Commit Graph
85 Commits
Author SHA1 Message Date
Nicolas Lempereur 4e24115a31 [FIX] http_routing: redirect no double query_string
Reproduction:

- have 308 redirection from /shop to /boutique and refresh routes
- go in incognito on /boutique?order=name+asc (don't go on
  /boutique first, or restart odoo to clear ORM cache)
- select a sorting option eg. price

=> we are redirected to /boutique?order=name+asc?order=list_price+asc
and this error is shown:

Invalid "order" specified (is_published desc, name asc?order=list_price
 asc, id desc).

This is happening because url_rewrite is keeping current query string
(see ir.http()._slug_matching) and caching it. So if the first call
caches:

  url_rewrite('/boutique') => /boutique?order=name+asc

all other url_rewrite('/boutique') calls will give you
/boutique?order=name+asc even if the query string has changed.

In addition to that, url_for may append query_string to url_rewrite
return value, so you may get a double query_string such as:

?order=name+asc?order=list_price+asc

which causes the error.

In this fix, we restore the removal of query string that was removed in
3beb4545c4.

opw-2702036

X-original-commit: 5dcf6e91fed769f4ab22ac63d3e5078cdd352e86
Part-of: odoo/odoo#82099
2022-01-04 10:26:16 +00:00
Fabio Barbero a66cdf3f7f [IMP] link_tracker, http_routing: ignore requests from social bots for link tracker
Purpose
=======
Avoid counting requests from social bots (twitter, facebook, linkedin...)
when tracking a link.

Specifications
=============
Social media platforms have a specific user agent in the HTTP headers that
can be used to detect them and to not increment the click count in that case.

Task-2578902

closes odoo/odoo#78806

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-12-14 09:11:15 +00:00
Jeremy Kersten 5945e8e4e3 [FIX] http_routing: don't remove trailing / during redirect
Before this commit, since we promote the use of route without trailing / for
best SEO (fee0113), we remove the trailing / during a redirect to avoid an
extra request.

Unfortunately, it will break some route with trailing / in case of multi lang.

So we remove this optimization, it will increase potentially number of http
request before to get the final url, but it will allow to continue to support
trailing slash in v15.

This commit partially revert the commit ae35117

closes odoo/odoo#80191

X-original-commit: 84d2f5b57ccf3dbcefebdbc795ab1872bc1504b9
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-11-22 16:27:09 +00:00
Xavier Morel b51b094c2b [IMP] http: avoid cycle on request 2021-01-26 09:05:35 +01:00
Jeremy Kersten 914fe1085e [FIX] http_routing: avoid extra redirect on logout in multi lang
context:
Connected in /fr on a website with /en as default lang.

Before this commit,
  /web/session/logout?redirect=/
  /
  /fr_FR/
  /fr_FR

Now
  /web/session/logout?redirect=/
  /fr_FR

Part 1 -> to say that we are in multilang context and use url_lang.
   multilang=False to avoid /web/session -> /fr/web/session
   website=True to have url_lang done in the request.redirect.
Part 2 -> to remove the trailing '/' that will be only useful for '/'

closes odoo/odoo#76290

X-original-commit: ae35117ee1e019c3c0c333f291478825a5722706
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-09-10 08:49:13 +00:00
Jeremy Kersten b290bceada [FIX] http_routing: is_frontend can be unset on request
AttributeError: 'HttpRequest' object has no attribute 'is_frontend'

e.g.: when we call request.redirect in ensure_db(), before that the _dispatch
method check if it is a is_frontend route or not.

closes odoo/odoo#73759

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-15 10:27:57 +00:00
Jeremy Kersten 478068c829 [IMP] *: always use Odoo Response
This branch adds request.redirect on all requests.
In case of a front end request, we do an url_for to the location.

We removed redirect_with_hash that was only for retro compatibility

local_redirect has been renamed to redirect_query, and param keep_hash has been
removed and moved.

Default code for redirect is 303 now instead of 302.

Now redirect and redirect_query make local redirect by default, you need to
pass local=False to make external redirect.

All werkeug.utils.redirect has been replaced by request.redirect.

Http.redirect now use an http.Response type, and it become easy to add an
override like 'set_cookies' e.g.

Dispatch of a website.page return an http.response too, so we first need to
check if it is a cached version before to check if it is an Odoo Response.

