Commit Graph
118 Commits
Author SHA1 Message Date
Olivier Dony 3cbc0915bb [FIX] web: expect explicit sign up parameters
Using an explicit list of sign up parameters will avoid
polluting the context with unrelated values, and make
debugging easier.
2021-10-02 15:04:53 +02:00
Jeremy Kersten 478068c829 [IMP] *: always use Odoo Response
This branch adds request.redirect on all requests.
In case of a front end request, we do an url_for to the location.

We removed redirect_with_hash that was only for retro compatibility

local_redirect has been renamed to redirect_query, and param keep_hash has been
removed and moved.

Default code for redirect is 303 now instead of 302.

Now redirect and redirect_query make local redirect by default, you need to
pass local=False to make external redirect.

All werkeug.utils.redirect has been replaced by request.redirect.

Http.redirect now use an http.Response type, and it become easy to add an
override like 'set_cookies' e.g.

Dispatch of a website.page return an http.response too, so we first need to
check if it is a cached version before to check if it is an Odoo Response.

Migrate your code:

http.redirect -> request.redirect(location, code, local)
http.local_redirect -> request.redirect_query(location, query, code, local)
http.redirect_with_hash -> request.redirect

Courtesy of odony for help and review ;)

closes odoo/odoo#72599

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-08 07:00:06 +00:00
Florent de Labarre 145d48d23b [IMP] auth_signup : add hook to add custom fields
closes odoo/odoo#65276

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2021-01-29 21:35:14 +00:00
Sébastien Theys 828ea9c523 [FIX] auth_signup: properly grab user lang from context
Follow up on d0a4b20d36

The `lang` at this step is compared to the locale `code` (eg. fr_BE) so the
split is a mistake.

To reproduce the issue:
- change the language of a website to fr_BE only
- allow free signup
- register as a new user

Notice how the language of the user is set to en_US before this PR instead of
fr_BE as it should be.

closes #63616

closes odoo/odoo#64089

X-original-commit: ba21dadf17ba96ecbba917f666a3b385d9b9fd5e
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2021-01-05 14:04:21 +00:00
Julien Castiaux ab4000fb3c [REF] base: Remove deprecated exceptions and osv
TL;DR: remember `osv` and `except_orm` ? You can forget about them.

* Deprecated `except_orm` dropped.
* `UserError` elevated as super type of all user-related
  errors.
* Unused `DeferredException` dropped.
* Unused `QWebException` dropped (real one is in `qweb.py`).
* `MailDeliveryException` made a python exception.
* `name` legacy exception attribute made an alias of the python standard
  `args[0]` attribute and deprecated.
* `value` legacy exception attribute dropped.
* `exception_type` RPC error response key dropped.
* Deprecated `osv` module dropped.
* `--osv-memory-age-limit` cli option made an alias of
  `--transient-age-limit` and deprecated.

The `odoo.exceptions.Warning` have long been a deprecated alias to
`UserError`. It is going to be removed in a future version but first we
explicitly deprecate it with a warning.

The `odoo.exceptions.DeferredException` was a very old internal
exception, it has been removed without deprecation notice as it is never
raised.

The `odoo.exceptions.except_orm` has been a deprecated exception type
with deprecation warning for 5 years, it has been removed in favor of
UserError which becomes the super class of all user-related errors.

The `odoo.base.models.ir_mail_server.MailDeliveryException` was
inheriting `except_orm`. As it is not related to a user error but is
more of a problem an admin much take care of, the exception has been
made a Python error.

The `exception_type` JSON key in RPC error responses was holding an
hardcoded value derived from the exception type. Its usage has been
dropped in favor of the `name` JSON key that holds the precise exception
name. Again as it was hardly used in the source code (beside the crash
manager) it has been dropped without deprecation warning.

Since we are here trying to clean odoo custom exceptions, we are also
deprecating the `name` exception attribute in favor of the more standard
`args[0]` attribute.

