website{_*}: website, website_blog, website_event, website_forum,
website_sale, website_slides
Since the generic search bar was introduced in [1] all text fields were
truncated in search results.
This caused problems for long URLs which were truncated as well, and
therefore could become invalid.
After this commit URL fields specify `'truncate': False` in their search
detail metadata, which informs the rendering to skip the text truncation
step for that field.
Also added previously missing controller-level tests of the
autocompletion.
Steps to reproduce:
- start odoo with website_forum and demo data
- go to the Help forum
- search for "configure" in the Help forum
- click on the auto-complete suggestion
- => redirected to a 404 page because the URL was shortened
To test the fix on other models, use a long enough name that causes the
problem. E.g.: "This product has such a long name its URL would have
been truncated without the fix contained in this branch".
Note that the problem did not occur on blogs because the URL does not
contain the name, but the same fix was applied for consistency.
[1]: https://github.com/odoo/odoo/commit/7559626c54e34b41e1549e28276a650accec6986
task-2727788
closesodoo/odoo#82621
X-original-commit: 045f741be35e62f5e3a636490c6c1d475b5d78eb
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
The enterprise module website_helpdesk_forum changes the demo data
karma_answer value to 0 for the default Help forum thus breaks the tour.
odoo/enterprise#19870odoo/upgrade#2681closesodoo/odoo#74353
Taskid: 2499623
Signed-off-by: Laurent Stukkens (ltu) <ltu@odoo.com>
The origin parameter must be an absolute link (starting with a /)
To be consistent and always have a leading slash (and avoid relative
links if the developer forgot to add a leading slash)
Since #45352, the dropdown actions "Edit" / "Close" / "Delete" were no
longer working; clicking on them was not submitting the form like it was
supposed to.
closesodoo/odoo#81156
Taskid: 2499623
X-original-commit: 2e7cb0e19a81598f3e52660753b925b3f2216a6d
Signed-off-by: Kevin Baptiste <kba@odoo.com>
This commit improves forums and forum posts list views. The changes are listed
below.
Forums list view:
- optional hidden `total_answers` and `total_favorites`
- added `slide_channel_id` and `visibility` fields
- added sum for `total_posts` and `total_views`
Forum posts list view:
- added badge widget on `state` field for better decoration
- added sum for `views` and `child_count`, updated their label to
'# Views' and '# Answers'
- removed `favourite_count` field
- moved `website_id` field at last as optional hidden
- added title for the demo data in which title was missing.
TaskID-2607467
Part-of: odoo/odoo#76930
Currently, when user open the question from helpdesk ticket and
user clicks on the back button of the forum page,
it redirects the user to the app switcher. It happens because the
back button contains the homepage URL as httprequest.referrer
does not support the fragment url with hash(#).
so this commit fixes the issue by binding the onclick event on the
back button so clicking on the back button redirects the user
to the helpdesk ticket.
task-2602604
closesodoo/odoo#77458
Signed-off-by: Laurent Stukkens (ltu) <ltu@odoo.com>
Purpose
=======
This commit is enhancing the website_slides module.
Specifications
==============
It changes placeholders for certain fields, it changes helpers in some
of the views.
It updates some of the main views of the menus and corrects wordings
inside of them.
It activates the Graph and Pivot views for the reporting of
Courses, Reviews and Quizzes.
It cleans up some of the measures inside of the Pivot and Graph views
of each menus where it is available.
It also merges 2 models: slide.slide.link and slide.slide.resource into
slide.slide.resource with a type Selection field.
This is done in order to create a single table for the additional
resources of a Content.
It also improves the front-end of the module with minor changes.
It fixes the problem of long names inside of breadcrumbs.
It also adds a message when there is no leaderboard in /profile/users.
task-2597345
See odoo/enterprise#20480
See odoo/upgrade#2784
Part-of: odoo/odoo#75646
Before Odoo saas-14.4, one should call `_get_http_domain()` on website to get
its domain. Indeed, that method was in charge of cleaning that domain, as it
was done with commit [1].
