Recommended by GitHub's repository alerts.
We normally stick as close as possible to the version we depend
on in the official DEB packages. This in turn depends on the version of
Debian stable at the time of release - for 9.0 that would be Debian 8
(jessie) and thus Pillow 2.6.1.
However Pillow versions before 3.3.2 and Jinja2 before 2.8.1 suffer
from a few issues that could lead to crashes of Odoo workers.
The bugfixes have been backported in the DEB packages for Pillow,
so users of Debian/Ubuntu LTS versions won't be affected if they are
keeping their systems updated.
However it's worth an exception to our rule for pip users.
When converting an opportunity to a quotation, marketing context (campaign,
medium and source) weren't copied to the newly created quotation.
opw 1863825
The token field is a technical data that the other users are not able to
use.
It may be confusing for users to see token on the user interface.
Still show it to administrator for debug reasons.
The dateutil package uses lazy import to selectively expose its
features: `parser`, `relativedelta`, `rrule`, `tz`.
Depending on installed modules and order of initialization, there was no
guarantee that a given feature was already loaded during the preparation
of the action context.
This patch ensures that we always preload the feature set we need, and
only that feature set. This way we have a consistent `dateutil` lib in
the action context at all times.
When using sudo, the administrator is logged as deleting the action.
For audit reason, log the correct user.
To avoid access rights errors, only group system can delete the action.
An ir.attachment record can be served as a request's reponse if:
- a request triggers a 404
- the ir.attachment record has its url field matching the url of
the failed and is of binary type
Following rev[1], portal users have the right to create these kind of
records, and it is a security concern.
This patch restrict the ability to create and write on the ir.attachment
records that may be served through the dispatch's exception mechanism to
settings users.
As the asset bundles files are served through the use of these special
ir.attachment, we make sure to retrieve only ir.attachment records
created by the superuser in the `get_attachment` method.
As website administrators often need to play with these special
ir.attachment, we also let to this group the permission to manage them.
[1] 61065b6d04
Make sure building reports using local resources are disabled.
This avoids get different report result based on the system if the
given resources are or not present (e.g. custom style)
In af64780a2 an improvement was done so a numerical fields like '-500'
was not breaked up over two lines after the hyphen.
But it seems in a very particular case of printing PDF in a given
combination of condition:
- printing over wkhtmltopdf which itself uses an old version of webkit
- particular font (issue happen with Arial but not "Segoe UI")
- particular version of windows (windows server 2012, not on windows 10)
the - character at the front of a monetary, float or integer field would
be displayed as | erroneously.
The problem is probably that the font system in the old webkit with
given windows will not find the code point in the given font, and
doesn't fallback correctly.
This commit replace using the "NON-BREAKING HYPHEN (U+2011)" by using
the "ZERO WIDTH NO-BREAK SPACE (U+FEFF)" which is an invisible character
with no width that prevent splitting at its location.
As a note, an alternative to this character is "WORD JOINER (U+2060)"
that may be preferred, but it presents exactly the same issue (with
-|500 instead of -{WORD JOINER}500) in the same environment.
mentioned in https://www.odoo.com/forum/1/question/118653
opw-1867842
fixes#17093fixes#25840closes#26019
Rendering in html was correct thanks to the webkit-padding-start 40px added
by the browser. But once printed with wkhtml, the padding was missing.
Now we force the padding manually.
This commit closes#7375
When there is no ACL for a model, the system emits a log with a sample
ACL entry that developers should consider adding. This proposed ACL
should be safe: a default read-only access for internal users
seems appropriate.
Closes#25919
For records having multiple translated terms per field (like html fields),
it was possible to have duplicated entries when synchronizing existing
entries with new ones.
Since ffda023295, the error is not 'OpenERP Server Error' but 'Odoo Server
Error'.
In case we change of name once again, check based on the name
Avoid "traceback not available" error in PoS when there is a traceback.
According to the CLA signing instructions, the date of signature must be
expressed in the following form:
> `<date>`: current date in the form `YYYY-MM-DD`
However, the date was wrongly expressed as "9-2-2015". That date not
only was following an incorrect format, but also it was ambiguous,
because it was not clear if the format was following M-D-YYYY or
D-M-YYYY (the latter one being the case).
This fixes the format, so it now fits the required one.
Closes#25665
If a user A deletes the res.users record of user B while B is connected,
the verification of the session token fails with a comparison of a boolean and
bytes values.
While the check should obviously fail, this patch gracefully inform the user B
its session has expired and redirect him to the login page.
Without the patch, the session is never invalidated in the user browser,
redirecting to a forbidden error page as long as the session has not been manually
cleared from the browser.
Fixes#25530Closes#25654Closes#25682
Cherry-Pick of 96f01c08f8
This reverts commit ef444da57a.
Changing a function signature is not supposed to happen in stable;
we have already received 3 opw's about broken customizations or
modules that extend the stock because code such as:
res = self.do_next_transfer()
if not res:
<bla bla>
stops without any warning.
As `pre-` migration scripts may use the registry, we must ensure that
all fields are set up before execution in order to have a consistent
registry.
This is required when loading a registry which contains modules to
install/upgrade without `-u` flag. In this case, the setup was only done
*after* module loading.
Backport following opw-1851612
[FIX] google_calendar: do not create an event with an invalid id
The id is useful to update existing events but sometimes we are getting some
ids that are not accepted by Google
Getting an error:
odoo.addons.google_account.models.google_service: Bad google request : {
"error": {
"errors": [
{
"domain": "global",
"reason": "invalid",
"message": "Invalid resource id value."
}
],
"code": 400,
"message": "Invalid resource id value."
}
}
Looks like existing events can have a _ in their id but new one, no longer.
It seems that these events are created by outlook calendar when synchronized
with Google Calendar.
- Store a token inside sessions to allow implicit session deactivation when needed.
backport of @da1f153d61d747d9357694382fe04f96c0ca886a @c8243e71c6da37547a19f61c58f25d5d03e13d38
In this commit, our hero backport c444b5a293 to 9.0
[FIX] google_account: fix google request exception management
Error thrown by google request is an urllib2.HTTPError that can be read
and loaded in JSON. However in some cases the result of the read may
be void or not JSON-ready. This was causing a crash in the error
management and hid the actual issue.
This commit tries to read and JSON-load the error but fall back on
simply displaying the raw error in case of issue when handling it.
opw-1851612
When returning None, the XML-RPC can trigger an error, making
the api unusable in certain cases.
So, we added return True and if the context is None we
use an empty dict, so if the context is returned in a dict,
it is not returning None either. Tests were adapted too.
Closes#22264
Steps to reproduce the bug:
- Create a recurring meeting, with a start date with time (not all day) (for example 09:00),
a duration (for example 5 hours) , each week for example on fridays, for 3 occurences.
-Save
Bug:
- The start_datetime ("Starting at") was increased with the duration of the meeting.
PS: The displayed start and stop in calendar view were computed in function "calendar_id2real_id"
with the virtual id.
opw:1858154
When removing Odoo Debian package, the directory /var/lib/odoo is also
removed. This directory could contain important data like filestore or
custom modules.
With this commit, this directory is preserved on removal and deleted
when the purge command is issued with a Debian package manager.
Fixes#22138