The `name` (along with `value`) were two attributes used to raise
`except_orm` exceptions before the introduction of `UserError`,
`AccessError` and related exceptions. The `name` attribute, at the time,
was holding the exception type/title. Nowadays it contains the error
message. The `value` attribute, at the time, was holding the error
message. Nowadays it is no more used.

The `osv` module contains very old deprecated aliases. There is no
simple way to log a deprecation warning for osv, osv_memory and
osv_abstract but as they have not been in use for ages, they have been
removed too. To be consistent, the `--osv-memory-age-limit` cli option
has been made a deprecated alias to the `--transient-age-limit`.

closes odoo/odoo#45723

Task: 2187728
Related: odoo/enterprise#9162
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2020-04-08 08:41:17 +00:00
Nicolas Martinelli 1766d3281e [FIX] auth_signup, website, base: identical logins
- Create a website:
  Free sign up
  Specific User Account activated
- In the backend, create a partner "test@test.com"
- Grant him portal access
  => user is not website-specific
- Go to the website, Sign Up with "test@test.com"
  => user is website-specific

At login, an expected singleton error arises at:
https://github.com/odoo/odoo/blob/c53f1c6a58b4c8c9e9b3c87f27281c9bfd65a0e1/odoo/addons/base/models/res_users.py#L613

Because this matches both users:
https://github.com/odoo/odoo/blob/c53f1c6a58b4c8c9e9b3c87f27281c9bfd65a0e1/addons/website/models/website.py#L44

When such a case arises, we make sure to always select the most specific
user first.

opw-2219618

closes odoo/odoo#49089

X-original-commit: 9e217125c0d8c951e895e9799795ac29b7962107
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
2020-04-06 16:22:31 +00:00
Thibault Delavallée 1838191eec [REF] mail, various: improve mail creation calls, notably author and email from default computation
Purpose of this commit is to correctly compute author_id and email_from
in mail_message and mail_mail as they depends from each other. Moreover it
is a good idea in various flows to specify email and author when giving
creation values to avoid default computation that is not always guaranteed to
be accurate notably when involving super user.

Mail message creation could lead to desynchronized values between author
and email_from. This is improved with this commit by correctly inheriting
from default_get and computing both of them at the same time instead of having
two default values. Indeed they depend on each other.

Same thing is done for mail composer. Mail Thread offers a tool method to
find email_from / author_id based on having one of those values or current
user and it is called whenever necessary.

Some calls to mail template send_mail are also cleaned.

Task ID 1853147
PR #32243
2019-11-29 13:35:14 +00:00
Sébastien Theys d0a4b20d36 [FIX] auth_signup: prevent crash if http_routing not installed
Follow up of 269aa59411

`request.lang` is only set on `http_routing` so it cannot be used here.

The fix here is the same as what was done on `web` on the mentioned commit.

To reproduce the issue:
- install any module, but not `http_routing`
- use reset password
- try to set a new password from the received link with token

A few notes about the mentioned commit:
- the `lang` `lazy_property` was removed because it was a string before and a
  record now, and lazy_property cannot return a record
- the `lang` on the `request` is now a record
- the `lang` on the `context` is still a string

closes odoo/odoo#36468

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2019-09-05 12:31:57 +00:00
Romain Derie 269aa59411 [IMP] http_routing, website: allow to customize the lang in URL
With this commit it is now possible to change the lang displayed in the URL.
Eg, you could use `/fr` instead of `/fr_BE`, or even a fancier `/french`.

Task-32838

Courtesy of pla@odoo.com

closes odoo/odoo#35135

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2019-08-26 16:35:19 +00:00
Martin Trigaux 85ee046b37 [IMP] *: use res.lang methods
get_installed and _lang_get_id are both ormcached and correctly check
the context

Retrieving a res.lang from a code is a frequent action that can be
achieved with _lang_get (cf previous commit).
Using _lang_get ensure the active_test in the context is correct and
is not poluted with another context propagation issue.
odoo/odoo#35490 discussion is an example of bad context propagation

closes odoo/odoo#35504

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2019-08-07 13:06:17 +00:00
aca 78565b1dc9 [REM] web_settings_dashboard: Merge module into base_setup
Purpose
=======

Currently, when we click on “Settings” on the Home Dashboard, we arrive
on a new Dashboard with several pieces of information like Installed Apps,
invite new users, or translations. Some informations are reachable in
several ways, which is not necessary.