Migrate your code:

http.redirect -> request.redirect(location, code, local)
http.local_redirect -> request.redirect_query(location, query, code, local)
http.redirect_with_hash -> request.redirect

Courtesy of odony for help and review ;)

closes odoo/odoo#72599

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-08 07:00:06 +00:00
Jeremy Kersten 1bf9367c6f [FIX] http_routing: fix url_for with querystring
before this commit

url_for('/fr?a=b') -> /fr/fr?a=b because /fr?a=b not in ['fr', 'en']

Now we split query string before to check that first path is a lang
2021-07-07 13:45:51 +00:00
Romain Derie 119d9437e0 [IMP] http_routing: remove trailing / for homepage with language
Before this commit, `/fr_BE/` and `/fr_BE` would both be served without one
being redirected to the other.
That would be considered as duplicate content, as 2 different URLs would be
serving the same content.

opw-2505818
opw-2513575
Community: https://github.com/odoo/odoo/pull/71065
Enterprise: https://github.com/odoo/enterprise/pull/18615
2021-06-03 12:06:07 +00:00
Jeremy Kersten 3e238439f2 [FIX] http_routing: url_rewrite return now a tuple
Fix of refactoring 91b9dce

closes odoo/odoo#66927

X-original-commit: 03a318ff36949c80008ae35b4c744272c9986b9e
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-02-26 14:03:30 +00:00
Jeremy Kersten 2ecc538d51 [FIX] website: handle RequestUID case in slug
Before this commit, a 308 on a route with a modelconverter for a model
that have a seo_name field will crash with an exception:
Cannot iterate on RequestUID

Another simplest solution was to use a with_user(SUPERUSER_ID) but in this case
it bypass the security set and display the name of the record even if not yet
published.

How to reproduce:

Create a 308 from /shop/<product> to /mag/<product>
Unpublish product 10
Try to access /shop/product-10

You have an unmanaged '500 internal error"
because slug_matching -> build -> to_url -> slug with a record with Requestuid
as env._uid.

X-original-commit: 4ac2cab96655a3c5e673b0a04be5599dba507850
2021-02-01 14:51:19 +00:00
Jeremy Kersten 4a88d09632 [FIX] website: fix url_for when no qs
Before this commit, old url was not rewrited in case you don't have any query
string.

X-original-commit: 959774b18283abe0c5a5c5ca0d379a1dda1d7a36
2021-02-01 14:51:19 +00:00
Jeremy Kersten 91b9dced64 [IMP] website: merge cache of is_multilang_url with url_rewrite
Fwd-port of 6e87ee0

closes odoo/odoo#64916

X-original-commit: 6e987e6f7f5e6422bb1d04ea8764ab298446ffb0
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2021-01-22 12:07:04 +00:00
Jeremy Kersten 62c208f8e7 [FIX] website: don't try to convert static url in multilang
Same for all /web/ urls that are no multilang

X-original-commit: 476978a1530469d7d93678aa5c0131d9b1fa767c
2021-01-22 12:07:03 +00:00
Adrian Torres b7017e58cc [FIX] *: adapt business code to function-redefined error
This commit adapts the business code in which
class/module/function/method redefinition took place so that it no
longer happens and the pylint test passes.
2020-10-16 12:56:52 +00:00
Xavier Morel 9e27956aa9 [FIX] core: handle cors preflight with custom auth
Odoo provides basic handling of CORS preflight requests: if an
endpoint is marked as `cors=<truthy value>` then it'll automatically
reply allowing the request.

*However* this is performed in `HttpRequest.dispatch` (likely in order
to correctly handle the nodb case), which means it's executed after
the auth handler has run... which means custom auth handlers will be
called on preflight requests.

This is a problem because they are missing relevant
information (e.g. which endpoint they're invoked for), plus having to
deal with preflight requests in every custom auth handler is annoying,
and simply allowing preflights could cause issues if the decision
diverges between the auth handler and the automatic
handling.

To fix this issue, extract the preflight *decision* into a separate
method so we get the same decision-making process everywhere, and in
case of CORS preflight set the auth to none to limit the eventual
capacity for nuisance in the span between the bypassed auth and the
automated preflight handling.

Also change the signature of IrHttp._authenticate so it's clearer if a
callsite was forgotten somehow (and this makes for less changes and
duplication at the callsites).

closes odoo/odoo#56029

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-08-19 13:41:24 +00:00
704bcc5527 [IMP] portal, *: move language switcher to portal
*: base, http_routing, website

Make the language switcher available on portal without website
installed.

