Commit Graph
1842 Commits
Author SHA1 Message Date
Benoit Socias a676344ecc [FIX] website{_*}: not truncate URLs in search results
website{_*}: website, website_blog, website_event, website_forum,
website_sale, website_slides

Since the generic search bar was introduced in [1] all text fields were
truncated in search results.
This caused problems for long URLs which were truncated as well, and
therefore could become invalid.

After this commit URL fields specify `'truncate': False` in their search
detail metadata, which informs the rendering to skip the text truncation
step for that field.
Also added previously missing controller-level tests of the
autocompletion.

Steps to reproduce:
- start odoo with website_forum and demo data
- go to the Help forum
- search for "configure" in the Help forum
- click on the auto-complete suggestion
- => redirected to a 404 page because the URL was shortened
To test the fix on other models, use a long enough name that causes the
problem. E.g.: "This product has such a long name its URL would have
been truncated without the fix contained in this branch".
Note that the problem did not occur on blogs because the URL does not
contain the name, but the same fix was applied for consistency.

[1]: https://github.com/odoo/odoo/commit/7559626c54e34b41e1549e28276a650accec6986

task-2727788

closes odoo/odoo#82621

X-original-commit: 045f741be35e62f5e3a636490c6c1d475b5d78eb
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2022-01-12 14:55:03 +00:00
Kevin Baptiste c0205b3431 [IMP] website_forum: adapt tours
The enterprise module website_helpdesk_forum changes the demo data
karma_answer value to 0 for the default Help forum thus breaks the tour.

odoo/enterprise#19870
odoo/upgrade#2681

closes odoo/odoo#74353

Taskid: 2499623
Signed-off-by: Laurent Stukkens (ltu) <ltu@odoo.com>
2022-01-06 16:21:08 +00:00
Martin Trigaux cfb9967d37 [FIX] website_forum: set return content-type
The request being of type http, the returned Content-Type was
text/html while the select2 request exepected json in the dataType
2021-12-20 13:55:00 +01:00
Martin Trigaux 4107d17b01 [FIX] website_profile,forum: avoid relative links
The origin parameter must be an absolute link (starting with a /)
To be consistent and always have a leading slash (and avoid relative
links if the developer forgot to add a leading slash)
2021-12-20 11:39:03 +01:00
Yannick TivisseandVictor Feyens 18952cdc76 [IMP] *: Convert single create method into multi
Taskid: 2703085
Part-of: odoo/odoo#80824
Co-authored-by: Victor Feyens <vfe@odoo.com>
2021-12-14 19:13:18 +00:00
Kevin Baptiste 7dc796f8d6 [FIX] website_forum: make link buttons work again
Since #45352, the dropdown actions "Edit" / "Close" / "Delete" were no
longer working; clicking on them was not submitting the form like it was
supposed to.

closes odoo/odoo#81156

Taskid: 2499623
X-original-commit: 2e7cb0e19a81598f3e52660753b925b3f2216a6d
Signed-off-by: Kevin Baptiste <kba@odoo.com>
2021-12-09 16:14:47 +00:00
Martin Trigaux d99cfd9416 [I18N] *: export saas-15.1 source terms
closes odoo/odoo#80964

X-original-commit: 0663892a34896980008eb0de69aeb58019a67e89
Related: odoo/enterprise#22759
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-12-07 13:48:53 +00:00
ijas ahammed a85f02a31f [IMP] website_{forum,slides_forum}: improve forum and forum post list views
This commit improves forums and forum posts list views. The changes are listed
below.

Forums list view:
  - optional hidden `total_answers` and `total_favorites`
  - added `slide_channel_id` and `visibility` fields
  - added sum for `total_posts` and `total_views`

Forum posts list view:
  - added badge widget on `state` field for better decoration
  - added sum for `views` and `child_count`, updated their label to
    '# Views' and '# Answers'
  - removed `favourite_count` field
  - moved `website_id` field at last as optional hidden
  - added title for the demo data in which title was missing.

