Commit Graph
43 Commits
Author SHA1 Message Date
Xavier Morel 74241b3766 [FIX] test_lint: support fstrings in sql injection checker
Those were not accounted for, leading to fstrings passing through
unflagged.

Also update the SQL checker to be stricter but smarter:

The previous version would "fail open", unknown nodes would be allowed
through hence f-strings not being flagged when they started appearing
in arg0 position, should now fail-closed, anything that's not allowed
is forbidden.

This flags a few more cases, all of which seem acceptable upon review.

However the previous version would also only resolve arg0 (in case it
had a `NAME`, to see if that resolved to an acceptable form of
query-building). The new version performs resolution during
`_check_concatenation` and should thus allow e.g. format strings to be
separate variables (though not e.g. module-level constants, yet
anyway).

In resolution, replace the ad-hoc process by astroid's built-in
`lookup` which seems to provide the same information. Slightly more in
fact, as it yields every assignment in case of e.g. conditionals, but
making use of that would require a lot more changes in the checker so
leaving the behaviour as-is for now.

It's important to *not* use `ilookup` here, because ilookup is not
"iterable" but "inferring", and we don't want values, we want
expression ASTs for analysis.

NOTE: previous improvements as well as fixes to existing code were
only implemented in 14.0, hence this being merged in 14.0 not 13.0
despite 13.0 still being supported.

closes odoo/odoo#81721

X-original-commit: 376ccf0944dae1bc53ae9c5385977c4e6b23e083
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-12-27 09:36:42 +00:00
Christophe Monniez c435e307df [IMP] test_lint: add a lint test for manifest keys
closes odoo/odoo#79977

Related: odoo/enterprise#22846
Related: odoo/upgrade#3078
Signed-off-by: Raphael Collet <rco@odoo.com>
2021-12-14 12:39:54 +00:00
Julien Castiaux 42b522bd83 [FIX] *: cleanup manifest files
*: base_address_city, base_address_extended, bus, crm, im_livechat,
   l10n_ae_pos, lunch, pos_restaurant_adyen, test_assetsbundle,
   test_converter, test_lint.

It is spelled `auto_install`, the `complexity` key is long gone, `qweb`
has been moved to `assets: {'web.assets_qweb': []}`. `js` and `css` are
long gone too, `maintainer` is redundant with `author` which is
"Odoo S.A." by default already, the `certificate` key is long gone.

closes odoo/odoo#80988

Related: odoo/enterprise#22766
Signed-off-by: Julien Castiaux <juc@odoo.com>
2021-12-08 11:17:22 +00:00
Victor Feyens ab022ec12d [FIX] *: target v15.0 documentation with doc links
X-original-commit: acc95ec204baa1dddbe292c379a1768fe1deccbf
Part-of: odoo/odoo#77923
2021-10-07 17:59:52 +00:00
Moises Lopez - https://www.vauxoo.com/ ae7184eb21 [FIX] test_lint: Fix some false results
* [FIX] test_lint: Consider variables for sql-injection

Using the following code:

```python
var = 'SELECT name FROM account WHERE id IN {}'
values = (1, 2, 3)
self._cr.execute(var.format(values))
```

It has a risky sql injection ignored before of this change

And allow psycopg2.SQL way mapping the variables declaration

* [FIX] sql-injection: AttributeError: 'NoneType' object has no attribute 'parent'

Using the following code:

    queries = [
        "SELECT id FROM res_partner",
        "SELECT id FROM res_users",
    ]
    for query in queries:
        self.env.cr.execute(query)

The check sql-injection shows the following error:
 - AttributeError: 'NoneType' object has no attribute 'parent'

So, Now it is validating if it is not None

* [REF] sql-injection: Using better naming for node_ofc -> node_assign

* [FIX] sql-injection: Fix false positive using BinOp "+"

Considering the following valid case:

    cr.execute('SELECT ' + operator + ' FROM table' + 'WHERE')

