Commit Graph
100007 Commits
Author SHA1 Message Date
Xavier Morel 8595bc2ff7 [IMP] csrf: better warning and documentation
After initial implementation CSRF protection had been left poorly
documented tripping up users and developers (#9538, #10139).

Add a warning in the logs for developers, and a more extensive
explanation of the whole thing in the @route docstring (and the official
documentation).

Fixes #10158
2015-12-21 13:10:45 +01:00
Xavier Morel f839c9358a [FIX] sudo() docstring
rST uses double-backticks for literal text, not single
2015-12-21 12:34:53 +01:00
Odoo Translation Bot 9e211ef127 [I18N] Update translation terms from Transifex 2015-12-20 01:26:02 +01:00
Jeremy Kersten 73c4c727d2 [FIX] website_crm: allow to prefill data from get params
Allow to arrive on the form with fields prefilled with params in url
2015-12-18 17:38:02 +01:00
Raphael Collet 34e3c66c7c [MERGE] yaml_import: fix calls to onchange() and sanitize returned values
Merge branch '9.0-opw-657357-rco' into 9.0
2015-12-18 16:53:13 +01:00
Raphael Collet 151118daf8 [FIX] resource: add missing field in resource.calendar.attendance form view 2015-12-18 16:51:52 +01:00
Raphael Collet ab4de2a453 [FIX] stock, stock_calendar: fix duplicate names of pickings in test files 2015-12-18 16:51:52 +01:00
Raphael Collet 8325014b63 [FIX] models: when evaluating old-API onchanges, ensure all fields are available 2015-12-18 16:51:52 +01:00
Raphael Collet 882bbf46e2 [FIX] models: in onchange, add missing fields when comparing values 2015-12-18 16:51:52 +01:00
Raphael Collet 36ee1ad813 [FIX] yaml_import: add field_parent in context for evaluating onchange on one2many lines 2015-12-18 16:51:52 +01:00
Raphael Collet f4a6f1bfde [FIX] yaml_import: use form views instead of tree views for cleaning up 2many field values 2015-12-18 16:51:52 +01:00
Raphael Collet 0b6058c585 [IMP] yaml_import: evaluate onchange on defaults first 2015-12-18 16:51:52 +01:00
Raphael Collet b96759ca07 [FIX] yaml_import: make post_process filter out readonly fields recursively 2015-12-18 16:51:51 +01:00
Raphael Collet d412203f4a [FIX] yaml_import: make process_vals sanitize field values recursively 2015-12-18 16:51:51 +01:00
Raphael Collet 3cd85bdeef [IMP] yaml_import: introduce and clean up helper functions 2015-12-18 16:51:51 +01:00
Raphael Collet 44240c0c4a [IMP] yaml_import: simplify algorithm for iterating over field elements 2015-12-18 16:51:51 +01:00
Raphael Collet 7056b5cb2a [IMP] yaml_import: small code improvements 2015-12-18 16:51:51 +01:00
Raphael Collet a751377760 [IMP] yaml_import: use method onchange() only to execute onchanges 2015-12-18 16:51:51 +01:00
Martin Trigaux 7892d99f3a [FIX] all: references to Odoo 8.0 version
In installation script or documentation

Fixes #10052
2015-12-18 15:06:46 +01:00
Xavier Morel d1dea6119f [IMP] base_import: add FAQ entry about CSV date formats
task 21446
2015-12-18 14:42:54 +01:00
Goffin Simon 513497dc03 [FIX] account: Invoice Date group_by
The default group_by for 'Date Invoice' in 'account.invoice.select'
view must group the 'account.invoice' with the field 'date_invoice'.

opw:660033
2015-12-18 13:48:57 +01:00
Thibault Delavallée 52e18acbc8 [FIX] mail: res_users: context update in create
Context was a new one instead of updating the existing one. This was
preventing a correct context propagation.
2015-12-18 13:30:13 +01:00
Nicolas Lempereur df2d0c4f10 [IMP] crm: add margin next activity 2015-12-18 12:38:42 +01:00
Goffin Simon 46399ec237 [FIX] product: name_get
When a product is linked to several "supplier.info" records with
the same name or same product_name, the name or product must only
appear once.

opw:660107
2015-12-18 11:50:19 +01:00
Denis Ledoux c3489b66bf [FIX] sale: deposit product auto creation as sudo
By default, users can only create/edit/unlink
personal `ir.values`, the values with themself as
`user_id`.