Since Odoo saas-14.4, that cleaning is automatically performed on domain before
saving it into database, thanks to commit [2].
Thus, we can now remove the `_get_http_domain()` and use directly the domain as
it is considered clean.
Note that migrated databases coming from version older than Odoo saas-14.4
could still have an incorrect domain (trailing slash, no scheme..).
This will be handled during migration with [3].
[1]: https://github.com/odoo/odoo/commit/3ad775aab717b395a5d11527aeb3596af66afa99
[2]: https://github.com/odoo/odoo/commit/042c95b0219bb0aa13e73385e092fa76ff1a1b0a
[3]: https://github.com/odoo/upgrade/pull/2951closesodoo/odoo#78766
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
This commit changes the title of new question page from 'new_question' to
'New Post'.
task-2167561
closesodoo/odoo#45352
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Co-authored-by: jpr-odoo <jpr@openerp.com>
Now, once the question is flagged, we show two options for it: 'Validate' and
'Mark as Offensive'.
So, one can directly validate (or not) directly from the question page.
task-2167561
Part-of: odoo/odoo#45352
Co-authored-by: jpr-odoo <jpr@openerp.com>
This commit display the tooltip "only one answer per question is allowed" only
for question-answer type of forum.
task-2167561
Part-of: odoo/odoo#45352
Co-authored-by: jpr-odoo <jpr@openerp.com>
Purpose
=======
Clean up messages related to email verification.
Specification
=============
Rephrase messages, add confirmation of email sent and let user change
email.
Do not show "Validation Email sent" if the current user changed their
email address.
PR: https://github.com/odoo/odoo/pull/77617
Task-2647065
closesodoo/odoo#77617
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Before this commit, a traceback was raise:
Cannot read properties of undefined (reading 'displayNotification')
Now, we correctly use self instead of this.
task-2657621
closesodoo/odoo#77360
X-original-commit: ab65d077b7b4ec04155401902eb65418b4d2f415
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
We clean various graph archs taking into consideration that:
- the default type of a graph is "bar".
- a bar chart is by default stacked.
- the field attributes type="row" and type="col" does not make sense for
a graph view (since its implementation was separated from the pivot
implementation a long time ago))
- the boolean attributes should now take 1 or 0 as value (but the other
values are accepted for retrocompatibility).
Part-of: odoo/odoo#76065
Before this commit the `_search_get_detail` result contained callback
functions to handle special behavior during fetching and rendering.
After this commit a `website.searchable.mixin` is introduced that must
be inherited by models that participate in website-based searches.
Custom behavior previously achieved with callbacks is now achieved by
overloading methods of this mixin.
task-2379555
https://github.com/odoo/odoo/pull/65871
Part-of: odoo/odoo#65871
(*: website_blog, website_event, website_forum, website_sale,
website_slides)
Before this commit the search bar was specific to products.
After this commit a generic search bar is available as a general feature
of website which can be configured to inspect specific models.
The snippet is used to replace the old search bar in blog, courses,
event, forum, page and shop.
The search results of these pages and the autocomplete of the search bar
run through the same search mechanism.
A new hybrid results page has also been created as a target of a search
on "Everything".
In each involved module, `website._search_get_details()` is implemented
to return search metadata for every model related to the `search_type`
parameter.
Search metadata for a single model is returned by `_search_get_detail()`
on that specific model.
The autocomplete runs through the additional
`website._search_render_results()` pre-rendering step that prepares the
data to fit in the autocomplete template.
task-2379555
https://github.com/odoo/odoo/pull/65871
Part-of: odoo/odoo#65871
That ID was removed with c8c8eb3d56, but the JS code is expecting to find
this ID inside the DOM to increment the flag counter.
