Commit Graph
662 Commits
Author SHA1 Message Date
Julien Castiaux 7da8e14669 [FIX] config: empty argument --foo= to disable
In the odoorc file, set a `logfile` path, but disable it via the command
line with `--logfile=`. The logs are output to the logfile configured in
the config file instead of stdout.

Parsing `--logile=` yield an empty string which was interpreted as
argument not set and skipped.

Closes #3852

closes odoo/odoo#60992

X-original-commit: bae0d99b8d654283be4d265e3b40a83247a2299c
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Signed-off-by: Julien Castiaux <Julien00859@users.noreply.github.com>
2020-10-29 13:50:07 +00:00
Paul Morelle 43dd5c70d1 [IMP] translate: add add/radd methods on _lt class
In order to ease the usage of lazy translation, add the possibility to
add the _lt objects together and with strings.

Adding two _lt objects together or to a string will execute their
translation, so these operations still must be done once the user's
language has been defined.

For example, this is now possible:

    MESSAGES = {
        1: _lt("Hello, world!"),
        2: _lt("Lorem ipsum"),
    }

    def get_text(code):
        return _("Text is: ") + MESSAGES[code]

closes odoo/odoo#60844

X-original-commit: c4596664e5514018c565eaf14b93e000d972bd30
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Signed-off-by: Paul Morelle <madprog@users.noreply.github.com>
2020-10-27 15:18:38 +00:00
Xavier Morel 7051a628c8 [FIX] core: PyPDF2 suppresses warnings
By default, PdfFileReader will monkeypatch the `warnings` module even
if it has no reason whatsoever to do so and suppress the
`captureWarnings` behavior.

This means as soon as we've loaded a PDF file, `warnings.warn` don't
trigger `logging` warnings anymore, and become invisible.

This can lead to non-deterministic behaviors depending as warnings may
or may not be suppressed depending when they occur relative to loading
a PDF e.g. load a module which runs a test which loads a PDF before a
module triggering a warning and the warning won't be visible, other
way around it will.

Except ofc while we have an override to PdfFileReader it's not
used *everywhere*, so need to monkeypatch the init.

closes odoo/odoo#60132

X-original-commit: 6b04dbcd4204a75d6bd68fc0b3010a2297779b32
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-10-15 17:34:57 +00:00
Luis González 6430ca499f [FIX] tools/safe_eval: Add missing builtin sorted
Before this commit, the function `sorted` wasn't available on
`safe_eval`, even though it's a Python built-in, which mades it
unavailable for Python-code evaluation, e.g. server actions.

After this commit, the above function is now accessible.

closes odoo/odoo#59715

X-original-commit: a725c8927963848c3f8ada3b71897a54b740cce6
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-10-12 08:12:19 +00:00
Jeremy Kersten 6538e20bb6 [FIX] tools.sql, website_*: increment counter with skip lock
*blog, forum, slides

Based on https://github.com/odoo/odoo/pull/48552#discussion_r440061218 suggestion

Add a new method 'increment_skip_lock' in tools.sql to allow to easily
increment a specific field of 1 if the record is not locked.

The method return boolean if at least 1 record has been incremented.

closes odoo/odoo#58765

X-original-commit: d92e61e89f468c2db2fbd68b2f0d6b36c77f1065
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-09-29 08:48:59 +00:00
Debauche StéphaneandXavier Morel 7ecb903bea [REM] *: ability to put raw modules in evaluation contexts
Co-authored-by: Xavier Morel <xmo@odoo.com>
2020-09-28 10:33:52 +02:00
Xavier Morel e56d4cc6dd [FIX] core: remove callbacks from queue before invocation
The callbacks system is not re-entrant: because we were only clearing
the callbacks after having executed them all, if one of the
post-commit callbacks commits then all the callbacks will get
re-executed (including the one which commits). Which at best can lead
to odd effects & data corruption and at worst crashing the software
because we're overflowing the stack (or maybe the other way around,
hard-crashing might be a better idea than unexpectedly calling the
same functions multiple times).

By popping the callbacks before executing them, we ensure that each
one will only get called once (unless it's explicitely re-pushed on
the stack).

closes odoo/odoo#57516

X-original-commit: 4257be4d771605ecd972bd5b04cb9c0f1163b455
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-09-11 11:23:22 +00:00
Victor Feyens 594ccdcbf4 [FIX] *: typos and english incoherences
Mainly transifex issues but also some errors found through 'grep' checks.

