Those were not accounted for, leading to fstrings passing through
unflagged.
Also update the SQL checker to be stricter but smarter:
The previous version would "fail open", unknown nodes would be allowed
through hence f-strings not being flagged when they started appearing
in arg0 position, should now fail-closed, anything that's not allowed
is forbidden.
This flags a few more cases, all of which seem acceptable upon review.
However the previous version would also only resolve arg0 (in case it
had a `NAME`, to see if that resolved to an acceptable form of
query-building). The new version performs resolution during
`_check_concatenation` and should thus allow e.g. format strings to be
separate variables (though not e.g. module-level constants, yet
anyway).
In resolution, replace the ad-hoc process by astroid's built-in
`lookup` which seems to provide the same information. Slightly more in
fact, as it yields every assignment in case of e.g. conditionals, but
making use of that would require a lot more changes in the checker so
leaving the behaviour as-is for now.
It's important to *not* use `ilookup` here, because ilookup is not
"iterable" but "inferring", and we don't want values, we want
expression ASTs for analysis.
NOTE: previous improvements as well as fixes to existing code were
only implemented in 14.0, hence this being merged in 14.0 not 13.0
despite 13.0 still being supported.
closesodoo/odoo#81721
X-original-commit: 376ccf0944dae1bc53ae9c5385977c4e6b23e083
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
*: base_address_city, base_address_extended, bus, crm, im_livechat,
l10n_ae_pos, lunch, pos_restaurant_adyen, test_assetsbundle,
test_converter, test_lint.
It is spelled `auto_install`, the `complexity` key is long gone, `qweb`
has been moved to `assets: {'web.assets_qweb': []}`. `js` and `css` are
long gone too, `maintainer` is redundant with `author` which is
"Odoo S.A." by default already, the `certificate` key is long gone.
closesodoo/odoo#80988
Related: odoo/enterprise#22766
Signed-off-by: Julien Castiaux <juc@odoo.com>
* [FIX] test_lint: Consider variables for sql-injection
Using the following code:
```python
var = 'SELECT name FROM account WHERE id IN {}'
values = (1, 2, 3)
self._cr.execute(var.format(values))
```
It has a risky sql injection ignored before of this change
And allow psycopg2.SQL way mapping the variables declaration
* [FIX] sql-injection: AttributeError: 'NoneType' object has no attribute 'parent'
Using the following code:
queries = [
"SELECT id FROM res_partner",
"SELECT id FROM res_users",
]
for query in queries:
self.env.cr.execute(query)
The check sql-injection shows the following error:
- AttributeError: 'NoneType' object has no attribute 'parent'
So, Now it is validating if it is not None
* [REF] sql-injection: Using better naming for node_ofc -> node_assign
* [FIX] sql-injection: Fix false positive using BinOp "+"
Considering the following valid case:
cr.execute('SELECT ' + operator + ' FROM table' + 'WHERE')
The representation tree is:
node.repr_tree()
BinOp(
op='+',
left=BinOp(
op='+',
left=BinOp(
op='+',
left=Const(value='SELECT '),
right=Name(name='operator')),
right=Const(value=' FROM table')),
right=Const(value='WHERE'))
Notice that left node is another BinOp node
So, it need to be considered recursively
closesodoo/odoo#77864
X-original-commit: ce1a0171f61d2808470c185a91e9f8299e4efd25
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
*test_discuss_full,test_lint
This commit adds the audio and video conference feature to mail channels
and integrate it with the groupDM/guest features.
Adds new mp3 and ogg files (from task-2554674) for sound effects.
- Adds three new tables:
* `mail.channel.rtc.session` to manage the peerToPeer interactions
during rtc calls.
* `mail.ice.server` to provide ICE servers necessary to establish
peerToPeer connections with webRtc.
* `res.users.settings.volumes` to hold the partner-to-partner volume
settings, each partner can create one new setting per other
partner to configure the volume coming from those partners during
calls.
- changes res.config.settings:
* Adds new fields for the Twilio credentials to use their STUN/TURN
service.
- changes res.user.settings:
* Adds 4 fields for the push to talk and voice activation.
- changes mail.channel:
* Adds a new field `rtc_session_ids` that represents the active
participants in a rtc call on that channel.
- changes mail.channel.partner:
* Adds a new field `rtc_inviting_session_id` that represents the
rtcSession of the user that is inviting that channelPartner to a
call.
task-2366708
closesodoo/odoo#66611
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
The license is missing in most enterprise manifest so
the decision was taken to make it explicit in all cases.
When not defined, a warning will be triggered starting from
14.0 when falling back on the default LGPL-3.
closesodoo/odoo#74245
Related: odoo/design-themes#48
Related: odoo/enterprise#19862
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
Assigning to const variable is always a programming error, and we almost
never want to have a debugger in production code (for those cases, an
ignore comment can be added).
closesodoo/odoo#73821
Related: odoo/enterprise#19694
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
This commit adapts the community codebase to the rewriting of the
/web application in owl.
