Before this commit, when the amount of rows was above xls format threshold (>65535), the xlwt library threw an obscure Traceback to the user.
We now test the amount of rows before even calling the library, raising a more helpful message to the user
OPW 767319
closes#19035
The old code don't resize correctly if you use params in request.
because if '200' > 500 => return True
Now we force the casting to int to be sure to compare apple to apple.
before: /web/image/<id>?height=100 => don't return an image with height=100px
after: /web/image/<id>?height=100 => return now an image with height=100px
In case of a MemoryError, there is no error message, the user gets a
"Database restore error: "
without any details.
Instead fallback to the repr.
This way, a wrong password is
"Database restore error: Access denied"
and a memoryerror
"Database restore error: MemoryError()"
Closes#17393
With this commit, we introduce a benchmarking infrastructure: a new
controller, accessible at the route /web/benchmarks which will render a
new template (web.benchmark_suite).
This template uses benchmark.js and qunit.js to display a list of
benchmarking informations. For example, the number of op/s for
instantiating and destroying a list view.
I hope that this is the start of the beginning of taking the habit to
check our JS code performance sometimes, and making sure we do not have
large regression without a good reason.
Since the new views merge, a lot of design elements were broken. This
was particularly impacting the fields in the editable list view; indeed
the editable list view is not using an inline form view anymore so the
fields in the list were not properly styled as the LESS was still
defined assuming the form view environment (for example the invalid
fields were red for o2m fields in form view but not in editable list
view even though they got the right CSS class).
This commit refactor the LESS following these rules:
- No more division of non-layout and layout rules. Dividing LESS rules
in x_layout.less and x.less was a mistake. Many rules can be
considered to be layout and not layout at the same time, developers
always have to switch from one file part to the other, many CSS
selectors (and rules!) are duplicated for nothing, ...
- Field style is extracted from x_view.less and put in the new
fields.less file. As before, the fields_extra.less will contain the
rules specific to community so that the enterprise repo can override
those by replacing the whole file.
- Many classes have been renamed so that o_form_x_y becomes o_x_y as
many classes can now be applied outside of form view. These classes
should not be used in templates anyway.
The commit also changes the DOM of fields so that it is more minimalist
(no useless parent div, etc).
Input elements are not automatically styled anymore, they have to get
the o_input class explicitely. This allows to fix lots of small style
bugs of previous versions (required monetary field had not the proper
style, readonly m2m tags appeared as editable, ...). This also improves
the LESS code.
The editable list view should also completely stop flickering on chrome
and firefox.
The commit also removes the orange outline on list view dirty cells.
The commit also removes deprecated static xml, LESS and other code.
Notice there are still styles to restore/fix and LESS to improve.
In v8, it was not allowed to create a DB with a name containing a space.
This should still be the case from v9 since it causes issuesfor backup
scripts, for example.
Reintroduces 1a0e9063d4
opw-727613
We generally consider this a low priority issue
as it is social-engineering based and many easier
options exist for targeting gullible users.
Nevertheless, protecting a couple of obvious pages
does not hurt.
About a `sudo` on ir.ui.menu, this commit (3649b7f359) removed it,
this commit (3d0cc2d6d2) re-added it.
Since portal user can not go on /web anymore, I think portal does not need to read ir.ui.menu.
Here some news scenario:
- if website is not installed, portal can log in, but will be redirected to login page
with an error message 'only employee can access'. Indeed, there is no page to display for
such user.
- if website is installed, but not website_portal, portal user can log in and will be
redirected to homepage. If he tries to manually access to /web, he will be redirect to
login page with access error (even if he will still be logged).
- if website_portal is installed, the portal user can fully enjoy its features.
The notification mail template of a SO and an Invoice displays the logo
of the company. However, the logo is always the logo of the superuser's
company.
When accessing the logo from an email client, the UID is not defined.
Therefore, we fall back on the superuser, and display the logo of his
company.
We add the support of a `company` key in the kwargs, so we can force the
company from which we retrieve the logo. Note that this key was used
elsewhere, such as:
addons/web/static/src/js/web_client.js
opw-705420
The database manager and selector triggered an internal server error
according to the modules installed.
The issue is that some modules (like utm) overrode ir_http's dispatch
and openned a cursor before calling super. Following rev[1], the
database manager can tell you the incompatible databases. For that, it
opens a new cursor to each database and get back the Odoo's version.
After the information is fetched, the cursor is closed. Closing a cursor
does not release it from the connection pool, so the database cannot be
dropped and here comes the fix [2]: this commit removes all cursors to
`database` from the connection pool.
Now, if a module overrides the ir_http's dispatch and open a cursor
before calling `super`, the automatic commit/close done at the end of
a successful request cannot succeed in the database manager or
selector as the cursor is closed during the call to super, leading to
an internal server error.
To workaround this issue, we explicitely set the cursor to None, as it
will prevent the automatic commit/close at the end of the request.
This is similar to rev 5c6087e38e
[1] 96f703ff84
[2] 610036756a