The representation tree is:

    node.repr_tree()
    BinOp(
    op='+',
    left=BinOp(
        op='+',
        left=BinOp(
            op='+',
            left=Const(value='SELECT '),
            right=Name(name='operator')),
        right=Const(value=' FROM table')),
    right=Const(value='WHERE'))

Notice that left node is another BinOp node
So, it need to be considered recursively

closes odoo/odoo#77864

X-original-commit: ce1a0171f61d2808470c185a91e9f8299e4efd25
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2021-10-05 14:18:05 +00:00
Simon Genin (ges) e3cf794cc1 [IMP] test_lint: add no-dupe-class-members rule
closes odoo/odoo#77719

X-original-commit: 591a94f6278abf51b114fd43870874c6ea8364ab
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2021-10-04 14:12:42 +00:00
Thanh Dodeur ac99b09cdc [IMP] mail*: add audio and video conference with webRTC
*test_discuss_full,test_lint

This commit adds the audio and video conference feature to mail channels
and integrate it with the groupDM/guest features.

Adds new mp3 and ogg files (from task-2554674) for sound effects.

- Adds three new tables:
    * `mail.channel.rtc.session` to manage the peerToPeer interactions
      during rtc calls.
    * `mail.ice.server` to provide ICE servers necessary to establish
      peerToPeer connections with webRtc.
    * `res.users.settings.volumes` to hold the partner-to-partner volume
      settings, each partner can create one new setting per other
      partner to configure the volume coming from those partners during
      calls.

- changes res.config.settings:
    * Adds new fields for the Twilio credentials to use their STUN/TURN
      service.

- changes res.user.settings:
    * Adds 4 fields for the push to talk and voice activation.

- changes mail.channel:
    * Adds a new field `rtc_session_ids` that represents the active
      participants in a rtc call on that channel.

- changes mail.channel.partner:
    * Adds a new field `rtc_inviting_session_id` that represents the
      rtcSession of the user that is inviting that channelPartner to a
      call.

task-2366708

closes odoo/odoo#66611

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2021-09-04 06:23:56 +00:00
Xavier-Do 288595f558 [FIX] *: add explicit license to all manifest
The license is missing in most enterprise manifest so
the decision was taken to make it explicit in all cases.
When not defined, a warning will be triggered starting from
14.0 when falling back on the default LGPL-3.

closes odoo/odoo#74245

Related: odoo/design-themes#48
Related: odoo/enterprise#19862
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2021-07-26 13:09:57 +00:00
wan 1010de2310 [FIX] l10n*: adapt test tags external + post_install
Add a static test to ensure all l10n tests are tagged in order to be
able to be run in runbot/mergebot.
2021-07-19 10:14:24 +00:00
Samuel Degueldre eb70a581b9 [IMP] test_lint: add no-const-assign and no-debugger rules
Assigning to const variable is always a programming error, and we almost
never want to have a debugger in production code (for those cases, an
ignore comment can be added).

closes odoo/odoo#73821

Related: odoo/enterprise#19694
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2021-07-16 08:24:05 +00:00
+1 14bffd983e [REF] *: adapt code to new owl webclient
This commit adapts the community codebase to the rewriting of the
/web application in owl.

Co-authored-by: Aaron Bohy <aab@odoo.com>
Co-authored-by: Bruno Boi <boi@odoo.com>
Co-authored-by: Géry Debongnie <ged@odoo.com>
Co-authored-by: Samuel Degueldre <sad@odoo.com>
Co-authored-by: Mathieu Duckerts-Antoine <dam@odoo.com>
Co-authored-by: Simon Genin (ges) <ges@odoo.com>
Co-authored-by: Francois (fge) <fge@odoo.com>
Co-authored-by: Michael Mattiello (mcm) <mcm@odoo.com>
Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Lucas Perais (lpe) <lpe@odoo.com>
Co-authored-by: Jorge Pinna Puissant <jpp@odoo.com>
2021-06-18 21:31:27 +02:00
Victor Feyens 0348b95aee [FIX] *: update documentation links
Following the recent reorganisation of the documentation in 12.0+,
the majority of the documents have been moved and their old links are no longer valid.
Some redirection rules will soon be deployed, but those rules might be dropped in some years
and we want the links to still work, which is why we still replace the links to the new ones.

