Commit Graph
1016 Commits
Author SHA1 Message Date
Sébastien Theys 413c63556f [IMP] tools,base,web: improve image tools
Add support for a 256*256 image, to be used in the following commit.

Define sizes in named variables instead of being hard-coded in several places in
the code.

Allow parameters `preserve_aspect_ratio` and `upper_limit` to be passed from
the different helper methods.

Factorize the code inside `image_resize_images` to make it easier to read.

Add new function to compute whether the size of an image is above a given size.

task-34045
PR: #30656
2019-02-14 16:03:09 +00:00
jbm-odoo 4960453db9 [IMP] web Add widget signature on binary field
Add a new widget for binary fields. It open a dialog box and the user can sign manually,
or an signature can be draw automatically or he can upload a picture of his signature.
Move fonts, controller, scss,templates about signature from portal to web to avoid redundance

closes odoo/odoo#30222
2019-02-14 12:59:10 +00:00
Martin Geubelle 7abeaf56b3 [REF] im_livechat, *: remove JSONP in favor of CORS
When embedding the livechat on an external website, we used to make JSONP calls.
As the support of JSONP calls has been dropped, we now use the CORS mechanism
instead.
2019-02-13 09:38:30 +00:00
Christophe Simonis 8c29df10e0 [MERGE] forward port branch saas-12.1 up to 93d736e905 2019-02-11 17:00:35 +01:00
Thanh Dodeur a86b726a27 [FIX] base: fixes http redirection
The 7d85ab1eac refactor of 'ir.http' introduced changes in `web/image` that
caused the route to no longer return early (to avoid data processing steps)
in the case of redirection and that caused `binary_content` to not set the
mimetype of the `ir.attachment` when it was an URL.

This commit fixes those issues, allowing `web/image` to redirect properly.

closes odoo/odoo#30777
2019-02-04 10:16:12 +00:00
Christophe Simonis f927c68ddb [MERGE] forward port branch 12.0 up to cb8fefa899 2019-01-31 16:59:58 +01:00
Christophe Simonis 4400cce820 [MERGE] forward port branch saas-12.1 up to 4524ad06a8 2019-02-04 13:27:22 +01:00
Nicolas Lempereur ce6e66cef9 [FIX] web: bar chart no crazy with 2 group by
In 3d2ca8104e some change were introduced to the graph view.

But part of it had no sense when displaying data over 2 group by.

eg. if the first level has 2 groups (2018, 2019) and each second level 2
    groups (Done,Cancelled), we could have:
     2018/Done: 0
     2018/Cancelled: 5
     2019/Done: 8
     2019/Cancelled: 9
    this gives us two main groups [2018: 5] / [2019: 17], the code
    remove the 2018 because [2018/Done] is 0 so we have something odd
    with columns not in order, and in stacked bar chart some part of
    a bar at the wrong offset

opw-1932517
closes #30529
2019-01-24 16:18:19 +00:00
7d85ab1eac [REF] base, *: refactor binary_content
*: tools, web, website, website_forum, mail, im_livechat

This commit refactors ir_http to make it more readable
and flexible.

Move the resize function of web/image to odoo.tools

Co-authored-by: XavierDo <xdo@odoo.com>
Co-authored-by: Antony Lesuisse <al@openerp.com>

closes: #28563
task: #1908896
2018-12-06 19:09:33 +00:00
Christophe Simonis ce4cc24621 [MERGE] forward port branch 12.0 up to 82a1e1dcc3 2018-11-29 20:06:16 +01:00
Adrian Torres 52f5528cfb [REF] *: replace deprecated pycompat helpers for builtins
This commit replaces calls to pycompat helpers that were intended for
python 2 <-> python 3 interoperability for python 3 builtins, as python
2 is no longer officially supported by Odoo.

This includes:
    * calls to imap/izip/ifilter replaced by map/zip/filter
    * uses of text_type replaced by str
    * uses of unichr replaced by chr
    * calls to implements_to_string, implements_iterator removed
    * string_types and integer_types replaced by str, int respectively
    * calls to to_native replaced by calls to to_text

This is done in preparation to the removal of these deprecated helpers
in the following commit.
2018-11-29 09:28:17 +00:00
Dharmang Soni fb051d3420 [IMP] mail: Allowing drag/drop files/images on mail composer
By this commit user can upload attachments by drag and drop in chatter composer.
This feature can be used from discuss UI, chat windows and form view chatter.

Before this commit chatter unlinks the attachment if another attachment uploaded
with same name. Criteria for removing duplicate attachment is changed with this
commit. Now it will remove the attachment based on name and size of attachment.
The reason for this change is, when you upload image with same name from different
directory with old condition it was not possible to attach more then one image/file
of same name.

