Commit Graph
8 Commits
Author SHA1 Message Date
Raphael Collet caf900e89e [FIX] *: use auth='public' in controllers that use request.env
The following trick used to work, because `sudo()` was actually making
an environment for the superuser to operate upon:

request.env[...].sudo().method(...)

It no longer works in general, since `sudo()` now makes an environment
in superuser mode but with `uid=None`!  It may still work by accident
for operations that never use `env.uid`, but is broken in general.

Using `auth='public'` fixes the problem by using the public user when no
user is available.

closes odoo/odoo#34297

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2019-07-04 11:32:22 +00:00
Thibault Delavallée b670911a92 [REF] link_tracker, mass_mailing: simplify add_click method and add tests
In this commit we rewrite a bit add_click in order to remove the inlined sudo
and ease inheritance and parameter management inside the method.

Access through controllers is sudo-ed as the main API method is now done
with current user access rights.

This commit is linked to task ID 1904277 and PR #28242.
2019-01-14 10:34:26 +00:00
Thibault Delavallée 75638ffb94 [REF] link_tracker: do not let public read technical / private link data
Link tracker models are rather technical and should not be accessed as it is
by external people. Let us delegate control to controllers and lessen a bit
model accessibility.

Currently everyone can use add_click method and generate statistics. Now
statistics will be generated only through dedicated routes. It will make
statistics more reliable and ensure technical data remain private.

Next commit will update code from controllers and main methods in order to be
have a more readable click API and avoid link between non dependent modules.

This commit is linked to task ID 1904277 and PR #28242.
2019-01-14 10:34:21 +00:00
Christophe Simonis 298e2032ea [MERGE] forward port branch saas-12 up to 9f28139 2016-09-09 18:13:31 +02:00
Denis Ledoux f19d179bb0 [FIX] link_tracker: fix link tracer when no geoip in session
The `geoip` is not always defined in the session,
and therefore one needs to check it's defined before
attempting to use it.

The same is done at different places in the code,
through the different modules.

opw-687783
2016-09-06 12:04:43 +02:00
Thibault Delavallée c8a313d51e [IMP] various: use odoo for imports instead of openerp and update class names 2016-08-10 15:48:07 +02:00
fwi-odoo d4e813b873 [REF] web, *: change deprecated import openerp.addons.web.http to odoo.http
We also remove the mock in web as there is no need for it anymore.
2016-08-03 13:42:05 +02:00
Christophe Matthieu fd5361c0f7 [IMP] mass_mailing: remove depends to website. Create a website_mass_mailing bridge to add subscribe snippet into website builder. Split website_links to have link_tracker to create short and trackable URLs, and website_links to have a website layout for link_tracker and add button to share page. 2015-07-10 17:00:15 +02:00