Courtesy of @dwa-odoo
Spotted while working on task-2167561
closesodoo/odoo#74819
X-original-commit: 2e3f78569e2bb2e0cd2ad9271b1877a43a8c4abb
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Signed-off-by: Romain Derie <rdeodoo@users.noreply.github.com>
In order to limit encoding decoding, the _render method returns a
unicode string in the markup safe object instead of a MarkupSafeBytes
closesodoo/odoo#68299
Related: odoo/upgrade#2454
Related: odoo/enterprise#17270
Signed-off-by: Antony Lesuisse (al) <al@openerp.com>
The configurator takes care of the organization of the links to the different
pages. Some links are put in the menu and some are put in the footer. The order
is predefined. If too many links are present in the menu then a sub-menu 'Company'
is created and some links are put in it. For the 'News' and 'Succes Stories' features
a website specific blog is created.
Links have the following order in the menu and are present only if their corresponding
website.configurator.feature has been selected in the configurator excepted for the 'Home'
and 'Contact us' links which are default links:
- 'Home'
- 'Shop'
- 'Event'
- 'Courses'
- 'Services'
- 'Pricing'
- 'Company': if more than 8 links in menu and more than 1 item in this submenu
otherwise the three following links are in the top menu.
- 'News'
- 'Success Stories'
- 'About us'
- 'Appointment'
- 'Contact us'
Links in footer:
- 'Privacy Policy'
- 'Help': if website_helpdesk installed. This is not a website.configurator.feature.
- 'Forum'
Community: https://github.com/odoo/odoo/pull/71993
Enterprise: https://github.com/odoo/enterprise/pull/18930
task-2518565
Co-authored-by: Sébastien Mottet (oms) <oms@odoo.com>
Co-authored-by: Romain Derie <rde@odoo.com>
Co-authored-by: Jeremy Kersten <jke@odoo.com>
This commit changes the sanitization of the welcome_message to be on par
with other modules that take advantage of web_editor.
Part of https://github.com/odoo/odoo/pull/67140
task-2381049
The link was added as text instead of HTML since the notification/t-raw
refactoring.
task-2601633
closesodoo/odoo#74276
X-original-commit: 3b5b460f20295983582946bfd841211884456cc5
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
Co-authored-by: qsm-odoo <qsm@odoo.com>
The license is missing in most enterprise manifest so
the decision was taken to make it explicit in all cases.
When not defined, a warning will be triggered starting from
14.0 when falling back on the default LGPL-3.
closesodoo/odoo#74245
Related: odoo/design-themes#48
Related: odoo/enterprise#19862
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
*: test_website
In a previous commit, the new services and environment were made
available in the frontend. This now allows errors to be handled by the
new error service, and makes the legacy crash manager redundant. This
commit removes it.
Part of #72675
Related: odoo/enterprise#19258
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
This branch adds request.redirect on all requests.
In case of a front end request, we do an url_for to the location.
We removed redirect_with_hash that was only for retro compatibility
local_redirect has been renamed to redirect_query, and param keep_hash has been
removed and moved.
Default code for redirect is 303 now instead of 302.
Now redirect and redirect_query make local redirect by default, you need to
pass local=False to make external redirect.
All werkeug.utils.redirect has been replaced by request.redirect.
Http.redirect now use an http.Response type, and it become easy to add an
override like 'set_cookies' e.g.
Dispatch of a website.page return an http.response too, so we first need to
check if it is a cached version before to check if it is an Odoo Response.
Migrate your code:
http.redirect -> request.redirect(location, code, local)
http.local_redirect -> request.redirect_query(location, query, code, local)
http.redirect_with_hash -> request.redirect
Courtesy of odony for help and review ;)
closesodoo/odoo#72599
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
Description of the issue/feature this PR addresses:
It is currently quite difficult to differentiate users. Most of the time, people
don't take the time to upload an actual avatar so everybody looks the same. This
PR generates a custom avatar with the users initials and random color to
differentiate them. For res.users, res.partner and hr.employee, image fields now
hold the binary image and avatar are used to show the image or svg.
Current behavior before PR:
Avatar had only random colors and was being saved in database, being inefficient
Desired behavior after PR is merged:
A new mixin defines image fields and in case no image is set, it generates an
SVG image with the user's initials and random color.
closesodoo/odoo#69819
Task: 2404630
Related: odoo/enterprise#18199
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
The container size of a forum post was not correct when an image was
displayed with right or left alignment.
