Commit Graph
436 Commits
Author SHA1 Message Date
Jeremy Kersten 71f42e274d [FIX] website: favicon use STATIC_CACHE_LONG that is a real year
365 * 24 * 60 is not a year, but year/60 ;)
While we fix it, it is the good time to change and use the dedicated
http.STATIC_CACHE_LONG that exists for it.

closes odoo/odoo#60807

X-original-commit: bb4d5bebaf926cbdf6f8842cd1ca0e5850523bf5
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-10-27 10:22:56 +00:00
Jeremy Kersten 550d2935bd [IMP] website: support generic website for dynamic snippet filters
Made the website_id non mandatory on website snippet filters and adapted
the fetching route so that it interprets an unspecified website_id as
the filter being available on any website.

Before this commit website snippet filters had to be limited to one
single website.

After this commit website snippet filters can be made available on all
websites by setting their website_id to no value (this is the new
default of the pre-defined filters).

https://github.com/odoo/odoo/pull/59831
task-2355369

closes odoo/odoo#59831

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-10-13 13:09:45 +00:00
David Beguin 4c9e39cfbd [FIX] website: get visitor tz directly from cookie
Since tz is now (from 6eb4762fee) added to the client cookie,
visitor timezone can directly be set when creating the visitor, using the
request.

Jstz can be removed as even for module in ENT that used this lib,
we can get the timezone using Intl lib instead.

This will also reduce the number of request made only to get visitor's
timezone.

This commit reverts part of 17e8402523
Linked ENT PR: 12963

Task ID: 2333825

closes odoo/odoo#59501

X-original-commit: 3d9a2de3575777c87327691319d89f9de6b8eada
Related: odoo/enterprise#13918
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2020-10-08 11:45:39 +00:00
Romain Derie 49dfe5e329 [FIX] website: prevent /web/become route to crash
Since 9f82605df1, any call to `_login_redirect()` without previously going
through `web_login()` method would crash, as `login_success` is set there.

In this case, it was:
Dispatch -> web_login -> redirect (new dispatch) -> _login_redirect()

task-2340941

closes odoo/odoo#57881

X-original-commit: 448fcb3c702c3346ca5af922bbf457231a7330f5
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-09-16 15:35:02 +00:00
Jeremy Kersten a019479d14 [FIX] website: check website_published exists before use
closes odoo/odoo#56786

X-original-commit: d23899b3c4ea91e4ac80163764c97cb9591d889c
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-08-31 09:17:10 +00:00
Laurent Stukkens (LTU) 0e7640b5f2 [IMP] website, website_sale: add dynamic snippets
* Implement new snippets that allow the user to choose a filter
  and a template.
  Three snippets have been created:
  - Dynamic Snippet: Displays the data in a grid format
  - Dynamic Carousel: Displays the date in a carousel
  - Dynamic Products: Let the user pick a product category and
                      displays the products in a carousel

task-2276740
PR #53175

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-08-18 17:40:25 +00:00
Xavier MorelandOlivier Dony a9a6509713 [ADD] auth_totp
New module for supporting two-factor authentication via time-base
one-time-password (TOTP).

Users (including portal users) can choose to enable two-factor auth in
their user account settings, by scanning a QR code and adding it to an
authenticator app, such as Google Auth, 1Password, etc.

When two-factor is enabled, password-based non-interactive RPC is only
possible by using API keys.

Co-authored-by: Olivier Dony <odo@odoo.com>
2020-08-14 23:06:24 +00:00
Xavier Morel 9f82605df1 [FIX] portal, website: login redirection
* migrate website to overriding web_login less (still needed to flag it
  as website-enabled) and use _login_redirect for its login redirection
  override needs
* modify portal and website to not replace / shortcut the redirection
  workflow, so it's possible to override those properly if / as
  necessary
2020-08-14 23:03:27 +00:00
Thanh Dodeurandqsm-odoo 59d46b51b1 [MOV] website: move google map snippet from themes to community
Improve the base code and adapt to new website features as well.

Part of https://github.com/odoo/odoo/pull/49101
task-2091396

Co-authored-by: qsm-odoo <qsm@odoo.com>
2020-07-28 07:45:40 +00:00
Jeremy Kersten c387ec19b4 [IMP] website: allow to have custom slug Ux
Now, slug uses seo_name if field exists before to fallback on display_name.

