Commit Graph
55 Commits
Author SHA1 Message Date
Christophe Simonis cb50970f3f [MERGE] forward port branch 11.0 up to eefe879a37 2018-01-25 15:41:45 +01:00
Christophe Simonis c6b2fa47ed Revert "[FIX] base: bad back-port"
This reverts commit 0ac6043ec7.
2018-01-25 12:43:02 +01:00
tbe-odoo c0f004205d [FIX] http: Implicit session deactivation -> Explicit destruction
- Replace the implicit session deactivation with explicit destruction.
2018-01-24 10:58:06 +01:00
Christophe Simonis 4708812b6c [MERGE] forward port branch 11.0 up to b37cc1f9b7 2017-12-12 18:50:59 +01:00
Jeremy Kersten 294dc70a38 [FIX] http_routing, website: fix and clean routing
Clean method _add_dispatch_parameters
Remove unused code for caching

Call super before to have the correct lang when we browse website.
Without it, menu was not loaded in correct language.
2017-12-12 17:47:08 +01:00
Miquel Raïch a578531ca3 [FIX] v11 urls
Was still pointing to old links

Closes #21590
2017-12-12 17:19:01 +01:00
Dave Lasley 8226aa1db8 [IMP] http.py: Allow to use odoo if unmet dependencies on uninstalled module
Purpose
=======

If an external dependency is unmet on a module that is not installed, it's actually impossible to launch an odoo server and load the web client without getting a traceback.

This commit removes this constraint and allow to use odoo in that case. Obviously the install will crash if the external dependency is still unmet.

Close https://github.com/odoo/odoo/pull/17790
Coming from https://github.com/odoo/odoo/pull/14850
2017-11-29 16:21:12 +01:00
Christophe Simonis 29590a61cd [MERGE] forward port branch 11.0 up to 8fb25e185b 2017-11-28 16:57:58 +01:00
Xavier Morel b46830858f [FIX] web: excel export of binary fields
* In Python 3 xlwt apparently does not support writing bytes values ->
  try to decode assuming the value may be base64-encoded, this is more
  or less the behaviour for CSV exports.

  This will most likely not allow the export anyway as Excel cells are
  limited to 32k data characters, which accounting for base64
  expansion means ~24k worth of data, but that is a pre-existing
  issue.
* Also removed support for way outdated browsers from
  content_disposition: the Safari case is for Safari 5 (circa 2012)
  but versioning apparently changed since then and modern Safari
  report their "external" version number rather than the webkit
  version number => the current Safari reports version 11, and gets
  routed to the "does not support unicode file names", which is
  further bugged in Python 3 as it %s's bytes, leading to a resulting
  filename of e.g. `b'res.partner.csv'.csv` (with the prefix and
  quotes).
* The IE case is for IE8, which has long been unsupported by the web
  client.
2017-11-27 11:11:48 +01:00
rde e19c6a5ead [IMP] website: set viewid in frontend & save template for dispatch
This commit is related to enterprise commit adding crm_track option to routes.

Before this commit:
We could not get template's name after dispatch() had been called. Indeed,
it will remove the template name from the response (response.flatten()) to
make it not considered as 'qweb' anymore (is_qweb()).

In some case (e.g. website_crm_score), we still need the template's name later.
(Eg: to retrieve the route's view being rendered and check if trackable or not)

Add view-id in template, when main_object is not an ir_ui_view, it avoid to
make extra rpc to get the view_id.

this commit closes #20313
2017-10-23 14:31:07 +02:00
Laurent Smet c23ef9a9b6 [FIX] remove 'report' from rpc dispatcher
This feature no longer exists since 3425752eac

reported on github issue 19887
2017-10-09 10:03:22 +02:00
Christophe Monniez aaa30a74b5 [imp] module,http: open manifest files as utf-8 in a python2/3 compatible way 2017-10-03 12:01:53 +02:00
Christophe Simonis 3ac2a1106c [MERGE] forward port branch saas-15 up to ec15765eec 2017-09-11 13:30:03 +02:00
Fabien Meghazi 6fa705399b [FIX] http/db: handle case when db_filter is empty in the config file
In such a case the db filtering won't be applied on an empty regex so
we use the list of databases passed to `db_name` (--database) as
the database list (and we also avoid to list all the databases present
on the postgresql cluster)

As a side effect, this patch allows to strengthen the postgresql security
by preventing Odoo to list all the databases present on the cluster.
2017-09-08 18:29:26 +02:00
Christophe Simonis d5382abeaa [MERGE] forward port branch saas-17 up to b8dd34fcbb 2017-09-06 17:40:59 +02:00
Christophe Simonis 827b1e8e3d [FIX] P3: reraise exception correctly 2017-09-06 10:57:35 +02:00
Olivier Dony f4d541e51a [IMP] http: set HTTPonly flag on session cookie
This will reinforce the framework against potential XSS exploits
escalating to session hijack
2017-09-05 10:06:35 +02:00
Christophe Simonis 017ee5eab3 [MERGE] forward port branch saas-17 up to 877e709871 2017-08-24 13:17:53 +02:00
Xavier Morel a65dfe2421 [FIX] P3: exception semantics issues 2017-08-23 14:34:50 +02:00
Olivier Dony 695716efb0 [FIX] P3: remove pycompat.{keys,items,values} helpers
Now that we're closer to switching to P3 for good, these helpers have
outlived their usefulness, and mostly add noise.