FW-Port of odoo/odoo#70675 (13.0)

closes odoo/odoo#70920

X-original-commit: bc9c1eef538ba6095e74c19d5d9ed9e01625ec7c
Related: odoo/enterprise#18361
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2021-05-17 19:26:27 +00:00
Xavier Morel 79a4d11e24 [FIX] *: bunch of mismarked translation specifiers
`_(xyz)` will wrap them in an underscore.js object, which when used in
a string context will just return the string. So it's basically a
no-op, but it certainly doesn't translate the terms.

closes odoo/odoo#70476

X-original-commit: 92352ed2b5524c97b0aeeba3193c6a8d93ed82a1
Related: odoo/enterprise#18172
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-05-06 12:06:22 +00:00
Jorge Pinna PuissantandSamuel Degueldre 7c032cb969 [IMP] test_lint: Add ESLint to the test suite
This commit allows using ESLint on the code JS to disallow undeclared
variables (no-undef) and disallow specific global variables
(no-restricted-globals) (error, event and self).

Co-authored-by: Samuel Degueldre <sad@odoo.com>
2021-05-04 13:32:45 +00:00
27166ff9df [REM] web_editor, website: remove Summernote wysiwyg rte library
Co-authored-by: David Monjoie <dmo@odoo.com>
Co-authored-by: Antoine Guenet <age@odoo.com>
Co-authored-by: Nicolas Bayet <nby@odoo.com>
Co-authored-by: Sébastien Geelen <sge@odoo.com>
Co-authored-by: Emilien Durieu <edu@odoo.com>
2021-04-01 12:49:47 +00:00
Christophe Monniez 1ba22f8aee [IMP] tests: add a test to avoid translations of template strings
When a template string that contains an expression is translated, the
resulting msgid is wrong.

e.g.:

    _t(`blah blah ${expression}`)

will generate a wrong msgid like this:

    msgid "blah blah ${expression}"

With this commit, a new test is added to find and forbid translations of
JS template-strings.

closes odoo/odoo#68165

X-original-commit: 9184ae45e0df179fc093c1fc48a7fa56d8fe9594
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2021-03-19 18:27:00 +00:00
Christophe Monniez db6a130889 [FIX] tests: test support for modules without __init__.py
Now that a test exists to enforce `__init__.py` in odoo module, we must
ensure that we keep the feature.

For that reason, a white-list system is added in `test_dunderinit` and a
test is added in order to be sure that a module without `__init__.py` can
be exists.

This this is made of a fake module `test_data_module` without
 `__init__.py` and a test module which ensure the fake module was
installed.

closes odoo/odoo#66778

X-original-commit: 506755ef8ced187c0f5cd2fa600e7bb1e1fc0fe3
Related: odoo/enterprise#16653
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2021-02-24 17:03:26 +00:00
Christophe Monniez 852aa5ae31 [FIX] tests: add a linter to check for __init__.py in modules
When a module is added, it happens that the `__init__.py` file is
forgotten. In that case, those modules are not packaged.

With this commit, a test is added to check that each Odoo module has the
file.

X-original-commit: edabed7b3ab351c76b9555378efa6258f9e76733
2021-02-24 17:03:25 +00:00
Simon Genin (ges)andFrancois 929fec3a54 [IMP] base: add support for native JS modules
Because of the way Odoo works at its core, we do not know before hand
which files will be loaded as an asset in the browser, because it
depends on the installed Odoo addons.  This is why it is historically
difficult to integrate Odoo with standard JS tooling, and this is why
Odoo needs to use a custom javascript module system.