The css property clear was added at the end of the posts so that
floating elements do not float over the next section.
task-2469516
Part of https://github.com/odoo/odoo/pull/70235
X-original-commit: 0c58901cbef8b1d1808f673b7b34d1de93c2fd6d
website_forum.faq_accordion is not rendered by a drag'n'drop
and data-parent is therefore not set on tabpanels by onBuilt.
closesodoo/odoo#70978
X-original-commit: d4e046209914a7be3aed976a1fc3a74020843309
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
* QWeb bodies should be markup-safe so `0` should always be
markup-safe.
* `head` is qweb-rendered so the same.
* The `json` pseudo-module in qweb templates is `json.scriptsafe`,
which should be markup-safe.
Add a big fat warning when the qweb compiler finds a `t-raw`.
`t-esc` should now be used everywhere, the use-case for `t-raw` should
be handled by converting the corresponding values to `Markup`
objects. Even though it's convenient, this constructor *should never
be made available in the qweb rendering context* (maybe that should be
checked for explicitely?).
Replace `werkzeug.escape` by `markupsafe.escape` in
`odoo.tools.html_escape`, this means the output of `html_escape` is
markup-safe.
Updated qweb to work correctly with escaping and `Markup`, amongst
other things QWeb bodies should be markup-safe internally (so that a
`t-set` value can be fed into a `t-esc`). See at the bottom for the
attributes handling as it's a bit complicated.
`to_text` needed updating: `markupsafe.Markup` is a subclass of `str`,
but `str` is not a passthrough for strings. So `Markup` instances
going through would be converted to normal `str`, losing their safety
flag. Since qweb internally uses `to_text` on pretty much
everything (in order to handle None / False), this would then cause
almost every `Markup` to get mistakenly double-escaped.
Also mark a bunch of APIs as markup-safe by default
* html_sanitize output.
* HTML fields content, sanitization is applied on intake (so stripped
by the trip through the database) and if the field is unsanitised
the injection is very much intentional, probably. Note: this
includes automatically decoding bytes as a number of default values
& computes yield bytes, which Markup will happily accept... by
repr-ing them which is useless. This is hard to notice without `-b`.
* Script-safe json, it's rather the point (though it uses a
non-standard escaping scheme).
* Note that `nl2br`, kinda: it should work correctly whether or not
the input is markup-safe, this means we should not need to escape
values fed to `nl2br`, but it doesn't hurt either.
Update some qweb field serialisations to mark their output as
markup-safe when necessary (e.g. monetary, barcode,
contact). Otherwise either using proper escaping internally or doing
nothing should do the trick.
Also update qweb to return markup-safe bytes: we want qweb to return
markup-safe contents as a common use-case is to render something with
one template, and inject its content in an other one (with Python code
inbetween, as `t-call` works a bit differently and does not go through
the external rendering interface).
However qweb returns `bytes` while `Markup` extends `str`. After a
quick experiment with changing qweb rendering to return `str` (rather
unmitigated failure I fear), it looks like the safest tack is to add a
somewhat similar bytes-based type, which decodes to a `Markup` but
keeps to bytes semantics.
For debugging and convenience reasons, MarkupSafeBytes does *not*
stringify and raises an error instead (`__repr__` works fine). This is
to avoid implicit stringifications which do the wrong thing (namely
create a string `"b'foo'"`).
Also add some configuration around BytesWarning (which still has to be
enabled at the interpreter level via `-b`, there's no way to enable it
programmatically smh), and monkeypatch `showwarning` to show warning
tracebacks, as it's common for warnings to be triggered in the bowels
of the application, and hard to relate to business logic without the
complete traceback.
`t-out`
=======
`t-esc` is a bit confusing for the new behaviour of "maybe escape
maybe not", so add a `t-out` alias with the same behaviour.
Unlike `t-raw`, `t-esc` is only soft-deprecated for now: there are
thousands of instances, so editing all the templates is not
great. Eventually we'll add a `ci/style` to prevent addition of new
ones, and eventually we might do a bulk-replace and hard-deprecate.
