Commit Graph
363 Commits
Author SHA1 Message Date
Romain Derie 2c8c079c05 [FIX] http_routing, website: prevent crash when using fw in url
Before this commit, the routing map generated and used would be the one from
the website the request is performed, instead of the one from the `fw` website
ID which will be the one we redirect the user to.

This issue was introduced with the routing map by website, be8fc2296b and is
restricted to a single case: a publisher using the website switcher, and it
won't happen on next page naviguation/refresh as the `fw` website id will be
the same as the current website's ID. Thus there won't be any routing map
mismatch.

Step to reproduce:
  - Create a page on website 2, set it as homepage
  - Naviguate to website 1 on '/' url
  - Naviguate to website 2 on '/' url
This will raise a werkzeug error about `EndPoint not iterable`.

----- Technical analysis ------

This is the current flow:
1. `_dispatch()` is setting `website_routing` to `get_current_website()` -> 2
2. `_dispatch()` is calling `_match()`
3. `_match()` is calling `routing_map()` with key = `website_routing`, which
   was set to 2 in step 1.
4. `routing_map()` is calling `_generate_routing_rules()` which generate the
   rules based on `website_routing`, which was set to 2 in step 1.
5. `_dispatch()` authenticate the user by calling `_authenticate()`
6. `_dispatch()` is calling `_add_dispatch_parameter()`, where URL param `fw`
   is forced in session, so `get_current_website()` now return the correct
   `website_id` -> 1

The issue: in order to handle the `fw` URL parameter (step 6.), we need to
check the rights to ensure we can allow the website switch.
To check rights, user need to be authenticated (step 5.), which is done after
generating the routing map (2. & 3. & 4.).
The routing map is generated based on the current website (step 1.)

Step 6 depends of steps 5 which depends of steps 2/3/4 which depend of step 1,
but step 1 should depend of step 6, which is an impossible cycle.

closes odoo/odoo#70397

X-original-commit: 4eb26497a774e934d7e1a6be9f505400fd9e2cdb
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Signed-off-by: Romain Derie <rdeodoo@users.noreply.github.com>
2021-05-05 11:01:15 +00:00
Raphael Collet 34d6f87d54 [REF] core: put field.depends on registry and make field.recursive explicit
The attributes field.depends and field.depends_context are problematic
for sharing fields across registries, because they depend on the model's
registry class, which may vary from one registry to another.  In order
to make computed fields shareable, we have to move those values away
from fields.

For the same reason, field.recursive should not be inferred, because its
value may depend on the registry, although it is generally not the case.
Moreover, the flag recursive=True is set on a field when field triggers
are determined (on the registry).  A compute method may be called before
the flag is set (if no update has been done yet), and that can lead to
incorrect computations.

This happened in test TestUsers2.test_reified_groups in module 'base'.
The user groups view was apparently determined without the flag being
set, and the view depends on the recursive field 'trans_implied_ids',
which was not correctly computed.

We thus force developers to be explicit about recursive computed fields.
The code now logs a warning when the flag is not set up properly.
2021-05-03 12:33:29 +00:00
Samuel DegueldreandTom De Caluwé 2cfb8658bf [FIX] web_editor: fix default shapes not reacting to palette changes
Previously, when toggling on background shapes, they always had the
default colours. In [1] we made it so that when you toggle on a shape on
a section, it would automatically reuse the colors of the surrounding
shapes if any.

Unfortunately, when the "implicit" colors were also the default colors,
they were still marked on the shape, and it got an explicit background
image that would no longer react to changes in the palette.

This was caused by the fact that the call to _getDefaultColors returns
an empty object when the section doesn't already have a shape-container,
this was not a problem before since we were not passing in any colors
when creating the initial shape previously, the the aforementioned
change made it so that we did.

This commit fixes the issue by creating the shape-container before
calling the method that will set the colors on the shape, this way
getDefaultColors works as expected, and the colors are not marked on the
section when they are the default ones, restoring the ability of the
shape colors to adapt to the palette

[1]: https://github.com/odoo/odoo/commit/875aca63f7dab287c61485ebe999b3b8dd89d91c

task-2500607

closes odoo/odoo#70054

X-original-commit: 63acc2b0d1957dedd40af2033722f9ea4ef2e597
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
Co-authored-by: Tom De Caluwé <tdc@odoo.com>
2021-05-03 09:27:44 +00:00
Xavier Morel e166077cb3 [FIX] base, website: fix entities in tests
`markupsafe.escape` always escapes single and double quotes, and
escapes them to their numeric values rather than symbolic

According to pallets/jinja@f35e28154f,
this is for compatibility with HTML 3.2: the only named entities in
the HTML 3.2 DTD are `amp`, `gt`, and `lt`.

Update tests to match.
2021-04-29 05:34:19 +00:00
Xavier Morel 01875541b1 [CHG] core, web: deprecate t-raw
Add a big fat warning when the qweb compiler finds a `t-raw`.

`t-esc` should now be used everywhere, the use-case for `t-raw` should
be handled by converting the corresponding values to `Markup`
objects. Even though it's convenient, this constructor *should never
be made available in the qweb rendering context* (maybe that should be
checked for explicitely?).

Replace `werkzeug.escape` by `markupsafe.escape` in
`odoo.tools.html_escape`, this means the output of `html_escape` is
markup-safe.

Updated qweb to work correctly with escaping and `Markup`, amongst
other things QWeb bodies should be markup-safe internally (so that a
`t-set` value can be fed into a `t-esc`). See at the bottom for the
attributes handling as it's a bit complicated.

`to_text` needed updating: `markupsafe.Markup` is a subclass of `str`,
but `str` is not a passthrough for strings. So `Markup` instances
going through would be converted to normal `str`, losing their safety
flag. Since qweb internally uses `to_text` on pretty much
everything (in order to handle None / False), this would then cause
almost every `Markup` to get mistakenly double-escaped.

Also mark a bunch of APIs as markup-safe by default

* html_sanitize output.
* HTML fields content, sanitization is applied on intake (so stripped
  by the trip through the database) and if the field is unsanitised
  the injection is very much intentional, probably. Note: this
  includes automatically decoding bytes as a number of default values
  & computes yield bytes, which Markup will happily accept... by
  repr-ing them which is useless. This is hard to notice without `-b`.
* Script-safe json, it's rather the point (though it uses a
  non-standard escaping scheme).
* Note that `nl2br`, kinda: it should work correctly whether or not
  the input is markup-safe, this means we should not need to escape
  values fed to `nl2br`, but it doesn't hurt either.

