Commit Graph
82 Commits
Author SHA1 Message Date
Louis (wil) 3f6f949fa5 [I18N] export sources
closes odoo/odoo#140002

Related: odoo/enterprise#49687
Signed-off-by: Louis Wicket (wil) <wil@odoo.com>
2023-10-27 08:36:16 +00:00
Thomas (thbe) 922d8efe79 [ADD] auth_{signup,totp}: New connection to user mail alert
Prior to this, there was no way of knowing when a new device logged
into your personnal account.

Adding the new version of the authenticate function, user's will now
automaticly receive a mail containing informations on a new connection
made to their account.  This system uses a mail template sent
automaticly on a new connection if the user has activated 2FA and if
his device his not in the trusted devices of his account.

task-3191567

closes odoo/odoo#115362

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-10-25 11:37:09 +00:00
Michael (mcm) 7422eb643c [IMP] *: remove legacy rpc
This commit removes the files ajax.js and rpc.js then adapts all the
places where their exports were used. For most of the changes, it's a
replace of `this._rpc({...})` by a new `useService("rpc|orm")` like
pattern in the widgets.

closes odoo/odoo#136271

Task: 3439226
Related: odoo/enterprise#47775
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2023-09-27 11:33:01 +00:00
Jorge Pinna Puissant 52e20a3dd3 [REF] web, *: change name noReload to reload
This commit change the name of the option noReload to reload, this is to
avoid having negative variables names for boolean. This is a general
known best practice, and in this case it's important to have a better
readability of the code (specially when a negation of a negative
variable occurs).

closes odoo/odoo#134317

Related: odoo/enterprise#46913
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2023-09-06 10:25:59 +00:00
Gorash 774a3fad0e [REF] base,all: Update modifier syntax: view migration
Apply of the migration script to update all view modifiers.

Part-of: odoo/odoo#104741
2023-08-18 09:49:13 +02:00
Bastien PIERRE 65242e31e9 [IMP] *: Remove alias in JS files
Rename all imports with alias old system to the new js module system
Task ID: 3266759

closes odoo/odoo#127414

Related: odoo/design-themes#671
Related: odoo/enterprise#43716
Signed-off-by: Bastien Pierre (ipb) <ipb@odoo.com>
2023-07-27 11:58:34 +02:00
218ad8456a [REF] *: adapt codebase to new RelationalModel
This commit adapts the code in addons w.r.t. the introduction of
the RelationalModel.

Main changes that were requested are:
 - record datapoints no longer always have an "id" key in their
 data (they still do if the id field is in the view), so we use
 record.resId instead
 - the new model is based on fined-grained reactivity, so several
 components that previously relied on onWillUpdateProps to update
 their internal state no longer worked. Typically, using the hook
 "observeRecord" is the way to go now.
 - specialdata are no longer handled in the model, so the components
 needing specialData can use the hook "useSpecialData"
 - more generally, all overrides of models (RelationalModel or
 KanbanModel) needed to be reworked.

Part of task~3179751

Part-of: odoo/odoo#114024
Co-authored-by: Aaron Bohy <aab@odoo.com>
Co-authored-by: FrancoisGe <fge@odoo.com>
Co-authored-by: Jorge Pinna Puissant <jpp@odoo.com>
Co-authored-by: Pierre Rousseau <pro@odoo.com>
2023-07-24 20:17:50 +02:00
Julien Carion (juca) 6c412be2ea [IMP] *: coherent hotkey uses
This commit makes hotkey uses more coherent throughout the entire
codebase by setting alt+q as main shortcurt for confirm and default
actions and alt+x for cancel actions.

task-3370463

closes odoo/odoo#127469

Related: odoo/enterprise#43694
Signed-off-by: Mathieu Duckerts-Antoine (dam) <dam@odoo.com>
2023-07-19 18:24:15 +02:00
Pierre Pulinckx (pipu) 8bfa76a842 [REF] *: Unify _t and _lt
The goal of this commit is to prepare ground to remove
lazytranslate function _lt() and keep only _t()
for a better understanding of the use of the translation function.

In this commit,

the translate function _t() has been updated to return the translation
if they are loaded. If not, it throws an error.
the lazytranslate function _lt() returns _t() function.
Corollaries :
Steps in test tours are now a function that returns an array of steps
to avoid any interpolation of _t in this ones before translations has
been loaded.

