The previous work on adding support for native JS modules needs to adapt
some existing files, which have an incompatible name (with a '/').
Also, we convert a few JS file in /web to the native JS module system,
to show that it can work.
Part of PR 63177
Co-authored-by: Simon Genin (ges) <ges@odoo.com>
Before this commit, the "Import" button was available in the
favorite menus of dialogs opened from many2one and many2many field
widgets. It makes no sense from those dialogs.
Task 2376279
closesodoo/odoo#62079
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
The German date format is the following: DD.MM.YYYY but when importing
such value, it is wrongly considered as a float value due to the '.'
being confused with the thousands separator in the regexp of method
_remove_currency_symbol.
We should check both date/time and float/monetary formats, so it will
correctly identify the German date format as well as float values.
closesodoo/odoo#62205
X-original-commit: 1bdd0cc247d36c869ffdee7d501cb65d36be47a6
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
Signed-off-by: Alex Tuyls <alt-odoo@users.noreply.github.com>
As part of QoL PR #26267 the way the recursion limit was
managed (where it is checked) was changed, effectively decreasing the
recursion limit by 1 (to the originally expected limit of 2).
According to #29877 this is an inconvenient change / regression in
e.g. accounting context: if an object has journal entries, updating a
field of a journal item requires 3 levels of indirection (entries ->
items -> field). The same would occur if an object is e.g. linked to
multiple projects (projects -> tasks -> field) or SO (-> lines ->
field).
Therefore bump the recursion limit up to 3.
Closes#29877closesodoo/odoo#61997
X-original-commit: 64ff41ce805c72eb700b45d55adfc7379de56862
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Before this commit, links to the documentation were referenced the
previous version, 13.0, instead of the current one, 14.0.
Eventhough there is a redirection done by NGINX of a "versionless" URL
to the latest one (e.g. /documentation/user/general/auth/google.html
-> /documentation/user/14.0/general/auth/google.html as of today), the
goal is to keep links owrking for users that will still be using the
14.0 in three years (and should not endup on the 17.0 doc).
closesodoo/odoo#60228
X-original-commit: 7ac08486d91d0ff0151abeeda057ffa6beda72e8
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Including demo data this time
closesodoo/odoo#58862
X-original-commit: 575abde110acb3d12b25f177a863374becef0894
Related: odoo/enterprise#13705
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Column mappings are updated in-place, if multiple users are importing records
of the same model at the same time, this will trigger concurrency errors.
This is made worse by the error only being reported on commit (after having
processed the entire import) and being retried automatically, so it slows down
the user and the entire system, the more concurrent imports the slower.
Log except:
INFO dbname odoo.addons.base_import.models.base_import: done
ERROR dbname odoo.sql_db: bad query: UPDATE "base_import_mapping" SET "field_name"='name',"write_uid"=%s,"write_date"=(now() at time zone 'UTC') WHERE id IN (%s)
ERROR: could not serialize access due to concurrent update
INFO dbname odoo.service.model: SERIALIZATION_FAILURE, retry 1/5 in 0.8720 sec...
closesodoo/odoo#57655
X-original-commit: 3f5e9ca625b53021c100245f5786bda4069974ad
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
this commit removes unnecessary uppercase used under the favorites menu
task - 2325684
closesodoo/odoo#57319
X-original-commit: 1d54564d280d23b506e3764294318a359c0ad681
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
Adaptation of the rest of the environment to the changes regarding the
refactored search panel and model.
This commit includes the following changes:
- Since the control panel model is now part of the search model, the
view widget is responsible of its instantiation with the appropriate
API; creating an ActionModel holding the required model extensions.
- The controller is now importing/exporting the state of the entire
search model as well as the current state of the search panel (given
throught its props). Changes have been made to adapt to this behaviour.
- The multiple components linked to the control panel model have been
adapted to reflect the changes brought to it (they will now listen to
the "searchModel" instead of the "controlPanelModel").
- The `test_utils_create` methods have also been adapted to properly
instantiate a searchModel
Part of task 2228968
Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Mathieu Duckerts-Antoine <dam@odoo.com>
Issue
Chrome
- Sales > Product
- Select a file
- Change something in the file
- Re-select it
Nothing changed
Cause
Chrome doesn't trigger change on
input if the file is the same
Solution
Clear the input value after the
parse_preview so we can load a new
file even if the preview failed.
OPW-2288191
closesodoo/odoo#54175
X-original-commit: f7d2bdf65901e3ee78e1055cab7cf8d60f798621
Signed-off-by: Jason Van Malder (jvm) <jvm@odoo.com>
This commit fixes all issues detected by the new pylint
gettext-variable test.
It converts some calls to the new syntax
_("Foo %s", bar)
to progressively migrate the code to the new syntax.