Fix typos and obscure english strings in xml contents, fields strings/helps, some docstrings, ...
ensuring correct translations base (and fallback when translations isn't available).

closes odoo/odoo#57276

X-original-commit: 4214f05d454bca2b60fda3a288d529c098e84f77
Related: odoo/enterprise#13053
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2020-09-08 18:12:26 +00:00
Raphael Collet e8f7cfd00a [FIX] core: cursor hooks API and implementation
Python 3.8 changed the equality rules for bound methods to be based on
the *identity* of the receiver (`__self__`) rather than its *equality*.
This means that in 3.7, methods from different instances will compare
(and hash) equal, thereby landing in the same map "slot", but that isn't
the case in 3.8.

While it's usually not relevant, it's an issue for `GroupCalls` which is
indexed by a function: in 3.7, that being a method from recordsets
comparing equal will deduplicate them, but not anymore in 3.8, leading
to duplicated callbacks (exactly the thing GroupCalls aims to avoid).

Also, the API of `GroupCalls` turned out to be unusual and weird.  The
bug above is fixed by using a plain list for callbacks, thereby avoiding
comparisons between registered functions.  The API is now:

    callbacks.add(func)     # add func to callbacks
    callbacks.run()         # run all callbacks in addition order
    callbacks.clear()       # remove all callbacks

In order to handle aggregated data, the `callbacks` object provides a
dictionary `callbacks.data` that any callback function can freely use.
For the sake of consistency, the `callbacks.data` dict is automatically
cleared upon execution of callbacks.

Discovered by @william-andre

Related to odoo#56583

References:

* https://bugs.python.org/issue1617161
* python/cpython#7848
* https://docs.python.org/3/whatsnew/changelog.html#python-3-8-0-alpha-1
  (no direct link because individual entries are not linkable, look for
  bpo-1617161)

X-original-commit: d4b2e9224839aed8fc160ebe5a89e0f7d4c6a5bb
2020-09-03 14:29:39 +00:00
Xavier Morel c1c43bbe38 [REM] core: assertion reports
That's a not-very-useful subset of OdooTestResult, so:

* make results merge-able (aka add ability to update a result with the
  contents of another)
* remove support for test data files, and transmission of the
  assertion report thing through the data-files loading
* replace "legitimate" uses of assertion report by test result
* have run_unit_tests manipulate and return a result instead of weird
  flags & ternaries
2020-08-19 14:08:12 +00:00
Xavier Morel 083c70bbb6 [IMP] core: replace dedicated uid cache by ormcache
Before this, invalidations to the UID cache is not synchronised
between workers because it's an ad-hoc solution (so a user changing
their password or an admin disabling a user would only lock out an
attacker currently using the API of one of possibly several
workers). Shift the entire thing to ormcache which already has proper
support for synchronising cache invalidation between workers.

Also simplify the cache invalidation mess in Users.write because the
caches have been unified into a single registry-level LRU, so the
half-dozen cache clears on specific ormcached methods & models is
pretty much the same as repeatedly calling clear_caches on the current
model.

**However** registry.cache is trivially accessible from server actions
and safe_eval as long as they provide access to a model (through
`model.pool.cache`). Which is common, and an issue given we're very
much putting sensible data in there.

Fix this by renaming `Registry.cache` to `Registry.__cache`, this
requires few editions and mangled names are not accessible from
safe_eval contexts.

The alternative would have been to add more bespoke handling of the
uid cache to hook it into the cache invalidation propagation
machinery.

After discussion with (@)odony, fixing LRU access and using that seems
cleaner and less error-prone.

Note on lazy_property
=====================

Make Registry.cache / Registry.__cache into a regular attribute: the
overhead of the LRU is not that high (compared to that of the registry
itself), it's rare that we *don't* need it, and it's assumed to be a
persisted attribute (it's not just a cache) so making it a normal
attribute seems fine; and lazy_property doesn't work for mangled
names: the name of the property is mangled using the name of the
definition class, but the name of the symbol (fget) is not mangled so
lazy_property would set the __cache attribute but then Python would
lookup _Registry__cache, creating a new cache every access.

