Commit Graph
61 Commits
Author SHA1 Message Date
Laurent Stukkens (LTU) b192d8d23f [FIX] website_form: allow to submit form without csrf if not logged
Chrome recently changed their SameSite policy default value from None to Lax,
the session is no more shared between the webpage and the iframe.
As a result, the csrf check systematically fails.

After this commit, the csrf_token check is only made when you have a session.

In case you are using your form in an iframe on another site, with the new
cookies policy, your cookies with the session_id (linked to the csrf token)
is not sent to the server and the check csrf always fails.

Since the purpose of the csrf is to prevent another website to submit a form
with your 'authenticated account', we can consider that if you are not logged
and so have no session_id, it is no critical and we can ignore the csrf check.

opw-2330286

closes odoo/odoo#58050

X-original-commit: 9a0c9f3192bc7043add89446cbe6c2650499a654
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-09-18 15:09:51 +00:00
Nicolas Lempereur 512a13f94c [FIX] website_form: lang arabic for date/datetime
When we send dates with website_form, if the language of the website is
eg. in arabic we will send moment.js arabic dates that can't be parsed
by the server.

This also happens with norwegian and any language which doesn't use
ascii numbers or textual format of month or days (and possibly RTL
language).

With this changeset, if we detect we are in a use case where this matter
(an existing field and a date format that will fail) the date will be sent
as odoo server format.

Expected change:

- what worked still work with or without server restart

- what didn't work works after server restart

- special case such as "english" with custom format in res.language
  containing textual month might now not work with code update without
  server restart (probability of this is low).

opw-2326882
closes #57042

closes odoo/odoo#57217

Note: the saas-13.5 version always force isoformat for existing fields
X-original-commit: f50f32ea656df62d16f0aeba1247fc3b2d394e5d
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2020-09-08 07:26:36 +00:00
Martin Trigaux 8458c58436 [IMP] website_form: avoid string concatanation
This is a slow operation and string join is significantly faster
https://stackoverflow.com/a/3055541/1398110

This can make a noticable difference when processing a long form

Courtesy of Nils Hamerlinck

closes odoo/odoo#52664

X-original-commit: 87a2702fdabdcfeb774ddfb9db2e28bdd5595f9a
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-06-09 08:47:07 +00:00
fja-odoo 5411486134 [IMP] google_recaptcha, *: integrate recaptchaV3
* = base_setup, website_form, website_sale, website_crm,
crm_iap_lead_website, website_hr_recruitment, website_mass_mailing

Integrate reCaptchaV3 on website_form submit and website_mass_mailing
subscription.
You can now use ReCaptchaV3 to add reCaptcha verification in any module
using google_recaptcha.

Also added a better error management on the form with custom messages.

task-2217980

closes odoo/odoo#48466

Related: odoo/enterprise#9649
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-06-05 10:58:50 +00:00
jvm-odoo 70a79da8a0 [FIX] website_form: fix wrong user sending email
Issue

	When you send a form which create a customer
	from the website, you get a 400 error.

	I used the customer database to reproduce
	the issue. I guess this is due to specific
	settings who set a value for `meta` here

	https://github.com/odoo/odoo/blob/5381e9d900b344e7d48a6b347c5fc551d433b15e/addons/website_form/controllers/main.py#L187

Cause

	The cause is the same than the one for fc8a0474b4
	Here, we use sudo:
	https://github.com/odoo/odoo/blob/5381e9d900b344e7d48a6b347c5fc551d433b15e/addons/website_form/controllers/main.py#L211

	sudo adds a flag "su" and does not replace the user in env
	So we have "public user" who doesn't have email instead
	of OdooBot who has an email, there is a raise who explain
	the issue but it's not forwarded to the error in the website

Solution

	Use with_user(SUPERUSER_ID) instead of sudo, in order to have
	the right user (as it is done few lines above.

OPW-2220816

closes odoo/odoo#48481

X-original-commit: 1dba2ec8166b934d0698220e7062280d347f8af1
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
Signed-off-by: Jason Van Malder (jvm) <jvm@odoo.com>
2020-03-27 09:50:27 +00:00
jvm-odoo 024010bbe1 [FIX] website_form: fix wrong user sending website forms
Issue
	- Set outgoing mail server
	- Install Online Ticket Submission
	- Publish an Helpdesk Team
	- Log out
	- Create a ticket from the helpdesk form

	The user who created the ticket is "Public User"
	He has no email address, so the mail is not sent

Cause

	insert_record method in website_form/main.py uses .sudo()
	In v12 => sudo replaces the user in env by the superuser => ok
	In v13 => sudo adds a flag "su" and does not replace the user in env

Solution

	Add a with_user(SUPERUSER_ID) to the create method's call in
	insert_record

OPW-2196668

closes odoo/odoo#46835

X-original-commit: 761ae16634b14bec7be522666bb2163490566ecc
Signed-off-by: Jason Van Malder (jvm) <jvm@odoo.com>
2020-03-04 09:53:50 +00:00
Nicolas Lempereur 36d4ff5c4c [FIX] website_form: binary work with website_crm_phone_validation
With this change, a binary field in a website form works when
website_crm_phone_validation (website_crm in 13.0) is installed.

