On windows when you copy paste text in and into Odoo (for example in the description when creating a ticket) a traceback occurs.
There is an isWhitelist function which verifies that a node is indeed in the authorized items via the following instruction
`item.matches (CLIPBOARD_WHITELISTS.nodes.join (','))`
But on windows there is a comment node containing `<--StartFragment-->`
Here is the clipboard data on linux and on windows for the same copied text (Hello):
- Linux
```
<meta http-equiv=\"content-type\" content=\"text/html; charset=utf-8\">
<span style=\"color: rgb(102, 102, 102); font-family: "Lucida Grande", Helvetica, Verdana, Arial, sans-serif; font-size: 13px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;\">Hello</span>
```
- Windows
```
<html>
<body>
<!--StartFragment--><span style="color: rgb(102, 102, 102); font-family: "Lucida Grande", Helvetica, Verdana, Arial, sans-serif; font-size: 13px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;">Hello</span><!--EndFragment-->
</body>
</html>
```
Except for this additional comment on Windows, the `.matches()` method does not exist.
This PR uses the `Array.includes` function on the item's `nodeName`, which should work in all cases while keeping the same behavior.
opw-2591597
closesodoo/odoo#74029
X-original-commit: 41802bc518b4bcd1c71d8659ac560cb748befd95
Signed-off-by: Achraf <abz-odoo@users.noreply.github.com>
Followup of odoo/odoo@edf729c09e where reveal_id was changed to
a reveal_ids on industry model (comma separated list of IDs). This was changed
in IAP Mining but not here.
Task ID-2608702
closesodoo/odoo#74051
X-original-commit: 99d1f09a7284bfa7f1bead42cb20e8122e800544
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Try to download a report file but knowing that the controller will raise an Exception
in the case of l10n_be: Tax Report
Remove the VAT number on the Belgian Company and export the report as xml
Before this commit, the error was not well handled, i.e. a traceback was shown
After this commit, a Redirect dialog is shown, giving the possibility to the user to go
on the company's list view and change some company's fields.
closesodoo/odoo#74021
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
odoo/odoo#74003 updated a few docstrings, half of them being the
typing of callbacks to not use the TypeScript syntax /
extension. However in doing so it dropped critical parts of the
signature (namely the specific type of the return value -- or the lack
thereof).
Update this error to restore the information that the callbacks have
no return value.
closesodoo/odoo#74083
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
The test needs the option "Lock Confirmed Sales" enabled
The current code doesn't really activate the option
closesodoo/odoo#74059
X-original-commit: eca297a01253e2bb4fb1be6205b8e1c0f9837d98
Signed-off-by: Arnold Moyaux <amoyaux@users.noreply.github.com>
Signed-off-by: Adrien Widart <adwid@users.noreply.github.com>
Suppose a recurrent event synced with both calendars. Suppose that the
current user is not the organizer. If one occurrence of the event is
cancelled, the user won't be able to sync the calendars.
To reproduce the event:
(Need two Microsoft accounts A01 and A02)
1. [On Microsoft, with A01] Create an event:
- Recurrent (next 3 days for instance)
- With A02
2. Set the address mail of current partner with A02's address
3. Sync with Microsoft
- Note that the 3 occurrences are displayed
4. [On Microsoft, with A01] Cancel one occurrence
5. Sync calendars
Error: A Validation Error is raised: "The operation cannot be completed:
- Create/update: a mandatory field is not set [...]"
At some point, the module updates each occurrence of the event and
stores the occurrence's values:
https://github.com/odoo/odoo/blob/4ae90dd6f9e28e6fdff45c7612a3a756665e1489/addons/microsoft_calendar/models/microsoft_sync.py#L213-L220
However, the cancelled occurrence will be incorrectly stored. Because it
is cancelled, `_microsoft_to_odoo_values` will return {'active': False}:
https://github.com/odoo/odoo/blob/4ae90dd6f9e28e6fdff45c7612a3a756665e1489/addons/microsoft_calendar/models/calendar.py#L63-L65
Therefore, in the previous code, `values` will contain `(<Recurrence
ID>, None, None)`
Later, when applying the recurrence, the module detects all
already-existing occurrences and the others (i.e., those that need to be
created):
https://github.com/odoo/odoo/blob/02886f65e9026e1f7617c8b23c3d87edd358b168/addons/calendar/models/calendar_recurrence.py#L190-L192
where the ranges are tuples like `(<start of the occurrence>, <end>)`.