And we can't (always) mangle things correctly on `__get__(obj,
owner)`: `owner` is just `type(obj)`, meaning in the case of
inheritance the type we get is the type through which the property is
accessed rather than the one it's defined on. So it would work in the
cases where no inheritance is involved (such as Registry.__cache) but
not in general (lest we want to play around walking the MRO ourselves
to find the definition source, which doesn't seem worth it).

lazy_property *could* be made to work properly on Python 3.6+: the
descriptor protocol gains `__set_name__(name, owner)`, which is called
with the properly mangled name — and with the definition class to boot
(though there might still be issues when overriding lazy properties as
the override will be mangled & named differently... or maybe that's a
feature?). However we're still supporting 3.5 at this point, AFAIK, so
that's not an option. Plus it feels unnecessary / not very useful.

However add an assertion to `lazy_property` so it signals when we try
to use it on a mangled method (as otherwise it kinda sorta work in the
sense that the property / object is accessible but is in effect a
slower way to write a regular property).
2020-08-14 23:03:27 +00:00
Martin Trigaux 7742f0b42b [FIX] tools: skip inexistant model
When trying to generate translation for a model that is not present in
the registry (leftover of migration?), the code used to return
self.browse(), expecting an empty recordset.

self was however a TranslationModuleReader that has no browse method
return empty recordset with no model specified

closes odoo/odoo#55574

X-original-commit: c004f00bdec83b7c56664425011db53db85da53a
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-08-06 14:16:08 +00:00
Jeremy Kersten 7e8a1f7a06 [FIX] tools: LRU doesn't have keys() method anymore
Since commit 1b30a78b, LRU is now based on OrderedDict and keys can be found
on dictionnary 'd' directly.

closes odoo/odoo#55541

X-original-commit: 3f093da75765d66ed1e2d828e8b41ed05d936d0b
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-08-06 10:54:07 +00:00
std-odoo ed4846dd9d [IMP] mass_mailing: add preview block for mailings
PURPOSE

When displaying an email in a list the mail client (gmail, outlook...) computes
a preview based on the content. This preview is generally not well computed as
it contains a lot of garbage and tags while it should contain only relevant
text.

SPECIFICATIONS

To build this preview, all mail clients read the content of the email.
The only way to be able to customize the preview is to add an invisible
HTML element at the beginning of the email with the wanted preview text.

We add at the end of the preview `&zwnj;` (zero-width non-joiner) to
fill the end of the preview in order to not have the beginning of the
mail at the end of the preview. It doesn't work with simple space as
the mail clients trim each HTML element content.

Task ID-2172125
PR #49886
2020-08-05 13:55:04 +00:00
Xavier Morel c8063af7a0 [IMP] core, account, lunch: make <menuitem> recursive
For clarity, some data files are formatted as pseudo-tree
structure. This is somewhat confusing and dangerous when the structure
has no meaning... so add meaning:

* allow nesting menuitems, nested items are set as children to the
  parent they're nested in
* update schema to allow an icon *or* a parent on regular menu items,
  and neither on nested (they have an implicit parent meaning can't
  have an icon)
* remove attributes which don't actually exist from the menuitem
  schema
* also type sequence as an integer while at it

Convert two large-ish menuitem data files to recursive form.

closes odoo/odoo#54564

Related: odoo/enterprise#11887
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-07-28 13:03:13 +00:00
Xavier Morel 6835aeb0de [REM] core, *: deprecate <act_window> and <report>
Convert deprecated tags through the codebase.
2020-07-28 13:03:13 +00:00
Thibault Francois 6f47bfd916 [FIX] base: cloc test and default exclude
- Python code is counted slightly differently
in python 3.8.

```python
a = """
  str
"""
```

is counted as 2 lines until python 3.7
and only one since python 3.8

This change will not impact a lot the count
but we have to make sure the test will pass
if the test are run
on python 3.8

- the folder migrations is not maintained
from version to version and thus should not be
counted for the maintenance.

closes odoo/odoo#54537

X-original-commit: 2a57a156c7b8e81c01afa095b3291361d208611f
Signed-off-by: Antony Lesuisse (al) <al@openerp.com>
2020-07-15 18:49:20 +00:00
Xavier Morel c0745584aa [FIX] core: handle recordsets in traverse_containers
Since recordsets are self-recursive, they should be treated like
strings (where iterating a string yields a string, infinitely) in case
somebody happens to return a non-downgraded recordset from a method.

closes odoo/odoo#54572

X-original-commit: 6d88845f339d164fc2667c3417dcc331b317e4db
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-07-16 12:04:57 +00:00
Julien Mougenot 669c2ebaec [IMP] web: improve eval context dates
This commit handles 2 things:

1) the merging of the `py_utils.context()` into the evaluation context
returned by `BasicModel._getEvalContext` to access the same time-related
keys,

2) the addition of 2 new keys into the `py_utils.context` (thus
transmitted to the basic model): `today` (an alias for the already
present `current_date`) and `now` which represents the current date and
time value.

