When creating a new database, a random master password for it is
generated and strongly suggested to be used.
The motivation for this change is to have, by default, a secure master
password set for any Odoo deployment.
Often, users do not realise that, when making an Odoo installation
accessible on internet, anyone else can also access it.
Use autocomplete="new-password" for updating the master password and
play nice with password managers
When generating a new password, use autocomplete="new-password" as
well to prevent autofill of password potentially saved in password
manager.
Make the eye click to toogle on click instead of need to maintain.
closesodoo/odoo#45117
Task-id: 2091260
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Go to the database manager, configure a password either via the
interface either via the `admin_passwd` `.odoorc` config file. Click on
the backup menu, let the `password` field empty and submit the form. The
modal is closed without any warning and no query is sent.
The problem is that even if the field is marked as `required`, there is
a event listener that catch the `onsubmit` event and close the modal
even if it is not valid.
opw-2031461
closesodoo/odoo#34669
Signed-off-by: Julien Castiaux <Julien00859@users.noreply.github.com>
The database manager was broken with BS4, this commit restores it. The
old BS3 layout was not perfect either, so this commit redesigns the
forms with BS4 too.
The 'form-horizontal' class have been removed; the '.form-group'
elements must now use the 'row' class for an horizontal layout.
The 'control-label' class was renamed to 'col-form-label'.
The 'help-block' class was renamed to 'form-text'.
The 'has-error' and 'has-success' classes have been removed and
replaced by a new system using the :valid and :invalid pseudo-classes,
when a parent has the 'was-validated' class. While this system is great,
it is not straightforward to use it in Odoo. Fortunately, BS4 provides
the 'is-valid' and 'is-invalid' classes as fallback. This commit
replaces the 'has-error' and 'has-success' classes by 'o_has_error' and
'o_has_success' classes (for JS compatibility) and use the 'is-*'
fallback classes. (The 'has-warning' class has no equivalent but was
unused in Odoo anyway).
Odoo made the bad choice of using the 'btn-sm' class for every button
instead of configuring the padding for default 'btn' to be smaller.
In BS4, the style of btn-sm is actually more complex, lowering the
font-size too. Also, btn-xs was removed so we would not have the
possibility to display smaller button than our default ones.
This commit removes btn-sm wherever it was used. Unfortunately, this
might remove it at some places where it made sense but this can be
restored in a second time.
Description of the issue/feature this PR addresses:
Accessibility improvements forbids the use of the syntax
`<i class="fa fa-check"/> Some text`
to create a labelled icon. But, by this, some fonts are changed.
Desired behavior after PR is merged:
The old syntax can be used.
Today, Odoo is really tricky to use without seeing the screen, it must be improved to be usable.
This PR forbid to use labels without a "for" attribute, add some title, rule and aria attributes in HTML. With that, Odoo will be fully usable with a screen reader.
* [IMP] Labels must have a for attribute. Improve accessibility.
* [IMP] Better error message when trying to read a missing cached value
* [FIX] Add some aria-label and title attributes for screen readers.
* [FIX] Template name is not included in the error message in case of SyntaxError in QWeb
* [FIX] Improve the Tour failed at step error message to be more explicit.
* [IMP] Add aria-labels
* [FIX] Add missing aria-label on failing test
* [IMP] aria-hidden means hidden. Fix all bad aria-hidden and hide aria-hidden for all.
* [IMP] Color names on kanban views and many2many tags
* [IMP] Add some checks on views for accessibility.
* [IMP] Add `alt` attribute on `img` tags.
* [IMP] Add aria-label and title on non-described icons
* [IMP] Add button role to widgets with btn class
* [IMP] Translate aria and formatted attributes.
* [IMP] Remove wrong aria-labelledby
* [IMP] Add menu role on dropdowns
* [IMP] Buttons must be focusable
* [IMP] Add aria attributes on progress bars
* [IMP] Improve accessibility of basic widgets
* [IMP] Change main layout to more semantic tags
* [IMP] Add menuitem role when missing
* [IMP] Remove wrong role='presentation'
* [IMP] Improve accessibility of tab panels
* [IMP] Add aria-invalid on invalid fields
* [IMP] Add aria-sort on ordered columns
* [IMP] Add role on alerts
* [IMP] Use dialog role, header, main and footer tags for modals
* [IMP] Add labels on o_status
* [IMP] Improve accessibility of kanban view with feeds and articles
* [IMP] Add alerts in case of new messages
* [IMP] Add widget, navigation or img role to aria-labelled items
- The `--no-database-list` option will now also block access to database
management functions and screens.
Presumably this flag should only be used in production when all
databases have been provisioned, so the admin should like to block
access to the db manager at the same time.
- If no `--database` or `-d` parameter is provided, the system will be
unable to fetch a list of databases at all, so users will be blocked
with an error message.
- Hide the link on the login screen to the DB manager when it is
disabled, to prevent sending users to an error page.
- Weak attempt at updating the documentation
Note: the security check for RPC methods could have been done in the RPC
dispatcher, however that would not have protected service methods when
called directly, e.g. by a controller (e.g. the dump method).
In v8, it was not allowed to create a DB with a name containing a space.
This should still be the case from v9 since it causes issuesfor backup
scripts, for example.
Reintroduces 1a0e9063d4
opw-727613
When a database is created, we are not auto-logged in to the new
database anymore because the login passed to the authentication request
is 'admin' instead of the one set in the creation form.
To fix this issue, we used the login parameter from the creation form
in the authentication request. We also set the login field to
required in the create database form view.
This bug comes from rev https://github.com/odoo/odoo/commit/903733a32
When you backup 3 dbs with the database manager, you had 3 times the warning.
Underscore is not loaded, so _.once not available.
This commit closes#13173
All actions of the database manager redirect the user after an action except the
backup option which returns an octet stream.
Close the modal after form submission to mimic the same behaviour.
Do not close the modal for other actions than database manager to avoid waiting
time for create that may be long to process.
Add message to warn the user about backup waiting time after cliking on submit
to be less confusing for big databases that may take a lot of time to be ready.
Fixes#10803
Add inputs e-mail address and country
when creating a newdatabase
This will provide the installation of the correct
chart of accounts at the installation of Accounting
Use the provided login as the admin login,
and set the email on the partner
if the login set is an email
Set the country on the company (and its partner)
The countries are parsed from XML country list
We take the opportunity to repair the `label for`
which bind the label with the input only if
the `id` attribute of the input is set with
what is set in the `for` attribute of the label
Avoid duplicating web addon in enterprise by extracting a common basis.
Enterprise features stay in enterprise, but use that common basis.
Mainly:
- JS refactoring and linting
- Conversion of .sass into .less split into multiple files
- Templates cleaning and DOM simplification
- Re-generation of web.pot, and update of .po files
If the module barcodes is installed, a BarcodeEvents singleton is
automatically instanciated. It listens to keypresses and, when a
sequence of keys represents a barcode, it broadcasts a 'barcode_scanned'
event on core.bus containing the barcode string.
boot.js log:
* ``Missing dependencies``:
These modules do not appear in the page. It is possible that the JavaScript
file is not in the page or that the module name is wrong
* ``Failed modules``:
A javascript error is detected
* ``Rejected modules``:
The module returns a rejected deferred. It (and its dependent modules) is not
loaded.
* ``Rejected linked modules``:
Modules who depend on a rejected module
* ``Non loaded modules``:
Modules who depend on a missing or a failed module