Related to task #32469
Closes #18914
2018-11-26 11:34:00 +00:00
Xavier Morel a0e05e2ab9 [IMP] fields: selection fields only use strings
closes odoo/odoo#29039
2019-01-26 14:25:44 +00:00
Xavier Morel 14ff69a46c [IMP] web: keep ?query on becoming superuser
Being in debug mode is necessary to become superuser (whether on the
login page or within the client), however because the becoming
endpoint would straight redirect to the _login_redirect result the
debug mode would be lost, which is commonly inconvenient.

Replace the redirect_with_hash call by local_redirect, which goes
through great pains to conserve the ?debug by default.

Task 1908202

closes odoo/odoo#29058
2018-11-27 09:32:57 +00:00
Jeremy Kersten c4e0e5461c [FIX] web: guess resize placeholder
Before this commit, if you ask for a small image, you was waiting a picture of
64x64 but in case this image was not found, a placeholder with an other size
was returned.

Now, we try to guess the asked size, and return a resized placeholder.

This bug appear since we change the default placeholder picture with a big one

This will fix several issue and avoid to hard code size everywhere in the code

Eg: commit 92f837c and commit https://github.com/odoo/odoo/commit/154fc7d9dd550d35b7266af024e54c20e18938fc#diff-9af1af2039d16d6b544d481b4ee1ed7cR144

closes odoo/odoo#27695
2018-10-11 17:21:53 +00:00
Pedro M. Baeza 1be50fdeaf [ADD] *: support SVG images
Introduce official support for SVG files in the framework, including the
following parts:

1. When client-side SVG images are uploaded, the content is displayed until
you save using data URI scheme according RFC 2397 [1]. This scheme requires
to specify content format. Using hardcoded "image/png" works for all images
types except SVG.
Type-sniffing is done using "magic byte" detection via the first base64
encode byte, so that the proper data URI scheme can be used.
This should not cause SVG-related security problems as the file is
displayed through `<img>` tag, which does not allow SVG scripting [2].

2. Make /web/image controller compatible with SVG

3. Add support for SVG files for company logo, which uses a dedicated
controller.

4. Resizing of SVG files is a no-op, as it makes little sense for a
vector-based format. We also want to avoid micro-alterations to the SVG
document (in "natural" viewport parameters) as we would store multiple
copies of the files in the filestore.

5. Because SVG files are inherently dangerous, upload of SVG files is
restricted to administrators, either by blocking it directly before
saving it in the database (binary fields with attachment=False), or by
neutering them to text/plain mimetype (for binary fields with
attachment=True)

6. Add tests for the SVG upload cases and for the non-admin uploads.

[1] https://tools.ietf.org/html/rfc2397
[2] https://www.w3.org/wiki/SVG_Security

Closes #26635
2018-10-03 17:48:01 +02:00
Xavier Morel 8fb358e563 [FIX] web: user's change_password wizard
Auth can now report errors less trivial than "incorrect password", the
wizard should report them instead of just assuming the original
password was not correct.
2018-10-02 20:54:00 +02:00
Xavier Morel 10228fe3ef [ADD] web: ability to become superuser (uid=1)
* requires that current user has group_system
* only visible in debug mode (?debug)
* available at login or via debug menu
* special systray color in superuser sessions

Closes #27254
2018-09-28 17:25:36 +02:00
ThanhDodeurOdoo 2d82692648 [REF] documents, base: binary_content
- Changed the binary_content method
to make it more generic and allow alternative ways of checking
the access rights by using a new method check_access_mode.

   Reason: Asked by ODO following documents' security review.

- if all pages are processed, splitting a pdf will
archive the original attachment.

   Reason: FP feedback.

Task: 1853490
2018-09-26 19:18:38 +02:00
Christophe Monniez 83e460b8da [IMP] web: add a phone input to the database manager
Task: 1879675
2018-09-18 13:54:19 +02:00
Christophe Simonis 68d36512ef [MERGE] forward port branch saas-11.4 up to d78f23df84 2018-09-07 20:20:45 +02:00
ThanhDodeurOdooandPierre Paridans 16aeecc73d [REF] base, mail: Documents (enterprise) related changes
-removed force_ext from ir.http.
    -added signature arg to web/image to differentiate cache entries by URL.
    -added an embed youtube viewer for youtube URL's
    -added a PDF splitter to the PDF viewer UI
    -added tests for mail's Document Viewer
    -added a "signature" param to web/image to go around the browser cache