Part of https://github.com/odoo/odoo/pull/55300
task-2203383

Co-authored-by: Jeremy Kersten <jke@odoo.com>
Co-authored-by: qsm-odoo <qsm@odoo.com>
2020-08-14 17:40:58 +00:00
Jeremy Kersten 3beb4545c4 [IMP] http_routing: add cache on rewrite computation
Before this commit each url was processed each time, now with have a cache
with the path (withtout query string) as key on each worker.
It reduces drastically the time of the rewrite check on hot. (~10x)

closes odoo/odoo#54690

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-07-22 07:25:00 +00:00
Jeremy Kersten 30e4873a2f [IMP] website: allow to have custom slug
Now, slug uses seo_name if field exists before to fallback on display_name.

It allow to have a custom url without change the product name already used in
backend e.g. or just because you want add some keywords for seo.

task-2291676
2020-07-07 13:11:57 +00:00
Martin Trigaux d9287caf94 [IMP] *: convert to private methods
render, render_template, load, activity_schedule_with_view,
get_website_pages should all be private:
It should not be possible to render an aribtrary template only with
its name or id

Still need to render some qweb views from js so the method
render_template is kept public.
This explains why the website editor still need read access on
ir.ui.view as we want to allow any snippet to be rendered.
2020-05-14 13:59:10 +02:00
alt-odoo d3ffc3248c [FIX] http_routing: small fixup due to commit 423402f1e5
Method _get_exception_code_values can return None value for code. We should avoid
getting a KeyError in HTTP_STATUS_CODES in this case.

closes odoo/odoo#50160

X-original-commit: ea138667d55b535d8ec51f86fd649e28d704ac76
Signed-off-by: Alex Tuyls <alt-odoo@users.noreply.github.com>
2020-04-24 14:30:17 +00:00
Julien Castiaux ab4000fb3c [REF] base: Remove deprecated exceptions and osv
TL;DR: remember `osv` and `except_orm` ? You can forget about them.

* Deprecated `except_orm` dropped.
* `UserError` elevated as super type of all user-related
  errors.
* Unused `DeferredException` dropped.
* Unused `QWebException` dropped (real one is in `qweb.py`).
* `MailDeliveryException` made a python exception.
* `name` legacy exception attribute made an alias of the python standard
  `args[0]` attribute and deprecated.
* `value` legacy exception attribute dropped.
* `exception_type` RPC error response key dropped.
* Deprecated `osv` module dropped.
* `--osv-memory-age-limit` cli option made an alias of
  `--transient-age-limit` and deprecated.

The `odoo.exceptions.Warning` have long been a deprecated alias to
`UserError`. It is going to be removed in a future version but first we
explicitly deprecate it with a warning.

The `odoo.exceptions.DeferredException` was a very old internal
exception, it has been removed without deprecation notice as it is never
raised.

The `odoo.exceptions.except_orm` has been a deprecated exception type
with deprecation warning for 5 years, it has been removed in favor of
UserError which becomes the super class of all user-related errors.

The `odoo.base.models.ir_mail_server.MailDeliveryException` was
inheriting `except_orm`. As it is not related to a user error but is
more of a problem an admin much take care of, the exception has been
made a Python error.

The `exception_type` JSON key in RPC error responses was holding an
hardcoded value derived from the exception type. Its usage has been
dropped in favor of the `name` JSON key that holds the precise exception
name. Again as it was hardly used in the source code (beside the crash
manager) it has been dropped without deprecation warning.

Since we are here trying to clean odoo custom exceptions, we are also
deprecating the `name` exception attribute in favor of the more standard
`args[0]` attribute.

The `name` (along with `value`) were two attributes used to raise
`except_orm` exceptions before the introduction of `UserError`,
`AccessError` and related exceptions. The `name` attribute, at the time,
was holding the exception type/title. Nowadays it contains the error
message. The `value` attribute, at the time, was holding the error
message. Nowadays it is no more used.

The `osv` module contains very old deprecated aliases. There is no
simple way to log a deprecation warning for osv, osv_memory and
osv_abstract but as they have not been in use for ages, they have been
removed too. To be consistent, the `--osv-memory-age-limit` cli option
has been made a deprecated alias to the `--transient-age-limit`.

closes odoo/odoo#45723

Task: 2187728
Related: odoo/enterprise#9162
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2020-04-08 08:41:17 +00:00
Jeremy Kersten 26c4de2f18 [IMP] http_routing: use cached code from lang
In case of short controller that don't use qweb template, we don't need
anyhting else that this url code that don't change frequently.