Example :

registry.category("web_tour.tours").add("example", {
    test: true,
    steps: () => [
        {...},
        {...},
    ],
});

task-3292454

closes odoo/odoo#124157

Related: odoo/enterprise#43153
Signed-off-by: Samuel Degueldre (sad) <sad@odoo.com>
2023-07-19 13:13:16 +02:00
Xavier-Do 595aa24843 [IMP] registry: multiple ormcache
One of the main issue with ormcache is that the invalidation clears
everything, meaning that some value, slow to compute but with a long
lifetime, can be removed from the cache because an easy to invalidate
value is cleared, like after writting or creating a product has an
example.

Most example in the code will try to invalidate the cache of the models
doing something like `env['ir.qweb'].clear_caches()` but it is
finally equivalent to `env.registry.clear_cache()`, and cross worker.

The idea is to have multiple cache, maybe with specific sizes for a
specific purpose.

Having one per model is maybe a bad idea because it will be difficult
to size the LRU correcly, and it is too dynamic. Checking invalidation
may be expensive.

The proposed solution is closed allow a limited number of named caches,
using onse sequence per cache. This is actually close to the
cache_longterm.

We want to discourage using a specific cache for one use case in
the buisness code. Adding a cache shouldn't be something easy, doable
in stable.

Note that we could also change the invalisation mecanism using an
insert only table. We an check the sequence of this table, but also
fetch all invalidation messages.
Another possible improvement, especially if we have more than x cache is
to have a global sequence, checking signaling would mean to check the
main sequence, and only the other ones if the main one changed.

Note that this poc is inspired from the long term cache but not all
use case where applie yet.

Part-of: odoo/odoo#119813
2023-07-18 11:42:26 +02:00
Denis Ledoux 58ea5e7b43 [IMP] http.py: do not inject context by default in JSON routes
Before this revision, when you pass `context` in the arguments
of a JSON routes, this one gets automatically injected
in the environment context.

This is not the case for regular HTTP routes.

It makes sense to propagate the context for the JSONRPC protocol,
JSON routes used by the backend, such as `call_kw`,
but it doesn't make sense to pass this context automatically
for any other kind of routes, such as front-end routes
or routes used by custom Javascript widgets.

This change brings a more unified behavior for routes
of types HTTP and JSON.
In addition, most developers were not aware of this "feautre",
that passing `context` in the arguments of a JSON route leaded
to the injection of this context in the environment context.
This is actually reflected by the diff size this changes required,
only a dozens of routes needed to be adapted, to manually
add the context in their route arguments and to inject it
in their environment context.

closes odoo/odoo#121726

X-original-commit: a7a5655631e6d5b05fd2ba3d0c80617aae6d9cfe
Related: odoo/enterprise#41229
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
2023-05-22 11:43:04 +02:00
stefanorigano (SRI) 79f57643ce [REF] web, mail, hr, website, auth_totp, test_apikeys: top-menu design
task-2818586

Part-of: odoo/odoo#116641
2023-05-12 22:59:13 +02:00
Michael (mcm) 8e3854e2ac [FIX] auth_totp: fix totp tours
This commit fixes the totp tours which fail on a step in
the profile dialog. The step searches for an element
".o_dialog_container" that is removed since commit
e51112e0df7f5e05d3cdf2c01d236c6bbbf123a6

closes odoo/odoo#117451

Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2023-04-04 13:35:18 +02:00
Michael (mcm) ff0d6dd580 [REF] *: replace odoo module by native one
This commit converts almost all odoo module by native module.
The goal is to deprecate odoo.define in favor of native module and then
simplify boot.js by removing the regexp that finds module dependencies.

task id: 3162300

closes odoo/odoo#117305

Related: odoo/enterprise#39118
Signed-off-by: Géry Debongnie <ged@odoo.com>
2023-04-03 17:07:24 +02:00
Joseph CaburnayandJulien Mougenot 3a798039d6 [REF] web_tour,*: convert web_tour to owl
* The tours are now run by the `MacroEngine` defined in `macro.js`.
  * This is accomplished by converting (at runtime) the user-defined tours to
    `Macro`s. See `tour_compilers.js` for the step (and tour-to-macro) compilation.
* API is kept the same as much as possible. Basically, declaring tours stayed
  the same with some exceptions:
  * `allowInvisible` can be provided in a step to allow consuming the trigger
    element even if it is invisible.
  * `isCheck` can now be used to replace the no operation `run` that is
    traditionally signals the runner to only perform a check.
  * Before, multiple `run`s can be called simultaneously. Now, each `run` method
    is awaited before proceeding to the next step.
* If the trigger element is `disabled`, the tour runner will *not* proceed on
  calling the `run` method and the runner will stay on current step until the
  trigger element becomes `enabled`.
  * However, the tour runner is okay with `disabled` trigger element if the step
    has `isCheck = true`. As long as the trigger element is found for `isCheck`
    step, the tour runner will happily move to the next step.
* Some tours are adjusted to properly run with this new tour runner.
* When the tour failed:
  * The dom string is not logged anymore.
  * However, a warning message containing the relative location of the step will
    be logged. This is better in helping the author in locating the failed step.

