Commit Graph
12 Commits
Author SHA1 Message Date
Christophe Simonis 5a3a06f26f [MERGE] forward port of branch saas-11 up to d4d09df 2016-07-04 13:16:34 +02:00
Denis Ledoux bc2a06c019 [FIX] http, website_form: preserve form input values order
By default, werkzeug doesn't preserve the order
of the parameters sent to routes.

As stated in the werkzeug documentation:
```
parameter_storage_class

the class to use for args and form.
The default is an ImmutableMultiDict which supports multiple values per key.
alternatively it makes sense to use an ImmutableOrderedMultiDict
which preserves order or a ImmutableDict which is the fastest
but only remembers the last key.
It is also possible to use mutable structures, but this is not recommended.

New in version 0.6.

```

For some of our use cases, it makes sense to keep the order
of the route parameters.

e.g. In the website builder, when building a form
with a bunch of inputs values that will be concatened
in a lead note, the user expects the answer to be displayed
in the same order than the form inputs.

This change is seen as a bit risky as it could lead to
performances issues in the http routes processing, and this
is the reason we do not merge this in stable 9.0 at the moment.

If needed, it could be back ported later to 9.0, after
several weeks/months of testing in this release(saas-10 atm).

opw-677508
2016-06-30 10:45:55 +02:00
Christophe Matthieu 7ede9bcb2d [IMP] base ir.qweb: compile template (and use ast) to improve rendering speed
* The compiled templates are cached per user, lang, inherit context values
* ir.ui.fields: attributes method return an dict, and record_to_html return only the content value of the field
* all rendered text use build_text and all attributes use build_attribute
* t-esc-options is removed and replace by format_value method
* AssetsBundle receive the list files and remains
2016-06-14 09:46:25 +02:00
Olivier Dony ee804e1d32 [MERGE] Forward-port 9.0 up to 74d8cbc190 2016-04-21 18:05:14 +02:00
Denis Ledoux d57623023b [FIX] website_form: handle date & datetime
Adding date & datetime inputs in the website
form builder couldn't work, because
the posted values for these input
types were not treated at all,
and they were not in the format
the date/datetime were stored in database.

opw-672674
2016-04-20 16:19:25 +02:00
Martin Trigaux 34348ebf8d [FIX] typo, English 2015-12-22 11:58:47 +01:00
Xavier Morel e3a2448ebe [ADD] form builder whitelisting: ACL check
Only users who can edit the website's structure should be allowed to
whitelist fields.
2015-11-30 16:39:13 +01:00
Xavier Morel 2afb5b43ef [IMP] form builder fields blacklisting
* blacklist all fields by default
* don't use blacklist in get_authorized_fields which is called to see if
  a field can be added to a form, instead only use it afterwards to see
  if the field can be written to by the formbuilder. That way
  formbuilder can whitelist fields which are actually added to forms
  on-demand resulting in a more secure interaction
2015-11-30 16:39:13 +01:00
Nicolas Lempereur 6f02ba9cbf [IMP] website_form: don't remove newline
In some instance, the mail content of a sent form would only be text
formatted. This could lead to a message with no newline, thus making it
illegible.

This fix has to be ugly since body_html field of a mail.mail is of type
text.
2015-11-18 11:41:25 +01:00
Nicolas Lempereur a4cfe7f6ec [FIX] website_form: be consistent when concatenating string
In the form builder, custom field name could contain special char but
the get key values are of the type str whilst the value are in unicode
type.

Thus when concatenating them, one should be converted so they are
uniform and don't lead to an encoding error.

opw-656745
2015-11-18 10:49:24 +01:00
David Monjoie d210744ef0 [IMP] website_form: various improvements
- Fixed the module name and category in manifest
- Fixed website_form_blacklisted being ignored
- Unauthorized readonly and magic fields
- Reset the form on successfull submit
- Added missing date field
- Added date and datetime validation
2015-09-15 14:00:36 +02:00
David Monjoie a77f5cf42f [ADD] website_form: generic form controller
Contains a new ajax post function that comes from mdo's
original code and that I was not able to get rid of.
2015-08-26 16:01:19 +02:00