It make only sense for model like lang, website, ... that will not change
frequently. And are called on each call by the dispatcher.

In case of a website page, we will btw browse lang later, but in case of
small controller like /favicon.ico, or page without qweb, ... we can just
use the same from last query.
2020-03-26 18:12:47 +00:00
Jeremy Kersten 9430dd1287 [FIX] website: perf - use lang cache in url for.
Before this commit, url_lang (= url_for) will make query to find the lang_code
but we alrady have this info in ormcache with get_available method.

So instead to rebrowse (search query) the lang, we use a new method that will
try to find it in cache if possible before to make the query.

The gain on each page is n-1 (where n is # lang installed)
Because the switcher of languages do an url_for for each lang available.

Related to #47257
task-2211013

X-original-commit: 2cecbe356ce283e15fb0bbd0a6e9aa4735af520e
2020-03-19 15:37:47 +00:00
Jeremy Kersten 4c40393490 [FIX] website: perf - translation - avoid query to find what we know
Before this commit, each module override _get_translation_frontend_modules_domain
from ir.http to add its own translation in website if needed and that module
is not starting by website_. Updating the domain from the super() call.
Since we know in most of the case the name, it is useless to do a:
   select name from module where name = 'name1' or name = 'name2'...

Now we support a new override of _get_translation_frontend_modules_name that will
allow to add the known module name directly in the list instead to make a search.

In case nobody override _get_translation_frontend_modules_domain, we don't need to
make an extra rpc to find the module.

Related to #47257
task-2211013

X-original-commit: 0dc54814161ab55c34dd2242f65dea23d19fdfca
2020-03-19 15:37:47 +00:00
Jeremy Kersten c2142a34f7 [FIX] website: perf - cache the compute hash for translation
Before this commit, we compute the hash on each request, to know if we need to
download the file from the frontend or if we can use cache.

Now we store the hash computed in cache. The cache will be invalidated when we
touch one of these translations (openerp-web in the comments) or when you
install a new lang (already the case).

+ avoid to use read on a record, since it will not use the cache from record.

Related to #47257
task-2211013

X-original-commit: d5aaecbc51de19ef1d8d9988b691177fc73a4b86
2020-03-19 15:37:47 +00:00
Xavier Morel de590816d8 [FIX] *: deprecated access to url_ utilities through werkzeug root
In 0.15 accessing werkzeug.urls functions directly through werkzeug
is deprecated, the shortcut will be removed in the eventual werkzeug
1.0.

Fix existing uses of these shortcuts. Also cleanup some imports when
they're not far from a werkzeug* import being altered.
2020-02-04 12:42:35 +00:00
Toufik Ben Jaa b22ba61c80 [FIX] website: rollback transaction before creating new one
- When rendering a website page, exceptions might happens.
    If so, an error page is displayed, to do so we create
    a new psyscopg cursor to read the view in database and render it.

    But if the current (failed) transaction was holding a lock, the new
    cursor might have to wait for this lock to be released further
    down the line. However, this will only happen after the
    request is done (and in fact it won't happen). As a result, the
    current thread/worker is frozen until its timeout is reached.

    So rolling back the transaction will release any potential lock
    and, since we are in a case where an exception was raised, the
    transaction shouldn't be committed in the first place.

closes odoo/odoo#44085

X-original-commit: 7a61c89da5ccaed983275eb5f4986475ebf8b48d
Signed-off-by: Toufik Benjaa (tbe) <tbe@odoo.com>
2020-01-28 11:13:55 +00:00
Romain Derie 9b3de32478 [FIX] http_routing, website: fix frontend lang in http dispatcher
This commit fixes 2 issues, both coming from a misbehavior in
`get_nearest_lang()`:
1. Anyone could reach the website in a lang available in backend but not in
   frontend. Eg, french is activated but not a website lang, going to `/fr`
   would show the page in french.
2. As a logged in user coming from backend in a lang not available in frontend
   (has request.lang set to that lang), the website would show a 500 error page
   since it would not filter out the current request lang.

Both these issues are fixed here by ensuring langs are filtered out if they do
not belong to the frontend (website langs).

Step to reproduce (bug 1):
  - Install french in backend lang (not on website)
  - Visit `127.0.0.X/fr_FR`, the frontend will be displayed in french even if
    it not a lang available in frontend.

