Add support for a 256*256 image, to be used in the following commit.
Define sizes in named variables instead of being hard-coded in several places in
the code.
Allow parameters `preserve_aspect_ratio` and `upper_limit` to be passed from
the different helper methods.
Factorize the code inside `image_resize_images` to make it easier to read.
Add new function to compute whether the size of an image is above a given size.
task-34045
PR: #30656
Add a new widget for binary fields. It open a dialog box and the user can sign manually,
or an signature can be draw automatically or he can upload a picture of his signature.
Move fonts, controller, scss,templates about signature from portal to web to avoid redundance
closesodoo/odoo#30222
When embedding the livechat on an external website, we used to make JSONP calls.
As the support of JSONP calls has been dropped, we now use the CORS mechanism
instead.
The 7d85ab1eac refactor of 'ir.http' introduced changes in `web/image` that
caused the route to no longer return early (to avoid data processing steps)
in the case of redirection and that caused `binary_content` to not set the
mimetype of the `ir.attachment` when it was an URL.
This commit fixes those issues, allowing `web/image` to redirect properly.
closesodoo/odoo#30777
In 3d2ca8104e some change were introduced to the graph view.
But part of it had no sense when displaying data over 2 group by.
eg. if the first level has 2 groups (2018, 2019) and each second level 2
groups (Done,Cancelled), we could have:
2018/Done: 0
2018/Cancelled: 5
2019/Done: 8
2019/Cancelled: 9
this gives us two main groups [2018: 5] / [2019: 17], the code
remove the 2018 because [2018/Done] is 0 so we have something odd
with columns not in order, and in stacked bar chart some part of
a bar at the wrong offset
opw-1932517
closes#30529
*: tools, web, website, website_forum, mail, im_livechat
This commit refactors ir_http to make it more readable
and flexible.
Move the resize function of web/image to odoo.tools
Co-authored-by: XavierDo <xdo@odoo.com>
Co-authored-by: Antony Lesuisse <al@openerp.com>
closes: #28563
task: #1908896
This commit replaces calls to pycompat helpers that were intended for
python 2 <-> python 3 interoperability for python 3 builtins, as python
2 is no longer officially supported by Odoo.
This includes:
* calls to imap/izip/ifilter replaced by map/zip/filter
* uses of text_type replaced by str
* uses of unichr replaced by chr
* calls to implements_to_string, implements_iterator removed
* string_types and integer_types replaced by str, int respectively
* calls to to_native replaced by calls to to_text
This is done in preparation to the removal of these deprecated helpers
in the following commit.
By this commit user can upload attachments by drag and drop in chatter composer.
This feature can be used from discuss UI, chat windows and form view chatter.
Before this commit chatter unlinks the attachment if another attachment uploaded
with same name. Criteria for removing duplicate attachment is changed with this
commit. Now it will remove the attachment based on name and size of attachment.
The reason for this change is, when you upload image with same name from different
directory with old condition it was not possible to attach more then one image/file
of same name.
Related to task #32469Closes#18914
Being in debug mode is necessary to become superuser (whether on the
login page or within the client), however because the becoming
endpoint would straight redirect to the _login_redirect result the
debug mode would be lost, which is commonly inconvenient.
Replace the redirect_with_hash call by local_redirect, which goes
through great pains to conserve the ?debug by default.
Task 1908202
closesodoo/odoo#29058
Before this commit, if you ask for a small image, you was waiting a picture of
64x64 but in case this image was not found, a placeholder with an other size
was returned.
Now, we try to guess the asked size, and return a resized placeholder.
This bug appear since we change the default placeholder picture with a big one
This will fix several issue and avoid to hard code size everywhere in the code
Eg: commit 92f837c and commit https://github.com/odoo/odoo/commit/154fc7d9dd550d35b7266af024e54c20e18938fc#diff-9af1af2039d16d6b544d481b4ee1ed7cR144closesodoo/odoo#27695
Introduce official support for SVG files in the framework, including the
following parts:
1. When client-side SVG images are uploaded, the content is displayed until
you save using data URI scheme according RFC 2397 [1]. This scheme requires
to specify content format. Using hardcoded "image/png" works for all images
types except SVG.
Type-sniffing is done using "magic byte" detection via the first base64
encode byte, so that the proper data URI scheme can be used.
This should not cause SVG-related security problems as the file is
displayed through `<img>` tag, which does not allow SVG scripting [2].
2. Make /web/image controller compatible with SVG
3. Add support for SVG files for company logo, which uses a dedicated
controller.
4. Resizing of SVG files is a no-op, as it makes little sense for a
vector-based format. We also want to avoid micro-alterations to the SVG
document (in "natural" viewport parameters) as we would store multiple
copies of the files in the filestore.
5. Because SVG files are inherently dangerous, upload of SVG files is
restricted to administrators, either by blocking it directly before
saving it in the database (binary fields with attachment=False), or by
neutering them to text/plain mimetype (for binary fields with
attachment=True)
6. Add tests for the SVG upload cases and for the non-admin uploads.
[1] https://tools.ietf.org/html/rfc2397
[2] https://www.w3.org/wiki/SVG_SecurityCloses#26635
Auth can now report errors less trivial than "incorrect password", the
wizard should report them instead of just assuming the original
password was not correct.