As a result, `ranges_to_create` will contain such a tuple `(None, None)`
which makes no sense
OPW-2571398
closesodoo/odoo#74052
X-original-commit: ccad42575ae32d7e8ffe72226cbfed2284e0326e
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
Signed-off-by: Adrien Widart <adwid@users.noreply.github.com>
Fixes taking a hald day outside of working hours counting as half a day
instead of nothing.
See odoo/odoo#68977closesodoo/odoo#74015
X-original-commit: 7ad9af5b6fd3086d280b42f6769c66d579dd7f5f
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
Signed-off-by: William Braeckman (wbr) <Williambraecky@users.noreply.github.com>
`load_views` calls `get_bindings` to render Action and Print menu. Before this
update, it read all action fields, including heavy computed fields
like `search_view` (which calls fields_view_get). But in fact just few fields
are used.
This slighly improves response time and data size.
closesodoo/odoo#73983
Signed-off-by: Géry Debongnie (ged) <ged@openerp.com>
Define `data-hotkey` on most used action buttons.
For the modals, the following keys are dedicated for "special"
actions:
- Alt+G: add
- Alt+V: save
- Alt+Z: cancel
closesodoo/odoo#73275
Taskid: 2588233
Related: odoo/enterprise#19464
Signed-off-by: Kevin Baptiste <kba@odoo.com>
When dragging out the last record of a filtered column, its filter is cleared and the column is reloaded.
Taskid-2454209
closesodoo/odoo#72755
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
BEFORE
Various scenarii leads to inconsistencies on the progressbars when a filter is activated:
- when dropping in a non matching record
- when the view domain is updated (e.g. from some input in the search panel)
NOW
These scenarii works fine.
Taskid-2491196
Taskid-2454209
This field was only used by thinking it was the banks owned by the
company, and not the banks registered for all partners by that
company.[1]
It has always been like that, since 7eab8e26d3
even though the field didn't exist on `res.company` before that
refactoring.
[1]: checked with the following regex `compan((y(_ids?)?)|ies)\.bank_ids`
closesodoo/odoo#73229
Signed-off-by: oco-odoo <oco-odoo@users.noreply.github.com>
Before this commit:
When there is too much records to post and it's take time more than 15 minutes then server was restarted.
So scheduler action will do the process with the same records again and again.
After this commit:
post record in batch of 1000
opw-2451446
closesodoo/odoo#70831
X-original-commit: 819321c3a129613890ce49e3efe9a903c3218070
Signed-off-by: rrt-odoo <rrt-odoo@users.noreply.github.com>
Since 14.3, Taxes have a country field. Newly created taxes don't always have the correct country set, thereby making the tax unusable.
Issue identified in task 2591541
closesodoo/odoo#74060
X-original-commit: e3a78dcb62200bf43c41c558a995afedf882d64a
Signed-off-by: Laurent Smet <smetl@users.noreply.github.com>
Signed-off-by: Habib Ayob <h4818@users.noreply.github.com>
Prior to this commit, if we go to visitors form view and clicked on
stat buttons like offline/connected or visits, a traceback was
thrown because the buttons are meant for showing stat only, they
aren't linked to real actions / methods. It used to work before, but
the recent traceback is result of more strict checks from the web-client
re-write. See the original commit[1] for more information.
This commit sets 'disabled' attribute on the buttons, and keeps the action
from being performed for display-only stat buttons.
commit[1] - https://github.com/odoo/odoo/commit/0573acae2306bf5da2005852da9323ddc59e5431
TaskID-2593552
closesodoo/odoo#73813
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
- Define a [DEMO] prod with tracking by SN and add some SNs
- Activate "use existing lot/serial number" on the receipt picking type
- Create a purchase order for [DEMO]
- Process the receipt in the barcode app:
* Scan the product
* Scan the SN barcode
* Validate
User will get an error.