Step to reproduce (bug 2):
  - Install french on frontend and remove english from frontend
  - Navigate to the backend /web
  - Navigate to frontend, it will crash

Fixes #40572 and fixes #40078

closes odoo/odoo#41146

X-original-commit: 4bfba037fbbf34c178abd532f7bf52b94ae40b27
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-12-02 08:31:26 +00:00
Jeremy Kersten dc77f67cad [FIX] website: match get/post in is_multilang_url
Old heuristic is not more True:
Force to check method to POST. Odoo uses methods : ['POST'] and ['GET', 'POST']

We have some controller that only allow 'GET' method, so we need to check GET
also when we try to know if an url is multilang or not.

This commit fix case where a controller '/test' only allow GET and you were in
another language that the default, in this case, the rendered url in qweb was
/get instead of /<lang>/get.

Closes #37223

closes odoo/odoo#40519

X-original-commit: c7650106f8588083be12812600a6c94ba703fd6f
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-11-26 14:35:46 +00:00
Jason Van Malder 16e6907efa [FIX] http_routing, portal: fix web translations not loaded
Reproduce the issue

    - Install eCommerce & Sales
    - Create a quotation
    - Preview
    - Switch to french on the website page
    - Click on "Signer & Payer"

    There is a lot of things not translated.

Cause

    On the website, the route `/website/translations` is called.
    The route calls a method `_get_translation_frontend_modules_domain`
    which teturn a domain to list the domain adding web-translations and
    dynamic resources that may be used frontend views.

    The missing translations are in the web module and the module is not
    loaded by the method.

This commit adds the `web` module to the domain and a missing
translation for the portal module

OPW-2120397

closes odoo/odoo#41072

X-original-commit: 50c2ecbc9ef0e446af0a1d4010ec1d923aa41bec
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2019-11-28 15:22:41 +00:00
jvm-odoo dc771b1a5c [FIX] http_routing: fix context language used when not available
A customer reported a problem when he deleted a language on the
website app.

In some cases, if you go on the odoo's generated website as a public
user let's imagine the following url: website.com/en_GB

The lang is saved in a cookie and sent to the context.

If you delete the language from the website languages (without
deactivating it) and you go on website.com as a public user,
the method will try to use the context or the cookie value which is
'en_GB' and it crashes.

This commit makes sure that the language is available

OPW-2129580

closes odoo/odoo#41007

X-original-commit: f3e9ca13f60ced0ec61cea0d13da45b2569da14e
Signed-off-by: Jason Van Malder <jasonvanmalder@users.noreply.github.com>
2019-11-27 12:14:21 +00:00
Xavier-Do fe0da16a24 [FIX] http_routing: revert b6ed34e1 and check _rewrite_len
Initial b6ed34e1 idea was to ensure that we always have
_rewrite_len and _routing_map defined. Unfortunately, this
is not correct since class attribute defined dynamically
are actually added in registry, and recomputed on each install.
More than that, the call si shared between multiple database
meaning that routing_map cache may be shared between multiple
database whcich is not correct.

After b6ed34e1, when installing discuss on a fresh database without
demo, all discuss routes will be unknown since None is already in
_routing_map and thus routing_map is not recomputed.

When routing_map is on the model class, in registry,
a new install will reset the class, remove the _routing_map attribute,
which will fix the problem.

Task #2117275

closes odoo/odoo#39640

Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2019-10-31 13:56:19 +00:00
Jeremy Kersten e239934abe [FIX] website: allow to modify the visibility of a page
Now, you can define a Visibility mode between:
    Public (All poeple)
    Connected (Portal or Employee)
    Restricted Group (Has this group or is Employee)
    With Password (Know password or is Employee)
    Internal Users (Is Employee)

It is a 'fair' feature, but without really warranty that the content is
really unreadable via others methods, ...

It is more for frontend display, that real secret. Dont use this like
a keychain ;)

We only catch the visibility on the main view and not the t-call inside.

Even if it should work on controller too, it is only display now on the
page property menu. (Or on the view directly in backend)

task-2091365
2019-10-29 16:04:47 +00:00
Xavier-Do d65fcfecb6 [FIX] web: avoid expensive 404 during js tests
A 404 will take 3 to 5 seconds to be resolved and execute +- 1900 query, to return
a rendered page which is quite expensive, especially when multiple missing images
are rendered in a view.