Attributes handling
===================
There are a few issues with respect to attributes. The first issue is
that markup-safe content is not necessarily attributes-safe
e.g. markup-safe content can contain unescaped `<` or double-quotes
while attributes can not. So we must forcefully escape the input, even
if it's supposedly markup-safe already.
This causes a problem for script-safe JSON: it's markup-safe but
really does its own thing. So instead of escaping it up-front and
wrapping it in Markup, make script-safe JSON its own type which
applies JSON-escaping *during the `__html__` call.
This way if a script-safe JSON object goes through `markupsafe.escape`
we'll apply script-safe escaping, otherwise it'll be treated as a
regular strings and eventually escaped the normal way.
A second issue was the processing of format-valued
attributes (`t-attf`): literal segments should always be markup-safe,
while non-literal may or may not be. This turns out to be an issue if
the non-literal segment *is* markup-safe: in that case when the
literal and non-literal segments get concatenated the literal segments
will get escaped, then attributes serialization will escape
them *again* leading to doubly-escaped content in attributes.
The most visible instance of this was the `snippet_options` template,
specifically:
<t t-set="so_content_addition_selector" t-translation="off">blockquote, ...</t>
<div id="so_content_addition"
t-att-data-selector="so_content_addition_selector"
t-attf-data-drop-near="p, h1, h2, h3, .row > div > img, #{so_content_addition_selector}"
data-drop-in=".content, nav"/>
Here `so_content_addition_selector` is a qweb body therefore
markup-safe, When concatenated with the literal part of
`t-atff-data-drop-near` it would cause the HTML-escaping of that
yielding a new Markup object. Normal attributes processing would then
strip the markup flag (using `str()`) and escape it again, leading to
doubly-escaped literals.
The original hack around was to unescape() `Markup` content before
stringifying it and escaping it again, in the attribute serialization
method (`_append_attributes`).
That's pretty disgusting, after some more consideration & testing it
looks like a much better and safer fix is to ensure the
expression (non-literal) segments of format strings always result in
`str`, never `Markup`, which is easy enough: just all `str()` on the
output of strexpr. We could also have concatenated all the bits using
`''.join` instead of repeated concatenation (`+`).
Also add a check on the type of the format string for safety, I think
it should always be a proper str and the bytes thing is only when
running in py2 (where lxml uses bytestrings as a space optimization
for ascii-only values) but it should not hurt too much to perform a
single typecheck assertion on the value... instead of performing one
per literal segment.
Note: we may need to implement unescape anyway, because it's still
possible to get double-escaping with the current scheme: given an
explicitly escape-ed `foo` and `t-att-foo="foo"`, `foo` will be
re-escaped.
fixup! [CHG] core, web: deprecate t-raw
Some instance options of Summernote remained in the code after replacing
Summernote with Odoo-Editor. This removes them as they effectively did
nothing.
Conversion of all modules to the new manifest assets declaration.
Part of task: 2352566
Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Simon Genin <ges@odoo.com>
In #67893 the image icon was removed, but it contradicts the interface
and made a feature that was working for employee less available.
Since saas-12.3, we always use the full media dialog when showing the
editor on the forum so we could not add an image with the image icon if
were not an employee.
Before saas-12.3, the original summernote image dialog was shown for
everyone but website editor that saw the full media dialog (beecause we
are using the same editor to do both things).
With this change, we always have the original dialog in the forum
message editor thanks to a new option "disableFullMediaDialog".
opw-2470720
closesodoo/odoo#68166
X-original-commit: c026c360fb77ce43f47f7645f48e37bced988b85
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
Cf odoo/odoo#61641 there is a conflict with the "All" string
from website_forum and the one from web
This is a workaround to make the term from website_forum a openerp-web
translation and avoid an untranslated "All" on the runbot but the real
patch should be done at the framework level
X-original-commit: 0d8bb4463012a4414e0d3373a4b39a9643cdf595