Commit Graph
103813 Commits
Author SHA1 Message Date
Olivier Dony d2605bccdb [FIX] requirements: bump up pillow,jinja2 reqs
Recommended by GitHub's repository alerts.

We normally stick as close as possible to the version we depend
on in the official DEB packages. This in turn depends on the version of
Debian stable at the time of release - for 9.0 that would be Debian 8
(jessie) and thus Pillow 2.6.1.

However Pillow versions before 3.3.2 and Jinja2 before 2.8.1 suffer
from a few issues that could lead to crashes of Odoo workers.
The bugfixes have been backported in the DEB packages for Pillow,
so users of Debian/Ubuntu LTS versions won't be affected if they are
keeping their systems updated.

However it's worth an exception to our rule for pip users.
2018-08-14 14:54:57 +02:00
Richard Mathot 2039c3c792 [FIX] anonymization: end of support
task: 51094
2018-08-14 14:36:18 +02:00
Christophe Simonis 2917b38f28 [FIX] crm: do not consider leads without emails as duplicated 2018-08-14 12:08:04 +02:00
len-odoo 549b7175ec [FIX] sale_crm: add marketing context when converting opportunity to quotation
When converting an opportunity to a quotation, marketing context (campaign,
medium and source) weren't copied to the newly created quotation.

opw 1863825
2018-08-13 15:22:26 +02:00
Damien Bouvy 663a6f19b2 [FIX] website_sale: badly formatted CSV
The gorup was evaluated to True and no group was set on the ACL
2018-08-08 08:16:57 +02:00
Christophe Simonis 5a64fffe9a [FIX] base: explicitly allow superuser to write on attachment's assets 2018-08-07 19:06:02 +02:00
Martin Trigaux 1b76b6168f [FIX] base: remove leftover print 2018-08-04 08:34:01 +02:00
Martin Trigaux 9b4dfd9978 [IMP] base: do not load local file resources
The generation of the manifest should not be platform dependent, its content
should be the same whatever local files are present on the filesystem
2018-07-28 11:25:24 +02:00
Martin Trigaux afde870da4 [FIX] http: avoid corruption with domain name
Domain names may have been interpreted as a regex by mistake
2018-07-18 10:32:42 +02:00
Nicolas Martinelli 57ea939eda [IMP] auth_signup: hide unusable field from users
The token field is a technical data that the other users are not able to
use.
It may be confusing for users to see token on the user interface.
Still show it to administrator for debug reasons.
2018-07-16 14:35:20 +02:00
Raphael Collet 67bf250ea5 [FIX] base: access rights on transient models 2018-07-23 16:21:07 +02:00
Raphael Collet a1b92ad2b8 [FIX] models: correct regex for onchange_v7
Ensure, we only match the expected az-A-Z characters for old-style
onchanges.
The \w allowed starting with 0-9 which should be prevented.
2018-07-12 13:55:42 +02:00
Olivier Dony e9624a8460 [FIX] auth_crypt: update write_date/uid when changing password
The change of password is done in SQL so does not update write_date/uid
fields or triggers base.action.rules
2018-07-14 18:08:42 +02:00
Olivier Dony 779ceac973 [FIX] base: always preload dateutil
The dateutil package uses lazy import to selectively expose its
features: `parser`, `relativedelta`, `rrule`, `tz`.

Depending on installed modules and order of initialization, there was no
guarantee that a given feature was already loaded during the preparation
of the action context.

