Using a few regex like
\((_\(.*%s.*)(\) % )([\w\[\]][\w .\[\]\(\)'"]*)\)
($1, $3))
Old syntax is still compatible but starts the migration to the new
syntax that catches error.
The use of the `deploy` command always fails because of an incorrect
CSRF token since commit 9bae56acd4. Indeed, the latter
re-introduces the session rotation, i.e. the session ID is changed at
authentication.
Practically, what happens server-side is:
- authentication
- generate CSRF token
- create the response with the token and a change of session ID
At this point, the token generated is not correct anymore since it is
based on the 'old' session ID. Therefore, when it is reused at
uploading, an error is raised.
It is actually possible to simplify the process by performing the
authentication and the file upload in a single request. There is indeed
no real use of extracting the authentication, since the request is then
only used to upload the module.
opw-1902863
closesodoo/odoo#28653
* disabled CSRF protection for login route
* return CSRF token from login and retransmit it during module upload
``deploy`` only sends CSRF token if given one by authenticate so that
the command can be used for non-updated modules.
Closes#9488
Checks that the provided user (or user in the provided dataset):
* is the superadmin
* or is a member of group_erp_manager
There are a number of hand-rolled "is_admin" checks in the codebase some
of which are fairly gnarly. The shortcut provides a single point of
contact, avoids forgetting about cases (e.g. SUPERUSER_ID) and is
relatively convenient when checking a user which is not the "current"
user.
closes#8146