All remaining dict.iter*() or dict.view*() must be converted to the
normal keys(), values() or items() calls.

Whenever the result is likely to be used for more than the scope of a
loop, or when the dict needs to be modified during iteration, the calls
must be wrapped in a ``list()``, to protect the new P3 semantics.
Those cases are very exceptional.

Also removed some dead code or improved the API to remove unnecessary
conversions.
2017-08-20 23:25:54 +02:00
Xavier Morel 555ff9ab84 [FIX] P3: quickfix URL/http text model 2017-08-20 23:25:54 +02:00
Xavier Morel 40d1246a17 [FIX] P3: Response wrapping in http
Explicitly check for both bytes and text results to wrap in a Response
object, as bytes is a string_type in P2 but not P3.
2017-08-20 23:25:54 +02:00
Xavier Morel b93613066f [FIX] P3: JSON is an object<->text encoding
It doesn't load bytes, and it doesn't dump to bytes.
2017-08-20 23:25:54 +02:00
Xavier Morel bc7dce254d [FIX] P3: text model, base_url is a string but query_string is bytes 2017-08-20 23:25:54 +02:00
Xavier Morel 481a00dc4b [FIX] P3: hash/hmac payload must be bytes 2017-08-20 23:25:54 +02:00
Xavier Morel 7dd062f835 [FIX] P3: text model types
* remove references to basestring & unicode (use relevant pycompat
  helpers)
* remove some str calls (either entirely or replaced by relevant
  helper, either text or native)
* use better API to avoid unnecessary conversions
* remove some XML declarations in views
2017-08-20 23:25:54 +02:00
Christophe Simonis 1fa8680286 [MERGE] forward port branch saas-17 up to 48b2ce60ed 2017-08-10 18:07:47 +02:00
Christophe Simonis 48b2ce60ed [MERGE] forward port branch saas-16 up to 85571bb78c 2017-08-10 17:01:05 +02:00
Christophe Simonis 85571bb78c [MERGE] forward port branch saas-15 up to dde62073ba 2017-08-10 16:22:36 +02:00
Christophe Simonis 40a82cdfda [FIX] http: ensure registry is still bound to the request before using it
A user can be logged out during a request, loosing the database (and
thus registry) information.
2017-08-08 19:14:05 +02:00
Fabien Meghazi 96af2823cb [FIX] http/db: fix bug introduced in b34e00540e
b34e00540e was not properly checking if db_name option was in use
2017-08-03 17:06:55 +02:00
Fabien Meghazi b34e00540e [IMP] http/db: change behaviour of list_dbs() when --db-filter is not provided (Closed #18526)
In case `--db-filter` is not provided and `--database` is passed,
Odoo will not fetch the list of databases available in the postgres
server anymore because it does not have anything to match against this
list. Instead, `list_dbs()` will use the value of `--database` as a
comma separated list of exposed databases.

This allows better security hardening in postgres access rights.

Basically, that means that those commands

    $ odoo-bin -d foobar
    $ odoo-bin -d foo,bar,baz

are now respectively equivalent to those commands

    $ odoo-bin -d foobar --db-filter='^foobar$'
    $ odoo-bin -d foo,bar,baz --db-filter='^(foo|bar|baz)$'

The old behaviour can still be used with this command:

    $ odoo-bin -d foobar --db-filter='.*'
2017-08-03 13:49:51 +02:00
Fabien Meghazi 2c0f6f39d7 [IMP] http: improve dumpstacks and remaining requests handling during tests (#18640)
This patch modifies Root#dispatch() in order to keep the httprequest url
in the current thread's attribute and use if for dumpstacks and the
phantomjs tests remaining requests handling.

