Commit Graph
24 Commits
Author SHA1 Message Date
Denis Vermylen cf0146934d [FIX] sql_db: ignore PG views when verifying table type
Collisions in table names of ORM models with built-in PG structures such
as "attributes", "domains", "routines", "parameters", ... could occur
and render the result of `table_kind` meaningless.

Based on what was done via https://github.com/odoo/odoo/pull/16651 more
than 2 years ago, it seems relying on our tables being in the 'public'
schema is safe, even though it's only a default from PG. We reuse that
same logic rather than the alternative of excluding
('information_schema', 'pg_catalog', ...), even though it looks safer at
first. If we did the latter we'd have to change the other comparison for
consistency, i.e. more risks.

closes odoo/odoo#42358

X-original-commit: d8e74eb14990c82f65a44ffe163aa84159d6ccc4
Signed-off-by: Denis Vermylen <Icallhimtest@users.noreply.github.com>
2019-12-24 19:08:11 +00:00
17c4f47b0a [FIX] base: allow custom model to use SQL (materialized) views instead of table
closes odoo/odoo#41267

X-original-commit: f17d389c4625e95f52c299c13a3f2983127c70bc
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
Co-authored-by: Denis Ledoux <dle@odoo.com>
Co-authored-by: Raphael Collet <rco@odoo.com>
2019-12-03 07:45:25 +00:00
Moisés López a5251e1d40 [ADD] test_lint: Add sql-injection pylint check
closes odoo/odoo#36583

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2019-10-02 14:16:38 +00:00
Raphael Collet c7f5c4afd2 [FIX] sql_db: add flush() in savepoint()
closes odoo/odoo#36060

Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2019-08-26 13:39:16 +00:00
Raphael Collet 9920f20e4c [IMP] models: ORM speedup
This branch is the combination of several optimizations in the ORM:

* store field values once in the cache: the cache reflects more
faithfully the database, only fields that explicitly depend on the
context have an extra indirection in the cache;

* delay recomputations by default: use method `recompute` to explicitly
flush out pending recomputations;

* delay updates in method `write`: updates are stored in a data
structure that can be flushed efficiently to the database with method
`flush` (which also flush out recomputations);

* make method `modified` take advantage of inverse fields to inverse
dependencies;

* filter records by evaluating a domain on records in Python;

* a computed field with `readonly=False` behaves like a normal field
with an onchange method;

* computed fields are computed in superuser mode by default.

Work done by Toufik Ben Jaa, Raphael Collet, Denis Ledoux and Fabien
Pinckaers.

closes odoo/odoo#35659

Signed-off-by: Denis Ledoux <beledouxdenis@users.noreply.github.com>
2019-08-20 12:43:59 +00:00
Stefan Rijnhart b3824aa6cb [RFR] Hide implementation of constraint definition storage, courtesy of Raphael Collet 2018-08-16 10:33:06 +02:00
Stefan Rijnhart 6327b8f97f [IMP] Store the original constraint definition as a comment on the constraint
and use it to determine if the constraint definition was changed. This prevents
endless readding of constraints that are reformatted by postgresql in an
unrecognizable way (in which e.g. "CHECK (credit*debit=0)" becomes
"CHECK ((credit * debit) = 0::numeric)")
2018-08-16 10:33:06 +02:00
Christophe Simonis c5f680200c [MERGE] forward port branch saas-17 up to d08b4407be 2017-09-12 12:09:11 +02:00
Christophe Simonis fdc4ef97c9 [FIX] core: only check table existance in public schema
This allow the use of tables defined in other schemas, like `domains`,
already defined in `information_schema`.

See #16651
2017-09-11 14:55:49 +02:00
Christophe Simonis d5382abeaa [MERGE] forward port branch saas-17 up to b8dd34fcbb 2017-09-06 17:40:59 +02:00
Christophe Simonis b8dd34fcbb [MERGE] forward port branch saas-16 up to 64d56995e0 2017-09-06 13:29:05 +02:00
Christophe Simonis 3ff4feafd2 [MERGE] forward port branch saas-15 up to 4d4d75709d 2017-09-04 18:12:00 +02:00
Christophe Simonis 4d4d75709d [FIX] core: also consider materialized views as existing
At the end of registry loading, a check is made on every model to
verify its table exists in the database. Materialized views weren't
considered during this check.

Note that we can't use `information_schema` views in this case because
it does include materialized views on purpose [1].

Forward-port of 4ca6945256

[1] http://www.postgresql-archive.org/Materialized-views-don-t-show-up-in-information-schema-tp5822643p5822644.html
2017-09-04 17:51:50 +02:00
Fabien Meghazi a867cce406 [IMP] sql: harvest less information from pg's information_schema (Fixes #18490)
Avoid `SELECT *` on `information_schema.columns` because specific access
right restrictions in the context of shared hosting (Heroku, OVH, ...)
might prevent a postgres user to read this field.
2017-08-07 12:59:34 +02:00
Raphael Collet faacacb45f [IMP] registry: check existence of tables with a single SQL query 2017-07-10 12:38:25 +02:00
Denis Ledoux ad67f7aff8 [FIX] sql: Do no consider a table exists if this is a schema table/view
Before this revision, this is not possible to create a model
with a `_table` set to `domains`, for instance.
2017-07-05 13:47:29 +02:00
Raphael Collet b59318ec12 [REF] registry: always perform registry/cache signaling at the end of request
Problem: the update of custom models/fields is not fully transactional, and may
potentially lead to an inconsistent database.  An other problem is creating two
custom fields by writing on a model: if the second one fails, the first one has
been committed without notice.  Retrying the request will give an unexpected
error (duplicate field name).

Solution: never commit in the middle of a request.  If the changes have an
impact on the registry, then mark it as invalid (with a new flag), and signal
registry invalidation after everything has been committed.  If the request
fails, reset the registry.  Both registry and cache invalidation are handled
the same way.
2017-05-03 15:41:05 +02:00
Christophe Simonis 9a769a8b47 [FIX] tools.sql: correct queries used to rename field 2017-04-28 18:59:14 +02:00
Raphael Collet 4deac93788 [FIX] tools/sql: column name in fix_foreign_key 2017-03-14 14:52:44 +01:00
Raphael Collet e78269664d [IMP] tools: use information_schema instead of pg-specific tables 2017-02-22 15:24:08 +01:00
Raphael Collet f8e573db23 [REF] models: refactoring of foreign keys 2017-02-22 15:24:08 +01:00
Raphael Collet d024c76021 [REF] tools: add functions for SQL schema manipulation
This helps factoring out a certain number of similar queries, and removing a
few methods from `BaseModel`.
2017-02-22 15:24:07 +01:00
Raphael Collet fa082019a0 [IMP] models: change API of _group_by_full
The dictionary `_group_by_full` is replaced by a field parameter `group_expand`
that is assigned to the method name.  The API of the method has been simplified
as well:

    @api.multi
    def _read_group_stage_ids(self, domain, read_group_order=None, access_rights_uid=None):
        # the stages are given by self.ids (wrong model);
        # read_group_order is the order given to read_group() on self;
        # return stages.name_get(), {stage.id: stage.fold)

    _group_by_full = {'stage_id': _read_group_stage_ids}

is now written:

    stage_id = fields.Many2one(..., group_expand='_read_group_stage_ids')

    @api.model
    def _read_group_stage_ids(self, stages, domain, order):
        # stages is a recordset;
        # order is the order to use on stages' model;
        # return a recordset which is a superset of stages
2016-09-16 17:35:24 +02:00
Raphael Collet 9e64f9f951 [REF] openerp: move openerp to odoo 2016-09-02 17:28:12 +02:00