Co-authored-by: Aaron Bohy <aab@odoo.com>
Co-authored-by: Bruno Boi <boi@odoo.com>
Co-authored-by: Géry Debongnie <ged@odoo.com>
Co-authored-by: Samuel Degueldre <sad@odoo.com>
Co-authored-by: Mathieu Duckerts-Antoine <dam@odoo.com>
Co-authored-by: Simon Genin (ges) <ges@odoo.com>
Co-authored-by: Francois (fge) <fge@odoo.com>
Co-authored-by: Michael Mattiello (mcm) <mcm@odoo.com>
Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Lucas Perais (lpe) <lpe@odoo.com>
Co-authored-by: Jorge Pinna Puissant <jpp@odoo.com>
Following the recent reorganisation of the documentation in 12.0+,
the majority of the documents have been moved and their old links are no longer valid.
Some redirection rules will soon be deployed, but those rules might be dropped in some years
and we want the links to still work, which is why we still replace the links to the new ones.
FW-Port of odoo/odoo#70675 (13.0)
closesodoo/odoo#70920
X-original-commit: bc9c1eef538ba6095e74c19d5d9ed9e01625ec7c
Related: odoo/enterprise#18361
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
`_(xyz)` will wrap them in an underscore.js object, which when used in
a string context will just return the string. So it's basically a
no-op, but it certainly doesn't translate the terms.
closesodoo/odoo#70476
X-original-commit: 92352ed2b5524c97b0aeeba3193c6a8d93ed82a1
Related: odoo/enterprise#18172
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
This commit allows using ESLint on the code JS to disallow undeclared
variables (no-undef) and disallow specific global variables
(no-restricted-globals) (error, event and self).
Co-authored-by: Samuel Degueldre <sad@odoo.com>
When a template string that contains an expression is translated, the
resulting msgid is wrong.
e.g.:
_t(`blah blah ${expression}`)
will generate a wrong msgid like this:
msgid "blah blah ${expression}"
With this commit, a new test is added to find and forbid translations of
JS template-strings.
closesodoo/odoo#68165
X-original-commit: 9184ae45e0df179fc093c1fc48a7fa56d8fe9594
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
Now that a test exists to enforce `__init__.py` in odoo module, we must
ensure that we keep the feature.
For that reason, a white-list system is added in `test_dunderinit` and a
test is added in order to be sure that a module without `__init__.py` can
be exists.
This this is made of a fake module `test_data_module` without
`__init__.py` and a test module which ensure the fake module was
installed.
closesodoo/odoo#66778
X-original-commit: 506755ef8ced187c0f5cd2fa600e7bb1e1fc0fe3
Related: odoo/enterprise#16653
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
When a module is added, it happens that the `__init__.py` file is
forgotten. In that case, those modules are not packaged.
With this commit, a test is added to check that each Odoo module has the
file.
X-original-commit: edabed7b3ab351c76b9555378efa6258f9e76733
Because of the way Odoo works at its core, we do not know before hand
which files will be loaded as an asset in the browser, because it
depends on the installed Odoo addons. This is why it is historically
difficult to integrate Odoo with standard JS tooling, and this is why
Odoo needs to use a custom javascript module system.
However, there is a way to use native JS modules (and gain all the
benefits from it: IDE autocompletion, ease of refactoring, intellisense,
...): we can write JS as native JS modules, but convert them at runtime
into Odoo custom modules. This is exactly the strategy applied by this
PR.
This has a lot of benefits, but there is a downside: we can no longer
serve statically JS files in debug=assets. This would be a dealbreaker,
if we did not have sourcemaps (implemented in the next commit).
This commit introduces the python code that will transpile native JS
modules into odoo JS modules.
Task ID: 2414902
PR: 63177
Co-authored-by: Francois (fge) <fge@odoo.com>
This reverts commit d431f94c75 and even
upgrade the EcmaScript version further to ES10/2019.
The original commit mainly targeted the support of MS Edge
(pre-Chromium) and earlier versions of iOS 11.
As with the release of Odoo 14, we don't support either of those (MS
Edge only Chromium-based and iOS 12), the original restriction can be
lifted and again target EcmaScript 9/2018.
But furthermore, some features of ES10/2019 are already in use in Odoo
14+ (e.g. `Object.fromEntries()` used in SpreadSheet, PoS, WebEditor,
Website Sale...) and the only browser not supporting them is Safari on
iOS versions < 12.2.
As there is no drop of supported devices between iOS 11 and 12 and they
all have access to - at least - the latest revision of iOS 12 (cf.
12.5), it looks reasonable to target the latest revision only and not
the earlier ones. This policy also matches the "ever-green-browsers"
policy applied on desktop.