**Some guidelines learned during the development:**

* Each step may trigger a dom mutation. It's a good practice to insert an
  intermediate step that *checks* the existence of an element that result from
  the action of the previous step.
* Refrain from using the `run` method for assertions. `run`, in principle, is
  provided to perform actions that are not offered by the helper. Use the
  `trigger` for assertions.
* During dev, find `SHOW_POINTER_DURATION` and set it to `250`. This will show
  the pointer (pointing to the trigger element) for 250ms when watching the
  tour.

closes odoo/odoo#107618

Task-id: 3082036
Related: odoo/enterprise#37560
Signed-off-by: Géry Debongnie <ged@odoo.com>
Co-authored-by: Julien Mougenot <jum@odoo.com>
2023-03-15 13:19:45 +01:00
Florian Vranckx 4ac35f1170 [IMP] auth_signup, auth_totp: isolate signup_token and auth_totp
This commit is a security reinforcement.

It applies the same logic as for the password of the user to the totp_secret and signup_token

closes odoo/odoo#113753

Signed-off-by: Vranckx Florian (flvr) <flvr@odoo.com>
2023-02-28 18:08:12 +01:00
Géry Debongnie b53f78e224 [REF] web_tour,*: use the registry in collecting the tours
This is a step closer to a goal of avoiding dependence on asynchronous
modules. Starting from this commit, new tour definition should be
registered to `registry.category("web_tour.tours")` registry.

So, instead of the following:

```js
import tour from "web_tour.tour";
tour.register(name, options, steps);
```

We now do:

```js
import { registry } from "@web/core/registry";
registry.category("web_tour.tours").add(name, optionsWithSteps);
```

Notice the `options` and `steps` params are merged when registering
the tour definition. It should look something like so:

```js
registry.category("web_tour.tours").add("account_tour", {
  test: true,
  steps: [ ... ],
});
```

And if the `TourManager` instance is needed, one can get it from the
registry like so `registry.get("tourManager")`. Note however that
this instance is only available when the `TourManager` has been
instantiated -- so it's not available at top level of the module.

closes odoo/odoo#111103

Related: odoo/enterprise#36335
Signed-off-by: Géry Debongnie <ged@odoo.com>
2023-01-27 23:17:35 +01:00
Martin Trigaux 776689b0f4 [I18N] *: export saas-16.1 source terms
closes odoo/odoo#110752

X-original-commit: 56b2b52287a8f2192d80ea417c7efac80a87c0a9
Related: odoo/enterprise#36173
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-01-24 10:20:30 +01:00
Julien Castiaux 3d1f486bcc [IMP] *: update modules to use the new geoip API
request.geoip is no more a dictionnary cached in the session. It is now
a full blown object with lazy and smart geolocalisation capabilities.

Among other things, the previous dictionnary API is now deprecated. The
changes are:

* `request.geoip['country_name']` -> `request.geoip.country_name`
* `request.geoip['country_code']` -> `request.geoip.country_code`
* `request.geoip['city']` -> `request.geoip.city.name`
* `request.geoip['latitude']` -> `request.geoip.location.latitude`
* `request.geoip['longitude']` -> `request.geoip.location.longitude`
* `request.geoip['region']` -> `(request.geoip.subdivisions[0].iso_code if request.geoip.subdivisions else None)`
* `request.geoip['time_zone']` -> `request.geoip.location.time_zone`

It is safe to access all the attributes. Doing `request.geoip.city.name`
when the geolocalization failed (missing db, invalid address, ...)
evaluates to None. It does not raise an AttributeError.

Task: 2848206
Part-of: odoo/odoo#91337
2023-01-03 13:16:02 +01:00
amdi-odoo 2a015600b2 [FIX] web,auth_totp,base: fix 2FA views
Web:

Adding a css rule constraint to avoid the rule
from overwriting the o_field_highlight css class
applied on a field in a form view.

Base, auth_totp:

Adding the o_field_highlight class on the 2FA
form fields to display the input bottom border and
thereby more easily identify the fields.

Adding a placeholder to the 2FA password field.

Modifying the 2FA title and toggle font to keep
a consistency between the different page titles.