A few calls were not technically incorrect but still detected by the
linter.
_("Foo" +
"Bar")
has been converted to
_("Foo"
"Bar")
as it has the same effect and make sure the argument is of type
asteroid.Const instead of BinOp).
closesodoo/odoo#53683
Related: odoo/enterprise#11467
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
Using a few regex like
\((_\(.*%s.*)(\) % )([\w\[\]][\w .\[\]\(\)'"]*)\)
($1, $3))
Old syntax is still compatible but starts the migration to the new
syntax that catches error.
The *Reload File* import functionality stands on an undefined behavior
or the HTML File API. The API is not clear about what should done in
case the underlying file change on the filesystem after it has been
imported in the browser.
It turns out the actual behavior vary among browsers and even among
OSes. The *Reload File* button only works as intended when importing
files via Chrome on Linux.
In other cases, the browser may refuse to send the file or may send it
in a corrupted HTTP request. Such malformed request is rejected in the
best cases by the backend web application but there is chance it hangs.
Security-wise, this problem is not much likely to happen as it requires
an authenticated user with importation privileges to perform the
operation. When it comes to the severity, it is possible to exhaust the
available workers by forcing every one of them to hang.
As there is a security impact, we decided to disable the *Reload File*
functionality.
Steps to reproduce
------------------
1) Import a CSV or XLSX document in any model.
2) Wait for the data visualization to come back to the browser.
3) Change the file on disk to
a) remove a few lines
b) add a few more lines.
4) Click the Reload button.
Wrong `size` attribute on Firefox.
----------------------------------
Impact: Firefox
The advertised `Content-Length` HTTP header in the POST request is
a) *greater* than the actual body length. The backend web application
hangs on a `socket.recv` like function waiting for those missing
bytes.
b) *smaller* than the actual body length. The request is truncated
and futher processing is impossible.
The malformed request should have been detected and reported by the http
web application as requested by the HTTP/1.1 spec [1]:
> When a Content-Length is given in a message where a message-body is
allowed, its field value MUST exactly match the number of OCTETs in
the message-body. HTTP/1.1 user agents MUST notify the user when an
invalid length is received and detected.
Mitigating the issue is possible using nginx as reverse-proxy. The
connection is closed after one minute if data are missing.
Invalid `ERR_UPLOAD_FILE_CHANGED`
---------------------------------
Impact: Chrome on Windows
Chrome prevent sending the XHR due to a `ERR_UPLOAD_FILE_CHANGED` error,
this error should only happens when the underlying file content have
been changed the second before the request. On Windows, the error
is triggered as soon as the file have been changed, not considering the
modification time.
[1]: https://www.w3.org/Protocols/rfc2616/rfc2616-sec4.html Section 4.4
opw-2252440
closesodoo/odoo#52276
X-original-commit: 30be09cdb7d5b80fb1e0221f58024586bd72ac61
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Signed-off-by: Julien Castiaux <Julien00859@users.noreply.github.com>
Purpose
=======
The current kanban view is messy. It is difficult to identify which
apps are installed or not. The user can completely miss a module
that might have interested him. A search panel would make things way
more readable.
closesodoo/odoo#44401
Taskid: 2181557
Related: odoo/enterprise#8144
Related: odoo/upgrade#879
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
Following changes needing ir.model.access on transient models too.
Remove groups declaration on the action to move it to ir.model.access
when possible.
Rules are strict by default with no unlink access by default and high
priviledge asked. Adaptations may be needed later.