Setting the default `deposit_product_id` should
therefore be done as sudo in case if the `deposit_product_id`
default value has already been created before by another user
but is no longer valid.

opw-660180
2015-12-18 10:52:22 +01:00
Denis Ledoux a678bd4e92 [FIX] project: needaction icon to fa-comments
To be consistent with the needaction icon
already used in the tasks/issues kanban view
2015-12-18 10:26:38 +01:00
Olivier Dony fde3a529ba [FIX] sale_timesheet: no product on timesheet line
Timesheet lines are meant to have no product, and instead rely
on an implicit "Service" product. The UoM used is the company's
project UOM (project_time_mode_id), and the nominal cost of this
product is set on each employee.

Forcefully using the SO product as was done before is useless
and actually caused inconsistencies. The `unit_amount` value
would be expected in the UoM of the SO product, while still
being computed/set in the company's project UoM.

When no nominal cost can be found for an employee, the cost is
assumed to be 0, so the `amount` value is 0 too.

In addition, the product field is not supposed to be visible on
any form where timesheet lines are recorded.

This patch fixes various bits of logic related to this, including
parts which expected the `amount` value to be non-zero, or
the product to be set.
2015-12-18 10:12:53 +01:00
Olivier Dony 6579fc2d49 [FIX] account: fiscal position computation precedence
Zip range and state filtering were added at
377a6ecab0, but the
precedence between country, group, vat_required,
and not required were not correct.

This commit fixes the precedence as follows and adds
the corresponding tests:

 0. Explict position on partner
 1. Direct match on all criterions
 2. Match on country+zip before country+state
 3. Match on country before country group
 4. Match on `vat_required` criterion on all
    the above before trying them all again without
2015-12-18 10:12:53 +01:00
Martin Trigaux 3d688e95c9 [FIX] account: duplicated key
Where do you come from?
2015-12-18 09:54:19 +01:00
Martin Trigaux 57e93f49e5 [FIX] account: missing labels on some fields
And reexport some missign terms
2015-12-17 15:17:49 +01:00
Denis Ledoux 7be2403cf5 [FIX] website_quote: condition to display the Pay Now button
Before this revision, the button "Pay now" on the quotation
in the frond-end was display only if the sale order
was in the state `manual` and that there was not
yet any payment transaction.

The thing is, since the release of 9.0,
the `manual`state no longer exists in `sale.order`,
and the pay now button was therefore never displayed.

From this revision, the condition to display the button
is based on the `invoice_status`, which need to be `to_invoice`,
meaning there is something to pay:
 - The sale.order needs to be in states `sale` or `done`
 - At least one line has to be invoiced:
   - If the product has the `invoice_policy` set to `order`
   - or if the product has the 'invoice_policy` set to `delivery`,
     and at least one quantity has been delivered.

opw-659931
2015-12-17 14:40:37 +01:00
sha-odoo 2f106aa5ac [FIX] sale-crm: default filters for stats button
As the stat button "Quotes(s)" counts Quotations only (draft SO),
and the stat button "Orders" sum the total of Sales orders only (confirmed SO),
clicking on the buttons should open the SO list with the according filters
set.

Closes #9715
opw-660041
2015-12-17 12:36:07 +01:00
sha-odoo a2e12b7a14 [FIX] crm_project_issue: remove unnecessary context from xmlid_to_res_id
Regression introduced with 3e8727e2aa
opw-654063
2015-12-17 12:21:29 +01:00
Denis Ledoux 2f4382f4b4 [FIX] ir_qweb: translatable fields
This revision is related to 5257721

`record._columns` doesn't contain all record fields,
computed non-stored fields are not included in `_columns`,

Therefore, when a computed non-stored field was used in the QWeb xml,
this crashed with a Keyerror exception.