The module website_crm_phone_validation would call `extract_data` method
to do some things, but when extract_data was called a second time to
really save data, the FileStorage werkzeug object would already consumed
and files would erroneously appear as empty.

opw-2191873

closes odoo/odoo#46241

X-original-commit: a168fe23cc6d9b817b44c189822952a1ee98d81d
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2020-02-25 13:19:39 +00:00
Nicolas Lempereur 1bcab2f42e [FIX] website_form: binary field do not need _filename
When a binary field is added to studio, the system will try to write the
name to {binary_field_name}_filename: this works if the field was
created with studio but could not work eg. if just a binary field is
created manually.

opw-2191873
closes #45994

closes odoo/odoo#46164

X-original-commit: 13b65d878d5240f07b279045e30d53915d176a61
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2020-02-24 19:40:58 +00:00
Prakash Prajapati a4c92c6aed [FIX] website_form: fix several issues when editing a form
This commit fixes the following points:

- While dropping a form builder, the default action is now set to
  'Send an email' instead of first available action.

- Titles of the forms which previously were readonly, are now editable.

- When sending an email, the 'reply-to' address is now set from the
  email field provided in the form, instead of the catchall mail.

- Hitting 'Send' button for 'Send an email' option now immediately
  sends the mail instead of putting it in the queue.

task-2082970

closes odoo/odoo#42515

X-original-commit: 7ada68cc91fde1b6eff151549808a20e85cb5bf7
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2019-12-30 17:06:39 +00:00
Jeremy Kersten 546f3cac3f [IMP] website: redo res config settings
task-2088625

closes odoo/odoo#40715

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-12-17 17:07:30 +00:00
Jason Van Malder 453e7ab3d5 [FIX] website_form: fix missing currency field in form builder
Issue

    - Install CRM & Website
    - Edit the website contact form
    - Add "Expected revenue" field

    Traceback

Cause

    Monetary fields are not handled by the form builder

Solution

    Add the monetary field in the form builder core

OPW-2150986

closes odoo/odoo#41558

X-original-commit: 6c27c3abf4907e1faac670ea8ef006992ec96063
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2019-12-09 09:58:36 +00:00
Fanny He 58b7907254 [FIX] website_form: link attachments to binary fields
If the name of a file input field is 'x_binary_input', before
commit 9be29371abcdfe57b1738484c5057ad81e76b00d (opw 2092653),
self.form_fields would have names of the form 'x_binary_input[i]'.
After this commit, they are of the form 'x_binary_input[i][j]'.
When calling extract_data, field_name would then be 'x_binary_input[i]'
instead of 'x_binary_input'. Therefore, the file would be considered as orphan
instead of being attached to x_binary_input.
We thus change the split so that it always returns 'x_binary_input'.

opw 2122624

closes odoo/odoo#41135

X-original-commit: 21ed2b971f66879fa3fa53dbd2c349ab39fa3fdb
Signed-off-by: fah-odoo <fah-odoo@users.noreply.github.com>
2019-11-29 10:55:09 +00:00
Julien Castiaux 4f03a5f136 [FIX] *: remove old deprecated modules/functions
PEP-594 is deprecating a bunch of modules. As part of the cleanup, we
are also dealing with long deprecated modules, functions and aliases.

* `assert_` -> `assertTrue`
* `assertEquals` -> `assertEqual`
* `assertNotEquals` -> `assertNotEqual`
* `assertAlmostEquals` -> `assertAlmostEqual`
* `assertRaisesRegexp` -> `assertRaisesRegex`
* `assertRegexpMatches` -> `assertRegex`
* `base64.encodestring` -> `base64.encodebytes`
* `base64.decodestring` -> `base64.decodebytes`
* `inspect.getargspec` -> `inspect.signature`
* `inspect.formatargspec` -> `inspect.signature`
* `logging.warn` -> `logging.warning`

closes odoo/odoo#36863

Task: 2003936
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2019-09-17 11:36:42 +00:00
Yannick Tivisse 0c07495391 [FIX] website_form: Allow to post a message with attachments
Coming from the sudo() modification. The mail.message is created in sudo,
but the user is still the public user, who doesn't have a email address,
leading to an raised error.
2019-07-26 08:47:03 +00:00
Martin Trigaux 1f5a4649a6 [MERGE] Forward port of saas-12.3 to saas-12.4 up to 87fc1554d6
closes odoo/odoo#34820