This patch ensures that we always preload the feature set we need, and
only that feature set. This way we have a consistent `dateutil` lib in
the action context at all times.
2018-07-23 16:15:10 +02:00
Thibault Delavallée 91486656ab [FIX] mail: log correct user deleting the record
When using sudo, the administrator is logged as deleting the action.
For audit reason, log the correct user.
To avoid access rights errors, only group system can delete the action.
2018-07-07 17:35:42 +02:00
Thibault Delavallée 6033439c67 [IMP] website_mail: allow per-module override of token_field
Instead of forcing a token field through an override, set it at the class level
to be changed in other model inheriting from the MailThread
2018-07-08 09:04:42 +02:00
Simon Lejeune e5984fbfc3 [FIX] base: strengthen ir.attachment access rights
An ir.attachment record can be served as a request's reponse if:
  - a request triggers a 404
  - the ir.attachment record has its url field matching the url of
    the failed and is of binary type

Following rev[1], portal users have the right to create these kind of
records, and it is a security concern.

This patch restrict the ability to create and write on the ir.attachment
records that may be served through the dispatch's exception mechanism to
settings users.

As the asset bundles files are served through the use of these special
ir.attachment, we make sure to retrieve only ir.attachment records
created by the superuser in the `get_attachment` method.

As website administrators often need to play with these special
ir.attachment, we also let to this group the permission to manage them.

[1] 61065b6d04
2018-07-29 14:10:42 +02:00
Simon Lejeune d5efba2561 [FIX] report: avoid local file resources
Make sure building reports using local resources are disabled.
This avoids get different report result based on the system if the
given resources are or not present (e.g. custom style)
2018-07-03 10:53:42 +02:00
Odoo Translation Bot 7cf29f04be [I18N] Update translation terms from Transifex 2018-08-01 02:42:16 +02:00
Nicolas Lempereur cb2a3afa7e [FIX] base: use -U+FEFF instead of U+2011 in -num
In af64780a2 an improvement was done so a numerical fields like '-500'
was not breaked up over two lines after the hyphen.

But it seems in a very particular case of printing PDF in a given
combination of condition:

- printing over wkhtmltopdf which itself uses an old version of webkit
- particular font (issue happen with Arial but not "Segoe UI")
- particular version of windows (windows server 2012, not on windows 10)

the - character at the front of a monetary, float or integer field would
be displayed as | erroneously.

The problem is probably that the font system in the old webkit with
given windows will not find the code point in the given font, and
doesn't fallback correctly.

This commit replace using the "NON-BREAKING HYPHEN (U+2011)" by using
the "ZERO WIDTH NO-BREAK SPACE (U+FEFF)" which is an invisible character
with no width that prevent splitting at its location.

As a note, an alternative to this character is "WORD JOINER (U+2060)"
that may be preferred, but it presents exactly the same issue (with
-|500 instead of -{WORD JOINER}500) in the same environment.

mentioned in https://www.odoo.com/forum/1/question/118653
opw-1867842
fixes #17093
fixes #25840
closes #26019
2018-07-27 17:07:38 +02:00
Christophe Simonis 2c5ec48f92 [FIX] http: only del existing attributes
Closes #25652
2018-07-25 11:01:07 +02:00
Lucas Perais (lpe) aa4ccef418 [FIX] account: fix planner extra features 2018-07-25 09:21:26 +02:00
Jeremy Kersten f045186f23 [FIX] report: fix padding for ul in report pdf
Rendering in html was correct thanks to the webkit-padding-start 40px added
by the browser. But once printed with wkhtml, the padding was missing.

Now we force the padding manually.

This commit closes #7375
2018-07-23 17:02:09 +02:00
Christophe Simonis af2e480e41 [FIX] http: refresh request environment after authentication
This allow the `/web/session/authenticate` route to return correct
partner and company.

Closes #25652
2018-07-23 13:25:42 +02:00
Ivan Yelizariev 1e1d3ed9e6 [FIX] base: suggested default ACL should be safer
When there is no ACL for a model, the system emits a log with a sample
ACL entry that developers should consider adding. This proposed ACL
should be safe: a default read-only access for internal users
seems appropriate.