Task-3083540

closes odoo/odoo#108611

X-original-commit: c128a01490bbbcbf824781f5e8716aa30e65ba5b
Signed-off-by: Warnon Aurélien (awa) <awa@odoo.com>
2022-12-26 11:39:47 +01:00
Damien Bouvy e647a2de09 [IMP] *: adapt to grid form views
The recent switch from tables to css grids for form views `group` nodes
has introduced several inconsistencies/issues with several views accross
modules - these will not be the last fixes.

closes odoo/odoo#102174

X-original-commit: 836568dfd59886a6d52f15e0e2109709903b6803
Related: odoo/enterprise#32295
Signed-off-by: Bouvy Damien (dbo) <dbo@odoo.com>
2022-10-11 13:15:12 +02:00
Martin Trigaux 1a8772769e [I18N] *: export 16.0 source terms
closes odoo/odoo#100573

Related: odoo/enterprise#31507
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2022-09-20 13:48:49 +02:00
Romain Estievenart 98a97d0fea [IMP] *: removes .form-group
this commit removes the usage of .form-group class which is deprecated
since BS5.

Here is the css rules that was used:

a) https://github.com/twbs/bootstrap/blob/8fa0d3010112dca5dd6dd501173415856001ba8b/dist/css/bootstrap.css#L1997
As we can see, it simply adds a `margin-bottom` of `1rem` which
corresponds to the `.mb-3` BS class.

b) https://github.com/twbs/bootstrap/blob/8fa0d3010112dca5dd6dd501173415856001ba8b/dist/css/bootstrap.css#L2326
As we already checked all `form-inline` in [1] and [2], we don't have to
do anything about these rules.

'''Breaking change: Dropped form-specific layout classes for our grid
system.
Use our grid and utilities instead of .form-group, .form-row, or
.form-inline.'''

https://getbootstrap.com/docs/5.0/migration/#forms

Notes:
- `position: relative` is already on `#new-password-group`.
- `.field-db`, `#editor-media-image`, `.unsplash_img_container` and
`#url-form-group` seems unused.
- Sometimes margins are unnecessary because of blocks overlapping.
  (e.g. `margin-bottom` is not needed if margin-top is set on the
  following node)
- CSS rules applied on `.s_website_form_rows > .form-group` are now in
the XML by adding `mb-0 py-2` BS classes.

Follow-up of:
[1] https://github.com/odoo/odoo/pull/97967
[2] https://github.com/odoo/enterprise/pull/30343

closes odoo/odoo#100052

Related: odoo/enterprise#31261
Signed-off-by: Adrien Dieudonné (adr) <adr@odoo.com>
2022-09-16 20:51:56 +02:00
Paul Morelle 972b54f918 [FIX] auth_totp,auth_totp_portal: fix typo in login verb
Login is a noun and not a verb. The corresponding verb is Log in.
And indeed the translation in French was "Identifiant" instead of
"Se connecter".

closes odoo/odoo#99478

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2022-09-06 10:58:13 +02:00
luvi 33925701aa [FIX] web: fix the copied tooltip of CopyButton
This commit fixes the style of the field, which was
pretty broken since the Owl conversion.
It also bring back the tooltip (as in legacy) when
the button is clicked.

The button now only shows the tooltip if the text
has been copied successfully to the clipboard, and
not appear when it is not allowed or not available
in the browser.

Tests have been added to assert those behaviors.

Enterprise PR to adapt a selector in tests:
https://github.com/odoo/enterprise/pull/30832

closes odoo/odoo#98340

Related: odoo/enterprise#30832
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2022-08-30 00:46:26 +02:00
Romain Estievenart 36628c9b1c [FIX] *: removes .form-inline
this commit removes the usage of .form-inline class which is deprecated
since BS5.

here is the css rules that was used:
https://github.com/twbs/bootstrap/blob/8fa0d3010112dca5dd6dd501173415856001ba8b/dist/css/bootstrap.css#L2303

'''Breaking change: Dropped form-specific layout classes for our grid
system.
Use our grid and utilities instead of .form-group, .form-row, or
.form-inline.'''

https://getbootstrap.com/docs/5.0/migration/#forms

We also took the opportunity to remove some .input-group-append and
.form-group. We are currently working to remove all of them.

Part-of: odoo/odoo#97967
2022-08-16 09:19:08 +02:00
Xavier Morel 5c02342704 [FIX] auth_totp: fix the incomplete fix
The previous pass in #97567 missed a small window of race condition
in *closing the fecking dialog*. Apparently that's still not
instantaneous enough and it's possible to have the check trigger in
the interval between clicking the button and the dialog being
completely torn down.