Using `_fields` solves this issue. Nevertheless, translate
is not always set, but is set when the fields is indeed translatable,
so the use of `getattr` was required.

opw-660072
2015-12-17 11:29:09 +01:00
Goffin Simon c090d9992a [FIX] analytic: _default_user
The "user_id" linked to the employee_id set on the sheet must be used
when editing a sheet.

opw:659647
2015-12-16 16:48:20 +01:00
Aaron Bohy 9cbab8a04b [FIX] bus: bus_check_disconnect_cron xml_id
Copy-paste error...
2015-12-16 16:31:08 +01:00
Aaron Bohy 5d1b3232fc [FIX] bus,mail: user presence
Before this rev., no notification was sent on the bus when the user presence
changed. Thus, the bullets displayed in Discuss were never updated and stayed
as they were on the initialilization of the chat_manager (on webclient launch).

This rev. makes the bus.presence notifications work, and handles them client
side.

Moreover, the disconnections detection is now performed at each poll (with a
maximum of 1 per minute), instead of randomly (1/100 chance) at each poll, as
it scales better than the former solution. We also added a cron that performs
this check every 5 minutes. It is needed to detect that the last connected user
just disconnected (useful for visitors in the website, trying to talk with a
livechat operator).

Also, the 'away' status is now handled client side, as it makes more sense
that way (being away at each poll, e.g. every 50seconds, during 10 minutes
doesn't mean that we didn't come back between two polls).

Finaly, in bus.js, CrossTabBus, we moved the code writing in/reading the local
storage after the tab registration as this code depends on the fact that the
tab is the master tab or not (and this is known only once the tab is
registered).

This rev. was necessary in stable because the livechat uses the user status to
detect if there is an operator available, and this was often inaccurate.
Moreover, it improves the user experience of the chat in the backend.
2015-12-16 15:48:43 +01:00
Aaron Bohy 89ba0a811b [FIX] mail: traceback on new msg in unpinned closed livechat
The traceback ocurred when the operator closed a livechat channel chat window,
and then unpinned it from the sidebar in Discuss. Then, if the visitor sent
him a message, the channel was automatically re-pinned to the operator, who
received two notifications: the first one being the new channel info and the
second one the message itself.

The channel fold_state being 'closed', the window manager was trying to close
it again, which produces the traceback as the channel didn't exist in the JS
cache anymore (it was re-added to the cache when processing the message
notification, so just after).

Anyway, closing this channel was useless as, even if it was in the cache, it
would already been closed. So this rev. simply checks whether or not the
channel is in the cache before trying to close it.
2015-12-16 15:48:43 +01:00
Aaron Bohy c58c8f4bd2 [FIX] im_livechat: use correct url to find rules that apply
The problem was that, when calling 'match_rules()' from the loader template,
we compared the wrong url with the url regexp defined in rules. Indeed, we used
the url of the page we were leaving, not the one we were going to.

We thus need to know if we are coming from the controller, or from the loader
template directly as the way to get the correct url differs.

Courtesy of JEM
2015-12-16 15:48:43 +01:00
Aaron Bohy 0c92788d88 [FIX] im_livechat: various fixes
- use channel configuration for the auto_popup
- clear auto_popup timeout when chat open to prevent opening the chat twice
  if the user opens it himself before the end of the timeout
- don't send message when no feedback given
2015-12-16 15:48:43 +01:00
Aaron Bohy 2b99a36921 [FIX] mail: sent messages are plaintext
The problem was that users couldn't write characters like <, > in their
messages because the messages are html (e.g. '3 < 5' resulted in '3' because
this wasn't html valid so the second part was trimmed).

Because of mentions, we can't force messages to be plaintext (mentions are
processed and replaced by html links before the message is stored in DB).