Task 2269697
2020-07-14 09:10:32 +00:00
william bffb3b7fce [REF] base: clean dosctring and remove deprecated function
The function check_with_xsd has been deprecated for more than 3 years.
Docstring is now compliant with PEP 257

closes odoo/odoo#54338

X-original-commit: 29938397ee17835645e89ee0dadb26e14ef45927
Signed-off-by: Josse Colpaert <jco@openerp.com>
2020-07-10 14:18:13 +00:00
william 048c7fef67 [IMP] base: _check_with_xsd from ir.attachment
Search the xsd files from in the database.
To enable this option, the Environment should be passed to the optional
`env` parameter. Both the XSD root and the XSD imported by the root and
the recusrively imported files will be searched in the database.

X-original-commit: 06a35f2e11230db81b8c21696d228097b31cf649
2020-07-10 14:18:12 +00:00
Martin Trigaux 110263df56 [IMP] tools: use same syntax for _lt than _
A new gettext syntax was added at odoo/odoo#52155 but only for _, not
for _lt
Allow to have the same syntax
2020-06-30 10:19:50 +00:00
Martin Trigaux d12813f7ee [IMP] tools: fallback on empty translation
Avoid returning False if, for any reason, the return is falsy (False,
None,...)

Following the discussion in odoo/odoo#53254, the root cause was a call in the form
  _(foo)

where foo was equal False

While nothing else than a string should be the argument of _, it's
still technically possible to pass something else and get a bad return
value.
Fallback on empty string to be consistent.
2020-06-30 08:53:29 +00:00
Nasreddin (bon) 3c169a415b [FIX] tools: Return input_str when removing accents if empty
Issue

	The misc feature remove_accents(input_str) return a
	string 'False' if the param is a boolean.

Solution

	Return input_str if equal '' or False.

opw-2278959

closes odoo/odoo#53572

X-original-commit: 3fc7ce3b5599355933734e5e3f59d14a7a9b199c
Related: odoo/enterprise#11391
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
Signed-off-by: bon-odoo <nboulif@users.noreply.github.com>
2020-06-24 11:06:01 +00:00
Benjamin Frantzen (bfr) ae15f89f73 [FIX] tools.pdf: do not crash when PDF has no attachments
In the PDF, `DictionaryObject` can be wrapped in `IndirectObject`. For nested
dictionaries, using `get` on a `DictionaryObject` will unwrap the result if it's
an `IndirectObject`, but not `__getitem__` so when trying to futher call `get`
on the result will cause an error: we need to unwrap the object first.
Instead, we patch `DictionaryObject.get()` for it to unwrap the object in case
it's an `IndirectObject`.

This is a follow-up commit of fece5ab1bf2fef043b131f1bd0886f0841116103

closes odoo/odoo#53269

X-original-commit: 189a0b28ec7fdb7472f936450cfd7b4bfd6912ed
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Signed-off-by: bfr-o <bfr-o@users.noreply.github.com>
2020-06-18 16:49:32 +00:00
Martin Trigaux ba244cef01 [IMP] *: replace to new _() syntax
Using a few regex like
\((_\(.*%s.*)(\) % )([\w\[\]][\w .\[\]\(\)'"]*)\)
($1, $3))

Old syntax is still compatible but starts the migration to the new
syntax that catches error.
2020-06-18 13:03:34 +02:00
Martin Trigaux 3c3b88f676 [IMP] tools: add placeholder support to _
Mimic the syntax of logging to use placeholders in translatable
message.
The main advantage is to be able to fallback on the source term if the
translation can not be formatted properly.
It is very common to have errors in translations with missing
placeholders or badly translated (ie. the source
     "%(subject)s" -> "%(sujet)s").

Instead of blocking the execution of the code, fallback on source
string.