It seems that Odoo is trying to create this SN instead of
matching the existing one
opw-2474347
closesodoo/odoo#73610
X-original-commit: 09a1252b8a5bc194ffccd6c2437985328d08ba08
Related: odoo/enterprise#19632
Signed-off-by: Rémy Voet <ryv-odoo@users.noreply.github.com>
Signed-off-by: agr-odoo <agr-odoo@users.noreply.github.com>
In 2018 geoip2 support was added to allow the new database format that
are freely available. But for these, only a subset of properties are
available.
Since Odoo 13 (August 2019), the sign module is using geoip latitude and
longitude for logging access to sign module signatures, but this was
only working for database using the first version of GeoIP databases.
In other use case there would never be any geolocalization recorded.
With this change, latitude and longitude are available in the session if
the right module/database is installed.
opw-2426323
closesodoo/odoo#73997
X-original-commit: 2be13b57749ac2c45de60717544c3061bbb29671
Signed-off-by: Christophe Simonis <chs@odoo.com>
jsdoc apparently doesn't understand arrow functions to indicate
function-valued attributes. Also add some default values in the
notifications typedefs.
closesodoo/odoo#74003
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Before this commit, overrided images was not visible if not logged in.
How to reproduce
----------------
Install a theme with configurator to have custom image of industries.
Log out
You have original image instead of industries
closesodoo/odoo#73921
X-original-commit: d1241379a7c5f999b7a82ca290dd8b5f212a0997
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Currently, some business object related menus have the
same names with the technical menus and it creates
confusion among users.
This commit renames the following menus:
- in fleet app, 'Models' menu is renamed to 'Vehicle Models'
- in website app, 'Views' menu is renamed to 'Page Views'
Apart from that, to be consistent with menu item, this commit
also renames the action 'website_visitor_view_action' from
'Views' to 'Page Views'.
TaskId-2595993
closesodoo/odoo#73755
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
The current behaviour implies that the quantity delivered will never
be updated if there are related moves that have been cancelled.
After the fix, when computing the quantity delivered, it will only
consider the stock moves that are not cancelled.
closesodoo/odoo#73573
X-original-commit: 6f6366888415c5e020ffee893a78cc7a3f6925f5
Signed-off-by: William Henrotin <Whenrow@users.noreply.github.com>
Signed-off-by: Arnold Moyaux <amoyaux@users.noreply.github.com>
non-owl JS-side of #68072:
* deprecates `t-raw`
* adds a `t-out` which `t-esc` aliases and which "does the right thing"
* introduces a `Markup` function / object which is considered markup-safe by t-out (thus left unescaped)
- unlike the python version, most of the override hooks (e.g. concatenation, formatting, ...) are not available in JS, we might eventually want to override some of the action methods (e.g. replace) but so far the needs seemed pretty limited
- and javascript pretty strongly differentiates between a string (primitive) and a String (object), the latter being what Markup gets
- so various constructs which can return a Markup in Python can't really afford to in JS: I tried with QWeb and e.g. jquery *really* does not deal well with non-primitive strings, as a result `_.escape` is shimmed to understand `Markup` objects but will not return markup objects when escaping strings
- `sprintf` (the one from web.utils) was updated for Markup-awareness for convenience though
- and `Markup` can be used as a template tag, in which case it will automatically escape the substitutions
- removed `messageIsHtml` from the non-owl notifications, replaced by the message being a markup object
- updated Dialog to work the same way (it did not even have a flag), removed explicit escaping from most of the callsites (only found one where we actually leveraged dialog titles being markup)
- modified the kanban view so HTML non-raw values automatically get wrapped in Markup
Also moved some formatting from the server to the client, either removing the need to inject markup entirely or making the use of `Markup` much cleaner than just "mark whatever the server returned as safe".