Update some qweb field serialisations to mark their output as
markup-safe when necessary (e.g. monetary, barcode,
contact). Otherwise either using proper escaping internally or doing
nothing should do the trick.

Also update qweb to return markup-safe bytes: we want qweb to return
markup-safe contents as a common use-case is to render something with
one template, and inject its content in an other one (with Python code
inbetween, as `t-call` works a bit differently and does not go through
the external rendering interface).

However qweb returns `bytes` while `Markup` extends `str`. After a
quick experiment with changing qweb rendering to return `str` (rather
unmitigated failure I fear), it looks like the safest tack is to add a
somewhat similar bytes-based type, which decodes to a `Markup` but
keeps to bytes semantics.

For debugging and convenience reasons, MarkupSafeBytes does *not*
stringify and raises an error instead (`__repr__` works fine). This is
to avoid implicit stringifications which do the wrong thing (namely
create a string `"b'foo'"`).

Also add some configuration around BytesWarning (which still has to be
enabled at the interpreter level via `-b`, there's no way to enable it
programmatically smh), and monkeypatch `showwarning` to show warning
tracebacks, as it's common for warnings to be triggered in the bowels
of the application, and hard to relate to business logic without the
complete traceback.

`t-out`
=======

`t-esc` is a bit confusing for the new behaviour of "maybe escape
maybe not", so add a `t-out` alias with the same behaviour.

Unlike `t-raw`, `t-esc` is only soft-deprecated for now: there are
thousands of instances, so editing all the templates is not
great. Eventually we'll add a `ci/style` to prevent addition of new
ones, and eventually we might do a bulk-replace and hard-deprecate.

Attributes handling
===================

There are a few issues with respect to attributes. The first issue is
that markup-safe content is not necessarily attributes-safe
e.g. markup-safe content can contain unescaped `<` or double-quotes
while attributes can not. So we must forcefully escape the input, even
if it's supposedly markup-safe already.

This causes a problem for script-safe JSON: it's markup-safe but
really does its own thing. So instead of escaping it up-front and
wrapping it in Markup, make script-safe JSON its own type which
applies JSON-escaping *during the `__html__` call.

This way if a script-safe JSON object goes through `markupsafe.escape`
we'll apply script-safe escaping, otherwise it'll be treated as a
regular strings and eventually escaped the normal way.

A second issue was the processing of format-valued
attributes (`t-attf`): literal segments should always be markup-safe,
while non-literal may or may not be. This turns out to be an issue if
the non-literal segment *is* markup-safe: in that case when the
literal and non-literal segments get concatenated the literal segments
will get escaped, then attributes serialization will escape
them *again* leading to doubly-escaped content in attributes.

The most visible instance of this was the `snippet_options` template,
specifically:

    <t t-set="so_content_addition_selector" t-translation="off">blockquote, ...</t>
    <div id="so_content_addition"
        t-att-data-selector="so_content_addition_selector"
        t-attf-data-drop-near="p, h1, h2, h3, .row > div > img, #{so_content_addition_selector}"
        data-drop-in=".content, nav"/>

Here `so_content_addition_selector` is a qweb body therefore
markup-safe, When concatenated with the literal part of
`t-atff-data-drop-near` it would cause the HTML-escaping of that
yielding a new Markup object. Normal attributes processing would then
strip the markup flag (using `str()`) and escape it again, leading to
doubly-escaped literals.

The original hack around was to unescape() `Markup` content before
stringifying it and escaping it again, in the attribute serialization
method (`_append_attributes`).

That's pretty disgusting, after some more consideration & testing it
looks like a much better and safer fix is to ensure the
expression (non-literal) segments of format strings always result in
`str`, never `Markup`, which is easy enough: just all `str()` on the
output of strexpr. We could also have concatenated all the bits using
`''.join` instead of repeated concatenation (`+`).

Also add a check on the type of the format string for safety, I think
it should always be a proper str and the bytes thing is only when
running in py2 (where lxml uses bytestrings as a space optimization
for ascii-only values) but it should not hurt too much to perform a
single typecheck assertion on the value... instead of performing one
per literal segment.

Note: we may need to implement unescape anyway, because it's still
possible to get double-escaping with the current scheme: given an
explicitly escape-ed `foo` and `t-att-foo="foo"`, `foo` will be
re-escaped.

fixup! [CHG] core, web: deprecate t-raw
2021-04-29 05:34:19 +00:00
Julien Mougenot 3e3dce0eb8 [REF] *: rename assets 'glob' to 'path'
Rationale:
The majority of cases where an ir.asset is manually declared
outside of manifest files is to specifically add a single asset file.
This means developers are specifying a single asset *path*, and not a
glob expression. In this context, it seems better to name the filepath
field `path`, and document that it can be specified with a glob
expression when (seldom) needed, rather than making the exception appear
to be the norm - possibly puzzling many developers (What's a glob and
why do I need one?)

The doc is updated as well, and some spell-checking and wording
improvements were done too.

This required some adaptations to the existing `ir.asset` declarations:
- odoo/enterprise#17465
- odoo/design-themes#459

closes odoo/odoo#68695

Related: odoo/upgrade#2348
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2021-04-07 20:39:10 +00:00
Romain Derie 8fcf930a6b [IMP] web_editor, website, *: introduce popover as edit system for links
*: website_form

This commit introduces a simple & light popover/tooltip (as in Google Doc) when
editing a link.

It will be used:
1. (web_editor) On every page links.
2. (website) In the website navbar, when clicking on a menu, it will replace the
popup shown to ask the user what he wants to do (edit the menu or go to the link
or do nothing). That popup was a bit invasive and old-fashioned.

Part of https://github.com/odoo/odoo/pull/64756
task-2439860

closes odoo/odoo#64756

Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2021-04-01 09:49:45 +00:00
Julien MougenotandSimon Genin 03641610c2 [REF] *: convert all modules to new asset system
Conversion of all modules to the new manifest assets declaration.

Part of task: 2352566

Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Simon Genin <ges@odoo.com>
2021-03-31 13:57:18 +02:00
8cc066173d [IMP] *: Improve assets management
This commit changes the way assets are declared in Odoo modules.

Before: assets were declared in template files. Template bundles were
generated from primary templates, so technically any qweb template could
have been called as an asset bundle, with the 't-call-assets' directive.

Being standard qweb templates, they had access to standard HTML tags
(script, link, with or without raw scripts or style definition), qweb
directives (t-call, t-raw, etc.) and could be inherited by other
templates.