    -thumbnail field of ir.attachment is now stored in the filestore
    as a distinct attachment.

task 1853490

Co-authored-by: Pierre Paridans <app@odoo.com>
2018-09-07 16:06:47 +02:00
Christophe Simonis 49c3264ce0 [MERGE] forward port branch saas-11.3 up to 4850fb0838 2018-09-07 14:43:48 +02:00
Christophe Simonis f19e6ce561 [MERGE] forward port branch 11.0 up to 213759b03e 2018-09-05 18:52:27 +02:00
ThanhDodeurOdoo 5e855453ae [FIX] web: web/image route image type fix
- the http route, when given width and height arguments is no
longer forcing the type PNG (which resulted in heavier images than the
original).
2018-09-05 16:33:25 +02:00
Olivier Dony fec74a6da5 [FIX] web: make server-wide modules ordered again
Rev. 279d928693 forced
`server_wide_modules` to include 'base' and 'web', because both contain
controllers that need to be always loaded.

However the patch used a set() that randomized the order of the list,
when combined with Python 3.5's randomized hash function.

This is turn could cause the checksum of asset bundles (web.assets_backend)
to randomly vary, which could cause rapid assets recycling and errors.
2018-09-05 14:47:55 +02:00
Nicolas Martinelli eaff0a71bd [FIX] web: export field with '/'
- Activate lots and SN
- Go to Inventory > Inventory Adjustments
- Export a record
- Select the field 'Inventories > Lot/Serial Number'

The `name_get` of the field is exported, not its XMLID.

This is because the parsing made in order to limit the depth of export
is made on the label, not on the field name.

Actually, it is not clear WHY this limitation exists, but we keep it for
compatibility purpose.

opw-1877092
2018-09-04 11:40:19 +02:00
Jeremy KerstenandDerie Romain 853e13800f [IMP] base,web,website: asset bundle make url overridable
Allow to override the asset url generation to add in the path the website ID
and avoid continue invalidation cache and bad cache by browser.

Asset url is:
    "/web/content/{id}-{unique}/{extra}{name}{page}{type}"
with:
    id = attachment id
    unique = hash
    extra = allow to add custom params eg: website_id/ or rtl/
    name = filename
    page = used in css to split rules 4095 / file
    type = css|js

Co-authored-by: Derie Romain <rde@odoo.com>
Co-authored-by: Kersten Jérémy <jke@odoo.com>
2018-08-13 20:16:34 +02:00
60aa9ffd01 [IMP] base,mail,web: attachments adaptation for documents
This commit is the counter-part of an enteprise commit introducing
the Documents app.

Here is a summary of what has been done:
  - tweak unlink of ir_attachment to prevent unlink recursivity
    (when attachments are attached to ir_attachments)
  - improve ir_attachment kanban view
  - add several arguments to binary_content controller:
    - 'force_ext': to force the extension in the filename, base on
      mimetype
    - 'share_token' and 'share_id': to autorize download from a
      share link
  - add 'thumbnail' field on ir_attachment to optimize Kanban view
  - add 'upper_limit' argument to image to allow to bypass the
    500*500 size limit
  - DocumentViewer now handles text files

More information available on task 1853490

Co-authored-by: Pierre Paridans <app@odoo.com>
Co-authored-by: sri-odoo <sri@odoo.com>
Co-authored-by: ThanhDodeurOdoo <tso@odoo.com>
2018-08-13 09:11:53 +02:00
Christophe Simonis 7499b47ffa [MERGE] forward port branch saas-11.4 up to edd586002e 2018-08-10 13:37:21 +02:00
Christophe Simonis 7717f082c0 [MERGE] forward port branch saas-11.3 up to af35aea6b0 2018-08-09 19:33:32 +02:00
Christophe Simonis 9cb97a8c2d [MERGE] forward port branch saas-11.2 up to 499af66727 2018-08-09 15:06:31 +02:00
William Henrotin 480184115d [ADD] base: report: qweb-text type
This commit adds a new ir.action.report type: qweb-text. It produces text files,
serves them with a text mimetype and these reports use the same rendering context
as the current other types (PDF and HTML).