TaskID-2607467

Part-of: odoo/odoo#76930
2021-11-23 09:39:35 +00:00
Hardik Prajapati 3d2fe2f2d8 [FIX] website_forum: fix forum back button url from backend
Currently, when user open the question from helpdesk ticket and
user clicks on the back button of the forum page,
it redirects the user to the app switcher. It happens because the
back button contains the homepage URL as httprequest.referrer
does not support the fragment url with hash(#).

so this commit fixes the issue by binding the onclick event on the
back button so clicking on the back button redirects the user
to the helpdesk ticket.

task-2602604

closes odoo/odoo#77458

Signed-off-by: Laurent Stukkens (ltu) <ltu@odoo.com>
2021-11-04 11:07:16 +00:00
Thomas Josse 91db19c187 [IMP] mass_mailing_slides / survey / website_forum / website_[sale_]slides_* : enhancing the views in eLearning
Purpose
=======
This commit is enhancing the website_slides module.

Specifications
==============
It changes placeholders for certain fields, it changes helpers in some
of the views.

It updates some of the main views of the menus and corrects wordings
inside of them.

It activates the Graph and Pivot views for the reporting of
Courses, Reviews and Quizzes.

It cleans up some of the measures inside of the Pivot and Graph views
of each menus where it is available.

It also merges 2 models: slide.slide.link and slide.slide.resource into
slide.slide.resource with a type Selection field.
This is done in order to create a single table for the additional
resources of a Content.

It also improves the front-end of the module with minor changes.
It fixes the problem of long names inside of breadcrumbs.
It also adds a message when there is no leaderboard in /profile/users.

task-2597345

See odoo/enterprise#20480
See odoo/upgrade#2784

Part-of: odoo/odoo#75646
2021-10-22 11:09:16 +00:00
Romain Derie 7d8a8ddea0 [IMP] website(_forum/_profile): remove _get_http_domain method
Before Odoo saas-14.4, one should call `_get_http_domain()` on website to get
its domain. Indeed, that method was in charge of cleaning that domain, as it
was done with commit [1].

Since Odoo saas-14.4, that cleaning is automatically performed on domain before
saving it into database, thanks to commit [2].

Thus, we can now remove the `_get_http_domain()` and use directly the domain as
it is considered clean.

Note that migrated databases coming from version older than Odoo saas-14.4
could still have an incorrect domain (trailing slash, no scheme..).
This will be handled during migration with [3].

[1]: https://github.com/odoo/odoo/commit/3ad775aab717b395a5d11527aeb3596af66afa99
[2]: https://github.com/odoo/odoo/commit/042c95b0219bb0aa13e73385e092fa76ff1a1b0a
[3]: https://github.com/odoo/upgrade/pull/2951

closes odoo/odoo#78766

Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2021-10-21 15:47:22 +00:00
Dhwani Patelandjpr-odoo 4aacc0edb8 [IMP] website_forum: rename the title of question page
This commit changes the title of new question page from 'new_question' to
'New Post'.

task-2167561

closes odoo/odoo#45352

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Co-authored-by: jpr-odoo <jpr@openerp.com>
2021-10-14 12:26:09 +00:00
Dhwani Patelandjpr-odoo d69c49349b [IMP] website_forum: improve the flagging question UX
Now, once the question is flagged, we show two options for it: 'Validate' and
'Mark as Offensive'.
So, one can directly validate (or not) directly from the question page.

task-2167561

Part-of: odoo/odoo#45352
Co-authored-by: jpr-odoo <jpr@openerp.com>
2021-10-14 12:26:09 +00:00
Dhwani Patelandjpr-odoo 7223f0e720 [IMP] website_forum: tooltip based on condition
This commit display the tooltip "only one answer per question is allowed" only
for question-answer type of forum.

task-2167561

Part-of: odoo/odoo#45352
Co-authored-by: jpr-odoo <jpr@openerp.com>
2021-10-14 12:26:09 +00:00
Fabio Barbero 2d65d022d9 [IMP] website_slides: change confirmation messages for email
Purpose
=======
Clean up messages related to email verification.

Specification
=============
Rephrase messages, add confirmation of email sent and let user change
email.
Do not show "Validation Email sent" if the current user changed their
email address.