Now: assets are defined in the module's manifest and generated by the
't-call-assets' directive.

More information on the new system can be found on the updated user
documentation (see the "JavaScript Reference" section).

Task: 2352566

Co-authored-by: Bruno Boi <boi@odoo.com>
Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Lucas Perais <lpe@odoo.com>
Co-authored-by: Mathieu Duckerts-Antoine <dam@odoo.com>
Co-authored-by: Raphael Collet <rco@odoo.com>
Co-authored-by: Simon Genin <ges@odoo.com>
2021-03-31 13:57:17 +02:00
Xavier Morel 2eb007074c [IMP] website: mockify test
instead of using ad-hoc weirds

closes odoo/odoo#66682

X-original-commit: 7a42cc19492ada223678b6b67fc85fb121155e2b
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2021-02-23 12:18:07 +00:00
Romain Derie 5e8ca1996e [FIX] website: add tests for #64446
As `standalone` tests were introduced in 14.0 (see 0453566a76), this commit
adds tests to ensure the `inherit_id` of COW views are correctly updated on
module updates.
This test could not be rewritten in a regular test and merged in 12.0 as module
operation in tests try to be avoided (see 5e7e7b00b7d).

See #64446 for more information about the original fix.

closes odoo/odoo#66096

X-original-commit: 9d2787b1dc1485ed132ca51d2b2a4c85b8c77d0c
Signed-off-by: Christophe Simonis <chs@odoo.com>
Signed-off-by: Romain Derie <rdeodoo@users.noreply.github.com>
2021-02-16 10:27:16 +00:00
Romain Derie 6a9b5bba9b [FIX] base, website: replicate inherit_id update on cow view
Before this commit, only whitelisted fields would be updated on cow views
during a module update.
A field would be whitelisted if he had the same value than the original view,
see it as a heuristic to not write on modified fields.

But `inherit_id` is not that simple, even if the cow view has a different value
than its original view, it doesn't mean it was modified by the user, it is just
because of the cow mechanism that assigned a copied view as inherit_id, which
is just a copy ofthe original one.

We can thus consider `inherit_id` as unchanged and whitelist it if the `key` is
the same.

In practice, it means that cow'd views did not receive the `inherit_id` updates
as in commit https://github.com/odoo/odoo/commit/c8577568a1e39f6692889b3e21652fa3b8df06b2#diff-823e5db841dca1798ff1300e243059a4e1c93343598d2be5a1d1dcd1d2d0c273R537
where `portal.my_account_link` had its `inherit_id` changed from
`portal.frontend_layout` to `portal.user_dropdow`, see https://github.com/odoo/upgrade/pull/2059:

Considering a module update changing `inherit_id` of D from A to B, the
following use cases are expected. Without this fix, D' never move:

CASE 1
  A    A'   B                      A    A'   B
  |    |                 =>                 / \
  D    D'                                  D   D'

CASE 2
  A    A'   B    B'               A    A'   B   B'
  |    |                 =>                 |   |
  D    D'                                   D   D'

CASE 3
    A    B                        A    B
   / \                   =>           / \
  D   D'                             D   D'

CASE 4
    A    B    B'                  A    B   B'
   / \                   =>            |   |
  D   D'                               D   D'

Opw: 2422773
Opw: 2422727
Opw: 2422770
Opw: 2423406
Opw: 2423859
X-original-commit: ff69f11e9c97d63d9319a8094a87af93984aba38
2021-02-12 15:52:37 +00:00
Francois (fge) 402740f73e [ADD] web: add /web/assets for assets bundle
Part of PR 63177
2021-02-15 10:55:00 +01:00
Samuel Degueldre 480327381a [FIX] website, web_editor: fix empty parallax snippet not being removed
Previously, when removing all the content of a snippet, that snippet
would get automatically deleted. This was not the case for parallax
snippets because we previously intended the user to drop the parallax
snippet, empty it, and drop other content inside of it.

Recently, we added the parallax option on all snippets, rendering the
previous workflow obsolete. There is now no longer any reason to keep
empty parallax snippets. This commit fixes that.

task-2446008

closes odoo/odoo#65551

X-original-commit: 61f410b57f1c28bd6464b86d1582c22b7fd846d5
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2021-02-04 15:18:36 +00:00
qsm-odoo 05627e4815 [IMP] website: test a website style can properly be edited
This test at least ensures that a SCSS edition through the editor can
properly be done and indirectly tests that the assets order is correct
(in prevision of a future asset refactoring).

closes odoo/odoo#64770

X-original-commit: fe19b48831df17352ea7dbb0b7fa2497ac2da38f
Signed-off-by: Romain Derie <rdeodoo@users.noreply.github.com>
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2021-01-19 18:56:42 +00:00
qsm-odoo d7be062403 [FIX] website: make automatic specific view on create
SOC for ir.ui.view creation. If a view is created without a website_id,
it should get one if one is present in the context. Also check that
an explicit website_id in create values matches the one in the context.

Note: it was already the case but kinda by chance and not entirely
correct. Most of the time, the 'arch' field was specified as a creation
value... and as it is a computed field with an inverse method, a COW
was triggered. But this had also the inconvenient of creating an extra
generic view without any arch.

closes odoo/odoo#43245

Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2021-01-14 11:26:59 +00:00
xO-Tx 86f0b53797 [IMP] website: update default theme tour
The goal of this commit is to update the default theme
tour (steps, changes on snippets...) as in other themes tours.

The url was changed in "registerThemeHomepageTour" function since
the homepage tours are supposed to start in edit mode.

task-2375011

closes odoo/odoo#63850

X-original-commit: b8b394f3824a1f07d76bed5f277b935f619dacbf
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2020-12-28 16:53:13 +00:00
qsm-odoo e5572c317a [REV] web_editor, *: remove Jabberwock
*: barcodes, mail, mass_mailing, note, test_website, web, web_tour,
   website, website_blog, website_event, website_form, website_forum,
   website_mail_channel, website_mass_mailing, website_profile,
   website_sale, website_twitter, doc

New solutions are being investigated in master. For the moment, it seems
better to remove Jabberwock to unlock difficult forward-port between
14.0 and 14.1/master, until we decide what to do once and for all in
a later master. We may un-revert this later but that would be way easier
than reverting Jabberwock in a few months.

