Commit Graph
83 Commits
Author SHA1 Message Date
wan a77dee7b98 [FIX] core: typo in field type check
closes odoo/odoo#82238

X-original-commit: 5164739b835445fa11b2efc53e2ff839a4bad10a
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Signed-off-by: William André (wan) <wan@odoo.com>
2022-01-04 20:16:47 +00:00
Xavier Morel 74241b3766 [FIX] test_lint: support fstrings in sql injection checker
Those were not accounted for, leading to fstrings passing through
unflagged.

Also update the SQL checker to be stricter but smarter:

The previous version would "fail open", unknown nodes would be allowed
through hence f-strings not being flagged when they started appearing
in arg0 position, should now fail-closed, anything that's not allowed
is forbidden.

This flags a few more cases, all of which seem acceptable upon review.

However the previous version would also only resolve arg0 (in case it
had a `NAME`, to see if that resolved to an acceptable form of
query-building). The new version performs resolution during
`_check_concatenation` and should thus allow e.g. format strings to be
separate variables (though not e.g. module-level constants, yet
anyway).

In resolution, replace the ad-hoc process by astroid's built-in
`lookup` which seems to provide the same information. Slightly more in
fact, as it yields every assignment in case of e.g. conditionals, but
making use of that would require a lot more changes in the checker so
leaving the behaviour as-is for now.

It's important to *not* use `ilookup` here, because ilookup is not
"iterable" but "inferring", and we don't want values, we want
expression ASTs for analysis.

NOTE: previous improvements as well as fixes to existing code were
only implemented in 14.0, hence this being merged in 14.0 not 13.0
despite 13.0 still being supported.

closes odoo/odoo#81721

X-original-commit: 376ccf0944dae1bc53ae9c5385977c4e6b23e083
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-12-27 09:36:42 +00:00
wan 2b80f3e5f1 [IMP] core: allow nested declaration of xml for one2many fields
Some data are formatted as a tree structure with a relation of parent.
We are adding meaning to the structure:

* This improves readability and allows to fold/unfold records in
  editors.
* This could be done before using `eval`, but this allows to have an
  xml_id for those records. It also allows to update the records without
  having to rewrite on the parent x2many field.

Part-of: odoo/odoo#76675
2021-11-25 00:31:16 +00:00
Martin Trigaux c7bac3dee0 [IMP] *: make ir.model.data helper private
No reason to interfact with them directly in RPC
2021-08-10 13:49:04 +02:00
Julien Castiaux 5815ce7753 [FIX] base: some fixes for ir.ui.view
Task: 2463632
2021-06-11 17:09:05 +00:00
Naglis Jonaitis e59b032f06 [FIX] core: fix <act_window> deprecation warning
Without the f-string literal the XML ID is not printed.

closes odoo/odoo#69419

X-original-commit: d0cbe52c111af923f0df5d0d231b164a150bf2db
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2021-04-16 15:57:07 +00:00
Julien Castiaux fb4cf35368 [FIX] base: View error reporting can lack a context
A context is attached to the ValidationError object when elements in the
view arch are broken. This context helps to locate the error in the
source file. When the view processing fails outside of the arch
evaluation, such context is missing.

closes odoo/odoo#68157

Signed-off-by: Julien Castiaux <Julien00859@users.noreply.github.com>
2021-03-19 16:13:17 +00:00
Julien Castiaux 6fc985794e [IMP] ir_ui_view: Refine error message
When installing/upgrading a module with broken xml views, the module
installation fails with an error message that should help the developer
locate and correct the error.

Before this commit, a 3-level traceback was thrown at the developer:

1. The initial ValueError containing the original error message and some
   view context information.
2. The noisy re-cast of the ValueError to a ValidationError with no
   additionnal information.
3. An additionnal re-cast of the exception to add the original source
   file path plus the entire XML source code that failed to be parsed.

We argue the error contains too much noise as developers are mostly
interrested in correcting their erronous tag of their view, they are not
interrested in `ir_ui_view` internals.