PR: https://github.com/odoo/odoo/pull/77617
Task-2647065

closes odoo/odoo#77617

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-10-12 11:44:40 +00:00
Jeremy Kersten 96f4b014bb [FIX] website_forum: fix tb on reflag of a post
Before this commit, a traceback was raise:
Cannot read properties of undefined (reading 'displayNotification')

Now, we correctly use self instead of this.

task-2657621

closes odoo/odoo#77360

X-original-commit: ab65d077b7b4ec04155401902eb65418b4d2f415
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-09-29 15:56:21 +00:00
Stefan Rijnhart 84cb5433ab [FIX] website_forum: prevent error when creating multi
closes odoo/odoo#76496

X-original-commit: f827177ef434eeb14e1214ff8948ee807d90de3a
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-09-18 14:03:46 +00:00
Martin Trigaux ef8ad324b0 [I18N] *: export 15.0 source terms
closes odoo/odoo#76542

X-original-commit: 63e6807437295519a0f4705fb88644d6d557ca3a
Related: odoo/enterprise#20882
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-09-16 07:17:40 +00:00
Mathieu Duckerts-Antoine 7545913020 [REF] *: graph archs cleaning
We clean various graph archs taking into consideration that:
 - the default type of a graph is "bar".
 - a bar chart is by default stacked.
 - the field attributes type="row" and type="col" does not make sense for
   a graph view (since its implementation was separated from the pivot
   implementation a long time ago))
 - the boolean attributes should now take 1 or 0 as value (but the other
   values are accepted for retrocompatibility).

Part-of: odoo/odoo#76065
2021-09-07 15:50:14 +00:00
Benoit Socias 9f9c4bb7e4 [IMP] website(_*): replace search callbacks by a mixin
Before this commit the `_search_get_detail` result contained callback
functions to handle special behavior during fetching and rendering.

After this commit a `website.searchable.mixin` is introduced that must
be inherited by models that participate in website-based searches.
Custom behavior previously achieved with callbacks is now achieved by
overloading methods of this mixin.

task-2379555
https://github.com/odoo/odoo/pull/65871

Part-of: odoo/odoo#65871
2021-09-03 06:59:33 +00:00
Benoit Socias 7559626c54 [IMP] website, *: make a generic search bar snippet available
(*: website_blog, website_event, website_forum, website_sale,
website_slides)

Before this commit the search bar was specific to products.

After this commit a generic search bar is available as a general feature
of website which can be configured to inspect specific models.
The snippet is used to replace the old search bar in blog, courses,
event, forum, page and shop.
The search results of these pages and the autocomplete of the search bar
run through the same search mechanism.
A new hybrid results page has also been created as a target of a search
on "Everything".

In each involved module, `website._search_get_details()` is implemented
to return search metadata for every model related to the `search_type`
parameter.
Search metadata for a single model is returned by `_search_get_detail()`
on that specific model.

The autocomplete runs through the additional
`website._search_render_results()` pre-rendering step that prepares the
data to fit in the autocomplete template.

task-2379555
https://github.com/odoo/odoo/pull/65871

Part-of: odoo/odoo#65871
2021-09-03 06:59:33 +00:00
Martin Trigaux 15692f3948 [IMP] *: merge ir.model.data helpers
remove _get_id and _get_object_reference that were one liner to
_xmlid_lookup
2021-08-10 13:49:05 +02:00
Martin Trigaux c7bac3dee0 [IMP] *: make ir.model.data helper private
No reason to interfact with them directly in RPC
2021-08-10 13:49:04 +02:00
Romain Derie f253018002 [FIX] website_forum: add missing ID which lead to broken JS
That ID was removed with c8c8eb3d56, but the JS code is expecting to find
this ID inside the DOM to increment the flag counter.

Courtesy of @dwa-odoo
Spotted while working on task-2167561

closes odoo/odoo#74819

X-original-commit: 2e3f78569e2bb2e0cd2ad9271b1877a43a8c4abb
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Signed-off-by: Romain Derie <rdeodoo@users.noreply.github.com>
2021-08-06 14:01:34 +00:00
Gorash 7df343dd1b [IMP] base: QWeb _render return Markup unicode instead of utf8 bytes
In order to limit encoding decoding, the _render method returns a
unicode string in the markup safe object instead of a MarkupSafeBytes

closes odoo/odoo#68299

Related: odoo/upgrade#2454
Related: odoo/enterprise#17270
Signed-off-by: Antony Lesuisse (al) <al@openerp.com>
2021-08-03 16:20:22 +00:00
15aae7ea34 [IMP] website: organize links in menu & footer on configurator apply
The configurator takes care of the organization of the links to the different
pages. Some links are put in the menu and some are put in the footer. The order
is predefined. If too many links are present in the menu then a sub-menu 'Company'
is created and some links are put in it. For the 'News' and 'Succes Stories' features
a website specific blog is created.