It allow to have a custom url without change the product name already used in
backend e.g. or just because you want add some keywords for seo.

task-2291676

closes odoo/odoo#54152

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-07-07 13:11:57 +00:00
DramixDw 714f0aa07f [IMP] website: reintroduce a way to post from js
It was deleted in 11.0 as it was not used anymore. Now, it is
reintroduce as it is a nice utility function for some external app or
fixes. Here, it is use so that /website/add and /website/add/<path> work
as a controller POST with a CSRF token.

task-2241766
2020-05-29 13:59:15 +00:00
Martin Trigaux d879300944 [REM] website: remove lazy template call
Was making a render_template on an arbitrary template
Does not seem to be used anymore
2020-05-14 13:59:10 +02:00
Martin Trigaux d9287caf94 [IMP] *: convert to private methods
render, render_template, load, activity_schedule_with_view,
get_website_pages should all be private:
It should not be possible to render an aribtrary template only with
its name or id

Still need to render some qweb views from js so the method
render_template is kept public.
This explains why the website editor still need read access on
ir.ui.view as we want to allow any snippet to be rendered.
2020-05-14 13:59:10 +02:00
Martin Trigaux 56a8c9e431 [FIX] *: add sudo when accessing views
The method fields_view_get should be the only way to retrieve the view
content. This method is executed in a super-user context.

To avoid retrieving views for a model a user does not have access to
(as it may reveal some informations like name of fields), add a
verification of 'read' rights before retrieving the view content.

Execute _postprocess_access_rights with sudo(False) as this method is
used to evaluate which buttons should be displayed.
Remove the su flag to avoid misleading the user and displaying a
button they won't be able to use.

Retrieving the database id from an view key is not considered as a
sensitive information and get_view_id and viewref can be left as a
public methods.

Add missing sudo when needed

Change _handle_visibility in website to avoid increasing the query
count: Checking the visibility (to fail most of the time) to retry in
sudo was making unecessary queries.
2020-05-14 13:59:10 +02:00
DramixDw 9b9829416b [IMP] website: simplify website menu
Some apps, once installed, automatically create a menuitem in website.
What complexify the UI and create useless menu withtout plusvalue.

It is not because you install livechat to make support online, that you want
a link in your menu to show stats e.g.

Now we remove the default menu created, and help user to find it when he create
a link. The autocomplete suggest most of the main App's controllers

task-2189613

closes odoo/odoo#49081

Related: odoo/enterprise#9733
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-05-01 07:59:07 +00:00
Thibault Delavallée 318f02b8e8 [REF] base: replace toggle method by already-existing toggle_active for ir.ui.view
Toggle method defined on ir.ui.view does the same job of toggle_active that
is the generic one available on all models.

Task ID 2170708
Community PR odoo/odoo#46563
2020-04-03 12:59:28 +00:00
Benjamin Vrayandqsm-odoo 5ba817c453 [IMP] website: add templates for footer
Also remove all t-fields from footers to have only static contents in
footers. For social links, a controller is added so that a "static url"
/website/social/xxx always redirect to the correct set URL for the given
xxx social network.

Part of https://github.com/odoo/odoo/pull/38950
task-2087641

Co-authored-by: qsm-odoo <qsm@odoo.com>
2020-03-31 18:16:08 +00:00
Romain DerieandJeremy Kersten 30f4f610bf [IMP] website: improvement regarding social image
This commit introduce multiple improvements regarding social image:
  - (perf) Don't read ir.attachment through `social_default_image` when it is
    not needed. Use a stored boolean to know if the field should be accessed.
    This will remove one SQL query in attachment for public user.
  - Show website logo, not the company logo since we now have a different logo
    for website.
  - Don't show images lower than 200 width or 200 height px. Logo will be
    shown regardless of his size.
  - Don't show website logo if there is a website social_default_image.
    Indeed, the spec was to prevent showing logo and social_default_image if
    they are the same image. Technically, this is hard to identify as they
    could be the same image uploaded with different resolutions (media dialog),
    especially if one of those was uploaded through the backend and one from
    the frontend.
    It is most likely we will never correctly identify duplicate as they won't
    be exactly the same.
    For this reason, it makes more sense to hide the website logo if the
    social_default_image is set. It avoids every issues while it makes sense
    since you won't want to use the logo over the social_default_image. If you
    really want to, you could reupload it through the SEO media dialog.

closes odoo/odoo#47848

Related: odoo/upgrade#1012
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Co-authored-by: Romain Derie <rde@odoo.com>
Co-authored-by: Jeremy Kersten <jke@odoo.com>
2020-03-30 16:06:13 +00:00
Jeremy Kersten a65d27cce9 [IMP] website: perf - favicon.ico cached for 1 year
Note that this route is only used when no icon is set in DOM, such as accessing
a PDF after an order.

task-2211013
2020-03-26 18:12:47 +00:00
Romain Derie 2c09e00a64 [IMP] website: perf - prefetch menus when serving a page
If we are rendering a page, the menus will most likely be rendered as well.
Note that even in a 403 case when the page is found but is not visible, the
menus will also be shown on the 403 page.