Task-id: 1853119
2020-06-18 13:03:34 +02:00
Dharmraj Jhala 5af661da7d [FIX] tools: fix tool method to check empty html content
Since a recent commit[1], we have a utility method in tools named
'is_html_empty'  that checks whether the given html content is
void(containing only formatting tags) or not. However, the re from
this method does not consider the case of self closing tags, fox ex
`<br/>`. In such cases, the method returns Falsy value even if the
content is void.

This commit fixes the issue by considering self-closing void tags
in the regular expression.

commit[1] - https://github.com/odoo/odoo/commit/974f512f5f5d3b9f80a8c3fcde290e4f55cf1230

Task - 2267689

closes odoo/odoo#53167

X-original-commit: 0fd6c9388dc959a9b6b7828850683175edb05b9d
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2020-06-17 14:19:09 +00:00
std-odoo b16843230d [IMP] mass_mailing: send a statistics email to the mailing responsible
Purpose
=======
Provide a follow-up/overview of the Mailing 24 hours after its been sent.

Specifications
==============
Send an email to the responsible of the mailing 24 hours the last email
of the mass mailing.

During the link trackers creation, extract the button label if exists
(so we can display them in the statistics email).

Technical remarks
=================
The statistics email is sent to the responsible of each mailing in the
CRON of mass mailing.

Task-2227411

closes odoo/odoo#49836

Related: odoo/upgrade#1094
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2020-06-12 11:49:45 +00:00
Nicolas Lempereur eaef67323b [FIX] tools: add bdi tag as safe tag
We already have BDO tag as allowed tag in sanitized HTML that is
similar to BDI tag, so this commit also adds BDI in allowed tags.

BDI* tags make sense in email since email client can have different
orientation than Odoo (alternative is to use `<div dir="auto"></div>`).

*: https://developer.mozilla.org/en-US/docs/Web/HTML/Element/bdi

opw-2256982
closes #52787

closes odoo/odoo#52801

X-original-commit: 68edebb0d862acb3dc14f839aaef744306c5e269
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2020-06-11 06:39:11 +00:00
Benjamin Frantzen (bfr) b1d19c61b1 [FIX] tools.pdf: do not crash when PDF has no attachments
Depending on the PDF version and the presence of embedded files, the PDF
document catalog `trailer["/Root"]` may not have any Name Dictionary
`["/Names"]`, and the latter may not have any `EmbeddedFiles` entry.

In that case `getAttachments()` should return an empty list rather than
raising a `KeyError`.

closes odoo/odoo#52312

Ref: Section 7.7.2, 7.7.4 and 7.11.4 of [PDF 1.7 spec](https://www.adobe.com/content/dam/acom/en/devnet/acrobat/pdfs/PDF32000_2008.pdf)
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2020-06-03 14:08:37 +00:00
1c522ee778 [ADD] odoo-bin cloc cli subcommand.
Odoo cloc is a tool to count the number of relevant lines written in Python,
Javascript or XML. This can be used as rough metric for pricing maintenance of
customizations.

It has two modes of operation, either by providing a path:

    odoo-bin cloc -p module_path

Or by providing the name of a database:

    odoo-bin cloc --addons-path=dirs -d database

In the latter mode, only the custom code is accounted for.
Both modes can be used simultaneously.

Files that cannot be parsed are shown at the end of the report.
Parsing can fail due to syntax errors or excessive file size.

closes odoo/odoo#52635

X-original-commit: ae858c3ac66267b4726db459032b91a6be1cc1d6
Related: odoo/enterprise#11018
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Co-authored-by: Thibault Francois <tfr@odoo.com>
Co-authored-by: Antoine Vandevenne (anv) <anv@odoo.com>
2020-06-09 00:30:55 +00:00
Martin Trigaux c9f93eb639 [FIX] tools: remove max language length constraint
There is no reason for this constraint to be. Languages with a code
longer than 5 do exists in standard, (e.g. ar_001, sr@latin)

Introduced at 004a0b996f

Fixes odoo/odoo#52558

closes odoo/odoo#52569

X-original-commit: 54340487adaed962750c9719fb50fc7e000da476
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-06-08 09:00:02 +00:00
Benjamin Frantzen (bfr) 0226901ec7 [IMP] base, tools: manage multiple attachments on PDF files 2020-05-29 07:16:30 +00:00
Stéphane Debauche 2244961314 [IMP] mail,tools: clean tags to kill list in HTML sanitizer
Some tags are not necessary in the HTML template and we can remove them to
have a proper HTML output.