Links have the following order in the menu and are present only if their corresponding
website.configurator.feature has been selected in the configurator excepted for the 'Home'
and 'Contact us' links which are default links:
- 'Home'
- 'Shop'
- 'Event'
- 'Courses'
- 'Services'
- 'Pricing'
- 'Company': if more than 8 links in menu and more than 1 item in this submenu
             otherwise the three following links are in the top menu.
  - 'News'
  - 'Success Stories'
  - 'About us'
- 'Appointment'
- 'Contact us'

Links in footer:
- 'Privacy Policy'
- 'Help': if website_helpdesk installed. This is not a website.configurator.feature.
- 'Forum'

Community: https://github.com/odoo/odoo/pull/71993
Enterprise: https://github.com/odoo/enterprise/pull/18930

task-2518565

Co-authored-by: Sébastien Mottet (oms) <oms@odoo.com>
Co-authored-by: Romain Derie <rde@odoo.com>
Co-authored-by: Jeremy Kersten <jke@odoo.com>
2021-07-30 13:51:33 +00:00
Arthur Detroux (ard) 3a23891fa1 [IMP] website_forum: change welcome message sanitization
This commit changes the sanitization of the welcome_message to be on par
with other modules that take advantage of web_editor.

Part of https://github.com/odoo/odoo/pull/67140
task-2381049
2021-07-30 12:52:30 +00:00
Dhruv Patelandqsm-odoo a7d5bb1035 [FIX] website_forum: restore karma guidelines link in notifications
The link was added as text instead of HTML since the notification/t-raw
refactoring.

task-2601633

closes odoo/odoo#74276

X-original-commit: 3b5b460f20295983582946bfd841211884456cc5
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
Co-authored-by: qsm-odoo <qsm@odoo.com>
2021-07-27 08:30:51 +00:00
Xavier-Do 288595f558 [FIX] *: add explicit license to all manifest
The license is missing in most enterprise manifest so
the decision was taken to make it explicit in all cases.
When not defined, a warning will be triggered starting from
14.0 when falling back on the default LGPL-3.

closes odoo/odoo#74245

Related: odoo/design-themes#48
Related: odoo/enterprise#19862
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2021-07-26 13:09:57 +00:00
Samuel Degueldre 57ba855b66 [REF] web, website, website_forum, *: remove crash manager from frontend
*: test_website

In a previous commit, the new services and environment were made
available in the frontend. This now allows errors to be handled by the
new error service, and makes the legacy crash manager redundant. This
commit removes it.

Part of #72675

Related: odoo/enterprise#19258
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2021-07-14 07:34:28 +00:00
Martin Trigaux 6758868731 [I18N] *: export saas-14.4 source terms
Without demo data

closes odoo/odoo#73560

X-original-commit: 802e46541117573e028b711ea33dad9df9075a39
Related: odoo/enterprise#19602
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-07-12 10:57:37 +00:00
Jeremy Kersten 478068c829 [IMP] *: always use Odoo Response
This branch adds request.redirect on all requests.
In case of a front end request, we do an url_for to the location.

We removed redirect_with_hash that was only for retro compatibility

local_redirect has been renamed to redirect_query, and param keep_hash has been
removed and moved.

Default code for redirect is 303 now instead of 302.

Now redirect and redirect_query make local redirect by default, you need to
pass local=False to make external redirect.

All werkeug.utils.redirect has been replaced by request.redirect.

Http.redirect now use an http.Response type, and it become easy to add an
override like 'set_cookies' e.g.

Dispatch of a website.page return an http.response too, so we first need to
check if it is a cached version before to check if it is an Odoo Response.

