The backend assets includes a list of the installed modules with:
```
odoo._modules = <t t-raw="get_modules_order()"/>;
```
Because of the randomization of Python 3.5 in the dict keys,
the order of the installed modules could change from time to
time, therefore making the assets being regenerated unnecessarily
This revision is a bit linked to the below one:
f3bb9ae679
In addition to have the dict keys always in the same
order, it's important for the values to always be
the same, and it was not the case for this list
which was in the content of the backend assets,
in various order.
opw-804747
* In Python 3 xlwt apparently does not support writing bytes values ->
try to decode assuming the value may be base64-encoded, this is more
or less the behaviour for CSV exports.
This will most likely not allow the export anyway as Excel cells are
limited to 32k data characters, which accounting for base64
expansion means ~24k worth of data, but that is a pre-existing
issue.
* Also removed support for way outdated browsers from
content_disposition: the Safari case is for Safari 5 (circa 2012)
but versioning apparently changed since then and modern Safari
report their "external" version number rather than the webkit
version number => the current Safari reports version 11, and gets
routed to the "does not support unicode file names", which is
further bugged in Python 3 as it %s's bytes, leading to a resulting
filename of e.g. `b'res.partner.csv'.csv` (with the prefix and
quotes).
* The IE case is for IE8, which has long been unsupported by the web
client.
This rev. introduces a new test suite meant to test the webclient
components on mobile devices. The key 'config.device.isMobile' is
forced to true in this test suite, so that mobile specific JS files
are properly executed, which isn't the case in the classic JS test
suite (setting isMobile to true in the test definition is too late,
as the JS files are already processed).
For now, this new test suite contains a single test, which was
skipped until this rev. as it couldn't be executed in the classical
JS test suite.
Both suites are executed at each build of the runbot, and they
can be manually executed from the webclient as well (via the debug
manager).
I don't quite get how it can trigger on user systems (as it apparently
requires resetlocale() to fail to set up an UTF-8-encoded-locale
somehow, disabling resetlocale() is how I could get the issue
triggered on my system), but anyway it's apparently possible for Odoo
to run with an ASCII system encoding, and it turns out Python 3 will
not use UTF-8 everywhere but will rather use whatever
locale.getpreferredencoding(False) yields, which in theory could be
completely bonkers.
This is an issue when using text IO with an implicit encoding, which
is what load_locale (/web/webclient/locale/<lang>) was doing.
* Fix by using binary IO
* Fix (2) by using direct-passthrough IO with specified encoding, that
way we let the WSGI server handle the file streaming
Fixes#20075
- The `--no-database-list` option will now also block access to database
management functions and screens.
Presumably this flag should only be used in production when all
databases have been provisioned, so the admin should like to block
access to the db manager at the same time.
- If no `--database` or `-d` parameter is provided, the system will be
unable to fetch a list of databases at all, so users will be blocked
with an error message.
- Hide the link on the login screen to the DB manager when it is
disabled, to prevent sending users to an error page.
- Weak attempt at updating the documentation
Note: the security check for RPC methods could have been done in the RPC
dispatcher, however that would not have protected service methods when
called directly, e.g. by a controller (e.g. the dump method).
- Add support for hashed master passwords (super-admin password) using a
strong scheme (PBKDF2_SHA512).
- Replace the password with a hash in memory (tools.config map), after
verifying it
- Automatically replace the plaintext master password with a hash when
saving it after a password change
- Preserve support for setting/using plaintext passwords when necessary
(e.g. as a temporary deployment thing)
Don't add useless routes or route that will return 404.
Improve generate function from ModelConverter to have a better management of
query_string.
Now we have an helper sitemap_qs2dom that will analyse the current route and
check if query string is plausible and if yes, generate a domain, when the
query_string don't seems to match the route, we return a Falsy domain.
Before this commit, if qs was /product/ipad, enumerate_page check for each
modelconverter of the route a name ilike '/product/ipad'.
Now we check all routes that contains product and one converter that match ipad
or routes that contains ipad and one converter that match product.
This commit a new way to declare the sitemap for a route.
def sitemap_xx(env, rule, query_string):
yield {'loc': '/my_url'}
@http.route(..., sitemap=sitemap_xx)
In this case, only the loc returned by this function will be in the sitemap
for all rules.
You can pass sitempa=False, if you don't want that route are into the sitemap
Introduce a new attachment field (access_token) to allow external
unauthenticated access. This will be an opaque unique number
(typically a UUID) that should be provided via an appropriate
controller, for unauthenticated display.
The field is intended to be NULL unless unauthenticated access has been
allowed, in which case a value will be set for the access_token.
This could be used e.g. for allowing access to images within mailings,
even when the recipient is not logged in (which is sometimes entirely
impossible, when email providers use restricted proxy servers to
load images)
Note 1: this is still a work-in-progress, but serves to freeze the API.
The implementation of the access check and provisioning of the new
field will be added later.
Note 2: namimg collisions with the file download token prevent the use
of a shorter 'token' parameter for download routes.
Apologies for the late (and incomplete) addition in saas-18 :-/
Before this commit, when the amount of rows was above xls format threshold (>65535), the xlwt library threw an obscure Traceback to the user.
We now test the amount of rows before even calling the library, raising a more helpful message to the user
OPW 767319
closes#19035
Now that we're closer to switching to P3 for good, these helpers have
outlived their usefulness, and mostly add noise.
All remaining dict.iter*() or dict.view*() must be converted to the
normal keys(), values() or items() calls.
Whenever the result is likely to be used for more than the scope of a
loop, or when the dict needs to be modified during iteration, the calls
must be wrapped in a ``list()``, to protect the new P3 semantics.
Those cases are very exceptional.
Also removed some dead code or improved the API to remove unnecessary
conversions.
* remove references to basestring & unicode (use relevant pycompat
helpers)
* remove some str calls (either entirely or replaced by relevant
helper, either text or native)
* use better API to avoid unnecessary conversions
* remove some XML declarations in views
* StringIO removed from stdlib, replace with io
* try to correctly handle BytesIO/StringIO (one is for bytes the other
is for text)
* fix base64: Python 3 removed bytes-encoding and bytes-bytes
codecs (via #encode) so replace all calls to str.encode('base64'),
also b64encode is a bytes->bytes conversion so attempt to properly
handle that
issue #8530
This commit moves the whole customer portal to the portal module.
It now completely uses portal and http_routing features and is not
dependent on website anymore.
An override of web controller is added in portal in order to redirect
portal users to /my instead of /web. That way once having the customer
portal installed all share users are correctly redirected to their
account.
All modules defining customer portal templates and controllers are
updated accordingly.
When you receive an url with parameters
* auth_signup_token: uuid
* auth_login: login
those will be stored in the session and used
* when the user will want to sign up in order to be linked to the right
partner;
* when he logs in so he's sure to log in with the right account +
autofill is nice
This commit only adds the support, future commits will support its use.