Add an explicit test for this to the existing `closeProfileDialog`
utility function.

closes odoo/odoo#97969

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-08-11 17:57:23 +02:00
Xavier Morel 4febee1998 [FIX] auto_totp: totp tours when hr is not installed
When #96517 was merged, it was missed that if hr is *not* installed,
then the user profile opens in a dialog in edition mode (always, can't
be readonly).

Since half the tours of `auth_totp` end in the profile screen (to
check that the totp state is what we expect) this means they work fine
in most test contexts where `hr` is installed, but they fail as soon
as `hr` is *not* installed.

Fix this by adding a helper function which checks whether the profile
screen uses a dialog or not, and closes the dialog if so (otherwise it
does nothing as the "form" profile screen is not in edition mode).

While at it, improve a bunch of steps:

- fold check steps which were really `extra_triggers` (something we
  wanted to check but not manipulate, in the same screen as something
  we do want to manipulate)
- convert a few promise-based functions to `async` (tours don't
  support promises but async functions work either way and lead to
  simpler code here)
- make better use of the tour action helpers (no need for explicit
  `_get_action_values` calls for the most part, and no need to
  call the internal versions either)
- clarify a pair of fixmes as I'd completely forgotten what they meant

closes odoo/odoo#97567

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-08-08 21:03:13 +02:00
+2 bc0a0cead6 [IMP] web,*: enable owl list & form views
The new list and form views were merged recently [1], but they
weren't activated because they weren't 100% ready yet. This is now
the case. This commit adds those views to the view registry. As a
consequence, a lot of qunit tests and tours needed to be adapted,
mostly for selector changes.

We also add legacy list and form views to the view registry, with
keys 'legacy_list' and 'legacy_form'. This allows to force those
legacy views when necessary. For instance, we did it in views
using complex custom legacy x2many field widgets that haven't been
converted yet (we have a compatibility layer but it isn't complete
and doesn't support every advanced usecases).

[1] odoo/odoo#92475

Part-of: odoo/odoo#78221
Co-authored-by: Aaron Bohy <aab@odoo.com>
Co-authored-by: Bruno Boi <boi@odoo.com>
Co-authored-by: Géry Debongnie <ged@odoo.com>
Co-authored-by: Samuel Degueldre <sad@odoo.com>
Co-authored-by: Mathieu Duckerts-Antoine <dam@odoo.com>
Co-authored-by: Simon Genin (ges) <ges@odoo.com>
Co-authored-by: Francois (fge) <fge@odoo.com>
Co-authored-by: Michael Mattiello (mcm) <mcm@odoo.com>
Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Lucas Perais (lpe) <lpe@odoo.com>
Co-authored-by: Jorge Pinna Puissant <jpp@odoo.com>
Co-authored-by: luvi <luvi@odoo.com>
2022-07-22 16:21:45 +02:00
Martin Trigaux d3cc71db72 [FIX] auth_totp: remove outdated trusted devices
The trusted devices are valid for maximum 90 days (TRUSTED_DEVICE_AGE).
No need to keep them in the list of trusted device, it may even be
confusing.

closes odoo/odoo#95796

X-original-commit: 49130e60a3c43fa3df0adddbd3359e437f5bc0b2
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2022-07-12 06:21:03 +02:00
Romeo Fragomeli 1fcd098af5 [REF] *: BS5: migration
Automated change made by a lot of RegEx to change all think that is
possible to automate.

https://getbootstrap.com/docs/5.1/migration

Task ID: 2766483

Part-of: odoo/odoo#95450
2022-07-07 13:30:24 +02:00
Romeo Fragomeli eee625bbb0 [REF] *: BS5: Migrate btn-block
Due to the removal of btn-block we need to change the display to grid

> Dropped .btn-block for utilities. Instead of using .btn-block on the
> .btn, wrap your buttons with .d-grid and a .gap-* utility to space
> them as needed

https://getbootstrap.com/docs/5.1/migration/#buttons

Task ID: 2766483

Part-of: odoo/odoo#95450
2022-07-07 13:30:23 +02:00
Olivier Dony 6b23d8a2ca [FIX] auth_totp: show trusted devices in user prefs
PR #75535 introduced trusted devices, but only made them visible in the
main user form (for admins) and in the portal.

It's quite useful for users to be able to view and manage their trusted
devices in their own user preferences as well.

This commit add them in the "Account Security" of the user profile.