This will be used in a following commit to produce ZPL scripts. Those scripts
are used for printing thermal label on Zebra printers.

task ID : 1837175
2018-08-09 14:33:03 +02:00
Christophe Simonis efe2dcd7ae [MERGE] forward port branch 11.0 up to ced9156a97 2018-08-07 19:08:07 +02:00
Xavier Morel aac21e4125 [CHG] Change login/auth internal protocol
* Make Users._login and session.authenticate always raise AccessDenied
  on authentication failure instead of only sometimes (cf
  Session.authenticate calling security.check() which raises and not
  catching the exception)
* Alter AccessDenied such that it's possible to add a custom access
  message, for use with login rate limiting instead of smuggling the
  information via the session
* Alter the RPC endpoints to catch and convert AccessDenied back to
  a boolean sentinel
2018-07-26 15:53:26 +02:00
Xavier Morel a8d868e287 [ADD] Rate limiting to (failed) login attempts
Task 31122 section 4.

Implement per-IP rate limiting of login attempts after some number
of failures.

* check_credentials has no reason to be public, make it private
* add hooks to check for login cooldown on a source IP (remote_addr:
  http://werkzeug.pocoo.org/docs/0.14/wrappers/#werkzeug.wrappers.BaseRequest.remote_addr)
  basis
* add baseline/default configuration of 60s cooldown
* add baseline threshold of 10 login failures, after checking odoo.com
  logs it looks like we have short runs of up to 7 failures (assumed
  to be legitimate) before the user either gets it right or goes and
  looks it up

Depends on #24187
2018-07-26 15:53:26 +02:00
Jigar Patel b60de0db41 [IMP] import/export UIs
Task 40692

Various changes to import/export (mainly) UIs:

* default to excel & "full" (non-import-compatible) export
* auto-detect encoding of CSV using chardet
* remember column -> field mapping after having imported a file (useful
   for repeated imports where auto-matching failed)
* better handle localised booleans & column names
* automatically select source list view's fields when exporting
* better integrate import templates feature and add a number of templates
2018-07-17 15:19:05 +02:00
Christophe Simonis 182c2c6919 [MERGE] forward port branch saas-11.4 up to 8285630ad2 2018-07-16 12:34:20 +02:00
Xavier Morel ccbfa94d32 [FIX] the ; in content-disposition is a separator not a terminator
According to RFC 6266,

content-disposition = "Content-Disposition" ":"
                      disposition-type *( ";" disposition-parm )

disposition-parm can't be an empty string, and thus a ; in terminal
position is not legal, even though browsers apparently work around it.
2018-07-13 17:31:22 +02:00
Christophe Simonis 8285630ad2 [MERGE] forward port branch saas-11.3 up to 609491ad0e 2018-07-13 17:12:07 +02:00
Christophe Simonis f3929aa0f7 [MERGE] forward port branch saas-11.2 up to 87dadc5bc8 2018-07-13 14:32:05 +02:00
Christophe Simonis c952a11770 [MERGE] forward port branch 11.0 up to 6e6e3d4c96 2018-07-13 10:47:18 +02:00
gmarcon baf6b29d45 [FIX] web: build xls file with maximum size
An MS Excel file can have maximum 32767 characters

Fixes #25653 
Closes #25700 

https://support.office.com/en-us/article/excel-specifications-and-limits-1672b34d-7043-467e-8e27-269d656771c3
2018-07-10 16:25:04 +02:00
Christophe Simonis 5decf4ab3d [FIX] web: clean data_file after restore
The file used for the restoration was not properly removed
2018-06-18 19:35:42 +02:00
Christophe Simonis 279d928693 [FIX] core: always load base and web as server wide modules
Since 285ead28e3, `base` should be loaded
as a server wide module to enable rpc routes.
2018-06-05 14:46:24 +02:00
Christophe Simonis 37eed7c509 [MERGE] forward port branch saas-11.2 up to 58e3552246 2018-05-25 14:34:18 +02:00
Christophe Simonis 2bc6ea1b37 [MERGE] forward port branch 11.0 up to 02ee3fd88e 2018-05-23 19:33:40 +02:00
len-odoo 8194e2cb80 [FIX] web: correctly handle admin svg images in channel
When posting an svg image, Odoo tries to resize it for thumbnailing
(like any image).
However this is of no interest since this is a vectorial file format, and
furthermore it distastefully makes the image library Pillow crash, since it only
supports raster formats.
The result would be a broken thumbnail instead of the image itself.

By not setting the thumbnail size if the mimetype contains svg,
we ignore the thumbnailing altogether.

Note that this only applies to the admin user, as otherwise the file is
treated as binary and thus no thumbnailing occurs anyway.

opw 1841153
2018-05-18 13:33:30 +02:00
Christophe Simonis 644f0959d0 [MERGE] forward port branch saas-11.2 up to 1655202924 2018-05-17 14:23:37 +02:00
Christophe Simonis fa8a67ee5f [MERGE] forward port branch 11.0 up to 5a943390f2 2018-05-15 20:18:14 +02:00