We would like to remove this page and replace it with the General Settings
page directly. That makes more sense to the user who click on “Settings”. The
present informations will be dispatched in the menu or in the general settings
for a better usability.

Specification
=============

This commit move code from web_settings_dashboard in order to put the features
in settings directly. To do so, we choose to move code to base_setup, and create
widget on the settings form view to keep features. Concerned features are: invite
users, dev tools, odoo edition number and IAP account link.

TaskID: 2006910

closes odoo/odoo#34290

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-07-26 09:53:46 +00:00
Denis Ledoux 7228c10884 [MERGE] forward port branch saas-11.3 up to 6fd637e131 2019-04-25 15:47:09 +02:00
Denis Ledoux 6fd637e131 [MERGE] forward port branch 11.0 up to b71b78035b 2019-04-24 14:31:10 +02:00
Denis Ledoux b71b78035b [MERGE] forward port branch saas-15 up to 0c46c8a929 2019-04-24 10:04:05 +02:00
Denis Ledoux 6fd092e131 [MERGE] forward port branch 10.0 up to 4730a884b4 2019-04-23 17:16:26 +02:00
Joseph Caburnay 0229ef4c4a [FIX] auth_signup: portal user redirect to /web after signup
To reproduce:
0. Start an odoo v10 instance with --load=saas_worker,web
1. Install ecommerce.
2. Enable "Allow external users to sign up" and "Enable password
reset from Login page" from General Settings.
3. Open different session then signup a new user.
4. After successfull signup, the new user will be redirected
to the backend (/web).

Facts to consider:
1. odoo.addons.auth_signup.controllers.main.AuthSignupHome and
odoo.addons.website.controllers.main.Website both inherit
odoo.addons.web.controllers.main.Home
2. When instantiating an odoo instance *without* saas_worker,web,
the mro is the following:

( <class 'odoo.http.Home (extended by Website, AuthSignupHome)'>
, <class 'odoo.addons.auth_signup.controllers.main.AuthSignupHome'>
, <class 'odoo.addons.website.controllers.main.Website'>
, <class 'odoo.addons.web.controllers.main.Home'>
, <class 'odoo.http.Controller'>
, <type 'object'>
)

while the mro *with* saas_worker,web loaded is:

( <class 'odoo.http.Home (extended by AuthSignupHome, Website)'>
, <class 'odoo.addons.website.controllers.main.Website'>
, <class 'odoo.addons.auth_signup.controllers.main.AuthSignupHome'>
, <class 'odoo.addons.web.controllers.main.Home'>
, <class 'odoo.http.Controller'>
, <type 'object'>
)

You can notice that depending on how the instance is instantiated,
the order of inheritance is different.

The problem occurs when saas_worker is loaded, so this bug can be
experienced by saas clients.

Explanation of the fix:
Notice that the original code calls web_login of its super in its
web_auth_signup method. This is technique is used normally during
optimization (according to RCO). If website is installed, the
portal user should be redirected to '/' instead of '/web' and this
is defined in web_login of website. However, the web_login of
"website" is not called after signup because "website" is not super
of "auth_signup" when saas_worker is loaded (see the mro above).

Calling self.web_login will make sure that web_login is called from
top to bottom, and regardless of the order of website and auth_signup,
web_login of "website" will be called and makes sure that the
new portal user is redirected to the '/' and not to '/web'.

opw-1956980

closes odoo/odoo#32741

Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
2019-04-19 07:06:37 +00:00
Joren Van Onder 4f6ec1cd2a [IMP] website,*: support multiple websites
This implements support to administer multiple websites. Although the
core functionality already existed, managing multiple websites was
fairly technical.