In addition:
- improve the layout of the trusted devices by wrapping them in a
  <group> to have them stand out from the surrounding prefs
- move the "Account is protected" label about the trusted devices, and
  under main the 2FA toggle button, where it's supposed to be.
- removed the custom form view for trusted devices inside the one2many.
  The point was to hide the extra `scope` field, but it's not worth it,
  and the Cancel button wasn't even working, the default form view is
  better.
- improve the confirmation message of the "Revoke All" button when it's
  located on the user management form (for admins) to clarify that it's
  not the admin's devices that will be revoked.
- change the 2FA label from "Your Account is protected" to "This account is
  protected" when located on the user management form for admins.

Note: this is a manual partial fwd-port of #94111, as this part was
mistakenly dropped in the fwd-port chain at #94193

closes odoo/odoo#94869

X-original-commit: d3a7910788ceff856fc6a843876579d379ce9caf
Signed-off-by: Olivier Dony <odo@odoo.com>
2022-06-29 17:11:39 +02:00
Olivier Dony 038cdc66b9 [IMP] auth_totp: add trusted device method to validate user
Adds a variant `_check_credentials_for_uid()` for auth_totp.device's
`_check_credentials()`. The new method will directly verify the device
key matches the given uid.

This spares the redundant uid comparison on the caller side, and
allows extension modules to customise the user/device matching logic.

closes odoo/odoo#94365

X-original-commit: 0e266eb3c73409950d1eb160c41eb6668d439856
Signed-off-by: Olivier Dony <odo@odoo.com>
2022-06-23 02:05:42 +02:00
Raphael Collet 6cf8db906f [REF] *: adapt code to new flush API
closes odoo/odoo#87527

Related: odoo/upgrade#3497
Related: odoo/enterprise#26939
Signed-off-by: Raphael Collet <rco@odoo.com>
2022-05-25 18:00:47 +02:00
Nicolas Martinelli 0edcd1ac41 [IMP] base, auth_totp: log user in case of failed login
When a login attempt is ignored, we add the user info for a better
understanding on the attack (brute force, credentials stuffing...).

closes odoo/odoo#91588

X-original-commit: 0f69448202244e808e1122a618be701806d606cf
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
2022-05-18 07:14:00 +02:00
Julien Castiaux 04e972660b [IMP] core: don't save visitor default session
Every request comes with a session, a dictionary that is persisted on
the filesystem and that saves various information such as the user
cart on the ecommerce.

When a user simply visits the website, a default session is created and
saved on disk, this bloats the filestore with many sessions. Creating
the session on-the-fly is cheaper than loading it from the filesystem.
With this work the default session is not saved on disk anymore unless
explicitly asked via `session.touch()`.

An exception to the statement "creating the session on-the-fly is
cheaper" is geoip, the ip geolocalization is not cheap. In this work,
geoip have been moved from http_routing/request.session.geoip to a
lazy property core/request.geoip. When requested the info is persisted
on the session. Like other keys from the default session, geoip will not
be persisted unless there is non-default stuff in the session.

Because the CSRF-TOKEN is based on the session-id, it is important the
session-id stays the same across multiples requests even when the
session is not persisted on disk. Even when a session is not persisted
on disk, the session-id cookie is still set so that the next session
created on-the-fly uses the same session-id.

Technical note regarding the session, it has been decided to drop the
session-snapshot protocol and to reintroduce a "modified" flag. It has
been decided not to use werkzeug's session (which natively comes with a
"modified" flag) and to keep our own session object. We decided to
extend MutableMapping instead of dict; using MutableMapping we only
have to override __setitem__ and __detitem__; using dict we would had to
override update()/pop()/... too.

Task: 2789035
Part-of: odoo/odoo#86015
2022-04-05 14:13:54 +02:00
Jeremy Kersten d2b4214409 [FIX] auth_totp: don't redirect to url prefixed with lang
This commit removes the multilang feature on the /web/login/totp controller,
it doesn't really add value since it triggers a redirect and that the page is
all the same translated.

It is a good practice by default for SEO, but in this case it brings
some bug with the IOS apps that doesn't follow the redirect, while we don't
need to optimize this page for Search Engine.

The bug into the IOS apps, create a loop when we request the totp screen.
    Device request /web/login/totp
    Server ask a redirect to /fr_FR/web/login/totp
    Device redirect to /web/login/totp
    Server ask a redirect to /fr_FR/web/login/totp
    ...

closes odoo/odoo#87810

X-original-commit: 4dea1b9b7cf0855095f9cfa37ff6a9a6db7cf55e
Signed-off-by: Adrien Dieudonné (adr) <adr@odoo.com>
Signed-off-by: Jérémy Kersten <jke@odoo.com>
2022-04-02 21:10:54 +02:00
Julien Castiaux 1dd3865208 [IMP] *: odoo.addons.web.controllers.main splitted
The odoo.addons.web.controllers.main python module have been splitted
over multiple files on the basis 1 controller = 1 file. In this work we
adapt all modules to use the new imports.