Catching static route and marking them as not frontend will help to avoid to handle miss
on static resources. In this case server returns a standard 404.

This commit also fix a iframe src in order to avoid a 404 on
/web/(test )/report/html/some_report (thx to aab-odoo)

X-original-commit: 818d0cb59fbae78d0edf06318082981f318e4db7
2019-10-17 17:10:06 +00:00
Christophe Simonis 97842368ef [FIX] http_routing: avoid using deprecated methods
Oversight of previous forward-port.
2019-10-09 02:39:09 +02:00
Christophe Simonis d74b451805 [MERGE] forward port branch 13.0 up to f4105eb9c7 2019-10-09 02:08:17 +02:00
Jeremy Kersten 17b0215ed5 [FIX] http_routing: remove useless redirection /website/translations
This reverts commit 08108486d5.
+ Fix the url that add a useless ending / and so a useless redirection.

There are no problem of mixed content or anything else, if you configure nginx
and launch your server in proxy-mode as specified into the documentation.

closes odoo/odoo#38196

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-08 12:22:54 +00:00
Jeremy Kersten 85c2a18dae [FIX] http_routing: fix request.redirect withtout website installed
In case you have a controller website=True without website installed, the
request.redirect() use url_for which one uses request.website_routing on the
request, without that it has been set by the website dispatcher.

closes odoo/odoo#38191

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-08 11:54:56 +00:00
fja-odoo 423402f1e5 [IMP] http_routing, *: move error pages to http_routing
* = portal, website, test_website, account, sms

Portal an Survey error pages were ugly default pages.
Now the error pages will be the same as the website ones.

Also fixing single module builds tests

task-2059969

closes odoo/odoo#35535

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-02 06:59:15 +00:00
Jeremy Kersten be8fc2296b [IMP] base, http_routing, website: allow custom routing rule
After this commit, you will be able (in technical mode) to update the url for
the python controllers.

Eg.
You can now rename /shop in /garden and /shop/product/ in /garden/vegetable/

Most of urls will be replaced at fly in the renderd qweb, with the function
url_for but all old urls will keep available. So if you access url /shop you
will be automatically redirected to /garden (308 Permanent Redirect).

As for cdn and other post-process of att, the automatically replacement in the
rendered qweb is only done when you will be not website editor. But the new
dispatch of URL will be applied in all cases.

For developper, since it is Permanent Redirect, don't forget to clear cache or
open chrome debug tool (with option 'Disable cache while DevTools is Open) to
see your lasts changes.

closes odoo/odoo#36555

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-09-30 13:58:14 +00:00
Romain Derie 3408c4dd1e [FIX] http_routing: restrict lang matching to installed lang
When accessing an URL, there is some computation to check if you try to access
a lang. Part of this job is to get the closest language available.
For instance, you could try to get `/fr_BE/..` and it would redirect to
`/fr_FR/..` if french is installed but not belgian french.

There is a known issue when loading files/assets from a module starting by the
same letter than a lang, in debug assets.
Only reported case was `hr_XXX` modules which would be redirected to `hr_HR`
lang (croatian).

So, the issue would only occur when:
1. Debug assets is enabled
2. hr_HR lang is activated
3. only hr_XX modules would be impacted

But since 269aa59411, the issue would appear even if `hr_HR` was not activated.

This commit restore the issue to its minimal case, when `hr_HR` lang is
activated.

closes odoo/odoo#37494

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2019-09-30 14:04:07 +00:00
Julien Castiaux b96e633b0b [IMP] web: upgrade the cache to use SHA2 over SHA1
SHA-1 is a cryptographic hash function that have weaknesses known since
2005, it has been deprecated by the NIST [1] about 10 years ago in 2011
and Google [2] have been able to perform a collision attack in 2017.

We use SHA-1 in order to generate unique URL for resources that can be
cached by the browser: assets bundle, translations, qweb templates and
qweb images.

Although practical attacks still requires quite a lot of computational
resources, it is time to upgrade SHA-1 to SHA-2.

We have selected the SHA-512/256 variant of the SHA-2 algorithm as
replacement for SHA-1 for the following reasons:

* On 64 bits platform, SHA-512 is the fastest SHA-2 variant, it is only
  ~1.5x slower than SHA-1. [3]
* Keeping only the 256 foremost bits protects against both collision
  attacks and length extension attacks.
* The hexadecimal digest is only 24 chars longer than SHA-1 which is
  nice to have somewhat short URLs.