In the interest of database updates and migration this attempts to
keep duplicated data to a minimum. To do this the usual generic
records are rendered unless some website-specific record exists that
replaces it. Copy-on-write (COW) is used to create these
website-specific records. Through this mechanism creating a
website-specific record is delayed until necessary. A COW mechanism
has been implemented on 4 models: ir.ui.view, website.page,
website.menu and ir.attachment. These COW mechanisms are activated
when editing data through the website (aka frontend). These frontend
edits (e.g. with web_editor) will be website-specific, possibly
creating a website-specific record when necessary. When editing data
in the backend nothing special will happen, even when editing a
generic record. Note that because of this mechanism also facilitates
the ability to create new, uncustomized websites because the generic
data is kept.

Support is provided for a website to have any theme. Themes are fairly
complex to handle. Standalone themes can depend on other standalone
themes (e.g. theme_beauty depends on theme_loftspace) and themes
usually modify some data of the themes they depend on. Because a theme
can be installed on multiple websites, using website_id m2o fields
does not work well. It would require duplicate data, making updates
and migration harder. Because of this, data for themes (ir.ui.view and
ir.attachment specifically) have a theme_id m2o. website has a
theme_ids m2m that identifies all theme modules currently installed on
it. Through these fields we figure out what to render. A theme is only
fully uninstalled when it's no longer active on any website. The
advantage of this approach is that upgrading or migrating theme data
is no different from the single-website case.

The website.published.mixin class was modified to handle multiple
websites. A wizard was added in the backend to easily manage this for
multiple website.

Although not used anywhere in this commit, a 'website_id' variable has
been added in the evaluation context of ir.rule. It allows to easily
make any model multi-website aware, all that's needed is a custom
website_id m2o field on a model and a custom record rule.
2018-08-13 19:51:10 +02:00
Olivier Dony fb31330451 [FIX] auth_signup: correct leftover from 6d16915d39
The /web/signup controller was also supposed to get the special frame
header, like all sign-in/up pages.
2018-07-26 23:48:58 +02:00
Christophe Simonis a0c5b58d5d [MERGE] forward port branch saas-11.3 up to 4846c30c90 2018-07-02 15:16:20 +02:00
Christophe Simonis 611c86dbc7 [MERGE] forward port branch 11.0 up to 21b2617d6f 2018-07-02 12:17:00 +02:00
Martin Trigaux c02fe10add [FIX] auth_signup: display meaningfull error message
Similar as 676022e3af for reset form
2018-06-28 15:56:16 +02:00
Christophe Simonis f36e6917bd [MERGE] forward port branch saas-11.3 up to 37eed7c509 2018-05-29 17:34:43 +02:00
Christophe Simonis 1655202924 [MERGE] forward port branch 11.0 up to 59a8a1cd8e 2018-05-17 13:19:49 +02:00
Olivier Dony cdabb9d74c [FIX] auth_signup: remove password from welcome message
Revision 054c68689b added by mistake the
password of the new user in the welcome message that is sent to users
who signed up with an invitation token.

There is no need for this, the user has just chosen their password, and
we should not send them a copy which could be compromised on the way to
their inbox or later in their inbox.
It may also give users the impression that their passwords is stored in
cleartext in the database, even when that is not the case.

This patch minimalizes changes to the template and its translations.
For existing databases where the code is updated without re-syncing the
template, the password will simply be missing in the message (until a
resync of auth_signup module is done)
2018-05-16 12:17:14 +02:00
dip-odoo 362613a2fa [IMP] auth_signup: change email invitation condition
Currently if a user has already been invited you cannot invite him again
via the web_settings_dashboard as it automatically tries to create a new
user.
This commit changes that behaviour in case you have the mail app
installed odoo will now send an invitation email to the invited user as
long as this user has never connected.