The solution is to escape them just before processing the mentions. In the case
of chat windows, we must be careful because chat windows are also used for the
livechat, for which messages are plaintext. So the escaping should be done for
chat windows in the backend, but not in the livechat.
2015-12-16 15:48:42 +01:00
Aaron Bohy f5e4fbb20c [FIX] mail: correctly redirect to channels
Clicking on a channel link should open that channel in Discuss, not the channel
form view.
2015-12-16 15:48:42 +01:00
Raphael Collet 1fb0136f5a [FIX] fields: in onchange, do not serialize the inverse field of a one2many 2015-12-16 15:39:15 +01:00
vnsoft 4b635a1da7 [FIX] report: barcode controller: correct humanreadable handling
humanreadble arg comes as a string, so bool(0) was True. Cast it to int before.
2015-12-16 14:48:25 +01:00
Cedric Snauwaert 47359af3af [FIX] account: when doing a reconciliation from journal items, amount was rounded with incorrect precision 2015-12-16 14:44:03 +01:00
Nicolas Lempereur b9520e22e9 [IMP] web: m2m_tags support _rec_name != 'name'
Currently, the m2m tags widget would only display the name present in
the "name" field. This prevent them from being used with custom
fields/models and other niceties.

opw-658490
2015-12-16 12:03:43 +01:00
Denis Ledoux cb9d7982c1 [FIX] payment, website_sale: condition to recreate a payment transaction
Before this revision, in the ecommerce,
a new payment transaction was created only
when the transaction reference was different than
the order number, meaning that the transaction id
in the user session no longer refers to the current order,
that the user created a new order which has nothing
to do with the transaction he has in his session
variable `sale_transaction_id`

This made sense when the transaction reference
strictly matched the order number, but,
since f89e8f9df2,
this is possible that a payment transaction reference
number no longer strictly matches its order number,
as the transaction reference can contain `-1`, `-2`
at the end of its reference, meaning there was
already another transaction existing with the sale
order number as reference. But the transaction
is still about this order.

Therefore, from this revision, the condition on
which a new transaction has to be created
should no longer be based on the transaction
reference, but to which `sale_order_id` the transaction belongs.

In addition, we add two more conditions for which a new transaction
should be created:
 - The transaction has been cancelled or in error
 - The acquirer has changed.

For the second case, this is to handle a corner case:
 - The user selects one payment acquirer (Ogone), then click
   on "Pay now", and is therefore redirected to the payment provider website (Ogone)
 - Then, the user opens a new browser tab on the ecommerce, on his cart,
   choose another payment provider (Paypal), then click "Pay now" and is
   redirected to this second payment provider website  (Paypal),
 - Then, the user comes back on the first tab, on which he is on the first
   provider website (ogone), and pays/validate the payment
 - Then, we receive the payment feedback (either from the user/DPN, either from
   the server to server call/IPN)

Before this revision, this use case would have lead to the feedback from the first
provider (`/payment/ogone/accept`) while the transaction is set with the second
payment provider (`Paypal`), therefore breaking the payment validation.

Creating a new transaction when the user changes of payment provider solves this issue.
He will nevertheless be able to pay twice, on each provider, but it was
already the case before.

opw-659294
2015-12-15 18:31:12 +01:00
Olivier Dony b4949f757c Revert "[FIX] web: Can't save a x2m in list editable if contains a m2m_tags with a color field"
Reverted because it causes issue #10083 when serializing
nexted x2many values, and produces invalid x2many commands,
such as:

    `[[6, false, [[5, false, false], [6, false, [8]]]]]`

Pending a proper fix for the oririginal issue.

This reverts commit 7e2628aeb2.

Closes #10083
2015-12-15 17:55:35 +01:00
David Monjoie fda5021e6b [FIX] mass_mailing: added missing models in form view
In 9.0, we created a simplified form view for mail templates, in
which the model_id field is retricted to show only the models for
which mass mailing makes sense. However, two of those models were
forgotten. There should have been some sort of override in their
respective modules, but considering the nature of the domain
attributes, there is no easy way to write such overrides, which is
probably why there wasn't any override to begin with. We decided
with tde and al to just add these models in mass_mailing, thus
breaking module abstraction, but avoiding a very complex override
mechanism for a rather simple case like this.
2015-12-15 15:20:27 +01:00
Goffin Simon cd5638ef46 [FIX] purchase: _default_picking_type
The function "_default_picking_type" must return a browse record.
2015-12-15 13:38:28 +01:00