generic chatter implementation
A new generic chatter template is available in website_mail
This template allows access rights escalation when some kind of token or uuid
is available on the model or if you use the object_shasign function in the
main controller of website_maill to generate a cryptographic signature to allow
commenting on any object.

To use this chatter, you need to make a t-call to website_maill.thread in your
template after having set the following variables:
- chatter_object: the browserecord of the mail_thread object (mandatory)
- token: if you use a token system  (optional)
- token_field: name of the field that stores the token on your object  (optional)
- sha_in: if you use a shasign to allow public comment  (optional)
- nosubscribe: set False if you want the partner to be set as follower of the object  (optional)
- message_type, subtype: see message_post in mail_thread.py
2015-08-07 01:47:06 +02:00
Denis Ledoux be98d30e79 [FIX] website_mail: advanced email features button snippet colors
Due to the fact the background color was hardcoded, it
wasn't possible to edit the colors of the button link
with the website editor wysiwyg

opw-646655
2015-08-04 15:18:18 +02:00
Odoo Translation Bot 218ffc1a5a [I18N] Update translation terms from Transifex 2015-08-02 01:59:36 +02:00
Christophe Matthieu 255136a500 [FIX] website_mail: font awsome icons are loose when save mass_mailing (don't use alias) 2015-07-31 11:56:59 +02:00
Odoo Translation Bot 0871f423a3 [I18N] Update translation terms from Transifex 2015-07-19 02:01:00 +02:00
Christophe Matthieu 9687a579f4 [FIX] website: media editor don't manage the font awsome alias 2015-07-17 12:13:07 +02:00
Odoo Translation Bot 99a7d530e0 [I18N] Update translation terms from Transifex 2015-07-12 01:51:44 +02:00
Christophe Matthieu 05daa152dc [IMP] mass_mailing: move code from website_mail to mass_mailing and use web_editor 2015-07-10 17:00:12 +02:00
Christophe Matthieu 9665882fba [IMP] web_editor: adapt css, js and xml to use web_editor 2015-07-10 17:00:12 +02:00
Thibault Delavallée 2470cde0e7 [CLEAN][DEMO] mail: cleaned mail.channel demo data. Less demo groups
and a bit more messages.
2015-07-09 11:13:02 +02:00
Thibault Delavallée 2c36354ca9 [RENAME] mail, website_mail, website_mail_group, various: mail.group
model has been renamed to mail.channel to prepare the slack modeling.

In future commits the mail.group model will be merged with the channel
model from im_chat. The first move is to rename mail.group into
mail.channel to have a model that will unite both features.
2015-07-09 11:12:50 +02:00
Thibault Delavallée a316295e36 [RENAME][MOV] mail, website_mail, website_mail_group: mail.group files
renamed to mail.channel.

At this point no model has been renamed; only files have been moved.
n mail, mail_group files have been renamed to mail_channel. The
website_mail_group addon has been renamed to website_mail_channel.
Some internal references have been updated (templates, linked files).
2015-07-09 10:13:41 +02:00
Odoo Translation Bot fe3835faff [I18N] Update translation terms from Transifex 2015-07-05 01:52:32 +02:00
Thibault Delavallée c128ddf827 [FIX] website: remove unnecessary dependency from website
to mail. The only use was to update a method of publisher_warranty.contract
model that is defined in mail.

This code has been moved to the bridge module between website and mail
aka website_mail.

Dependency to share has also been removed.
2015-07-01 10:58:20 +02:00
Nicolas Lempereur 6316bce8fe [FIX] website_mail: special case for css splitting
The css of a mail is inlined as best as possible for the mail sending.

Previously, if there was a selector like .ch[onclick="ga(this,event)"]
the simple splitting would split in the middle and get one erroneous
selector (which then would trigger an error).

With his commit, rules containing " or ' are ignored.

opw-643548
2015-06-30 12:21:07 +02:00