Fetching the menus before accessing the requested page will prefetch that page
as well in one go if that page is in the menus, without any costs for the pages
not in the menus.

There is a tradeoff for 'non-layout' pages, which only occurs in advanced
technical cases:
1. Create a page with specific extension as name suffix (page.css) in which
   case the page will be bootstraped accordingly, without call to layout.
2. Remove the call to layout in HTML editor or backend
3. Remove the call to submenus template in HTML editor or backend
For those cases, the menus will be prefetched for no reason.

Note that homepage '/' is rendered through a controller, same logic is applied
there.

task-2211013
2020-03-26 18:12:47 +00:00
Martin Trigaux 40667755b1 [FIX] website: restrict access to route
This route was public by mistake, probably introduced to test during
ddf32f4 but no reason to make it public, public user has not the write
access on models anyway.

Courtesy of Swapnesh Shah

closes odoo/odoo#44915

X-original-commit: 66ac96b25aa4cf2b074f6c06b57ed8be72d6d647
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-02-07 19:51:09 +00:00
qsm-odoo 6fb4ed44a0 [IMP] website, *: make theme custo options act as simple snippet options
* web_editor, theme_bootswatch

Instead of having an entirely dedicated system for theme options in a
third tab of the left panel, those theme options are now simple snippet
options. See the customizeWebsite generic method.

This allows to make any option available in the third tab or on any
meaningful element like the header or the footer. This also allows to
take advantage of all the features of the left panel: dependencies,
visibility update, etc.

Note: same as before, those changes do apply the color/size/layout
immediately on the website, even if not saved. Changing that behavior
is complex and might be the job of another task.

Part of https://github.com/odoo/odoo/pull/41166
task-2088298
2020-02-05 23:49:53 +00:00
Samuel Degueldre 3bb666c226 [REF] website, web_editor: move theme customization to edit mode
Previously, theme customization was done through a modal dialog in the
website module, this was not very user friendly since the rest of the
customization for the website design was done from edit mode, meaning
the user had to exit edit mode to customize things such as theme colors
or fonts. It was also rather confusing to have these seemingly related
things in completely unrelated places.

This commit moves all of the options that used to be in the theme
customization modal into a new tab in the editor's left panel.

This commit is mainly just about rendering the old modal as a third left
panel content. See next commit for deeper changes.

Note: same as before, those changes do apply the color/size/layout
immediately on the website, even if not saved. Changing that behavior
is complex and might be the job of another task.

Part of https://github.com/odoo/odoo/pull/41166
task-2088298
2020-02-05 23:49:53 +00:00
Xavier Morel de590816d8 [FIX] *: deprecated access to url_ utilities through werkzeug root
In 0.15 accessing werkzeug.urls functions directly through werkzeug
is deprecated, the shortcut will be removed in the eventual werkzeug
1.0.

Fix existing uses of these shortcuts. Also cleanup some imports when
they're not far from a werkzeug* import being altered.
2020-02-04 12:42:35 +00:00
Jeremy Kersten 546f3cac3f [IMP] website: redo res config settings
task-2088625

closes odoo/odoo#40715

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-12-17 17:07:30 +00:00
Jeremy Kersten ab56c9e464 [IMP] website: add edit robots.txt in settings
task-2091358
2019-12-16 11:07:19 +00:00
Romain Derie e788c040f6 [FIX] website: set correct value in frontend_lang cookie
Before this commit, the `url_code` field value was stored in the cookie instead
of the `code` field.
This was making the language selector in the frontend to not change the lang
correctly when trying to access the website default lang, ONLY for the lang
having an `url_code` different than its `code` value (typically the case for
principal languages).

Step to reproduce:
  - Add `fi_FI` as main lang on website
  - Visit frontend and change lang to `Suomi`, it won't change

This behavior was only related to the language switcher. It did not affect
dispatching (if correct lang in url) and nearest lang finder.