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2019-07-12 13:59:35 +00:00
Julien Castiaux 0e2f3b1445 [FIX] website_form: set filename on studio binary
Using studio, add a file field on a form. Using the web form builder,
append that field on a form. Upload a file, `x_field_filename` is left
empty thus the filename is lost.

opw-2028071

closes odoo/odoo#34491

Signed-off-by: Julien Castiaux <Julien00859@users.noreply.github.com>
2019-07-01 13:20:51 +00:00
Thanh Dodeur c212cfe899 [REF] *: removes datas_fname from ir.attachment
This commit removes the field `datas_fname` from `ir.attachment` as
it was unnecessary and most of the time the duplicate of `name` or
`url`.

Task #1909865

closes odoo/odoo#32976

Signed-off-by: Martin Geubelle (mge) <mge@openerp.com>
2019-06-05 09:12:13 +00:00
Jigar Patel fb51d5c648 [IMP] wesbite_form: change custom fields title for mail.mail
task-32212
2019-04-19 07:24:02 +00:00
Christophe Simonis 15f686eef6 [MERGE] forward port branch 11.0 up to 468dab6748 2018-11-15 20:39:10 +01:00
Nicolas Lempereur 5f066552c3 [FIX] website_form: custom file -> mail attachments
There was a code that on:

- a form that sent a mail
- with a custom file field

would set the file as attachments, but the code was dead because of a
typo in `if` statement order.

opw-1906883
closes #28525
2018-11-09 11:09:32 +00:00
Christophe Simonis 2bc6ea1b37 [MERGE] forward port branch 11.0 up to 02ee3fd88e 2018-05-23 19:33:40 +02:00
Christophe Simonis 02ee3fd88e [MERGE] forward port branch saas-15 up to 1b81f1a5c9 2018-05-23 18:36:28 +02:00
Christophe Simonis 373a1c1128 [MERGE] forward port branch 10.0 up to 682ae1cc64 2018-05-23 18:30:36 +02:00
David 682ae1cc64 [FIX] website_form: set meta field
Before this commit, if you enable website_form_enable_metadata, that
will crash with a "KeyError: 'meta'"

This commit closes #24848
2018-05-23 09:16:32 +02:00
Christophe Simonis 4aa5ec3fa5 [MERGE] forward port branch 11.0 up to d67b410dfc 2018-03-07 18:46:38 +01:00
Christophe Simonis d67b410dfc [MERGE] forward port branch saas-15 up to cb87388d72 2018-03-07 17:42:02 +01:00
Christophe Matthieu 108d22ecdf [FIX] website_form: public user can send attachment
Issue:
An additional information page is part of our shop process to allow
additional information to be submitted. If this form is left blank,
then selecting the next button allows the process to continue.
However, if data is added to the form the form freezes and the process
will not continue when 'next' is selected.

Why:
Public user can not read the field 'model' of 'ir.model' (to save the
attachments)

opw-1818592
2018-03-06 09:26:34 +01:00
Thibault Delavallée 1fbc29a641 [MOV] base: move ir_* models into models/ 2017-11-27 11:15:03 +01:00
Deep Patel eb9d7f8b6f [IMP] website_form: name of submitted attachments
In case of custom field 'upload file', the attachement
name will be the technical name of the input tag of the
form (aka 'attachments'). It is more user friendly to have
the name of the uploaded file.
2017-10-25 15:24:53 +02:00
Xavier Morel fccbe4ff4f [FIX] website_form: custom field thing blows up in P3
Custory reading seems to denote that field names are probably already
text in the normal case, and thus should not need decoding? It only
blows up in a tour so...
2017-09-14 12:21:26 +02:00
Olivier Dony 695716efb0 [FIX] P3: remove pycompat.{keys,items,values} helpers
Now that we're closer to switching to P3 for good, these helpers have
outlived their usefulness, and mostly add noise.

All remaining dict.iter*() or dict.view*() must be converted to the
normal keys(), values() or items() calls.

Whenever the result is likely to be used for more than the scope of a
loop, or when the dict needs to be modified during iteration, the calls
must be wrapped in a ``list()``, to protect the new P3 semantics.
Those cases are very exceptional.