The new exception report is much less talkative, the two tracebacks from
`ir_ui_view` are logged at the `DEBUG` level. The new exception still
contains the original error message with some context on the view record
and the original source file path but it only show 5 lines of XML around
the erronous tag.

closes odoo/odoo#62757

Task: 2366612
Related: odoo/enterprise#15104
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2020-12-07 15:35:15 +00:00
Julien Castiaux eded14b4c4 [ADD] fields.py: New x2many command helper
We provide a new helper class to help redact x2many commands for create
and write methods. To ensure best compatibility with the xmlrpc layer we
do not change the protocole, the commands are still 3-elements tuples
where the first element is still an integer in between 0 and 6. The
helper class provide the cannonical constants and static methods to ease
working with the commands. The new helper class is also available in QWeb.

Developers are encouraged to transition their code so it uses this new
helper class.

Task: 2366606
2020-11-30 10:16:09 +00:00
jev-odoo 12b612d798 [FIX] core: incomplete traceback
XML loading always raises a ParseError, however when an XML loading error is triggered from an HTTP request (e.g. a button) the final ParseError logged & shown to the user would not be properly chained to its ancestor, leading the original cause to be lost and issues being much harder to diagnose.

This cause is lost in _handle_exception where we duplicate the exception in order to chain it correctly, the __cause__ of the source exception was not properly copied over, and would thus break the chain.

The fix also requires explicitly chaining the ParseError to its cause, this should not be necessary but the cause is also lost if this is missing, it is not clear why.

opw-2381776

closes odoo/odoo#62117

X-original-commit: 650476812ee7d57f1d954be5557a3856448ffe5e
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-11-20 16:55:41 +00:00
Debauche StéphaneandXavier Morel 7ecb903bea [REM] *: ability to put raw modules in evaluation contexts
Co-authored-by: Xavier Morel <xmo@odoo.com>
2020-09-28 10:33:52 +02:00
Xavier Morel c1c43bbe38 [REM] core: assertion reports
That's a not-very-useful subset of OdooTestResult, so:

* make results merge-able (aka add ability to update a result with the
  contents of another)
* remove support for test data files, and transmission of the
  assertion report thing through the data-files loading
* replace "legitimate" uses of assertion report by test result
* have run_unit_tests manipulate and return a result instead of weird
  flags & ternaries
2020-08-19 14:08:12 +00:00
Xavier Morel c8063af7a0 [IMP] core, account, lunch: make <menuitem> recursive
For clarity, some data files are formatted as pseudo-tree
structure. This is somewhat confusing and dangerous when the structure
has no meaning... so add meaning:

* allow nesting menuitems, nested items are set as children to the
  parent they're nested in
* update schema to allow an icon *or* a parent on regular menu items,
  and neither on nested (they have an implicit parent meaning can't
  have an icon)
* remove attributes which don't actually exist from the menuitem
  schema
* also type sequence as an integer while at it

Convert two large-ish menuitem data files to recursive form.

closes odoo/odoo#54564

Related: odoo/enterprise#11887
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-07-28 13:03:13 +00:00
Xavier Morel 6835aeb0de [REM] core, *: deprecate <act_window> and <report>
Convert deprecated tags through the codebase.
2020-07-28 13:03:13 +00:00
Paul Morelle 98d5770e5d [FIX] tools: stop evaluating twice <function eval="..."> in _eval_xml
After a bad merge d785adba6c the eval code
was evaluated twice.

closes odoo/odoo#45554

X-original-commit: c0316bb807e6c2db9c3567cba1aeb52da946cae7
Signed-off-by: Paul Morelle <madprog@users.noreply.github.com>
2020-02-17 17:35:19 +00:00
wan d8c5cc1335 [IMP] account: add a readonly group
Task 2092079
Accounting firms that want to give access to their customers avoiding
mistakes and risks will love this profile that can't do anything
wrong... Maybe as well as companies auditors..?

closes odoo/odoo#39860

Related: odoo/enterprise#6576
Signed-off-by: Quentin De Paoli (qdp) <qdp@openerp.com>
2020-01-22 11:23:16 +00:00
Xavier-Do 8bb0530017 [IMP] base: improve error context for view validation errors
closes odoo/odoo#36373

Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2019-11-13 16:12:24 +00:00
Xavier Morel badb95fbce [FIX] core: further pycompat cleanup
odoo/odoo#28519 removed large parts of pycompat, but left reraise
despite that not having much value.