There are a few things I'm not entirely sure about e.g. whether even using markup is necessary for `formatMonetary`, doesn't the "unicode" NBSP work fine in HTML? Though we may need to keep `forceString` to ensure something like ascii-compatibility.
closesodoo/odoo#70004
Related: odoo/enterprise#18005
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Remove t-raw and mark website_description as markup-safe right after
fetching it.
Also update `_fetchSponsor` to use async/await, and remove seemingly
unnecessary empty div in template, and convert `<span>` to `<div>` as
the contents is arbitrary and thus could be a block.
Replace the t-raws used for the end-of-quiz message by t-outs.
This requires marking the two subfields of `quiz/submit` as Markup,
rewrite the method in a more modern style while at it.
Also update the tour to ensure that the message is indeed inserted as
markup, reset the users' karma to a known value to ensure the
motivational message is predictable.
* direct product attributes seem to not be necessary at all,
`list_price` and `price` are just numbers
* mark `description_sale` as markup-safe at load
* mark ribbon.html as markup-safe at load
* mark embed code value as safe on rendering
Mark the fragments as markup-safe after fetching them.
Also make _render private (don't see any reason for it to be publicly
accessible), and avoid unnecessary intermediate enc/dec in it.
Update `_deletePage` to mark `.text` as markup-safe, and modernize the
code base: the outer promise seems useless, and so does the
`cancel_callback` of the dialog.
Using `sale_product_matrix`'s tour as `product_matrix` doesn't
actually have any test for this.
Remove t-raw from the product_matrix(.extra_price) template, by moving
the formatting to the client side (unclear why it was done by the
server in the first place).
Also fixes a bug where a negative price_extra would have *two* `-`
signs: one before the currency, and one after the currency: the price
being formatted should be abs'd to avoid a negation being generated by
the monetary formatting. Also uses non-breaking spaces everywhere
where the server-side formatting mixed breaking and non-breaking
spaces. Keeps from the original the peculiarity that the extra price
should always have a sign positioned before prefix currency signs.
Also changes the calling conventions of `product_matrix.extra_price`:
instead of being called with a formatted `price` it's now called with
the entire cell object.
Replace t-raw by t-out when outputting the chatter message.
Mark message body as safe during preprocessing: messages from the
portal chatter are automatically escaped when
posted (`/mail/chatter_post` assumes the message body is plaintext,
and escapes it before formatting it based on newlines, maybe one day
it'll accept markdown) while messages from the backend chatter are
"HTML-light" and should be sanitized.
And convert the `t-esc` in the template to `t-out` while at it.
So this was a bit of a bummer initially, the PopoverWidgetField gets a
pile of JSON as its value (so from the server), and that pile contains
a template name (optionally) and... the template context,
basically. For leadDaysPopOver the issue was some of that context is
supposed to be rendered HTML to straight inject into the template,
marking that as HTML-safe would be a bit of an issue (having the JSON
specify which parts of the value it returns are HTML-safe being a bit
of a conflict of interest).
However turns out the thing is way over-complicated and
over-engineered: `lead_days_description` necessarily has a very
regular structure owing to being injected as a set of table rows, so
the various overrides to `_get_lead_days` just make their own lives
complicated by formatting the values they want to return into table
rows matching the format of an unrelated template.
Instead we can change the signature of `_get_lead_days` so the
"description" is a list of values to inject in the table (list of
pairs, each pair matching the corresponding columns of the table). The
template can then take care of formatting those values into table rows
the usual way, removing the need for any injection of raw content.
This also makes for better / clearer translation strings.
Remove t-raw of alert messages:
* Add alert testing to one of the existing tests.
* Transform widget data straight in `_fetchWidgetData` so the widget
itself only ever sees the "proper" shape of things (to come), this
includes the existing parsing and reformatting of `wallet`, as well as
the new wrapping of all alerts' `message` in a `Markup`.
Note: conditional updating of `alerts` because while the endpoint
actual always sets it, test data doesn't necessarily do so (?).