Also removed some dead code or improved the API to remove unnecessary
conversions.
2017-08-20 23:25:54 +02:00
Olivier Dony 5f4db9df66 [MERGE] Forward-port saas-16 up to 5afe894f44 2017-05-16 18:23:15 +02:00
Olivier Dony 5afe894f44 [MERGE] Forward-port saas-15 up to 878fbc75ff 2017-05-16 17:09:45 +02:00
Olivier Dony 9b3ca1af23 [MERGE] Forward-port 10.0 up to 1545995b39 2017-05-16 12:12:30 +02:00
xmo-odoo fffaf735f5 [FIX] P3: list -> iterable builtins (#16811)
In Python 3:

* various builtins and dict methods were changed to return
  view/iterable objects rather than lists
* and the separate Python 2 view/iterable builtins and methods were
  removed altogether

This is problematic when using these items as list (which the happens
repeatedly in Odoo), but more viciously when iterating *multiple times*
over them (which also happens, which I've messed up multiple times while
writing this, and which is a pain to debug even when you've just created
the issue).

Convert all code using these to semantics-matching cross-version
helper functions to get the LCD behaviour between P2 and P3, and
forbid the builtins via lint.

issue #8530
2017-05-10 09:39:55 +02:00
Thibault Delavallée 16884487e7 [FIX] website_form: do not subscribe administrator to all records from website form
As administrator is used to create all records from website form he is
also put into followers. This creates a lot of unnecessary notifications
and/or emails depending on the system configuration.

Using the magic context key this behavior is modified. Administrator
will not follow every records created through the website form anymore.
2017-05-09 09:31:11 +02:00
xmo-odoo b4429c2a91 [FIX] Various P3-related import changes
* LDAP import: python-ldap is not python3-compatible, pyldap is

  Warning: only supported from debian Stretch (current testing)?
  https://packages.debian.org/search?searchon=names&keywords=pyldap

* implicitly relative imports
* imports of moved or removed stdlib modules

issue #8530
2017-04-28 09:06:53 +02:00
Xavier Morel 3979f6802e [#8530] convert exception handlers to except..as syntax
Futurize fixers:
* lib2to3.fixes.fix_except
2017-04-11 14:53:29 +02:00
Christophe Simonis 45045bb7a1 [MERGE] forward port branch saas-15 up to c8f01e3b62 2017-03-17 18:06:16 +01:00
Denis Vermylen 9995deda86 [FIX] website_sale: fix extra-step
truly fix 328a5a7ea3
sudo() was applied at the wrong step.

mea culpa
2017-03-15 10:44:52 +01:00
Jeremy Kersten 9edaf9fdf0 [IMP] website_form, website_hr_recruitment: improve thankyou page
Improve thank page after the application to a job.
Stop duplicate Magic field, using global fields
Add helper method on website to retreive the last created record
2017-03-10 18:20:11 +01:00
Raphael Collet 4a18d5744e [FIX] base: restrict read access to ir.model and ir.model.fields to employees 2017-01-20 10:05:10 +01:00
Raphael Collet 3649b7f359 [FIX] base: access rights of ir.model and ir.model.fields
This partially reverts commits 5d746d0ac6 and
73de86c768.

The tightening of access rights was too strong: regular users need to be able
to read models and fields (to create an email templace, for instance.)

[FIX] ir_values: in `get_actions`, exclude field `code`
2017-01-17 16:15:26 +01:00
Raphael Collet 5d746d0ac6 [IMP] base, *: tighten ir.model access rights
Remove unrestricted "read" access.  To make code internally using `ir.model`
work, add a private method `_get` on `ir.model` to retrieve the record
corresponding to a model name, without access rights issue.

Change signature of method `get_authorized_fields` to make it use a model name
instead of a model id.  This removes the necessity of a search on `ir.model`.
2017-01-03 16:52:49 +01:00
Christophe Simonis 235ed4b2c1 [MERGE] forward port branch saas-12 up to 9ad5f26 2016-08-20 18:08:19 +02:00
Christophe Simonis 9ad5f26b3f [MERGE] forward port branch saas-11 up to 3a2147d 2016-08-20 17:18:31 +02:00
Christophe Simonis bc1a0a32ca [MERGE] forward port branch 9.0 up to 58cbcba 2016-08-19 16:59:29 +02:00
Nicolas Martinelli 19e556b34f [FIX] website_form: traceback when sending an attachment
The form builder offers the possibility to add a "Custom File Upload"
field. When the user clicks on "Send", an error occurs ("An error has
occured, the form has not been sent.").

This is because we try to send a mail linked to "mail.mail", which
doesn't make sense.

The case was actually taken into account in the code, there was just an
oversight in the code.

opw-684040
2016-08-17 14:52:10 +02:00
Thibault Delavallée c8a313d51e [IMP] various: use odoo for imports instead of openerp and update class names 2016-08-10 15:48:07 +02:00
Christophe Simonis 5a3a06f26f [MERGE] forward port of branch saas-11 up to d4d09df 2016-07-04 13:16:34 +02:00