This was done as safely as possible by removing any commit related to
Jabberwock, then resolving conflicts, then reforcing commits from 14.0
that were hugely adapted for 14.1/master, then forcing the whole diff
over a rebased 14.1/master. The only possible miss (other than me making
a mistake) would be commits that were not forward-ported to 14.1 thanks
to Jabberwock handling the issue on its own (I know we had such commits
in website, which I manually included in this revert, see below).

For reference:

Commits which were reforced to their 14.0 version:
- https://github.com/odoo/odoo/commit/1a916fc2362c0b006460d94a219366ade1cce058
- https://github.com/odoo/odoo/commit/fd9e58a675bb7ec1bf97cb77b21b3c65369d51fe
- https://github.com/odoo/odoo/commit/bdfddace29b16404c06a7ebfc0cc242463a0e768
- https://github.com/odoo/odoo/commit/42b3ad10e0b32b7fc72f801e2c67d6baf938c566
- https://github.com/odoo/odoo/commit/710784da1f02d45cbe898da426ba7e2ac63dc711
- https://github.com/odoo/odoo/commit/597585c9b8b1350bcfd84e8433ea6c82060bcc3d
- https://github.com/odoo/odoo/commit/333a9124608ff655bd9ad5e63044a5cb7ef9c636

Commits that were not forward-ported to 14.1/master and now are:
- https://github.com/odoo/odoo/commit/55ff2d971b672dec5f103215be39101c88856b6c
- https://github.com/odoo/odoo/commit/ebbb3de1e5f363689a5ba1647bb4c26416e42d5b

+ Adapt this forward-port: https://github.com/odoo/odoo/pull/60976 (as
  it was simplified for non-stable master version relying to the
  Jabberwock implementation and now needed to be adapted to the
  summernote implementation).
  See `!$el.data('oe-expression') && $el.data('oe-xpath')`

+ Revert https://github.com/odoo/odoo/pull/60477 and reforce original
  14.0 fix https://github.com/odoo/odoo/commit/746bf53b4aecfc601f0581a948d7cb7153812c82

Note: this also means that any good refactoring that was done by the
Jabberwock-related commits is lost for now. Once the revert reaches
master, I'll try and restore what we want from those commits. Here
are their references (but obviously they have the opposite conflicts
than those resolved during this revert):

e766842a92b6 [REM] web_editor,website: empty summernote files
08c94c986e09 [REF] web_editor,web: adapt to new jabberwock editor
1546c1b74713 [REF] mass_mailing: adapt to new jabberwock editor
fd0b963c6028 [REF] website: adapt to new jabberwock editor
0113d05c6c94 [ADD] web_editor: add new Jabberwock editor lib
d0c88a396493 [FIX] web_editor: don't change background color out of the website editor
d52d3d67d4e1 [FIX] web_editor : better icon in text style dropdown
61cb2f0d21da [FIX] web_editor: should not ask if want to leave the page twice
c42012b863b5 [FIX] web_editor: trigger a resize when use the mobile preview
d934d05d6e39 [FIX] web_editor: need to build the snippet before commit it into vDom
495bea924745 [FIX] web_editor: remove box shadow on the #wrap container
bffb5612e689 [ADD] field_html: add resizer in most field_html
f3c94e40cccf [IMP] web_editor: update Jabberwock library to commit 41e4063
cc87dea3ef32 [FIX] web_editor: update header change position to work with JW
5d9b25f66704 [FIX] web_editor: do not insert chars around step icon on click
70d3f0e4630c [IMP] web_editor: update Jabberwock library to commit 0bd94881
a57f13891f82 [FIX] web_editor: open media modal in appropriate tab on dblclick media
5b7537397e08 [IMP] web_editor: update Jabberwock library to commit a7ba7c34
a8d7ec235eeb [FIX] web_editor: adapt iframe Qunit test to new editor
5f794eac7209 [FIX] mass_mailing: hide all panels on show themes
551d45641d19 [IMP] website: remove unused reference
10580e1c102f [IMP] wesbite: add comment in tour
c17049f6b764 [FIX] web_editor: Fix description toggle in pricelist snippet
18a428e854b1 [IMP] web_editor: update Jabberwock library to commit 43a10003
58a161c645a5 [REF] web_editor, website: use editor helper setClass
62dd0bd3bc66 [FIX] web_editor: properly deactivate snippets and reactivate the last
99eebcaa34cb [FIX] web_editor: disable snippet in preview mode on mouse leave options
a84216932958 [FIX] web_editor: fix the image gallery snippet
f8dd4ea3e7d5 [FIX] web_editor: fix shadow selector for Safari
e50a4f3a16de [IMP] web_editor: update Jabberwock library to commit de13ed7e
4a2718f7a5ba [FIX] web_editor: ensure dom is properly cleaned at end of save test
03684c004a4e [FIX] website: ensure reset of bg-image on add bg-video
d63397159708 [FIX] web_editor: fix image remove from images wall
82fa5142f1a5 [IMP] note: restyle note without sheet or resizer
8b9f1ce603d5 [FIX] web_editor: properly mock createWysiwygIntance (sic) in tests
fc2183b66305 [FIX] web_editor: image overlay did not update with changes
cd0d2f5791cd [FIX] web_editor: add color preview to color picker
28a168172454 [FIX] web_editor: restore removal of spinner
67c90dd3b946 [FIX] website_forum: properly initialize editor
920dfe2a430a [FIX] website_forum: better css in the JW toolbar
43f33fd651af [IMP] web_editor: update Jabberwock library to commit 6853b60
71246c92f8de [FIX] Web_editor: table options button should be inside the toolbar
12b9e5916692 [FIX] web_editor: properly update the image options on replace image
e889cf8583da [FIX] website, website_sale: properly save filter id of dynamic snippets
e0fd11e36e45 [IMP] web_editor: update Jabberwock library to commit 4b2c903b
8f2b7ba35614 [FIX] web_editor: properly stop snippet option changed event propagation
a30c2c4105c7 [FIX] website: fix megamenu snippet editor behavior
312091cf822b [FIX] web_editor: fix overlay that is not reappearing
9f1d03dda613 [FIX] web_editor: table picker not fully displayed
814ddada6124 [IMP] web_editor: remove message before leaving page if editor is destro
4f38e26af7da [FIX] web: allow saving copyright footer
01e947b6123b [FIX] web_editor: only save translations that changed
103676072c50 [FIX] web_editor: prevent traceback on open crop dialog
5844ff66d4a0 [FIX] web_editor: apply image crop in jw on save dialog
1b435652e4a0 [FIX] website_forum: ensure media modal opens on click button
4f4a6ca0b8ac [FIX] web_editor: ensure valid default html value
51e22026ac7b [IMP] web_editor: update Jabberwock library to commit ab1184f8
2413fa19be0e [FIX] web_editor: Qunit test properly wait for editor stop
aa89e1ea3e97 [FIX] web_editor: properly save view blocks with an id
e2e90b53992e [FIX] web_editor: ensure language selector is non editable
0efd72089d5c [IMP] web_editor: clean useless lines
f54dfc7631f9 [IMP] web_editor: remove useless comment
3995ab1b84f2 [IMP] web_editor: update Jabberwock library to commit b8d73691
0834b1e5740a [IMP] web_editor: withDomMutations
f1459fb7b45c [FIX] web_editor: fix non-deterministic error in QUnit wysiwyg tests
6e8acc6c8cc7 [IMP] web_editor: update Jabberwock library to commit 3bbb175c
18a0c95d51cb [FIX] website, web_editor: #wrapwrap in body
4686a92e742c [FIX] website_form: allow edition of success message
78cc4da075cc [FIX] web_editor: allow edition of branded nodes only
bcffa7353448 [FIX] web: dialog should not use field value footer items
67ff56e14746 [FIX] web_editor,website_mass_mailing: display the popup preview
3cb9bea50c20 [IMP] web_editor: update Jabberwock library to commit a20492ea
518f03e6f1c9 [FIX] web_editor: use withIntangibles to find ZoneNode
d0ad6a568f49 [FIX] website: move sidebar out of theme
d690f5da13ea [FIX] website: properly save popup id
43b3433df3e6 [FIX] web_editor: fix non-deterministic error in QUnit wysiwyg tests
4ee8f4dedc30 [FIX] web_editor: prevent deadlock when removing child snippet of popup
850be198ef6d [FIX] web_editor: prevent traceback on reposition background image
4c3eaba41f5d [FIX] mass_mailing: adapt tour to the new editor design.
496d3ea272ed [FIX] web_editor: properly position sidebar scrollbar
5be4de703074 [FIX] web_editor: Show the toolbar when select the text in forum edition