Also added a counter in order to avoid looping forever when trying to join unclosed http requests
in phantomjs test suite after a phantomjs failure + added a log.warning in such a case so it's easier to troubleshoot runbot's ir.logging.
2017-08-03 10:50:18 +02:00
Ankit Joshi 16ebec2324 [FIX] http: avoid crash in web/database/selector when selecting invalid database (#17830) 2017-06-27 16:52:20 +02:00
Joren Van Onder b41a987767 [FIX] http: fix forward-port of eaa3682bb6
Forward-ported at
1b50c829ef. b4429c2a91
changed the import to allow for either urllib or urlparse.
2017-06-15 18:31:57 -07:00
Joren Van Onder b31435ab5d [FIX] http: replace forward-ported urlparse with werkzeug.urls
Introduced by forward-port of eaa3682bb6
at ed2ddeccdf. At
01e3514147 urlparse was replaced with
werkzeug.urls.
2017-06-15 14:19:30 -07:00
Christophe Simonis ed2ddeccdf [MERGE] forward port branch saas-16 up to 1b50c829ef 2017-06-15 18:46:47 +02:00
Christophe Simonis 1b50c829ef [MERGE] forward port branch saas-15 up to 9713dc2e1f 2017-06-15 18:44:16 +02:00
Olivier Dony eaa3682bb6 [FIX] http: force protocol when missing in URL 2017-06-15 16:23:35 +02:00
Xavier Morel 01e3514147 [FIX] P3: urllib, urllib2 and urlparse
In Python 3, all of these were "consolidated" under urllib(.request,
.parse, .errors) which is inconvenient.

Since we already have hard dependencies on requests and
werkzeug(.urls, which is a backport of Python 3's unicode-aware
urllib.parse) migrate *everything* to that.

A sticking point is urllib2.URLError, those were (mostly) replaced by
the slightly more general IOError which URLError extends.
2017-05-15 12:26:30 +02:00
xmo-odoo 6659d5a7d2 [FIX] P3: metaclasses handling
* cross-version metaclass spec
* more formally deprecate browse_record and browse_null since they
  were using metaclasses anyway
* update docstrings referencing the latter
2017-05-11 15:25:36 +02:00
xmo-odoo fffaf735f5 [FIX] P3: list -> iterable builtins (#16811)
In Python 3:

* various builtins and dict methods were changed to return
  view/iterable objects rather than lists
* and the separate Python 2 view/iterable builtins and methods were
  removed altogether

This is problematic when using these items as list (which the happens
repeatedly in Odoo), but more viciously when iterating *multiple times*
over them (which also happens, which I've messed up multiple times while
writing this, and which is a pain to debug even when you've just created
the issue).

Convert all code using these to semantics-matching cross-version
helper functions to get the LCD behaviour between P2 and P3, and
forbid the builtins via lint.

issue #8530
2017-05-10 09:39:55 +02:00
Raphael Collet b59318ec12 [REF] registry: always perform registry/cache signaling at the end of request
Problem: the update of custom models/fields is not fully transactional, and may
potentially lead to an inconsistent database.  An other problem is creating two
custom fields by writing on a model: if the second one fails, the first one has
been committed without notice.  Retrying the request will give an unexpected
error (duplicate field name).

Solution: never commit in the middle of a request.  If the changes have an
impact on the registry, then mark it as invalid (with a new flag), and signal
registry invalidation after everything has been committed.  If the request
fails, reset the registry.  Both registry and cache invalidation are handled
the same way.
2017-05-03 15:41:05 +02:00
xmo-odoo b4429c2a91 [FIX] Various P3-related import changes
* LDAP import: python-ldap is not python3-compatible, pyldap is

  Warning: only supported from debian Stretch (current testing)?
  https://packages.debian.org/search?searchon=names&keywords=pyldap

* implicitly relative imports
* imports of moved or removed stdlib modules

issue #8530
2017-04-28 09:06:53 +02:00
xmo-odoo 2e6a589f41 [FIX] builtins removed from Python 3
* Reverse wrapper courtesy of @rco-odoo's original P3 branch
* thin compat module stripped down from werkzeug (to augment as needed)

issue 8530
2017-04-27 13:59:33 +02:00
xmo-odoo 90645ad392 [FIX] function introspection attributes
Introspection attributes on function and methods were originally
prefixed with func_ or im_ e.g. im_class or func_name. For coherence with the
rest of the data model, Python 3 added dunder attributes (__func__,
__code__) and removed the old style, the dunder attributes were
backported to Python 2.6.

Use dunder attributes everywhere we're currently using func_* or im_*
attributes.

Fixers:
    lib2to3.fixes.fix_funcattrs
    lib2to3.fixes.fix_methodattrs

#8530
2017-04-24 15:19:55 +02:00
Xavier Morel 3979f6802e [#8530] convert exception handlers to except..as syntax
Futurize fixers:
* lib2to3.fixes.fix_except
2017-04-11 14:53:29 +02:00
Christophe Simonis 27496730d8 [MERGE] forward port branch saas-11 up to c2569b9df1 2017-03-28 14:51:14 +02:00
Christophe Simonis 44276dfdc3 [MERGE] forward port branch saas-11 up to a0aca47fef 2017-01-17 19:12:20 +01:00
Christophe Simonis 3d085f632d [MERGE] forward port branch saas-12 up to 6386037 2016-11-08 15:01:20 +01:00