Task 2171753

closes odoo/odoo#51757

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2020-05-25 07:28:19 +00:00
Martin Trigaux c142f1628d [FIX] tools: reimport translations in csv
Before this commit trying to reimport csv of a translation failed.
The reason was that before 632fa044c3 the parsing was common
between po and csv while now it's split in two different parsers.
The res_id column of the CSV is the external id of the record and is
handled by IrTranslationImport.

Use DictReader instead of csv_reader to easily add new keys and still
be flexible on the given csv files.

Match the POReader format with a imd_model and imd_name column.

As for the PoFileReader, the code translations are unique and must be
discarded in case of duplicate.

Correct the error message if the imported file is not correct (was
missing an argument)

Fixes odoo/odoo#50975

closes odoo/odoo#51468

X-original-commit: 3cedadb5ba606e156f52e70ed08b25ac2df8d58b
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-05-19 08:01:17 +00:00
std-odoo 1c7c837a10 [FIX] mass_mailing: improve opened traces tracking
Purpose of this commit is to improve tracking of opened traces. Notably
a token is added to ensure we do not mess with traces and have unique
tracking URLs.

MIGRATION REMARK

Emails sent before the migration will not be marked as opened anymore after
migration. We recommend to avoid sending statistically important mass mailings
about one week before migrating database. Indeed statistics show that most of
open emails happen within the first week after being sent.

Task 2223146

closes odoo/odoo#49139

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2020-05-18 08:30:59 +00:00
Stéphane Debauche 55cb0de1db [IMP] tools: remove unnecessary lxml Cleaner override
Purpose
=======

Currently a custom override of Cleaner.allow_element()
exists in tools to allow object tags for SVG images.
This was due to the first prototype of website builder
and its first implementation of image and svg management.

This is not necessary anymore as using the tag is sufficient.
We can safely clean code in the cleaner, allowing to speedup
its performances. As it is used in most html fields and email
parsing each unnecessary code removed is time gainged.

Task 2215228

closes odoo/odoo#51294

X-original-commit: 4a0b09fd3b0d3b63f2df00f002e4d6825cac4eef
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-05-14 18:51:22 +00:00
Martin Trigaux d9287caf94 [IMP] *: convert to private methods
render, render_template, load, activity_schedule_with_view,
get_website_pages should all be private:
It should not be possible to render an aribtrary template only with
its name or id

Still need to render some qweb views from js so the method
render_template is kept public.
This explains why the website editor still need read access on
ir.ui.view as we want to allow any snippet to be rendered.
2020-05-14 13:59:10 +02:00
Victor Feyens d2652e971a [IMP] doc: add information on the new populate feature.
* Cmdline interface: how to trigger database population
* Testing: how to implement database population on a given model.
  * autodocumentation of the population methods

+ improve population methods docstrings.

closes odoo/odoo#50596

Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2020-05-13 15:47:04 +00:00
Julien Castiaux afcb734908 [IMP] ir_mail_server: IDNA and SMTPUTF8 capabilities
It has been a recurrent request from customers to be able to send email
messages to email addresses containing non-ascii characters. [IDNA] is a
domain extension to allow unicode characters in domain names. [SMTPUTF8]
is a SMTP extension to allow unicode in any header.

IDNA defines the [punycode] encoding which translates unicode to an
ascii representation. This encoding MUST be used to encode domains.

SMTPUTF8 is an SMTP extension that allow utf-8 in all headers on the
envelope.

[IDNA] https://tools.ietf.org/html/rfc5890
[SMTPUTF8] https://tools.ietf.org/html/rfc6531
[punycode] https://tools.ietf.org/html/rfc3492

Task: 2116928
opw-2229906
opw-2248251

closes odoo/odoo#47709

Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2020-05-05 09:17:15 +00:00
Jeremy KerstenandRomain Derie 9247c5e8fd [IMP] tools: avoid useless query on res.users
Without this commit, if `lang_code` or `env.context.get('lang')` was set, we
would still access `env.user.company_id.partner_id.lang` to fill the loop array
even if we break and don't need that value.

Switching from loop to if conditions prevents that.

task-2211013

Co-authored-by: Romain Derie <rde@odoo.com>
Co-authored-by: Jeremy Kersten <jke@odoo.com>
2020-04-27 13:49:01 +00:00
Nicolas Lempereur b781fb588e [FIX] mail.py: escape plaintext email
A plaintext email is displayed in a `<pre/>` tag to conserve spacing.