Mark the message body as safe pretty much as soon as we receive the
message from the server:
* when receiving message-type notifications
* while loading history
Also reorder history loading a bit while at it:
* convert willStart to async
* immediately reverse & wrap history right there, seems unnecessary to
wait until willStart since `reverse()` works in-place anyway
* when loading messages into the thread, `_.each` seems unnecessary,
Array#forEach will do fine
Need to check and mark legit uses of HTML as Markup. Also fix some
title formattings which are not great (mostly around translations) and
de-escape titles which don't need to be escaped anymore.
Requires markup every markup-using tip content as Markup. Would be a
nice occasion to migrate everything to a markup-safe markdown I think,
especially if we could migrate the translations so we don't lose them.
Add HTML fields support to kanban view (currently bespoke but maybe it
should be done via `format`), and remove t-raw for HTML fields there.
Also just strip some t-raws which were completely unnecessary to start with
Descriptions which need to use markup should be explicitly marked as
such. Update examples test to check that both Markup and String
descriptions work fine.
`escFormat` had to be modified quite a bit and ended up requiring
being its own Markup-adjacent type: if the `sprintf()` result is wrapped
in a `Markup`, then what happens is we first decide to escape because
the object returned by `escFormat` only has a `toString()`, then that
blows up because `toString` returns a non-primitive object and the
regex used to implement `_.escape` is very very unhappy.
`escFormat` could return a `Markup` object but then it wouldn't be
lazy anymore which would rather miss the point.
Therefore implement `[_.escapeMethod]` on the thing, such that it
doesn't get escaped, because it's safe (ish).
Also as a result the icons probably don't need to be markup-ed. Oh
well shouldn't really matter.
A note concerning the attributes which I will probably need to take a
look at in the vdom version: the Python version has to process attf in
order to stringify individual elements, and separately stringify the
attribute value so it gets forcefully escaped even if it's
markup-safe (because markup-safety and attributes-safety are
different).
The first should not need to be performed on the JS side, because
Markup can not overload addition, therefore in JS String + Markup is
String whereas in Python it's Markup (and the String gets forcefully
escaped). In general, js!markup is currently much simpler than
py!markup, both by necessity (can't overload operators) and
simplicity (we might want to overload some of the operations
e.g. String#replace, but that's complicated and it's not been strictly
necessary for now).
Also wrt Markup / _Markup: `class` ctors can only be invoked with
`new` meaning they can't be used as template strings or regular
functions. Here `class` is useful to avoid the mess of calling the
super's constructor explicitly (which may not even be possible for
`String`), however it means we need a facade function to support our
use-cases.
Also update `utils.sprintf` to be Markup-aware: if the format string
is a Markup object, interpolated values get automatically escaped (if
necessary) and the result remains a Markup object.
If we need to perform explicit instance check we can always set
`Markup.prototype = _Markup.prototype` (I think), however in theory
that's not necessary: there are protocols in place for the relevant
pseudo-escaping operations and they ought suffice.
qweb/js divergence from qweb/py
===============================
Unlike qweb/py, qweb/js will *not* return a Markup object. That is
because in js a primitive `string` and a boxed `String` object don't
match when typechecking, and while `markup instanceof String` passes,
`typeof markup === 'string'` does not.
The overwhelming majority of string typechecks are the latter: there
are all of 6 `instanceof String` in the entire codebase, all in
dependencies, while there are hundreds of `typeof $X === 'string'`,
several of which get fed the output of template rendering
e.g. `jQuery.parseXML` or `AbstractView#init` (some widgets will
render a template then use it as the `arch` of a subview, so
`viewInfo.arch` can be the output of a qweb template rendering). This
makes for very annoying and somewhat gnarly debugging.
Plus jQuery in particular really doesn't like being fed a boxed
String, as it will interpret said boxed string as an array, and assume
it's an array of DOM elements to wrap, leading to a rather strange
jQuery object as output. Since feeding the result of a template
rendering to jQuery is a major use-case in non-vdom widgets... that's
a bit of an issue.
For the same reason while `_.escape` is `Markup`-aware, unlike
`markupsafe-escape` it does not *produce*, though it is
`Markup`-transparent.