However, there is a way to use native JS modules (and gain all the
benefits from it: IDE autocompletion, ease of refactoring, intellisense,
...): we can write JS as native JS modules, but convert them at runtime
into Odoo custom modules. This is exactly the strategy applied by this
PR.

This has a lot of benefits, but there is a downside: we can no longer
serve statically JS files in debug=assets.  This would be a dealbreaker,
if we did not have sourcemaps (implemented in the next commit).

This commit introduces the python code that will transpile native JS
modules into odoo JS modules.

Task ID: 2414902
PR: 63177

Co-authored-by: Francois (fge) <fge@odoo.com>
2021-02-15 10:18:11 +01:00
Pierre Paridans fd0ff95f23 [IMP] test_lint: adjust ES version for supported browsers
This reverts commit d431f94c75 and even
upgrade the EcmaScript version further to ES10/2019.

The original commit mainly targeted the support of MS Edge
(pre-Chromium) and earlier versions of iOS 11.

As with the release of Odoo 14, we don't support either of those (MS
Edge only Chromium-based and iOS 12), the original restriction can be
lifted and again target EcmaScript 9/2018.

But furthermore, some features of ES10/2019 are already in use in Odoo
14+ (e.g. `Object.fromEntries()` used in SpreadSheet, PoS, WebEditor,
Website Sale...) and the only browser not supporting them is Safari on
iOS versions < 12.2.

As there is no drop of supported devices between iOS 11 and 12 and they
all have access to - at least - the latest revision of iOS 12 (cf.
12.5), it looks reasonable to target the latest revision only and not
the earlier ones. This policy also matches the "ever-green-browsers"
policy applied on desktop.

Note: please note that the tool (es-check) used for testing the
EcmaScript version targeted has for primary goal to catch unsupported
syntax and reserved keywords only, but not the actual APIs available for
a given EcmaScript version. (e.g. async/await keywords or string
literals are tested *but not* Object.fromEntries() or
Array.prototype.flatMap()).

References:
- https://kangax.github.io/compat-table/es2016plus/
- https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Object/fromEntries
- https://en.wikipedia.org/wiki/IOS_12

closes odoo/odoo#63430

Signed-off-by: Adrien Dieudonné (adr) <adr@odoo.com>
2020-12-16 11:46:14 +00:00
Raphael Collet c3c465551c [FIX] test_lint: check for duplicate entries in POT files
X-original-commit: 4e29fbada592e887459dabee71708c6d0dd01715
2020-12-08 12:21:33 +00:00
Adrian Torres 169d383d88 [IMP] test_lint: add checker for raise in unlink overrides
This commit adds a pylint checker that will check every override of
`BaseModel.unlink` to verify that there are no raise statements within
the body of the method, if that is the case, an error will be raised.

closes odoo/odoo#58517

Related: odoo/enterprise#13557
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2020-12-04 09:16:16 +00:00
Adrian Torres ce83249d97 [IMP] test_lint: check for function-redefined error with pylint
With this commit, pylint will now point out when the same
function/class/method is defined more than once in the same scope which
is a recurring mistake.

closes odoo/odoo#60044

Related: odoo/enterprise#14090
Signed-off-by: Adrian Torres (adt) <adt@odoo.com>
2020-10-16 12:56:52 +00:00
Victor Feyens fdb23e282b [IMP] *: wrong any() usage
Replace wrong usages of any(list|recordset), by any(generator)
to speed up computations, avoiding list creations and/or looping twice on a recordset
for nothing.

any([generator]) => any(generator)
any(filtered) => any(generator)

closes odoo/odoo#55768

Related: odoo/enterprise#12360
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2020-08-14 09:56:10 +00:00
Xavier Morel e162e6f714 [FIX] test_lint, *: false negative in sql injection linter
The linter would miss / fail to warn on injection of *local variables*
in some cases.