Migrate your code:

http.redirect -> request.redirect(location, code, local)
http.local_redirect -> request.redirect_query(location, query, code, local)
http.redirect_with_hash -> request.redirect

Courtesy of odony for help and review ;)

closes odoo/odoo#72599

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-08 07:00:06 +00:00
Fabien Pinckaers a65f6a5872 [IMP] various: clean most urls to odoo's website
Pages changed on odoo.com so let's update links.

closes odoo/odoo#72707

Related: odoo/enterprise#19239
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-06-24 15:14:29 +00:00
Leonardo Pavan Rocha c53724ebc3 [IMP] *: adds generic user avatar
Description of the issue/feature this PR addresses:
It is currently quite difficult to differentiate users. Most of the time, people
don't take the time to upload an actual avatar so everybody looks the same. This
PR generates a custom avatar with the users initials and random color to
differentiate them. For res.users, res.partner and hr.employee, image fields now
hold the binary image and avatar are used to show the image or svg.

Current behavior before PR:
Avatar had only random colors and was being saved in database, being inefficient

Desired behavior after PR is merged:
A new mixin defines image fields and in case no image is set, it generates an
SVG image with the user's initials and random color.

closes odoo/odoo#69819

Task: 2404630
Related: odoo/enterprise#18199
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2021-06-01 14:36:23 +00:00
Younn Olivier fa2ffd6976 [FIX] website_forum: fix image size in posts
Before this commit, big images would overflow from posts containers.

task-2469516
Part of https://github.com/odoo/odoo/pull/70235

closes odoo/odoo#71444

X-original-commit: 17f736c19ae67acbaa16d2f8452e9ccb58dd3ef3
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2021-05-28 16:48:37 +00:00
Younn Olivier 8299191d92 [FIX] website_forum: fix image display in a forum post
The container size of a forum post was not correct when an image was
displayed with right or left alignment.

The css property clear was added at the end of the posts so that
floating elements do not float over the next section.

task-2469516
Part of https://github.com/odoo/odoo/pull/70235

X-original-commit: 0c58901cbef8b1d1808f673b7b34d1de93c2fd6d
2021-05-28 16:48:35 +00:00
Sébastien Mottet (oms) 7923ec5898 [FIX] website_forum: add data-parent to fix faq accordion
website_forum.faq_accordion is not rendered by a drag'n'drop
and data-parent is therefore not set on tabpanels by onBuilt.

closes odoo/odoo#70978

X-original-commit: d4e046209914a7be3aed976a1fc3a74020843309
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-05-18 12:42:30 +00:00
Sébastien Geelen (sge) fa2e0a6349 [IMP] web_editor: Add rel="ugc" to some user generated links
See odoo task : https://www.odoo.com/web#action=333&active_id=1695&cids=1&id=2319575&menu_id=4720&model=project.task&view_type=form

closes odoo/odoo#70614

Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
2021-05-17 08:58:50 +00:00
Martin Trigaux 41d8b8cf68 [I18N] *: export saas-14.3 source terms
closes odoo/odoo#70673

X-original-commit: bcb9ff784e44462384b0a43a0a23eed7a1111bc5
Related: odoo/enterprise#18269
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-05-11 12:28:28 +00:00
Xavier Morel 25aeaecf85 [FIX] website_forum: de-raw-ify
`post_content` is rendered template content, so should be makup-safe.

`result_msg` is qweb template content, so it's markup-safe.
2021-04-29 05:34:20 +00:00
Xavier Morel 996cb85c27 [FIX] *: mass replace known t-raws by t-out
* QWeb bodies should be markup-safe so `0` should always be
  markup-safe.
* `head` is qweb-rendered so the same.
* The `json` pseudo-module in qweb templates is `json.scriptsafe`,
  which should be markup-safe.
2021-04-29 05:34:20 +00:00
Xavier Morel 01875541b1 [CHG] core, web: deprecate t-raw
Add a big fat warning when the qweb compiler finds a `t-raw`.

`t-esc` should now be used everywhere, the use-case for `t-raw` should
be handled by converting the corresponding values to `Markup`
objects. Even though it's convenient, this constructor *should never
be made available in the qweb rendering context* (maybe that should be
checked for explicitely?).

Replace `werkzeug.escape` by `markupsafe.escape` in
`odoo.tools.html_escape`, this means the output of `html_escape` is
markup-safe.

Updated qweb to work correctly with escaping and `Markup`, amongst
other things QWeb bodies should be markup-safe internally (so that a
`t-set` value can be fed into a `t-esc`). See at the bottom for the
attributes handling as it's a bit complicated.