But since there is no escaping, if in this text there was XML tags or
HTML entities, they would appear as HTML in browser which is not wanted.

Do note that this was not a security issue since the content will still
be subjected to the checks and foundling of HTML emails.

Without the change, the added test would fail because character &,<,>
were not escaped.

opw-2242323
closes #50003

closes odoo/odoo#50123

X-original-commit: 932532b5b59e0b71c8e16dadfb2ff36c38764208
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-04-24 09:08:08 +00:00
Christophe Monniez eec563c2f1 [FIX] packaging: include _vendor in packaging
Since a0f9ef56, a _vendor module was added without `__init__.py` file,
following the PEP 420 specifications.

Unfortunately, as the `setuptools.find_packages()` only recognize
packages if they have such an init file, the _vendor module is not
packaged. This leads to an import error when running Odoo from the
src,deb and rpm packages.

The `setuptools.find_namespace_packages()`, which is compliant with PEP
420, could have been used instead. But this function does not exists in
setuptools 39.0.1 which is the one packaged in Ubuntu Bionic.

Finally, this commit simply adds the missing dunder init file.

closes odoo/odoo#50051

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2020-04-24 07:43:14 +00:00
Xavier Morel 9d4ee88263 [FIX] core: vendored sessions.py so it actually works
* remove SessionMiddleware we don't need as it's responsible for most
  imports
* fix relative imports to absolute imports from werkzeug
* remove py2/py3 compatibility imports, shims and conditions as we're
  P3 only
* remove deprecation warning (duh)
2020-04-22 09:28:14 +00:00
Xavier Morel 39fb7f9d31 [ADD] core: vendor werkzeug 0.16's sessions.py
In Werkzeug 1.0, sessions support was moved out and into a separate
package (secure-cookies). Issue is distros are already starting to
update werkzeug to 1.0, without necessarily adding
secure-cookies (e.g. arch, debian experimental). Plus secure-cookies
has some changes e.g. different filename & al. So just vendor the
"continuity" version which is the last werkzeug before removal.

This commit copies the original file as-is so we can track eventual
changes if necessary.
2020-04-22 09:28:14 +00:00
Xavier Morel 0655974d5a [IMP] safe_eval: opcodes blacklist & cleanup
There are bytecode operations we don't support because we've never
needed them, and there are bytecode operations we don't support
because they're vectors of security issues.

Currently no difference is being made between the two, so when looking
to add a new opcodes it's hard to know whether it's been considered
and rejected or whether it just hasn't been considered (or found
useful) yet.

Add an explicit blacklist, which is explicitly subtracted to all
opcodes lists, to allow motivating the bans of certain
opcodes. Opcodes listed in no lists are the "graylists" of opcodes we
either haven't yet considered or have not had a use for.

Also cleanup the existing lists of opcodes to remove long-gone (or
even never-existing) opcodes, and add a few missing opcodes:

* DUP_TOPX was removed from Python 3, replaced by DUP_TOP_TWO
* STORE_MAP was removed in Python 3.5
* BINARY_DIVIDE and INPLACE_DIVIDE were removed from Python 3 (they
  were used to invoke P2's integer division)
* the SLICE+<X> were removed from Python 3, which only uses
  BUILD_SLICE
* CALL_FUNCTION_VAR and CALL_FUNCTION_VAR_KW were removed in Python
  3.6 and functionally replaced by CALL_FUNCTION_EX (bpo-27213)
* JUMP_IF_FALSE and JUMP_IF_TRUE were removed back in 2.7, replaced by
  POP_JUMP_* and JUMP_*_OR_POP (bpo-4715)
* various finally-related bytecode instructions were added to Python
  3.8 to improve and speed up the handling of return, break and
  continue (bpo-17611).
* INPLACE_REMAINDER, INPLACE_LEFTSHIFT and INPLACE_RIGHTSHIFT were
  mentioned in PEP 202 but never actually implemented: INPLACE_
  instructions were intended to mirror the BINARY_ instructions, these
  mnemonics didn't match the BINARY_ ones, so the actual mnemonics are
  INPLACE_MODULO, INPLACE_LSHIFT and INPLACE_RSHIFT
* while at it, BINARY_ and INPLACE_ mnemonics: as noted above they're
  mirrors of one another with different prefixes (except for SUBSCR
  which doesn't have an INPLACE version), we only supported a fraction
  of the INPLACE codes for unknown reason.