1) Mail app not installed:
   - if user is active     > display error (this email is already in use)
   - if user not active    > activate the user
   - if user doesn't exist > create new user

2) Mail app installed:
   - if user is active && state confirmed > display popup (this email is
   already in use)
   - if user is active && never connected > resend invitation mail
   - if user is inactive > activate the user
   - if user doesn't exist > create new user and send invitation mail

This commit is related to task #54023
Closes #23081
2018-05-04 18:07:31 +02:00
Richard Mathot a18bd499ac [REF] various: convert res.config.settings to use ir.config_parameter integration
This commit updates the various res config of Odoo addons to use the
newly-introduced config_parameter field attribute.
2018-01-16 13:34:29 +01:00
Jeremy Kersten a0a5443e8f [FIX] auth_signup: properly display the error message
Was "Internal Error 500"

Introduced at c3bf161

This closes #20941
2017-11-17 12:02:05 +01:00
Christophe Simonis 45958ab312 [MERGE] forward port branch saas-16 up to 5f9c3f51a8 2017-11-07 11:45:42 +01:00
Olivier Dony ec00c27ca3 [FIX] auth_signup: correct leftover from 6d16915d39
The /web/signup controller was also supposed to get the special frame
header, like all sign-in/up pages.
2017-11-01 23:38:56 +01:00
Martin Trigaux c3bf1618bd [FIX] auth_signup: properly display the error message
Was "('Passwords do not match; please retype them.', '')"

Introduced at 676022e3
2017-10-30 11:19:00 +01:00
Jeremy Kersten 1b52b00d2a [IMP] website*: clean sitemap + add method to declare sitemap function.
Don't add useless routes or route that will return 404.
Improve generate function from ModelConverter to have a better management of
query_string.

Now we have an helper sitemap_qs2dom that will analyse the current route and
check if query string is plausible and if yes, generate a domain, when the
query_string don't seems to match the route, we return a Falsy domain.

Before this commit, if qs was /product/ipad, enumerate_page check for each
modelconverter of the route a name ilike '/product/ipad'.

Now we check all routes that contains product and one converter that match ipad
or routes that contains ipad and one converter that match product.

This commit a new way to declare the sitemap for a route.
    def sitemap_xx(env, rule, query_string):
        yield {'loc': '/my_url'}
    @http.route(..., sitemap=sitemap_xx)

    In this case, only the loc returned by this function will be in the sitemap
    for all rules.

    You can pass sitempa=False, if you don't want that route are into the sitemap
2017-09-27 21:33:49 +02:00
Olivier Dony 695716efb0 [FIX] P3: remove pycompat.{keys,items,values} helpers
Now that we're closer to switching to P3 for good, these helpers have
outlived their usefulness, and mostly add noise.

All remaining dict.iter*() or dict.view*() must be converted to the
normal keys(), values() or items() calls.

Whenever the result is likely to be used for more than the scope of a
loop, or when the dict needs to be modified during iteration, the calls
must be wrapped in a ``list()``, to protect the new P3 semantics.
Those cases are very exceptional.

Also removed some dead code or improved the API to remove unnecessary
conversions.
2017-08-20 23:25:54 +02:00
Denis Vermylen 054c68689b [IMP] auth_signup: various usability improvements in signup process
* allow new signup on invalid token
 * relabel signup buttons
 * send a welcome email upon signup with a signup token.

This way, should the token somehow be usurped by someone else,
the original partner's email address will be notified.
(before the usurper can change the email)
2017-07-06 12:53:39 +02:00
Denis Vermylen 6977a363e4 [IMP] web, auth_signup: add signup and login values to session
When you receive an url with parameters

 * auth_signup_token: uuid
 * auth_login: login

those will be stored in the session and used

 * when the user will want to sign up in order to be linked to the right
   partner;
 * when he logs in so he's sure to log in with the right account +
   autofill is nice

This commit only adds the support, future commits will support its use.
2017-07-06 12:53:39 +02:00
Denis Vermylen 676022e3af [IMP] auth_signup: display meaningfull and translated error messages
Since 5425316eff errors when signing up will only display two
messages:

 * "Another user is already registered using this email address." or
 * "Could not create a new account."