closes odoo/odoo#63768

Related: odoo/enterprise#15458
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2020-12-24 13:36:49 +00:00
6d6f42f489 [REF] website: adapt to new jabberwock editor
Co-authored-by: Nicolas Bayet <nby@odoo.com>
Co-authored-by: Sébastien Geelen <sge@odoo.com>
Co-authored-by: Antoine Guenet <age@odoo.com>
Co-authored-by: Christophe Matthieu <chm@odoo.com>
Co-authored-by: David Monjoie <dmo@odoo.com>
2020-10-14 10:29:11 +00:00
Raphael Collet b951579d31 [FIX] core: non-stored binary fields should have attachment=False
This prevents some code (in controllers) to retrieve an attachment for a
field that is not stored, as the code only relies on `field.attachment`.
This also makes the field definition more consistent.

closes odoo/odoo#57980

X-original-commit: 7325c3f8c538a8b8c0435963cdda3ced6fe4b324
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2020-09-17 16:54:02 +00:00
Jeremy Kersten c2c2fed0a2 [FIX] website: make test determinist for single install
When running -i website --test-enable, the test was falsy.
The last page created page was present in matching_page wich one is a criteria
to be excluded from last modified page to avoid duplicate suggested page.

Now we substract correctly them before comparison.

https://github.com/odoo/odoo/blob/saas-13.4/addons/website/controllers/main.py#L243

closes odoo/odoo#57777

X-original-commit: 19319a7f88f474a6410ea1dabc6bcc1ac51e97bb
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-09-15 16:49:40 +00:00
Jeremy Kersten 72753073da [IMP] website: remove extra step of banner tour
Now that we will write tour by theme, this part is useless.
We just keep the old steps that will be not covered by future theme tour.

task-2172208

X-original-commit: 02e1b1f659d5f588cc4e52f48217f8e2c7771ad4
2020-09-11 16:31:49 +00:00
Victor Feyens 2f3dcb8947 [IMP] base,website*: do not store country flags.
1) Avoid the storage of all country flags as ir_attachment (230+
ir_attachment in a new db) to reduce the filestore of databases.

The country flags are nearly static and not expected to be modified on
Odoo instances.

This change is based on the new "image_url" widget logic (see previous commits).

2) Extend the flag coverage for countries

Add the missing country flags & specify a mapping to provide flags
for overseas administrated countries/territories.
2020-09-02 16:43:45 +00:00
Cocographique 118057927e [IMP] portal, website: review sign in templates
Move it in an external view to be able to place it at a different
location depending on the header template.

Part of https://github.com/odoo/odoo/pull/56427
task-2264627

X-original-commit: b4866d192e6f4fdfba15b65fa2c209b35b7eb8c0
2020-08-28 08:19:37 +00:00
Jeremy Kersten cbf8d3b304 [IMP] website: perf - cache public page
closes odoo/odoo#56331

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-08-21 17:50:00 +00:00
Lucas Perais (lpe) 9708c6e992 [IMP] bus: notify user when assets have changed
Use case:
When the server is restarted, the python is updated,
but some users may have an ongoing session in a browser tab
This may lead to code being unsynchronized and ultimately to some
odd bugs.

Purpose:
When we are in such a case, that is, the assets were recomputed
after a update of the code and a restart of the server by the request of another user,
notify connected users that assets have changed.
Then propose them to reload the page.

Known caveats:
- This is not a developer's feature.
Since assets computing is ORM cached, they have limited
opportunities to rebuild. Namely, the feature won't trigger
each time the JS has changed, rather, it will
when JS has changed AND the cache has been reset somehow (e.g. when the server is restarted).

- This not a portal/website feature either, but only in backend.
Business clients won't be notified that the JS has changed.

- While requests debug=assets do trigger a recomputing
of the *components* of bundles, they do not save a bundle
This means that the requests that sends the notification
cannot be debug=assets.

Task 2034462

closes odoo/odoo#39875

Signed-off-by: Mathieu Duckerts-Antoine <Polymorphe57@users.noreply.github.com>
2020-08-21 12:16:25 +00:00
Xavier Morel c1c43bbe38 [REM] core: assertion reports
That's a not-very-useful subset of OdooTestResult, so:

* make results merge-able (aka add ability to update a result with the
  contents of another)
* remove support for test data files, and transmission of the
  assertion report thing through the data-files loading
* replace "legitimate" uses of assertion report by test result
* have run_unit_tests manipulate and return a result instead of weird
  flags & ternaries
2020-08-19 14:08:12 +00:00
Xavier Morel dccbf425a1 [FIX] core: ensure we create a new session for each tour
The browser itself would get mostly cleaned up between tours, but the
session object would not get cleaned, and apparently in some cases
that could lead to an incoherent session: a tour would add data to the
session which the next tour (logging in as a different user) would
not (fully) override, leading to a session inconsistency and a Session
Expired exception during the tour.