A non-exhaustive list of where stuff have been moved:

* main.Home		--> home.Home
* main.Session		--> session.Session
* main.WebClient	--> webclient.WebClient
* main.clean_action	--> action.clean_action
* main.ensure_db	--> home.ensure_db

The complete list is accessible in odoo.addons.web.controllers.main.

closes odoo/odoo#87571

Related: odoo/enterprise#25746
Signed-off-by: Raphael Collet <rco@odoo.com>
2022-03-31 02:10:53 +02:00
Pierre Paridans 7df7ecae9b [FIX] auth_totp,web: TOTP login from mobile apps
Since PR odoo/odoo#78857 , the TOTP authentication support is broken
when used inside either Android or iOS mobile apps.

Due to our inability to update the iOS app (following review from
Apple), this commit aims at restoring the bare minimum requirements to
make the current mobile apps (specially iOS but also Android)
authentication workflow works.

As extended explanation:
- Set-Cookie header is expected to be sent even when session_id hasn't
  changed (iOS specific).
- Successful credentials check on `/web/session/authenticate` expect a
  successful response with a result containing `uid` set to `null` to
  mark the need of an additional totp handshake (both platforms).

closes odoo/odoo#85463

Signed-off-by: Julien Castiaux <juc@odoo.com>
2022-02-26 13:41:23 +00:00
Julien Castiaux f04b90b6e8 [REF] core: HTTPocalypse (12) web ir.http & login
This commit is the 12th commit of a comprehensive refactor of our HTTP
framework. See odoo/odoo#78857 for complete historic, discussions and
rationnals.

The web module is twofold, on one side there are many controllers: /,
/web, /web/login, /web/database/selector, /web/dataset/call_kw, etc, on
the other side there is `session_info`: the method responsible to create
the web client's environ.

This module is kinda an exception as it is (with base) a server wide
module. In the case of the HTTP framework, it means that the controllers
of web are always accessible, i.e. going to / or /web/login will never
return a 404 Not Found even if the user is not connected to a database.

This is both a blessing and a curse. It is a blessing because the
controllers are always accessible it means that a new users can freely
access those routes. It is a curse because *any* user can access them,
even user who don't have a session yet thus who are not connected to a
database yet. From a developer standpoint, we have to put extra care to
correct serve users with and without a database. An example is the
/web/login route, the login/password pair is stored in a database,
without database it is impossible to validate a user login but users can
still access this route without db.

To solve this problem, there is the `ensure_db` function. This function
attempts to find a database using various sources (?db= query-string,
session db, mono db) and to save it on the user session. In case no db
is found, the user is redirected to the database selector. In a way,
this function grants a database to the user in a seamingly experience.
In a way, this function brings a welcome differentiation between
`auth='none'` with a database and `auth='none'` without a database. Such
differentiation only matters for the server wide modules as "regular"
module controllers are only accessible via the ir.http routing map, i.e.
it is not possible to declare a nodb controller outside of server wide
modules.

An important changement is the `session.authenticate` method, before it
was possible to call the method when the cursor was not yet initialized,
authenticate would open a cursor against the given database, setup a
registry and an environment and ultimately save everything on the
current request. Because the cursor is now greedily created, it is no
more possible to update the request environment when authenticating on
another database.

PR: odoo#78857
Task: 2571224
2022-02-24 13:30:50 +00:00
Antoine Vandevenne (anv) adf70bf9dc [FIX] *: retarget documentation links to master
closes odoo/odoo#84990

X-original-commit: 39bdf46
Related: odoo/enterprise#24582
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-02-21 17:01:02 +00:00
Denis Ledoux a08a0b6454 [ADD] auth_totp_mail: 2FA using code sent by email
Add the possibility to force the two-factor authentication for all users,
using a two-factor authentication by email
when the 2FA using an Authenticator app is not configured for the user.

Two possibilities:
 - Force the 2FA only for employee users using the system parameter `auth_totp.policy=employee_required`
 - Force the 2FA for all users, employees and portals, using the system parameter `auth_totp.policy=all_required`

closes odoo/odoo#83750

Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
2022-02-01 17:15:30 +00:00
Florent de Labarre eb0c5f2566 [FIX] auth_totp: "Disable TOTP" only available in list view
The action server is only available on view list. It is hard to find this.

closes odoo/odoo#83455

X-original-commit: 2fa29557d048e43bc9ed0a9fc9047de203b0c4f0
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-01-27 07:03:03 +00:00
simonev 2857980a6c [FIX] auth_totp: add missing model decorator on change_password method override
Declared as an api.model in all the other modules except auth_totp

closes odoo/odoo#79726

X-original-commit: 61b319ea2b5ffc70e0fd80eb62b8a3f700be0f1f
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-11-12 18:07:15 +00:00
std-odooandnounoubensebia cd8e0e9f46 [IMP] base, *: hide non-relevant fields for portal users
Purpose
=======
Hide non-relevant fields for a portal user. E.G. we want to hide the
notification type,  the menu customization... Because those fields
make no sense for a portal user.