While Odoo creates a multitude of other comprehensible error messages
such as

 * "Passwords do not match; please retype them."
 * "Signup token '%s' is no longer valid"

This commit now separate UserError and AssertionError from SignupErrors.
Those are still hidden in a general message (see 5425316eff for reasons) while
the other ones are fully displayed.

This commit also improves translations of messages.
2017-07-06 12:53:39 +02:00
Olivier Dony 5f4db9df66 [MERGE] Forward-port saas-16 up to 5afe894f44 2017-05-16 18:23:15 +02:00
Olivier Dony 5afe894f44 [MERGE] Forward-port saas-15 up to 878fbc75ff 2017-05-16 17:09:45 +02:00
Olivier Dony 9b3ca1af23 [MERGE] Forward-port 10.0 up to 1545995b39 2017-05-16 12:12:30 +02:00
Xavier Morel 07ab8b6cd2 [FIX] P3: Exception.message removed 2017-05-12 16:15:40 +02:00
xmo-odoo fffaf735f5 [FIX] P3: list -> iterable builtins (#16811)
In Python 3:

* various builtins and dict methods were changed to return
  view/iterable objects rather than lists
* and the separate Python 2 view/iterable builtins and methods were
  removed altogether

This is problematic when using these items as list (which the happens
repeatedly in Odoo), but more viciously when iterating *multiple times*
over them (which also happens, which I've messed up multiple times while
writing this, and which is a pain to debug even when you've just created
the issue).

Convert all code using these to semantics-matching cross-version
helper functions to get the LCD behaviour between P2 and P3, and
forbid the builtins via lint.

issue #8530
2017-05-10 09:39:55 +02:00
Olivier Dony 6921da00b3 [FIX] auth_signup: properly log password reset requests 2017-05-05 17:02:46 +02:00
xmo-odoo b4429c2a91 [FIX] Various P3-related import changes
* LDAP import: python-ldap is not python3-compatible, pyldap is

  Warning: only supported from debian Stretch (current testing)?
  https://packages.debian.org/search?searchon=names&keywords=pyldap

* implicitly relative imports
* imports of moved or removed stdlib modules

issue #8530
2017-04-28 09:06:53 +02:00
Xavier Morel 3979f6802e [#8530] convert exception handlers to except..as syntax
Futurize fixers:
* lib2to3.fixes.fix_except
2017-04-11 14:53:29 +02:00
Olivier Dony 6d16915d39 [FIX] web: no frames on login/preferences screen
We generally consider this a low priority issue
as it is social-engineering based and many easier
options exist for targeting gullible users.
Nevertheless, protecting a couple of obvious pages
does not hurt.
2017-03-27 18:47:45 +02:00
Raphael Collet d0ca2d115e [REF] ir_config_parameter: remove group_ids and simplify
Add `sudo()` to call `get_param` where necessary, and make the web client use a
controller instead of directly accessing parameters.
2017-01-03 16:52:49 +01:00
Raphael Collet 7543afb070 [IMP] base, *: tighten ir.config_parameter access rights
Add `base.group_system` on existing parameters:
 - `auth_signup.allow_uninvited`,
 - `auth_signup.reset_password`,
 - `auth_signup.template_user_id`,
 - `google_redirect_uri`,
 - `mail.bounce.alias`,
 - `mail.catchall.alias`,
 - `mail.catchall.domain`.
2017-01-03 16:52:49 +01:00
Christophe Simonis 321b7dc5b6 [MERGE] forward port branch 9.0 up to 9c8422a 2016-12-09 15:09:36 +01:00
Christophe Simonis 9c8422a405 [MERGE] forward port branch saas-6 up to 75e7f0d 2016-12-09 15:07:00 +01:00
Christophe Simonis 75e7f0da10 [MERGE] forward port branch 8.0 up to 5ece76b 2016-12-09 15:04:42 +01:00
sergiov 4792a669d3 [FIX] auth_signup: display full error message
When the user name entered hasn't an email specified the error message wasn't
displayed in the reset view.
The error message was in e.name, not e.message
2016-12-09 14:32:16 +01:00