Write access is given as a wizard may need to be modified in case the
action triggers an error and the user has to correct a value
account*: use account.group_account_user for all transient by default
remove account.print.journal relic
stock*: use stock.group_stock_user by default
survey: survey user can send invitations
mail: allow any employee to execute wizards
additional verifications are made to ensure they are executed
only on the documents the user has access to you
give portal access to mail.compose.message as portal still does
some actions like posting messages on the forum
add ir.rule to avoid reading somebody else messages
increase the query count because of undeterminist count
crm: saleman for lead2opp, manager for massmailing
partner manager for actions linked to partners
avoid a write in test_lead_lost
sms: any employee can send sms
mrp: mrp user can execute wizards
give unlink access as making write during do_produce operation
base_import: employees can import files
delivery: stock user can deliver
event_sale: sale user can configure the wizards
event user inherit from sale rights
gamification: employee can give badge
google_service: resolve FIXME
hr: add specific rights
manager can set a plan according to group on button
anyone who can write on an employee can register a departure
hr_expense: set rights based on buttons
hr_holidays: an approver can make a summary report
hr_recruitment: recruiter can refuse a candidate
hr_timesheet: can use the wizard if can create a timesheet
l10n_eu_service: managers can create fiscal positions
mass_mailing: same group as on mass.mailing.list
membership: accountant can create invoice from membership
payment: accountant can create a link
as the source is an account.move
keep the payment.acquirer.onboarding.wizard to system user
only as it is called during company configuration
point_of_sale: PoS manager only can use wizards
never create closing_balance_confirm_wizard records
product_expiry: stock user has rights on stock.picking
product_margin: access from accounting menus
repair: same rules as for above models
sale: set ir.rule for self wizard only
add rule from model introduced in payment to add salesman group
sale_crm: saleman can create a quotation from a lead
sale_coupon: any saleman can generate coupon
add self ir.rule
sale_product_configurator: salesman can select product variants
snailmail: employee can send letters
website: designers can write on website
website_crm_partner_assign: same rule as group on action
website_sale: sale ACL as for payment.acquirer.onboarding.wizard
website_slides: anyone can send invitation
base: base.language.*: allow employee (cf lang_install)
change.password.user: can not read change password wizard of
other users
test.*: no access is needed
Courtesy of Damien Bouvy, William Andre and Antoine Prieëls for review
of acl
Steps to reproduce:
-install sales
-try to import a product file with volumes set to scientific notation
(9.2e-05 for example)
Previous behavior:
scientific notation is not recognized by the base_import module
and raises a small warning
Current behavior:
scientific notation is converted to decimal notation on the fly
when possible
opw-2162353
closesodoo/odoo#42591
X-original-commit: 9acd76c5d116abd07207af3b548658ad983ff82d
Signed-off-by: Jorge Pinna Puissant (jpp) <jpp@odoo.com>
Without demo data, for the odoo-master transifex project
closesodoo/odoo#41935
X-original-commit: dab7670b73506fb3a835695ee3bd735e0c5e5c2b
Related: odoo/enterprise#7287
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Followup of a425695e
The terms were back in 12.0
Courtesy of Juan José Scarafía
closesodoo/odoo#41624
X-original-commit: 85d0c7001a997748d7691205bbb8d066597591a5
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Excel can store data in multiple tables, each is called a sheet. Odoo
was only importing the first sheet making the process to import a file
containing multiple sheets cumbersome.
It is now possible to select the sheet in the import options. By default
the first sheet is selected.
closesodoo/odoo#40728
Task: 2043768
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Test import of a file with xml ids.
At the first dry run, the xml id X is associated with id R for each such record.
If some records refer to X via a relational field, then in SQL it reduces
to a query using R as id; but R does not exist since it was a dry run.
As a result, subsequent runs fail.
The cache should be cleared after a dry run, since the xml ids are not reliable.
opw 2068446
closesodoo/odoo#37396
X-original-commit: 1b35294d7b8d07f373eca24977e2952b9cfb2c7d
Signed-off-by: Nans Lefebvre (len) <len@odoo.com>
* If the item is not an acceptable URL, check if it's base64 and
return an error if it's not, otherwise it just ends up blowing later
when the content of the field is assumed to be base64 and explodes
* The URL having to contain png or jpg or tiff or gif or bmp doesn't
make much sense (especially in this modern world where
placekitten.com doesn't add extensions, not to mention this doesn't
actually check for extensions). After discussing with odo it doesn't
seem to have any security impact, the only thing this filter does is
annoy people for no reason.
various UI changes
------------------
* renamed "test import" button to "test"
* move relation fields thing to debug mode
* remove "Defer parent/child computation" option as it was deprecated
/ removed from the backend in
80f1ac3599, turns out this checkbox
existed inactive for longer than it's been of any use (added in
68cb2ade09 on 2017-11-29, made
non-operating on 2018-01-24, that's so sad)
batching
--------
* add support for batching imports (skip & limit parameters)
* modify client to use batched imports & properly adapt responses so
it still looks like a single import for the client (more or less)
e.g. update row numbers in error messages, etc...
* properly handle partial imports though
* disable usual loading throbber to have a single progress
notification displayed continuously throughout all the batches: the
normal throbber only shows after 3s of waiting for an RPC response,
so it would keep flashing in and out (appear 3s into a batch's
import then disappear at the end only to reappear 3s into the next
batch's loading)
NOTE: the limit is row-wise. If a record straddles the limit (because
of nested O2M records), the record is imported in full and the "next
row" is whatever row follows the record. This means a limit of 10 can
lead to an import of 17 lines, and as the progress indicator is in
records# the increments can jump around.
Task 2059448
Slovenian language, as many others languages, is not present in the
beta/master projects in Transifex.
For some reason, Transiflex removed all current translations, this was
already fixed in 12, but as there are not automatic forward-port for
translations, this is a manual forward-port.
opw-2060055
closesodoo/odoo#36374
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>