Fix by not storing the session on the test object, the session is
created during authentication then set on the opener & browser.
2020-08-14 21:20:47 +00:00
Jeremy Kersten 617c716aea [IMP] website: ir_qweb - add lazyloading by default on img
closes odoo/odoo#55945

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-08-14 13:49:30 +00:00
0659a500ef [IMP] website_event_online: ensure to link visitor at registration
RATIONALE

Events are sometimes held online, gathering a community. In this merge we
improve Event application to better support full-online events with improved
tracks, wishlists, chat rooms, ...

PURPOSE

Ensure to have a visitor when people registers, in order to enable wishlist
or notifications. Improve visitor model to keep information when people change
device.

SPECIFICATIONS: REGISTRATION FLOW

This commit ensures a visitor is created when a registration is done on an
event. Creation is done only if a visitor does not already exists like all
visitor-based flows.

In case of multiple registrations made by the same visitor, only the first
registration is linked to the created/existing visitor. We take the opportunity
to update the visitor's information based on the registration's infos.

We also add some fields to get all visitors from an event, based on visitor
and registration link. This could be used for example to contact them, like
sending a mailing or push notification to all attendees of an event.

SPECIFICATIONS: VISITOR LOGIN / INFORMATION UPDATE

When a user is linked to a visitor (e.g. when customer logs in) its partner
is propagated to the registration. Using visitor as middle-model it allows
to propagate information through those models, leading to better contact
data notably.

SPECIFICATIONS: VISITOR IMPROVEMENTS + PUSH TOKEN

In this commit we improve visitor behavior. Currently when there are several
visitors that may be linked to the same user, only the last one is kept and
other one are unlinked.

However visitor model holds push tokens, allowing to store approval for push
notifications. Unlinking records is therefore a bad idea as we may loose
information. In order to solve this an intermediate solution is implemented.
A new parent_id field is added on visitors. Instead of unlinking "duplicates"
we link them to the parent and de-activate them. This means more visitors
are present in database, but this is required to keep push tokens.

A better solution would probably be to separate visitor from push tokens
but as this merge targets a stable version it was difficult to do in a clean
way.

LINKS

Community PR #53540
Enterprise PR odoo/enterprise#11384

Task ID-2252655 (Main Online Event task)
Task ID-2283796 (Event B2Basics / Registration Flow
Task ID-2284043 (Visitor-based track wishlist)
Task ID-2283869 (Notify attendees by push)

Co-Authored-By: Aurélien Warnon <awa@odoo.com>
Co-Authored-By: David Beguin <dbe@odoo.com>
Co-Authored-By: Thibault Delavallée <tde@odoo.com>
2020-08-04 14:28:29 +00:00
stefanorigano (SRI) b7fe2bdae2 [IMP] website, *: review snippets thumbs
*: website_blog, website_event, website_form, website_mail_channel,
   website_mass_mailing, website_sale, website_twitter

Part of https://github.com/odoo/odoo/pull/55089
task-2157252
2020-07-30 10:13:07 +00:00
Raphael Collet e1f514f100 [FIX] website: adapt query count
closes odoo/odoo#54878

Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2020-07-24 08:30:00 +00:00
8ae4544b76 [REF] website: improve visitor / user synchronization at authenticate
RATIONALE

Event will soon gain a major update called Event Online, allowing to better
support full-online events. In order to prepare its merge, preparatory merge
are done to lessen the final diff and have a smooth integration in a stable
version (13.3).

PURPOSE

Purpose of this merge is to clean visitor synchronization and tests. It
prepares further improvements to visitor model linked to Event Online.

SPECIFICATIONS

Add anchor methods to somehow merge visitors and update partner linked
to visitors and their sub records.

Main idea would be to be able to

  * avoid unlinking visitors, notably because we have keys linked to them
    allowing push notifications. As a given user may be linked to several
    devices (different keys / different visitors) keeping them in database
    improves push efficiency;
  * allow to link sub-records to a main visitor, like tracked pages history,
    even if multiple visitors are linked to the same identity;

In this stable we cannot remove current unlink of duplicate visitors due
to constraint of partner_id / visitor_id. However those methods allow to
tweak behavior by override. This will be done in future tasks.

LINKS

Task ID 2290016 (improve visitor synchronization and tests)
Prepares Task ID 2252655 (main Online Event task)
Prepares Task ID 2284043 (Visitor-based track wishlist)
PR #54036

X-original-commit: 8a8d2d4412d1b58545ee4f0240cca5114e541b6a
Co-authored-by: Aurélien Warnon <awa@odoo.com>
Co-authored-by: David Beguin <dbe@odoo.com>
Co-authored-by: Thibault Delavallée <tde@odoo.com>
2020-07-22 09:02:55 +00:00
2648840624 [REF] website: allow to configure delay before archiving visitors
RATIONALE

Event will soon gain a major update called Event Online, allowing to better
support full-online events. In order to prepare its merge, preparatory merge
are done to lessen the final diff and have a smooth integration in a stable
version (13.3).

PURPOSE

Purpose of this merge is to clean visitor synchronization and tests. It
prepares further improvements to visitor model linked to Event Online.

SPECIFICATIONS

Introduce a new configuration parameter in website allowing to set number of
days before de-activating visitors: ``website.visitor.live.days`` . It is
set to 30 days instead of 7 as before.

Purpose of extending delay is to be able to use visitor information a bit
longer in business flows. For example one could contact visitors 2 weeks
after an event to get their feedback. Adding a bit of delay allow to keep
those visitors alive a bit longer by default. Allowing to configure it gives
more flexibility to admins and deployment.