Try to improve it to be stricter and more reliable, after discussion
with odo, sql which is "correctly" dynamic should use psycopg2's sql
package in order to bypass the linter (bonus: it should also properly
escape & quote identifiers).

closes odoo/odoo#53938

Related: odoo/enterprise#11718
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-07-10 07:12:35 +00:00
Martin Trigaux 241f06d868 [ADD] test_lint: add test to detect bad usages of _
More often than it should, translations calls are made using
  _("Foo %s" % bar)

instead of
  _("Foo %s") % bar

or the even better (but more recent)
  _("Foo %s", bar)

The issue of using the first writing is that the translation lookup
won't work at the execution (looking for ir.translation for src "Foo
Alice", "Foo Bob",... instead of "Foo %s").

Add a pylint test to ensure this won't happen anymore
2020-06-30 10:19:59 +00:00
Xavier Morel ff669b68cb [IMP] test_lint: disable deprecated-method
It's not super useful as we've re-enabled DeprecationWarnings though
logging, and it turns out to be a *very* expensive lint, as it more
than doubles the runtime of pylint locally:

Before:

    odoo.addons.test_lint.tests.test_pylint ran 1 tests in 376.27s, 2 queries

after:

    odoo.addons.test_lint.tests.test_pylint ran 1 tests in 114.05s, 2 queries

It also seems to significantly increase peak memory consumption (by
~60% though that's not a precise measurement), which can lead to
non-deterministic memory errors.

Also disable mixed-indentation since it doesn't do anything (mixed
indentation is illegal in Python 3).

closes odoo/odoo#53562

X-original-commit: 8062098d0586048a9e91543290c6ab1c8d8d7009
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-06-24 09:52:28 +00:00
Yannick Tivisse 4c291e3f70 [IMP] base: Display searchpanel on ir.module.module views
Purpose
=======

The current kanban view is messy. It is difficult to identify which
apps are installed or not. The user can completely miss a module
that might have interested him. A search panel would make things way
more readable.

closes odoo/odoo#44401

Taskid: 2181557
Related: odoo/enterprise#8144
Related: odoo/upgrade#879
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2020-03-05 14:03:45 +00:00
Victor Feyens 11ff605319 [REM] test_lint: uninstall hook
closes odoo/odoo#44027

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2020-01-27 15:20:42 +00:00
Xavier Morel a2a1e294d7 [IMP] core: deprecate returning domains from onchanges
* add a runtime warning when an onchange method contains the string
  'domain'
* add a lint test to forbid the string 'domain' in onchange methods,
  this is easy to defeat (e.g. `dict(domain=...)`) and can have false
  positives (literal `'domain'` strings for reasons other than an
  onchange result) but overall it seems to work nicely
* implemented as a non-pylint test as pylint takes ages to run. While
  at it, remove the long-disabled and long-useless
  PEP3110TokenChecker (checks for `except Exception, a` which is a
  syntax error in P3)

Task 2115472

closes odoo/odoo#41918

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-01-06 10:35:52 +00:00
fw-bot 828c251056 [FIX] test_lint: force absolute path to compute odoo path
When using the flamegraph module from a parent directory of odoo, the
dirname method returns a relative path, leading to a traceback.

With this commit, the odoo_path is enforced to be an absolute path.

closes odoo/odoo#40147

X-original-commit: 75efe4b4ca6c0ccef6ec592b317e7c2b572f28fc
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2019-11-12 15:39:57 +00:00
Christophe Monniez 4fdb07f81b [IMP] test_lint: add a test to detect git conflict markers
Since the deployement of the forward-port bot, chances to merge code
with conflict markers has greatly increased.