`to_text` needed updating: `markupsafe.Markup` is a subclass of `str`,
but `str` is not a passthrough for strings. So `Markup` instances
going through would be converted to normal `str`, losing their safety
flag. Since qweb internally uses `to_text` on pretty much
everything (in order to handle None / False), this would then cause
almost every `Markup` to get mistakenly double-escaped.

Also mark a bunch of APIs as markup-safe by default

* html_sanitize output.
* HTML fields content, sanitization is applied on intake (so stripped
  by the trip through the database) and if the field is unsanitised
  the injection is very much intentional, probably. Note: this
  includes automatically decoding bytes as a number of default values
  & computes yield bytes, which Markup will happily accept... by
  repr-ing them which is useless. This is hard to notice without `-b`.
* Script-safe json, it's rather the point (though it uses a
  non-standard escaping scheme).
* Note that `nl2br`, kinda: it should work correctly whether or not
  the input is markup-safe, this means we should not need to escape
  values fed to `nl2br`, but it doesn't hurt either.

Update some qweb field serialisations to mark their output as
markup-safe when necessary (e.g. monetary, barcode,
contact). Otherwise either using proper escaping internally or doing
nothing should do the trick.

Also update qweb to return markup-safe bytes: we want qweb to return
markup-safe contents as a common use-case is to render something with
one template, and inject its content in an other one (with Python code
inbetween, as `t-call` works a bit differently and does not go through
the external rendering interface).

However qweb returns `bytes` while `Markup` extends `str`. After a
quick experiment with changing qweb rendering to return `str` (rather
unmitigated failure I fear), it looks like the safest tack is to add a
somewhat similar bytes-based type, which decodes to a `Markup` but
keeps to bytes semantics.

For debugging and convenience reasons, MarkupSafeBytes does *not*
stringify and raises an error instead (`__repr__` works fine). This is
to avoid implicit stringifications which do the wrong thing (namely
create a string `"b'foo'"`).

Also add some configuration around BytesWarning (which still has to be
enabled at the interpreter level via `-b`, there's no way to enable it
programmatically smh), and monkeypatch `showwarning` to show warning
tracebacks, as it's common for warnings to be triggered in the bowels
of the application, and hard to relate to business logic without the
complete traceback.

`t-out`
=======

`t-esc` is a bit confusing for the new behaviour of "maybe escape
maybe not", so add a `t-out` alias with the same behaviour.

Unlike `t-raw`, `t-esc` is only soft-deprecated for now: there are
thousands of instances, so editing all the templates is not
great. Eventually we'll add a `ci/style` to prevent addition of new
ones, and eventually we might do a bulk-replace and hard-deprecate.

Attributes handling
===================

There are a few issues with respect to attributes. The first issue is
that markup-safe content is not necessarily attributes-safe
e.g. markup-safe content can contain unescaped `<` or double-quotes
while attributes can not. So we must forcefully escape the input, even
if it's supposedly markup-safe already.

This causes a problem for script-safe JSON: it's markup-safe but
really does its own thing. So instead of escaping it up-front and
wrapping it in Markup, make script-safe JSON its own type which
applies JSON-escaping *during the `__html__` call.

This way if a script-safe JSON object goes through `markupsafe.escape`
we'll apply script-safe escaping, otherwise it'll be treated as a
regular strings and eventually escaped the normal way.

A second issue was the processing of format-valued
attributes (`t-attf`): literal segments should always be markup-safe,
while non-literal may or may not be. This turns out to be an issue if
the non-literal segment *is* markup-safe: in that case when the
literal and non-literal segments get concatenated the literal segments
will get escaped, then attributes serialization will escape
them *again* leading to doubly-escaped content in attributes.

The most visible instance of this was the `snippet_options` template,
specifically:

    <t t-set="so_content_addition_selector" t-translation="off">blockquote, ...</t>
    <div id="so_content_addition"
        t-att-data-selector="so_content_addition_selector"
        t-attf-data-drop-near="p, h1, h2, h3, .row > div > img, #{so_content_addition_selector}"
        data-drop-in=".content, nav"/>

Here `so_content_addition_selector` is a qweb body therefore
markup-safe, When concatenated with the literal part of
`t-atff-data-drop-near` it would cause the HTML-escaping of that
yielding a new Markup object. Normal attributes processing would then
strip the markup flag (using `str()`) and escape it again, leading to
doubly-escaped literals.