Closes #25919
2018-07-23 13:18:04 +02:00
Ivan Yelizariev 592ee660a5 [FIX] doc: remove incorrect statement 2018-07-20 12:27:10 +02:00
Goffin Simon 67449ced66 [FIX] purchase: State 'bid' on PO doesn't exist
Since this commit: https://github.com/odoo/odoo/commit/cb01be235e73cf948418e41642d4906ff84906a6
the state 'bid' doesn't exist on model 'purchase.order'

With courtesy of @rim-odoo

opw:1867594
2018-07-19 11:28:32 +02:00
Christophe Simonis e62e17d078 [MERGE] forward port branch 8.0 up to 9e8f70e484 2018-07-17 15:45:25 +02:00
Sébastien Theys b6ed005e0a [IMP] doc: remove duplicate line
The same content is already there 2 lines above.

cherry-pick of 57676dc7d1
2018-07-17 15:14:28 +02:00
Christophe Simonis 4bd58029f4 [FIX] base: avoid duplicated translation entries
For records having multiple translated terms per field (like html fields),
it was possible to have duplicated entries when synchronizing existing
entries with new ones.
2018-07-17 14:39:32 +02:00
Josse Colpaert 9e8f70e484 [FIX] hw_escpos: small fix to avoid error on throwing error 2018-07-13 13:45:13 +02:00
Martin Trigaux 476207e9a4 [FIX] point_of_sale: display traceback
Since ffda023295, the error is not 'OpenERP Server Error' but 'Odoo Server
Error'.
In case we change of name once again, check based on the name

Avoid "traceback not available" error in PoS when there is a traceback.
2018-07-12 15:47:47 +02:00
Stéphane Bidoul (ACSONE) 189e0088e0 [FIX] account: preserve deactivated taxes on move lines
Similar to cd3f52ba10 that was made for invoices.

Was PR #25655. Courtesy of Stéphane Bidoul (ACSONE)
2018-07-11 16:56:59 +02:00
Luis González 2d0621da05 [CLA] fix date format of Vauxoo's agreement
According to the CLA signing instructions, the date of signature must be
expressed in the following form:
> `<date>`: current date in the form `YYYY-MM-DD`

However, the date was wrongly expressed as "9-2-2015". That date not
only was following an incorrect format, but also it was ambiguous,
because it was not clear if the format was following M-D-YYYY or
D-M-YYYY (the latter one being the case).

This fixes the format, so it now fits the required one.

Closes #25665
2018-07-10 17:35:09 +02:00
Martin Trigaux 00a55f4428 [FIX] service: properly invalidate session of deteled users
If a user A deletes the res.users record of user B while B is connected,
the verification of the session token fails with a comparison of a boolean and
bytes values.
While the check should obviously fail, this patch gracefully inform the user B
its session has expired and redirect him to the login page.

Without the patch, the session is never invalidated in the user browser,
redirecting to a forbidden error page as long as the session has not been manually
cleared from the browser.

Fixes #25530
Closes #25654
Closes #25682

Cherry-Pick of 96f01c08f8
2018-07-10 16:03:23 +02:00
Andreas Perhab 8b25099aea [FIX] auth_oauth: validate db against db_filter 2018-07-09 18:55:11 +02:00
Florent de Labarre 95990a31b4 [FIX] ir.autovacuum: should be executed by the admin
Closes #23453
2018-07-09 18:55:10 +02:00
Damien Bouvy b1a373c664 Revert "[FIX] stock: do_new_transfer callable in xml-rpc"
This reverts commit ef444da57a.

Changing a function signature is not supposed to happen in stable;
we have already received 3 opw's about broken customizations or
modules that extend the stock because code such as:
res = self.do_next_transfer()
if not res:
	<bla bla>

stops without any warning.
2018-07-06 08:47:40 +02:00
Christophe Simonis b5c50fa824 [FIX] core: set up registry before running migration scripts
As `pre-` migration scripts may use the registry, we must ensure that
all fields are set up before execution in order to have a consistent
registry.