We have not used SHA-3 because:

* At the moment of writing, it is too slow (~3x slower than SHA-1) [3]
* It is not guaranteed to be available with the Python 3.5 `hashlib`
  module.
* One of the author of SHA-3 is Belgian.

[1] https://csrc.nist.gov/projects/hash-functions/nist-policy-on-hash-functions
[2] https://shattered.io/
[3] http://bench.cr.yp.to/results-hash.html
[4] http://www.commitstrip.com/en/2017/02/27/the-sha-1-alternative/
2019-09-04 09:52:01 +00:00
Sébastien TheysandJairo Llopis 1781041f13 [IMP] website, website_event, website_slides: add rel=canonical tag
The canonical tag is important for SEO, indeed it prevents search engines from
indexing duplicate content.

Reasoning
=========

The choice has been made to create the canonical tag automatically depending on
the request path, ignoring the query string, and manually prefixing the
appropriate domain and language code.

Indeed creating it manually for each resource would create a lot of code and
potential mistakes.

It is more dangerous to do it the generic way, but after investigation it
appears that it is an acceptable trade-off since the vast majority of our routes
are well built and already ready for this:

- using query string only for minor features that do not change the main content
- having the models, the ids, the pager and other important features in the path

Override
========

It is still possible to override the default behavior by passing
`canonical_params` manually to the view or to the different methods.

This is done for `/event` because the only way to display Past Events is to add
`date=old`.

Languages
=========

Fix an issue where it was possible for a bot to be on the URL without language
code but to use a language that is not the default language.

Adapt hreflang, because it:
- must only be present on canonical pages
- must always lead to canonical pages
- should not be set if there is no alternate language

Misc
====

task-1958075
closes #12532

Inspired by OCA module `website_canonical_url` courtesy of Jairo Llopis.

closes odoo/odoo#35852

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>


Co-authored-by: Jairo Llopis <jairo.llopis@tecnativa.com>
Co-authored-by: Sébastien Theys <seb@odoo.com>
2019-09-03 12:11:35 +00:00
Romain Derie 269aa59411 [IMP] http_routing, website: allow to customize the lang in URL
With this commit it is now possible to change the lang displayed in the URL.
Eg, you could use `/fr` instead of `/fr_BE`, or even a fancier `/french`.

Task-32838

Courtesy of pla@odoo.com

closes odoo/odoo#35135

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2019-08-26 16:35:19 +00:00
Martin Trigaux bdec8efabf [ADD] web: add the language code in the translation widget
The planet icon is not very clear for translation feature.
Replace it with the code of the current language.

Task-id: 2028152
2019-08-13 14:12:17 +00:00
Martin Trigaux 85ee046b37 [IMP] *: use res.lang methods
get_installed and _lang_get_id are both ormcached and correctly check
the context

Retrieving a res.lang from a code is a frequent action that can be
achieved with _lang_get (cf previous commit).
Using _lang_get ensure the active_test in the context is correct and
is not poluted with another context propagation issue.
odoo/odoo#35490 discussion is an example of bad context propagation

closes odoo/odoo#35504

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2019-08-07 13:06:17 +00:00
Martin Trigaux ab7ab7ebbb [FIX] web,http_routing: correctly invalidate cache translation
cache_hashes was introduced at 8a28cc22fd to reduce the number of reload
The cache is correctly reseted when the translations content changed but did
not contain all the translation-related parameters that are, however, stored
in the session_info

This commit fixes two bugs:

Language parameters invalidation:
1. Access the webclient in a specific language
2. Modify the language parameters (e.g. thousands separator)
3. Refresh the page
--> webclient is still using old language parameters (from cache)

No translation flag after installing a language:
1. Load a database in English in mono-language
2. Load a second language
3. Access a record with a translated field
--> translation button not present on translated field (multi_lang is still
false in cache value)

To fix it, this commit adds all the information that are returns by the
/web/webclient/translations call to make sure the hash represent the reality

closes odoo/odoo#34266

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2019-06-20 08:38:47 +00:00
Christophe Simonis 25e3f27062 [MERGE] forward port branch saas-12.3 up to 48a9f5a633 2019-06-17 13:20:35 +02:00
Bohdan Lisnenko bd3a788479 [FIX] http_routing: slugify_lib - max_length param should be int
closes odoo/odoo#33858

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-06-04 10:53:17 +00:00