LINKS

Task ID 2290016 (improve visitor synchronization and tests)
Prepares Task ID 2252655 (main Online Event task)
Prepares Task ID 2284043 (Visitor-based track wishlist)
PR #54036

X-original-commit: f83af1d53716499dcad94f363aff609a2f8e55d9
Co-authored-by: Aurélien Warnon <awa@odoo.com>
Co-authored-by: David Beguin <dbe@odoo.com>
Co-authored-by: Thibault Delavallée <tde@odoo.com>
2020-07-22 09:02:55 +00:00
Thibault Delavallée 17d83775db [IMP] website: improve visitor tests
RATIONALE

Event will soon gain a major update called Event Online, allowing to better
support full-online events. In order to prepare its merge, preparatory merge
are done to lessen the final diff and have a smooth integration in a stable
version (13.3).

PURPOSE

Purpose of this merge is to clean visitor synchronization and tests. It
prepares further improvements to visitor model linked to Event Online.

SPECIFICATIONS

Make tests independent from existing database data, notably existing visitors.
Use newly-introduced tools and data. Clean tests and make them easier to
understand, notably connection / disconnection effects. Make more tests about
visitor data: name, partner_id, tracks move from visitor to authenticatedf
visitor, ...

LINKS

Task ID 2290016 (improve visitor synchronization and tests)
Prepares Task ID 2252655 (main Online Event task)
Prepares Task ID 2284043 (Visitor-based track wishlist)
PR #54036

X-original-commit: 015f70dd1ce1394d279f8fbb949948f4845c65fc
2020-07-22 09:02:55 +00:00
Thibault Delavallée 150a24ad81 [IMP] website: use HttpCaseWithUserDemo for tests and clean boostrapping
RATIONALE

Event will soon gain a major update called Event Online, allowing to better
support full-online events. In order to prepare its merge, preparatory merge
are done to lessen the final diff and have a smooth integration in a stable
version (13.3).

PURPOSE

Purpose of this merge is to clean visitor synchronization and tests. It
prepares further improvements to visitor model linked to Event Online

SPECIFICATIONS

Clean existing visitor tests. Use HttpCaseWithUserDemo and clean bootstrapping
of data.

Introduce a mock for visitor from request allowing to shortcut some visitor /
user synchronization and test directly expected results without too much
boilerplate in tests.

LINKS

Task ID 2290016 (improve visitor synchronization and tests)
Prepares Task ID 2252655 (main Online Event task)
Prepares Task ID 2284043 (Visitor-based track wishlist)
PR #54036

X-original-commit: 4e0d4e7c315b5a9d880754e02966debd6a59c728
2020-07-22 09:02:55 +00:00
Benjamin Vray a2fd2dacd9 [IMP] website: review carousel snippet
Add the width option for each slides in the carousel snippet.
Remove share links from the third slide of the carousel.

Part of https://github.com/odoo/odoo/pull/45096
task-2162952
2020-07-17 11:28:11 +00:00
Nicolas Lempereur 94db81d8d2 [FIX] website: load specific view translation
When a view is:

- a specific view (duplicated for a specific website)
- inherited by a new view that is translated

the inheriting view will also be duplicated, but the translation will
only be created for the generic version and not the specific ones.

With this changeset, we duplicate translation of arch_db terms of the
generic view onto matching specific views.

Without the change, added test fails with:

  AssertionError: '<div>hello</div>' != '<div>hi</div>'
  loading module translation copy translation from base to specific view

fixes #51579
opw-2261278
closes #52451

closes odoo/odoo#53012

X-original-commit: 989d58d26f8803b40c1411cb97b0171b05d274d7
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2020-06-16 06:27:19 +00:00
Nicolas Lempereur 4c4a0eab95 [FIX] web{site,_editor}: oe_structure save clean data-oe-*
Since dd139948f0 when saving oe_structure for the first time, for eg.
a `<div class="oe_structure" id="oe_structure_part_1"/>` structure, when
edited we will create an inheriting view that fills it.

But this inheriting view would contain branding data and "data-note-id"
which would make this use case erroneous:

- edit page and fill oe_structure => data-note-id="1" saved on view
- edit page and add link in other oe_structure => error

This happen because the data-note-id refers to the editor of the
element currently being edited, since we saved it previously we get two
elements with `data-note-id="1"` and the code will just get the first
one which in reality could have not been in editing.

With this change, we strip the branding data on the parent element.

Without the change, added test failed with:

  AssertionError: '<div class="oe_structure" data-test="1"
  id="oe_structure_test" test="2">hello</div>' not found in
  '<t t-name="dummy"><div class="oe_structure" data-test="1"
  id="oe_structure_test" data-oe-id="55" test="2">hello</div>
  </t>' :
  saved element attributes are saved excluding branding ones

opw-2268836
closes #53321

closes odoo/odoo#53346

X-original-commit: 855438be92ee71d8f8d5afedd52459e149ec49f7
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2020-06-19 14:51:34 +00:00
Raphael Collet a6c43e0366 [FIX] website, website_blog: adapt tests
closes odoo/odoo#52865

X-original-commit: ae268ec99e25d246593b3996981b4287a0ed3081
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2020-06-11 15:26:29 +00:00
fja-odoo 061ff011df [IMP] base, website: fix prewebsite specific views
Things to know about specific views:

Since the introduction of website specific views, we can have multiple
views that are related to a website (specific views). These views have
no xml_id as it is only set on the original view (generic view).
We rely on the view's key to identify related views as it is the same
for all specific views of a generic view. Also the key is equals to the
xml_id.

When a generic view is updated, we will check if the specific views have
the same values as the generic view. If it is the case, the value that
are the same are considered updatable and are updated on both the
generic and specific view. Else these are considered as noupdate.

When a generic view is created we will check if the potential parent
generic view has specific views. If it is the case we will create a copy
of the created view for each specific view.

The issue:

The method that checks if a created/updated view has specific views is
located in website. When we update a module, each modules are
initialized and updated in a specific order. If a generic view that has
specific views located in a module loaded before website this view's
specific views will not be updated/created as the method does not exist.
This issue is mainly affecting portal views at the moment.

The solution:

For write:
We now COW(copy on write) the views in base module, meaning this will
apply to all qweb views that are duplicated and not only the website
specific ones.

For create:
We  will create the generic view as before but wait until we have
updated all the modules to gather all generic views that are supposed
to have a specific view but don't and create the specific views.
This will result in a change of behavior being that if a specific view
that have a parent is deleted it will be recreated on update
(same behavior as a generic view).

closes odoo/odoo#52629

X-original-commit: b1a90ee2bb441aa52e3cf4607c43fb464b55b1d7
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Signed-off-by: fja-odoo <fja-odoo@users.noreply.github.com>
2020-06-08 17:23:59 +00:00
fja-odoo 7630ef3388 [IMP] website: add tests for website_visitor
website visitor testing had some flaws.

task-2079873

closes odoo/odoo#52281

X-original-commit: 4e5f049e48f06eb4be2a9972d06167e68bba1d61
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-06-02 16:08:43 +00:00
fja-odoo 1eb7c577ec [FIX] website_theme_install, base: fix theme update
When a theme module is updated the changes made on a view are considered
as user changes, prenventing the view from being updated in the future.