Fixes #41522

closes odoo/odoo#41728

X-original-commit: b62b2828552abb38c8adc74c69cb427c3fd98605
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2019-12-11 13:33:22 +00:00
Jeremy Kersten 56b4764b18 [IMP] website: allow to don't show specific view in name
and uses it in customize_show.

closes odoo/odoo#40887

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-11-26 14:39:28 +00:00
Jeremy Kersten 3ff6efac8d [FIX] website: set controller favicon.ico as nomultilang
Avoid redirect from /favicon.ico to /<lang>/facivon.ico at each request

closes odoo/odoo#40535

X-original-commit: 94bcbc92e5e5a6fd3de7267e3c01f8c11fb045f4
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-11-19 18:29:20 +00:00
Jeremy Kersten e19227d3ba [IMP] website*: clean sitemap
From now, you need to explicitely add sitemap=True if you want your controller
into the sitemap.

It's the default value, but if you forgot it, it will raise a Warning on runbot.
It will avoid wrong controller in sitemap and duplicate (empty) content.

From now, if your model contains a field website_id, the modelConverter for
sitemap will automatically add the domain:
   "[('website_id', 'in', (False, current_website_id))]"

It avoid redundant declaration and ugly url in redirect/rewrite view.

Migration: need to remove it from url_from in website.rewrite

task-2065018

closes odoo/odoo#39427

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-28 10:36:56 +00:00
Jeremy Kersten 2cab9a8341 [FIX] website: clean sitemap
followup of 8a0fc6476c70a4126043de3b3efbd1096e41f968

task-2065018

closes odoo/odoo#39211

X-original-commit: bfa239b59c4d02c2b03ab8a84b52bc8f77704e41
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-22 16:36:37 +00:00
Jeremy Kersten 708759d82a [IMP] website: connect with search google easily
You need to provide a small part of the code, because to avoid fraud, google
make several request to be sure that you don't allow all codes :)

So the 'WPS' solution was dropped, now we take the first request from google
that match the part provided, as the good one, and refuse all others requests.

task-2086915

closes odoo/odoo#39186

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-22 13:49:45 +00:00
Jeremy Kersten fef7ec7c97 [FIX] website,*: remove useless route from sitemap
preparation for cleaning of v13
task-2065018

closes odoo/odoo#39051

X-original-commit: 8a0fc6476c70a4126043de3b3efbd1096e41f968
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-18 14:59:02 +00:00
Jeremy Kersten 3233c46d4b [FIX] website: Missing module in Apps
closes odoo/odoo#38971

X-original-commit: 562a2ac270ef8aac3afde05625008cef64f62f89
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-17 15:36:04 +00:00
Romain Derie f4105eb9c7 [FIX] website: prevent endless loop if homepage is unpublished..
.. and first menu is a container with # as url.

There is a particular case where the / url would loop endlessly.

1. Unpublished the homepage /
2. Edit the menu so the first menu is a container. There is a hint telling you
   a container menu should have its URL set to `#` as a good practice.
3. This will lead to endless loop for public user as the code will check if the
   homepage can be accessed. Since it is unpublished, it will then fallback on
   the first menu which is not '/' and redirect to it.
   Sadly, the code was not expecting `#` to be handled as `/`.

opw-2081969

closes odoo/odoo#38234

X-original-commit: cff11bdb66f1dda41cf333a28b67df7ef20a3de9
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2019-10-08 16:54:07 +00:00
Jeremy Kersten be8fc2296b [IMP] base, http_routing, website: allow custom routing rule
After this commit, you will be able (in technical mode) to update the url for
the python controllers.

Eg.
You can now rename /shop in /garden and /shop/product/ in /garden/vegetable/

Most of urls will be replaced at fly in the renderd qweb, with the function
url_for but all old urls will keep available. So if you access url /shop you
will be automatically redirected to /garden (308 Permanent Redirect).

As for cdn and other post-process of att, the automatically replacement in the
rendered qweb is only done when you will be not website editor. But the new
dispatch of URL will be applied in all cases.

For developper, since it is Permanent Redirect, don't forget to clear cache or
open chrome debug tool (with option 'Disable cache while DevTools is Open) to
see your lasts changes.

closes odoo/odoo#36555

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-09-30 13:58:14 +00:00
David Beguin 17e8402523 [IMP] website : store visitor timezone
In order to be able to send push notifications using recipients timezone,
the visitor timezone is now stored in DB.

