When more than one parameter is present in a message, it helps the
translation to use named placeholder. This way, the order can be
changed. It also helps the comprehension of the message.
Multi is the default api for methods, it is not necessary to explicitly
decorate methods with it, adds clutter and most people use it because
they see that the rest of the code uses it.
Done with `find . -type f -name '*.py' | xargs sed -i '/@api.multi/d'`
Create a quotation and send an email to the customer, let the customer
reply by email, as a portal user go on the portal view of that
quotation, he does not see the emails.
opw-2008653
closesodoo/odoo#34611
Signed-off-by: Jérome Maes (jem) <jem@openerp.com>
Before this commit, it was possible to post a message on a document
the user has no access, thanks to a token. In addition to this token,
if a hash (signed token with a partner id), the author_id of the message
was forced.
This commit change a little bit that logic by distinguish 2 cases:
1/ Token only: anyone with the token can post a message on the document. If
the user is not logged (public with token), the author_id will be the
customer of the document (or the public user). This case is moslty used
for business document, through the portal or with the "share link" for
instance.
2/ Signed token: user has no write access to the document, but can post a
message on it. The user have to be logged, as the token is signed with its
identifier. The goal here is to avoid leaking the access token's document
to all visitors. This case is mostly used for public content, such as blog
posts, slides, ...
The token case was already existing. The second is now working with this
commit. To do so, it was required to
- move `_sign_token` from the portal mixin to mail.thread.
- transfering 'pid' and 'hash' parameters from the controller to template
to js widgets.
This commit also change the `_message_post_helper` signature by making
the 3 first parameters required, as to post a message you need at lease
res_model, res_id and the message body. The optional argurments and kwargs
are here to check the bypassing access rights mecanism.
Task-1902304
After removing the `sha_in` params a while ago, we get rid of
the deprecated `token_field` option.
- Make `token_field` a model attribute, so that each model can easily
define the token field that should be used, and it does not need
to be passed around all the time anymore.
- Rename `_special_access_object()` to `_has_token_access()`, much more
readable since it returns a bool
- Do not forward the `attachment_ids` keyword arg to message_post,
as it sometimes contains unrelated IDs (the helper is not meant
to post attachments anyway)
- Update callers accordingly