Create a record.
Add an attachment, using the widget (aptly named 'add an attachment').
It is not set as message_main_attachment_id.
If you add the message through 'log note', then it is.
We add a hook to make sure that it is set as message_main_attachment_id
when added through the widget.
opw 1950403
closesodoo/odoo#31847
Signed-off-by: Nans Lefebvre (len) <len@odoo.com>
In 3d2ca8104e some change were introduced to the graph view.
But part of it had no sense when displaying data over 2 group by.
eg. if the first level has 2 groups (2018, 2019) and each second level 2
groups (Done,Cancelled), we could have:
2018/Done: 0
2018/Cancelled: 5
2019/Done: 8
2019/Cancelled: 9
this gives us two main groups [2018: 5] / [2019: 17], the code
remove the 2018 because [2018/Done] is 0 so we have something odd
with columns not in order, and in stacked bar chart some part of
a bar at the wrong offset
opw-1932517
closes#30529
Being in debug mode is necessary to become superuser (whether on the
login page or within the client), however because the becoming
endpoint would straight redirect to the _login_redirect result the
debug mode would be lost, which is commonly inconvenient.
Replace the redirect_with_hash call by local_redirect, which goes
through great pains to conserve the ?debug by default.
Task 1908202
closesodoo/odoo#29058
Before this commit, if you ask for a small image, you was waiting a picture of
64x64 but in case this image was not found, a placeholder with an other size
was returned.
Now, we try to guess the asked size, and return a resized placeholder.
This bug appear since we change the default placeholder picture with a big one
This will fix several issue and avoid to hard code size everywhere in the code
Eg: commit 92f837c and commit https://github.com/odoo/odoo/commit/154fc7d9dd550d35b7266af024e54c20e18938fc#diff-9af1af2039d16d6b544d481b4ee1ed7cR144closesodoo/odoo#27695
Introduce official support for SVG files in the framework, including the
following parts:
1. When client-side SVG images are uploaded, the content is displayed until
you save using data URI scheme according RFC 2397 [1]. This scheme requires
to specify content format. Using hardcoded "image/png" works for all images
types except SVG.
Type-sniffing is done using "magic byte" detection via the first base64
encode byte, so that the proper data URI scheme can be used.
This should not cause SVG-related security problems as the file is
displayed through `<img>` tag, which does not allow SVG scripting [2].
2. Make /web/image controller compatible with SVG
3. Add support for SVG files for company logo, which uses a dedicated
controller.
4. Resizing of SVG files is a no-op, as it makes little sense for a
vector-based format. We also want to avoid micro-alterations to the SVG
document (in "natural" viewport parameters) as we would store multiple
copies of the files in the filestore.
5. Because SVG files are inherently dangerous, upload of SVG files is
restricted to administrators, either by blocking it directly before
saving it in the database (binary fields with attachment=False), or by
neutering them to text/plain mimetype (for binary fields with
attachment=True)
6. Add tests for the SVG upload cases and for the non-admin uploads.
[1] https://tools.ietf.org/html/rfc2397
[2] https://www.w3.org/wiki/SVG_SecurityCloses#26635
Auth can now report errors less trivial than "incorrect password", the
wizard should report them instead of just assuming the original
password was not correct.
* requires that current user has group_system
* only visible in debug mode (?debug)
* available at login or via debug menu
* special systray color in superuser sessions
Closes#27254
- Changed the binary_content method
to make it more generic and allow alternative ways of checking
the access rights by using a new method check_access_mode.
Reason: Asked by ODO following documents' security review.
- if all pages are processed, splitting a pdf will
archive the original attachment.
Reason: FP feedback.
Task: 1853490
-removed force_ext from ir.http.
-added signature arg to web/image to differentiate cache entries by URL.
-added an embed youtube viewer for youtube URL's
-added a PDF splitter to the PDF viewer UI
-added tests for mail's Document Viewer
-added a "signature" param to web/image to go around the browser cache
-thumbnail field of ir.attachment is now stored in the filestore
as a distinct attachment.
task 1853490
Co-authored-by: Pierre Paridans <app@odoo.com>
Rev. 279d928693 forced
`server_wide_modules` to include 'base' and 'web', because both contain
controllers that need to be always loaded.
However the patch used a set() that randomized the order of the list,
when combined with Python 3.5's randomized hash function.
This is turn could cause the checksum of asset bundles (web.assets_backend)
to randomly vary, which could cause rapid assets recycling and errors.