With this commit, a new test is added to grep for those markers in most
common code files.

closes odoo/odoo#40029

X-original-commit: 19bf61c0e0c0464058064565be1051e5f43516ab
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2019-11-08 13:04:59 +00:00
Christophe Simonis d74b451805 [MERGE] forward port branch 13.0 up to f4105eb9c7 2019-10-09 02:08:17 +02:00
Moisés López a5251e1d40 [ADD] test_lint: Add sql-injection pylint check
closes odoo/odoo#36583

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2019-10-02 14:16:38 +00:00
Julien Castiaux 4f03a5f136 [FIX] *: remove old deprecated modules/functions
PEP-594 is deprecating a bunch of modules. As part of the cleanup, we
are also dealing with long deprecated modules, functions and aliases.

* `assert_` -> `assertTrue`
* `assertEquals` -> `assertEqual`
* `assertNotEquals` -> `assertNotEqual`
* `assertAlmostEquals` -> `assertAlmostEqual`
* `assertRaisesRegexp` -> `assertRaisesRegex`
* `assertRegexpMatches` -> `assertRegex`
* `base64.encodestring` -> `base64.encodebytes`
* `base64.decodestring` -> `base64.decodebytes`
* `inspect.getargspec` -> `inspect.signature`
* `inspect.formatargspec` -> `inspect.signature`
* `logging.warn` -> `logging.warning`

closes odoo/odoo#36863

Task: 2003936
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2019-09-17 11:36:42 +00:00
Pierre Paridans d431f94c75 [FIX] test_lint: adjust ES version for supported browsers
The EcmaScript version was recently raised (see commit
odoo/odoo@7423e20) to ES9/ES2018.

Sadly this specification is not fully supported by all ever-green
browsers (Chrome, Firefox, Edge, Safari...).

This commit rollback to ES8/ES2017 because MS Edge doesn't support the
"Spread in destructuring" operator (e.g. used for the creation of a new
object).

In a nutshell this version is equivalent to es2016 + async/await.

References:
- https://github.com/tc39/proposal-object-rest-spread/blob/master/Spread.md
- https://kangax.github.io/compat-table/es2016plus/#test-object_rest/spread_properties
- https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Operators/Spread_syntax
2019-08-27 21:43:42 +00:00
Martin Geubelle 372475e7ae [IMP] test_lint: raise max es version
ESNext is now supported in master so the max version number has been raised.
Note that es-check is still used but not for the original purpose ; it is
still useful for JS syntax checking.

closes odoo/odoo#34362

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2019-06-25 13:26:28 +00:00
Christophe Simonis b6f7fe9a81 [IMP] test_lint: correctly format es-check error message 2019-06-17 14:09:31 +02:00
Christophe Simonis ced0e5becf [FIX] test_lint: also ignore js files in static/src/tests directory 2019-06-14 18:09:58 +02:00
Christophe Simonis 8853e6b594 [MERGE] forward port branch 12.0 up to 7ef4ba03c4 2019-06-11 15:20:13 +02:00
Christophe Simonis bdc62d8031 [FIX] test_lint: move custom pylint checkers to new module
Oversight of previous forward-port.
2019-06-07 12:08:29 +02:00
Christophe Simonis 9bf4766f3d [MERGE] forward port branch saas-15 up to 6c6e652673 2019-06-07 11:38:48 +02:00
Christophe Monniez b27077bb0c [MOV] test_pylint, test_lint: add es-check linter
Because Odoo still supports Android Kitkat and Internet Explorer, ES5 is
the highest ECMAScript allowed version.

This commit adds a new test that parses each javascript file found in
addons. The test fails if unsupported js code is found.  As ES6 is
allowed during tests, the files under a path that contains 'static/test'
are just skipped.

This test uses the es-check tool
(https://www.npmjs.com/package/es-check).

If the es-check tool cannot be found, the test is simply skipped.

Also the test_pylint module is renamed to a more generic name test_lint,
that way, every linter test can find a shelter  here.

closes odoo/odoo#33724

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2019-05-30 11:22:10 +00:00