This is required when loading a registry which contains modules to
install/upgrade without `-u` flag. In this case, the setup was only done
*after* module loading.
2018-07-05 12:26:28 +02:00
Mykhailo Panarin 80b325bbb2 [CLA] create mpanarin
Backport to 9.0 of #23708

Closes #25595
2018-07-04 10:58:44 +02:00
Odoo Translation Bot 83d2dd5521 [I18N] Update translation terms from Transifex 2018-07-01 02:38:03 +02:00
Martin Trigaux 4ca9ee2548 [FIX] google_calendar: backport 052bc38805 to 9.0
Backport following opw-1851612

[FIX] google_calendar: do not create an event with an invalid id

The id is useful to update existing events but sometimes we are getting some
ids that are not accepted by Google

Getting an error:
odoo.addons.google_account.models.google_service: Bad google request : {
 "error": {
  "errors": [
   {
    "domain": "global",
    "reason": "invalid",
    "message": "Invalid resource id value."
   }
  ],
  "code": 400,
  "message": "Invalid resource id value."
 }
}

Looks like existing events can have a _ in their id but new one, no longer.
It seems that these events are created by outlook calendar when synchronized
with Google Calendar.
2018-06-29 10:32:28 +02:00
Toufik Benjaa 29c00a56da [IMP] http: Sessions implicit deactivation
- Store a token inside sessions to allow implicit session deactivation when needed.

backport of @da1f153d61d747d9357694382fe04f96c0ca886a @c8243e71c6da37547a19f61c58f25d5d03e13d38
2018-06-27 16:39:45 +02:00
Martin Trigaux c1b6cfaab8 [FIX] google_account: backport of c444b5a293
In this commit, our hero backport c444b5a293 to 9.0

[FIX] google_account: fix google request exception management

Error thrown by google request is an urllib2.HTTPError that can be read
and loaded in JSON. However in some cases the result of the read may
be void or not JSON-ready. This was causing a crash in the error
management and hid the actual issue.

This commit tries to read and JSON-load the error but fall back on
simply displaying the raw error in case of issue when handling it.

opw-1851612
2018-06-27 15:52:03 +02:00
Ruchir Shukla ef444da57a [FIX] stock: do_new_transfer callable in xml-rpc
When returning None, the XML-RPC can trigger an error, making
the api unusable in certain cases.
So, we added return True and if the context is None we
use an empty dict, so if the context is returned in a dict,
it is not returning None either.  Tests were adapted too.

Closes #22264
2018-06-26 15:07:23 +02:00
Lucas Perais (lpe) ea7bddcc3e [FIX] event, event_sale, website_event: allow portal access to own registrations
OPW 1859364
2018-06-26 13:13:15 +02:00
Nicolas Martinelli 22084bc52e [FIX] website_quote: token assignation
Speed up assignation of initial access tokens for large databases.

opw-1856946
2018-06-21 10:45:14 +02:00
Nicolas Martinelli 25b6dd6e88 [FIX] sale_mrp, sale_stock: sort moves
`sorted` returns a new sorted recordset, but doesn't modify the actual
one. Therefore, the current code doesn't work as expected.

opw-1824734
2018-06-21 10:34:49 +02:00
Goffin Simon 9cb37398f2 [FIX] calendar: Calendar recurring start date is wrong
Steps to reproduce the bug:

- Create a recurring meeting, with a start date with time (not all day) (for example 09:00),
a duration (for example 5 hours) , each week for example on fridays, for 3 occurences.

-Save

Bug:
- The start_datetime ("Starting at") was increased with the duration of the meeting.

PS: The displayed start and stop in calendar view were computed in function "calendar_id2real_id"
with the virtual id.

opw:1858154
2018-06-19 08:50:30 +02:00
Christophe Monniez 27e7d24256 [FIX] packaging: stop removing Odoo lib dir
When removing Odoo Debian package, the directory /var/lib/odoo is also
removed. This directory could contain important data like filestore or
custom modules.

With this commit, this directory is preserved on removal and deleted
when the purge command is issued with a Debian package manager.

Fixes #22138
2018-06-15 11:58:06 +02:00