* requires that current user has group_system
* only visible in debug mode (?debug)
* available at login or via debug menu
* special systray color in superuser sessions
Closes#27254
- Changed the binary_content method
to make it more generic and allow alternative ways of checking
the access rights by using a new method check_access_mode.
Reason: Asked by ODO following documents' security review.
- if all pages are processed, splitting a pdf will
archive the original attachment.
Reason: FP feedback.
Task: 1853490
-removed force_ext from ir.http.
-added signature arg to web/image to differentiate cache entries by URL.
-added an embed youtube viewer for youtube URL's
-added a PDF splitter to the PDF viewer UI
-added tests for mail's Document Viewer
-added a "signature" param to web/image to go around the browser cache
-thumbnail field of ir.attachment is now stored in the filestore
as a distinct attachment.
task 1853490
Co-authored-by: Pierre Paridans <app@odoo.com>
Rev. 279d928693 forced
`server_wide_modules` to include 'base' and 'web', because both contain
controllers that need to be always loaded.
However the patch used a set() that randomized the order of the list,
when combined with Python 3.5's randomized hash function.
This is turn could cause the checksum of asset bundles (web.assets_backend)
to randomly vary, which could cause rapid assets recycling and errors.
- Activate lots and SN
- Go to Inventory > Inventory Adjustments
- Export a record
- Select the field 'Inventories > Lot/Serial Number'
The `name_get` of the field is exported, not its XMLID.
This is because the parsing made in order to limit the depth of export
is made on the label, not on the field name.
Actually, it is not clear WHY this limitation exists, but we keep it for
compatibility purpose.
opw-1877092
Allow to override the asset url generation to add in the path the website ID
and avoid continue invalidation cache and bad cache by browser.
Asset url is:
"/web/content/{id}-{unique}/{extra}{name}{page}{type}"
with:
id = attachment id
unique = hash
extra = allow to add custom params eg: website_id/ or rtl/
name = filename
page = used in css to split rules 4095 / file
type = css|js
Co-authored-by: Derie Romain <rde@odoo.com>
Co-authored-by: Kersten Jérémy <jke@odoo.com>
This commit is the counter-part of an enteprise commit introducing
the Documents app.
Here is a summary of what has been done:
- tweak unlink of ir_attachment to prevent unlink recursivity
(when attachments are attached to ir_attachments)
- improve ir_attachment kanban view
- add several arguments to binary_content controller:
- 'force_ext': to force the extension in the filename, base on
mimetype
- 'share_token' and 'share_id': to autorize download from a
share link
- add 'thumbnail' field on ir_attachment to optimize Kanban view
- add 'upper_limit' argument to image to allow to bypass the
500*500 size limit
- DocumentViewer now handles text files
More information available on task 1853490
Co-authored-by: Pierre Paridans <app@odoo.com>
Co-authored-by: sri-odoo <sri@odoo.com>
Co-authored-by: ThanhDodeurOdoo <tso@odoo.com>
This commit adds a new ir.action.report type: qweb-text. It produces text files,
serves them with a text mimetype and these reports use the same rendering context
as the current other types (PDF and HTML).
This will be used in a following commit to produce ZPL scripts. Those scripts
are used for printing thermal label on Zebra printers.
task ID : 1837175
* Make Users._login and session.authenticate always raise AccessDenied
on authentication failure instead of only sometimes (cf
Session.authenticate calling security.check() which raises and not
catching the exception)
* Alter AccessDenied such that it's possible to add a custom access
message, for use with login rate limiting instead of smuggling the
information via the session
* Alter the RPC endpoints to catch and convert AccessDenied back to
a boolean sentinel
Task 31122 section 4.
Implement per-IP rate limiting of login attempts after some number
of failures.
* check_credentials has no reason to be public, make it private
* add hooks to check for login cooldown on a source IP (remote_addr:
http://werkzeug.pocoo.org/docs/0.14/wrappers/#werkzeug.wrappers.BaseRequest.remote_addr)
basis
* add baseline/default configuration of 60s cooldown
* add baseline threshold of 10 login failures, after checking odoo.com
logs it looks like we have short runs of up to 7 failures (assumed
to be legitimate) before the user either gets it right or goes and
looks it up
Depends on #24187
Task 40692
Various changes to import/export (mainly) UIs:
* default to excel & "full" (non-import-compatible) export
* auto-detect encoding of CSV using chardet
* remember column -> field mapping after having imported a file (useful
for repeated imports where auto-matching failed)
* better handle localised booleans & column names
* automatically select source list view's fields when exporting
* better integrate import templates feature and add a number of templates
According to RFC 6266,
content-disposition = "Content-Disposition" ":"
disposition-type *( ";" disposition-parm )
disposition-parm can't be an empty string, and thus a ; in terminal
position is not legal, even though browsers apparently work around it.
When posting an svg image, Odoo tries to resize it for thumbnailing
(like any image).
However this is of no interest since this is a vectorial file format, and
furthermore it distastefully makes the image library Pillow crash, since it only
supports raster formats.
The result would be a broken thumbnail instead of the image itself.
By not setting the thumbnail size if the mimetype contains svg,
we ignore the thumbnailing altogether.
Note that this only applies to the admin user, as otherwise the file is
treated as binary and thus no thumbnailing occurs anyway.
opw 1841153