The visitor timezone is only updated once, when found_visitor_timezone
cannot be found in localstorage. Once the timezone is updated,
found_visitor_timezone is added to localstorage.

Task ID : 1936643
PR #34973
2019-09-20 14:44:56 +00:00
Romain Derie 269aa59411 [IMP] http_routing, website: allow to customize the lang in URL
With this commit it is now possible to change the lang displayed in the URL.
Eg, you could use `/fr` instead of `/fr_BE`, or even a fancier `/french`.

Task-32838

Courtesy of pla@odoo.com

closes odoo/odoo#35135

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2019-08-26 16:35:19 +00:00
Andrea Ullianaandqsm-odoo 7deceae18c [IMP] website, *: use "auto" widget for font customization
* theme_bootswatch, theme_default, website_theme_install

This commit makes use of the new 'auto' widget for font selection:
instead of enabling a template which will enable a scss file which sets
a font variable to a specific value... we directly allow to do a scss
custo which sets that value.

The code in charge of resetting font customizations on theme switching
is also moved and refactored here in website (instead of being specific
to each theme).

Part of https://github.com/odoo/odoo/pull/33442
task-1974659

Co-authored-by: qsm-odoo <qsm@odoo.com>
2019-07-30 09:59:28 +00:00
Raphael Collet b7fd679a6c [FIX] *: sudo() -> with_user() 2019-07-04 11:32:22 +00:00
Christophe Simonis 9035fb8a2a [MERGE] forward port branch saas-12.4 up to 618ea1ab67 2019-06-18 10:24:25 +02:00
Christophe Simonis 25e3f27062 [MERGE] forward port branch saas-12.3 up to 48a9f5a633 2019-06-17 13:20:35 +02:00
Christophe Simonis 34a8754d4f [MERGE] forward port branch saas-12.2 up to 498b4b4350 2019-06-14 15:20:01 +02:00
Christophe Simonis 8853e6b594 [MERGE] forward port branch 12.0 up to 7ef4ba03c4 2019-06-11 15:20:13 +02:00
Christophe Simonis 9e9e9acef1 [MERGE] forward port branch saas-11.3 up to a2582c4252 2019-06-07 19:04:43 +02:00
Romain Derie 9efc11c8da [FIX] website: redirect user
Before this commit, user would be redirect to / instead of /my after signup.
That error was detected with task-1829827 which has a tour ensuring user is
correctly redirected to /my after signup on the checkout summary after payment.

Since 0229ef4c4a, the `web_login()` super call order has been changed when
called from the `/web/signup` route.
See the commit for more details but basically, before the fix, it went only
through:
1. web.web_login
2. portal._login_redirect

Where now, it goes through:
1. website.web_login
2. auth_signup.web_login
3. web.web_login
4.portal._login_redirect

Thus, portal._login_redirect is not returning `/my` as redirect anymore.
Indeed, website.web_login will ignore its super() and force redirect to `/`

With this commit, website's user are redirected to /my as expected.
Side effect: website's user will also be redirected to /my on login instead of
`/`, which is also prefered.

closes odoo/odoo#33865

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-06-04 09:38:44 +00:00
Andreas Perhab 8242ddbc10 [FIX] website: provide favicon for pdf tabs
When opening the pdf at the end of an order Chrome tries to load
/favicon.ico which returns 404 before this patch. We provide the
favicon from the current website.

closes odoo/odoo#33746

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-05-29 10:02:18 +00:00
qsm-odoo d7da1d648c [IMP] website, *: improve customize dialog no-reload updates
* base

Before this commit, if an option was customized thanks to the customize
dialog, the page was not reloaded, only the new scss <link/> elements
were retrieved and replaced in the DOM.
There were two problems with this:
- The <script/> and <style/> tags were also retrieved for no reason (as
the whole result of t-call-assets was returned)
- This made use of a deprecated ir.qweb method that we want to remove
(see https://github.com/odoo/odoo/pull/33432)

This commit removes the use of the deprecated method by improving the
system: only the <link/>'s new URLs are returned on customization.

closes odoo/odoo#34040

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2019-06-11 16:06:07 +00:00
qsm-odoo d0573de2b6 [IMP] website_sale, *: save the layout mode in the user session
* website

Part of https://github.com/odoo/odoo/pull/31147
task-1925327
2019-05-28 15:05:42 +00:00
Christophe Simonis 0e7675847f [MERGE] forward port branch saas-12.1 up to 0f4abc5c22 2019-02-22 16:25:02 +01:00