  Initially looked at simply aligning the BINARY and INPLACE mnemonics
  e.g.

       'BINARY_POWER',  'BINARY_MULTIPLY',  'BINARY_FLOOR_DIVIDE',
      'INPLACE_POWER', 'INPLACE_MULTIPLY', 'INPLACE_FLOOR_DIVIDE',
      ...

  so it would be easier to notice discrepancies, but it seems simpler
  and clearer to just move the suffixes to a single list and generate
  the BINARY_ and INPLACE_ mnemonics from that
* moved STORE_SUBSCR from EXPR to SAFE, I don't see how `foo[...] = 3`
  could be in an expression
* remove pseudo-graylist `_POSSIBLE_OPCODES_P3`, was intended as a
  list of new P3 opcodes we might want to add, but the purpose was
  hard to understand and a proper blacklist makes way more sense

closes odoo/odoo#41085

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2020-03-23 08:56:21 +00:00
Lucas Perais (lpe) 69b51ce05e [FIX] translate: do not export OWL directive's attribute
Have a static template of the form:

```xml
<div t-name="ComponentA">
 <ComponentB title="no export" />
</div>
```
To be used by OWL (github.com/odoo/owl)
In this context, the title in the attributes of ComponentB
should not be considered as *the* title attribute of HTML
but as a sort of variable declaration

Before this commit, the string contained in the value of this
title attribute was exported. It was not translated at runtime,
but we want to export as less stuff as possible in PO files

So, after this commit, none of the attributes held by a OWL directive
are exported

This commit relies on OWL Syntax, which makes mandatory
for a component directive's first letter to be capitalized
https://github.com/odoo/owl/blob/master/doc/reference/component.md#composition

Also, it relies on the good practice and widespread convention to have
every HTML node lower cased
https://www.w3schools.com/html/html5_syntax.asp

closes odoo/odoo#46191

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-04-17 12:55:32 +00:00
Romeo Fragomeli fbd1d7584a [FIX] tests,tools: remove unused code
Due to this commit: odoo/odoo@0ea67467b1 ( https://github.com/odoo/odoo/blob/0ea67467b1301b39a263a386a622e931784eb0de/odoo/tools/config.py#L521 )

the screencasts value is not a string anymore but a valid PATH.

So now you can't set '1', 'true' or 't' to force to have the
same directory as the screenshot dir.

Steps to reproduce:
odoo-bin ... --screencasts 1 (with a failed JS test to produce a screencast)

closes odoo/odoo#49665

X-original-commit: ab1bf59a3b78f3c0857755cb2439636b6df297c3
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
Signed-off-by: rfr-odoo <rfr-odoo@users.noreply.github.com>
2020-04-16 13:28:07 +00:00
Xavier Morel 1ecb0641ef [FIX] core: calling read_group / name_search over xmlrpc
Also non-browser jsonrpc (as it goes through a similar process): for
internal performance reasons, name_search and read_group have been
converted to a *lazy* name_get, so the "display name" is not
unnecessarily computed.

However this is an issue for the RPC endpoints (/xmlrpc and /jsonrpc)
as they have no support for `lazy` and thus tend to blow up and / or
do the wrong thing when trying to output a lazy:

* xmlrpc has no way to handle lazy at all and straight blows up
* jsonrpc falls back to `json_default` so they try to stringify the
  lazy, which might have worked except

*Problematically* both endpoints delegate the actual work to
`dispatch_rpc` which handles dispatching between various services and
ultimately creates a *new* cursor before calling model
methods (`object` service and `execute`/`execute_kw`).

This means by the time the result is serialized to be output, the
lazy's cursor has long been closed, and thus any access to an
unevaluated `lazy` errors out when trying to fetch the underlying
item.

This also means we can't just add a hook to serialize the lazy
in the xmlrpc marshaller, though we do have to do that. We *also* (for
both xmlrpc and jsonrpc) have to force evluation of lazy values before
our cursor is closed, meaning it has to be done right after the method
is invoked, iterating the entire response.

Related to task 2170343

closes odoo/odoo#49286

X-original-commit: e2b5a359c1d5eccbe725c1c3169b4130d7bca49b
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-04-09 09:06:34 +00:00