Fixed by comparing the arch being written with the arch of the original
view. If it is the same the record should not be noupdate.
Plus added a test to make sure the theme views receive theme updates
after being updated once.

Introduced by: https://github.com/odoo/odoo/commit/4acf177b4c55f3a16362cbeafea3d332ef4fe819

closes odoo/odoo#51557

X-original-commit: 221470ab9c9eda3f3a4e2da0fa1a7bb23d6288cc
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-05-19 15:42:55 +00:00
Martin Trigaux d9287caf94 [IMP] *: convert to private methods
render, render_template, load, activity_schedule_with_view,
get_website_pages should all be private:
It should not be possible to render an aribtrary template only with
its name or id

Still need to render some qweb views from js so the method
render_template is kept public.
This explains why the website editor still need read access on
ir.ui.view as we want to allow any snippet to be rendered.
2020-05-14 13:59:10 +02:00
Nicolas Lempereur 5f7de6226b [FIX] website: menu translation on website
Currently, the menu are only translated for installed language when we
create a new website.

When we create a new menu (eg. by installing a module) or install a new
language we will only translate menu without website_id set, so the menu
are not translated.

With this changeset, we try to match translation of menu without
website_id to menu with website_id when translations are updated:

- when a language is installed/updated
- when a module is installed/updated

Without the changeset, the added test would fail with:

- "Menu in english" != "Menu en français"
  Load translation add missing translation from template menu

- "Menu in french" != "Menu en français"
  Load translation with overwriting update existing menu from template

fixes #43365
opw-2209864
closes #48031

closes odoo/odoo#50498

X-original-commit: 998987f8ee148235f4025eb97a424e838ac6fc9f
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-04-30 15:45:58 +00:00
DramixDw 9b9829416b [IMP] website: simplify website menu
Some apps, once installed, automatically create a menuitem in website.
What complexify the UI and create useless menu withtout plusvalue.

It is not because you install livechat to make support online, that you want
a link in your menu to show stats e.g.

Now we remove the default menu created, and help user to find it when he create
a link. The autocomplete suggest most of the main App's controllers

task-2189613

closes odoo/odoo#49081

Related: odoo/enterprise#9733
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-05-01 07:59:07 +00:00
DramixDw 52c23e01e3 [REM] website,*: remove About us page and references
Remove the default about us page because it could be easily recreated and
doesn't add a lot of value to the website.

task-2189613
2020-05-01 07:58:11 +00:00
fja-odoo 11c60739e4 [IMP] website, *: warn user about outdated blocks
* = mass_mailing, web_editor, website_crm, website_event, website_form,
website_forum, website_hr_recruitment, website_mail_channel,
website_mass_mailing, website_sale, website_slides

When an outdated snippet's option are activated we display a warning
in the left panel that inform the user about the potential
malfunctions.

To do so the snippet's template key is added to the snippet as
data-snippet.
If a snippet is "t-call" inside another snippet, it will need to use
t-snippet-call instead of t-call to have the key on himself.

Those unique keys are used on snippet selection to retrieve the
snippet's version in the left panel and compare it with the currently
selected snippet's version. Versions are describe with data-vcss,
data-vjs and data-vxml. If a snippet's key is not in the left panel we
consider that snippet as outdated.

Added some tests to ensure that t-snippet and t-snippet-call really have
their template key as data-snippet

Adapted the views to the data-snippet changes adding
data-snippet="tmpl_key".

Part of: https://github.com/odoo/odoo/pull/44569
task-2189669

closes odoo/odoo#50254

X-original-commit: 28a6cd49b6e87b75c2e70771e241c41778bf9e87
Related: odoo/enterprise#10236
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2020-04-27 16:36:31 +00:00
Xavier Morel 0ce9165ca5 [FIX] website: search_pages w/ werkzeug 0.15 or higher
The (private) Rule.build method takes a values *dict* parameter. From
the start it was called with an invalid argument, but before 0.15
`append_unknown` would lead to just not using the argument at all
unless the rule is dynamic (aka has converters)[0].

In 0.15 the code was refactored and the `values` mapping is now used
in every case[1], leading to a pretty systematic error when calling
`search_pages`, which occurs any time an auto-completed URL field gets
used on the website e.g. when converting text to a link using the page
editor or when trying to update menu items.

Fixing this in 13.0 because while the current debian stable ("buster")
still bundles 0.14, the soon-to-be-released Ubuntu LTS (20.04) updates
werkzeug to 0.16. Debian Testing (bullseye) also bundles 0.16 but
isn't expected to get released for another year so it's less of a
concern.

Fixes #47356
Relates to odoo/docker#299

[0]
https://github.com/pallets/werkzeug/blob/c769200d1dcf1e21daaa2781f0c5109586daad42/werkzeug/routing.py#L797-L828

[1] https://github.com/pallets/werkzeug/blob/048cdfd9b969c0c3a133d7ff43b8ad1ad6a673ec/src/werkzeug/routing.py#L1020-L1032

closes odoo/odoo#50194

X-original-commit: 4f1589075d2aae65c67a01c5c0f75c19c50a61d6
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-04-27 07:34:05 +00:00
qsm-odoo e4a7103517 [FIX] web, web_editor: allow editor instantiation from public user
If for some reason someone wanted to develop a textarea using the
editor which is supposed to work as a public user (like we are trying
to do on Odoo.com), it was not possible. The code was "designed" to
allow it but there was one problem: the lazy loading of the editor
assets required a `render_template` call to the server... which cannot
be done from a public user.

This commit solves the issues by allowing the lazy loading of assets
to use a custom route if required. That route is then used by the editor
"root". That route performs the render_template as a superuser provided
that the view's xmlid is whitelisted.

Note: there was another unauthorized call for public user: the
colorpicker. This was solved by disabling the colorpicker template rpc
for public user, they will still get the default summernote one.

Part of https://github.com/odoo/odoo/pull/48981

closes odoo/odoo#48981

closes odoo/odoo#49398

X-original-commit: e84a0bfdc99c21406861b88c02b11c925d92f927
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2020-04-10 11:54:03 +00:00