The original hack around was to unescape() `Markup` content before
stringifying it and escaping it again, in the attribute serialization
method (`_append_attributes`).

That's pretty disgusting, after some more consideration & testing it
looks like a much better and safer fix is to ensure the
expression (non-literal) segments of format strings always result in
`str`, never `Markup`, which is easy enough: just all `str()` on the
output of strexpr. We could also have concatenated all the bits using
`''.join` instead of repeated concatenation (`+`).

Also add a check on the type of the format string for safety, I think
it should always be a proper str and the bytes thing is only when
running in py2 (where lxml uses bytestrings as a space optimization
for ascii-only values) but it should not hurt too much to perform a
single typecheck assertion on the value... instead of performing one
per literal segment.

Note: we may need to implement unescape anyway, because it's still
possible to get double-escaping with the current scheme: given an
explicitly escape-ed `foo` and `t-att-foo="foo"`, `foo` will be
re-escaped.

fixup! [CHG] core, web: deprecate t-raw
2021-04-29 05:34:19 +00:00
Nicolas Bayet da435ceff1 [FIX] web_editor: update toolbar
closes odoo/odoo#69194

X-original-commit: 82072abe8f22a2326c32905c7d8b827aebadb4bb
Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
2021-04-13 15:46:28 +00:00
Antoine Guenet 82ba0ce081 [REF] web_editor, website_forum: remove unused wysiwyg options
Some instance options of Summernote remained in the code after replacing
Summernote with Odoo-Editor. This removes them as they effectively did
nothing.
2021-04-02 09:43:39 +00:00
740168ce8d [REF] web_editor, website_*, mass_mailing: adapt to Odoo Editor
Co-authored-by: David Monjoie <dmo@odoo.com>
Co-authored-by: Antoine Guenet <age@odoo.com>
Co-authored-by: Nicolas Bayet <nby@odoo.com>
Co-authored-by: Sébastien Geelen <sge@odoo.com>
Co-authored-by: Emilien Durieu <edu@odoo.com>
2021-04-01 16:01:06 +00:00
27166ff9df [REM] web_editor, website: remove Summernote wysiwyg rte library
Co-authored-by: David Monjoie <dmo@odoo.com>
Co-authored-by: Antoine Guenet <age@odoo.com>
Co-authored-by: Nicolas Bayet <nby@odoo.com>
Co-authored-by: Sébastien Geelen <sge@odoo.com>
Co-authored-by: Emilien Durieu <edu@odoo.com>
2021-04-01 12:49:47 +00:00
Julien MougenotandSimon Genin 03641610c2 [REF] *: convert all modules to new asset system
Conversion of all modules to the new manifest assets declaration.

Part of task: 2352566

Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Simon Genin <ges@odoo.com>
2021-03-31 13:57:18 +02:00
Nicolas Lempereur 8a5d22826c [FIX] website_forum: show normal image modal in forum
In #67893 the image icon was removed, but it contradicts the interface
and made a feature that was working for employee less available.

Since saas-12.3, we always use the full media dialog when showing the
editor on the forum so we could not add an image with the image icon if
were not an employee.

Before saas-12.3, the original summernote image dialog was shown for
everyone but website editor that saw the full media dialog (beecause we
are using the same editor to do both things).

With this change, we always have the original dialog in the forum
message editor thanks to a new option "disableFullMediaDialog".

opw-2470720

closes odoo/odoo#68166

X-original-commit: c026c360fb77ce43f47f7645f48e37bced988b85
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2021-03-19 18:30:00 +00:00
Oussama MESSAOUDI afce9559ac [FIX] website_forum, *: refit the forum biography popover
*: web

task-2276974

closes odoo/odoo#67902

X-original-commit: 1207b99b73f5906209499cb2935b750faecd756d
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2021-03-15 19:20:48 +00:00
Martin Trigaux d2043167af [I18N] website_forum: avoid conflict with "All" of web
Cf odoo/odoo#61641 there is a conflict with the "All" string
from website_forum and the one from web
This is a workaround to make the term from website_forum a openerp-web
translation and avoid an untranslated "All" on the runbot but the real
patch should be done at the framework level

X-original-commit: 0d8bb4463012a4414e0d3373a4b39a9643cdf595
2021-03-01 10:31:34 +01:00