Note: please note that the tool (es-check) used for testing the
EcmaScript version targeted has for primary goal to catch unsupported
syntax and reserved keywords only, but not the actual APIs available for
a given EcmaScript version. (e.g. async/await keywords or string
literals are tested *but not* Object.fromEntries() or
Array.prototype.flatMap()).
References:
- https://kangax.github.io/compat-table/es2016plus/
- https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Object/fromEntries
- https://en.wikipedia.org/wiki/IOS_12closesodoo/odoo#63430
Signed-off-by: Adrien Dieudonné (adr) <adr@odoo.com>
This commit adds a pylint checker that will check every override of
`BaseModel.unlink` to verify that there are no raise statements within
the body of the method, if that is the case, an error will be raised.
closesodoo/odoo#58517
Related: odoo/enterprise#13557
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
With this commit, pylint will now point out when the same
function/class/method is defined more than once in the same scope which
is a recurring mistake.
closesodoo/odoo#60044
Related: odoo/enterprise#14090
Signed-off-by: Adrian Torres (adt) <adt@odoo.com>
Replace wrong usages of any(list|recordset), by any(generator)
to speed up computations, avoiding list creations and/or looping twice on a recordset
for nothing.
any([generator]) => any(generator)
any(filtered) => any(generator)
closesodoo/odoo#55768
Related: odoo/enterprise#12360
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
The linter would miss / fail to warn on injection of *local variables*
in some cases.
Try to improve it to be stricter and more reliable, after discussion
with odo, sql which is "correctly" dynamic should use psycopg2's sql
package in order to bypass the linter (bonus: it should also properly
escape & quote identifiers).
closesodoo/odoo#53938
Related: odoo/enterprise#11718
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
More often than it should, translations calls are made using
_("Foo %s" % bar)
instead of
_("Foo %s") % bar
or the even better (but more recent)
_("Foo %s", bar)
The issue of using the first writing is that the translation lookup
won't work at the execution (looking for ir.translation for src "Foo
Alice", "Foo Bob",... instead of "Foo %s").
Add a pylint test to ensure this won't happen anymore
It's not super useful as we've re-enabled DeprecationWarnings though
logging, and it turns out to be a *very* expensive lint, as it more
than doubles the runtime of pylint locally:
Before:
odoo.addons.test_lint.tests.test_pylint ran 1 tests in 376.27s, 2 queries
after:
odoo.addons.test_lint.tests.test_pylint ran 1 tests in 114.05s, 2 queries
It also seems to significantly increase peak memory consumption (by
~60% though that's not a precise measurement), which can lead to
non-deterministic memory errors.
Also disable mixed-indentation since it doesn't do anything (mixed
indentation is illegal in Python 3).
closesodoo/odoo#53562
X-original-commit: 8062098d0586048a9e91543290c6ab1c8d8d7009
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Purpose
=======
The current kanban view is messy. It is difficult to identify which
apps are installed or not. The user can completely miss a module
that might have interested him. A search panel would make things way
more readable.
closesodoo/odoo#44401
Taskid: 2181557
Related: odoo/enterprise#8144
Related: odoo/upgrade#879
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
* add a runtime warning when an onchange method contains the string
'domain'
* add a lint test to forbid the string 'domain' in onchange methods,
this is easy to defeat (e.g. `dict(domain=...)`) and can have false
positives (literal `'domain'` strings for reasons other than an
onchange result) but overall it seems to work nicely
* implemented as a non-pylint test as pylint takes ages to run. While
at it, remove the long-disabled and long-useless
PEP3110TokenChecker (checks for `except Exception, a` which is a
syntax error in P3)
Task 2115472
closesodoo/odoo#41918
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
When using the flamegraph module from a parent directory of odoo, the
dirname method returns a relative path, leading to a traceback.
With this commit, the odoo_path is enforced to be an absolute path.
closesodoo/odoo#40147
X-original-commit: 75efe4b4ca6c0ccef6ec592b317e7c2b572f28fc
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
Since the deployement of the forward-port bot, chances to merge code
with conflict markers has greatly increased.
With this commit, a new test is added to grep for those markers in most
common code files.
closesodoo/odoo#40029
X-original-commit: 19bf61c0e0c0464058064565be1051e5f43516ab
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
ESNext is now supported in master so the max version number has been raised.
Note that es-check is still used but not for the original purpose ; it is
still useful for JS syntax checking.
closesodoo/odoo#34362
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
Because Odoo still supports Android Kitkat and Internet Explorer, ES5 is
the highest ECMAScript allowed version.
This commit adds a new test that parses each javascript file found in
addons. The test fails if unsupported js code is found. As ES6 is
allowed during tests, the files under a path that contains 'static/test'
are just skipped.
This test uses the es-check tool
(https://www.npmjs.com/package/es-check).
If the es-check tool cannot be found, the test is simply skipped.
Also the test_pylint module is renamed to a more generic name test_lint,
that way, every linter test can find a shelter here.
closesodoo/odoo#33724
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>