Force the non-internal user to receive notifications by emails since
they can not open Discuss.

Task-2508521

Part-of: odoo/odoo#77766
Co-authored-by: nounoubensebia <neb@odoo.com>
2021-11-09 14:45:49 +00:00
Romeo Fragomeli 0cecf918a6 [FIX] auth_totp,mail,web: TOTP authentication with JSON-RPC
Since [1] and [2], the mobile app gets this error when trying to login
on v15, while it was working fine in v14 with TOTP enabled.

The 'authenticate' JSON-RPC route tries to authenticate the user and
then call `session_info()`. As no UID is defined, some methods in
`session_info()` raise an exception and an unexpected error is sent:
* `_is_public()` -> "Expected singleton: res.users()"
* `get_web_translations_hash()` -> "lang"

In this fix, this exception is avoided and the proper result is sent,
allowing the authentication process to continue.

Steps to reproduce:
* Try to connect to an account with TOTP on the mobile app (v15+) => BUG

Refs:
[1] odoo/odoo@80d74e7ee0
[2] odoo/odoo@401fc7efe9

X-original-commit: 65dca67ecdcc2228d90781a9f5ccd99f290ada6c
Part-of: odoo/odoo#79182
2021-10-29 11:54:21 +00:00
b63ee52552 [FIX] *: remove scss 'extend' from dropdown components
This commit removes all the 'extend' initially introduced to avoid code
repetition and ensure visual consistency across Bootstrap and Owl dropdowns.

Despite achieving the desired results, using 'extend' in this context
was seriously impacting the bundle generation time, probably due to an
underestimated amount of Apps' legacy-code applied on these elements.

In order to achieve the same results, the chosen strategy is to add
Bootstrap default classes directly into Owl dropdowns.
Also, it moves code related to bootstrap dropdown in 'webclient.scss',
leaving 'core/dropdown/dropdown.scss' for Owl code only.

Due to the discrepancies between Bootstrap and Owl html
structure, the '.dropdown-item' class could not have been added
directly to Owl's '.o_dropdown_item' itself, without refactoring
the Dropdown component structure.

// ==== Bootstrap 4.6 default Structure ================================
<div class="dropdown-menu">
  <button class="dropdown-item" type="button">Action</button>
  <a class="dropdown-item" href="#">Another action</a>
</div>

// ==== OWL default Structure before this commit =======================
<ul class="o_dropdown_menu">
  <li class="o_dropdown_item">
     <span>Action</span>
  </li>
  <li class="o_dropdown_item">
     <a href="#">Another action</a>
  </li>
</ul>

// ==== OWL Structure after this commit ================================
<div class="o-dropdown--menu dropdown-menu">
  <span class="dropdown-item">Action</span>
  <a class="dropdown-item" href="#">Another action</a>
</div>

// ==== web.assets_backend.css Bundle Generation Comparison ============
With all modules installed (enterprise edition over runbot):
Before this commit, bundle took ~2.5s and ~4s to generate and weighted ~322kB (~2.5MB uncompressed)
After this commit, it takes between ~1.2s and ~1.6s and weights ~257kB (~1.6MB uncompressed)

closes odoo/odoo#77649

X-original-commit: 84715436d87bb05b421bc9ccaacda67d07571690
Related: odoo/enterprise#21370
Signed-off-by: Géry Debongnie (ged) <ged@openerp.com>
Co-authored-by: Stefano Rigano <sri@odoo.com>
Co-authored-by: François Georis <fge@odoo.com>
Co-authored-by: Bruno Boi <boi@odoo.com>
2021-10-04 07:57:00 +00:00
Martin Trigaux ef8ad324b0 [I18N] *: export 15.0 source terms
closes odoo/odoo#76542

X-original-commit: 63e6807437295519a0f4705fb88644d6d557ca3a
Related: odoo/enterprise#20882
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-09-16 07:17:40 +00:00
Xavier Morel 499b1621ba [FIX] *: non-accessible buttons
closes odoo/odoo#76581

Related: odoo/enterprise#20897
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2021-09-15 15:22:58 +00:00