- Activate lots and SN
- Go to Inventory > Inventory Adjustments
- Export a record
- Select the field 'Inventories > Lot/Serial Number'
The `name_get` of the field is exported, not its XMLID.
This is because the parsing made in order to limit the depth of export
is made on the label, not on the field name.
Actually, it is not clear WHY this limitation exists, but we keep it for
compatibility purpose.
opw-1877092
Allow to override the asset url generation to add in the path the website ID
and avoid continue invalidation cache and bad cache by browser.
Asset url is:
"/web/content/{id}-{unique}/{extra}{name}{page}{type}"
with:
id = attachment id
unique = hash
extra = allow to add custom params eg: website_id/ or rtl/
name = filename
page = used in css to split rules 4095 / file
type = css|js
Co-authored-by: Derie Romain <rde@odoo.com>
Co-authored-by: Kersten Jérémy <jke@odoo.com>
This commit is the counter-part of an enteprise commit introducing
the Documents app.
Here is a summary of what has been done:
- tweak unlink of ir_attachment to prevent unlink recursivity
(when attachments are attached to ir_attachments)
- improve ir_attachment kanban view
- add several arguments to binary_content controller:
- 'force_ext': to force the extension in the filename, base on
mimetype
- 'share_token' and 'share_id': to autorize download from a
share link
- add 'thumbnail' field on ir_attachment to optimize Kanban view
- add 'upper_limit' argument to image to allow to bypass the
500*500 size limit
- DocumentViewer now handles text files
More information available on task 1853490
Co-authored-by: Pierre Paridans <app@odoo.com>
Co-authored-by: sri-odoo <sri@odoo.com>
Co-authored-by: ThanhDodeurOdoo <tso@odoo.com>
This commit adds a new ir.action.report type: qweb-text. It produces text files,
serves them with a text mimetype and these reports use the same rendering context
as the current other types (PDF and HTML).
This will be used in a following commit to produce ZPL scripts. Those scripts
are used for printing thermal label on Zebra printers.
task ID : 1837175
* Make Users._login and session.authenticate always raise AccessDenied
on authentication failure instead of only sometimes (cf
Session.authenticate calling security.check() which raises and not
catching the exception)
* Alter AccessDenied such that it's possible to add a custom access
message, for use with login rate limiting instead of smuggling the
information via the session
* Alter the RPC endpoints to catch and convert AccessDenied back to
a boolean sentinel
Task 31122 section 4.
Implement per-IP rate limiting of login attempts after some number
of failures.
* check_credentials has no reason to be public, make it private
* add hooks to check for login cooldown on a source IP (remote_addr:
http://werkzeug.pocoo.org/docs/0.14/wrappers/#werkzeug.wrappers.BaseRequest.remote_addr)
basis
* add baseline/default configuration of 60s cooldown
* add baseline threshold of 10 login failures, after checking odoo.com
logs it looks like we have short runs of up to 7 failures (assumed
to be legitimate) before the user either gets it right or goes and
looks it up
Depends on #24187
Task 40692
Various changes to import/export (mainly) UIs:
* default to excel & "full" (non-import-compatible) export
* auto-detect encoding of CSV using chardet
* remember column -> field mapping after having imported a file (useful
for repeated imports where auto-matching failed)
* better handle localised booleans & column names
* automatically select source list view's fields when exporting
* better integrate import templates feature and add a number of templates
According to RFC 6266,
content-disposition = "Content-Disposition" ":"
disposition-type *( ";" disposition-parm )
disposition-parm can't be an empty string, and thus a ; in terminal
position is not legal, even though browsers apparently work around it.
When posting an svg image, Odoo tries to resize it for thumbnailing
(like any image).
However this is of no interest since this is a vectorial file format, and
furthermore it distastefully makes the image library Pillow crash, since it only
supports raster formats.
The result would be a broken thumbnail instead of the image itself.
By not setting the thumbnail size if the mimetype contains svg,
we ignore the thumbnailing altogether.
Note that this only applies to the admin user, as otherwise the file is
treated as binary and thus no thumbnailing occurs anyway.
opw 1841153
Before this commit, when uploading a file as attachment in Safari,
The file icon kept on showing 'downloading' whereas the request was successful
This was because the return from the server had a different UTF-8 norm than Safari
After this commit, it works well
OPW 1836545
closes#24307