Remove that helper and replace it by just a `raise` in most cases:
when raising from an except block, the old exception is automatically
chained to the new one, no need to mess around.

There is one exception: in http we have to re-raise an existing
exception explicitly (aka `raise exc` rather than just `raise).

This is less than ideal as Python *concatenates* stacks: the
previously reified stack (from the except clause) is stacked on top of
the new stack (from this raises), this leads to tracebacks "jumping
around" at the break point of the handler and is somewhat confusing.

So we want to use explicit chaining (`raise a from b`) with the
"source" providing the caught exception's original traceback and the
child providing the rest.

However since callers rely on the exception making sense, we need the
re-raised exception to be the original[0]. Copying the exception
doesn't work (see [0]), chaining an exception to itself doesn't
do anything useful, and while we could probably copy exceptions using
the pickle method[1] that's still risky.

So the most reliable option seems to be to create a new "cause"
exception, move the old traceback over to it, then re-raise the
original exception having cleared its traceback, chained to new the
cause.

[0] or a copy thereof but Odoo exceptions don't all work properly with
    copy.copy and we don't want that to fail so not really an option,
    we can't rely / bet on every new exception being cleanly copy-able
[1] create an "empty" instance using __new__ (or an instance of
    something else onto which we re-set the __class__ in case the exctype
    actually overrides __new__) then copy the __dict__

closes odoo/odoo#39709

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2019-11-05 08:14:10 +00:00
Christophe Simonis 64e43808b7 [MERGE] forward port branch saas-12.5 up to 58a83d1222 2019-09-20 17:34:45 +02:00
fja-odoo e33172e832 [IMP] website_sale, *: keep track of products viewed
*= website, website_livechat, website_rating

///// Tracking Product /////

Now when a user browse products in eCommerce, we keep track of the
products he looked at. We use the website_visitor
to store the products viewed. A cookie is added with a TTl of 30 min it
will prevent the RPC for that time. We track the page only if the
product view is tracked.

The recently viewed products are displayed as a snippet but also
with the customize option in product pages of website_sale.

Products that are in cart will not be returned as recently viewed.

It is possible to add a recently viewed product to the cart directly
from the carousel, it will not redirect to the cart. If we are on the
cart page, the product is displayed in the cart.

The Visitor page in website now references products viewed

///// Tracking Page /////

Feature to track a view was remove in: https://github.com/odoo/enterprise/pull/4834

That feature is now reintroduced and will use website_track instead of
leads to be stored.

The track field is now on the view instead of the page.

url field is added to website.track, it will store the url for pages and
views

The Visitor page in website now references urls viewed

Add some tests

task-1984575

closes odoo/odoo#35810

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-09-16 09:38:53 +00:00
Julien Castiaux 4f03a5f136 [FIX] *: remove old deprecated modules/functions
PEP-594 is deprecating a bunch of modules. As part of the cleanup, we
are also dealing with long deprecated modules, functions and aliases.

* `assert_` -> `assertTrue`
* `assertEquals` -> `assertEqual`
* `assertNotEquals` -> `assertNotEqual`
* `assertAlmostEquals` -> `assertAlmostEqual`
* `assertRaisesRegexp` -> `assertRaisesRegex`
* `assertRegexpMatches` -> `assertRegex`
* `base64.encodestring` -> `base64.encodebytes`
* `base64.decodestring` -> `base64.decodebytes`
* `inspect.getargspec` -> `inspect.signature`
* `inspect.formatargspec` -> `inspect.signature`
* `logging.warn` -> `logging.warning`

closes odoo/odoo#36863

Task: 2003936
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2019-09-17 11:36:42 +00:00
Raphael Collet 5324921861 [FIX] *: do not use '' as many2one value
closes odoo/odoo#35907

Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2019-08-22 13:40:40 +00:00
Hiral Bhavsar 3cd7ed07a2 [IMP] *: remove 'view_type' on window actions.
The old tree views don't really exist anymore, this odd pseudo-flag to
dispatch between "list" and "tree" tree views has no reason to remain.

Task 1937686

closes odoo/odoo#31243

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2019-06-17 11:34:17 +00:00
Christophe Simonis 71a50a2214 [MERGE] forward port branch saas-12.3 up to 409679866b 2019-06-06 11:54:35 +02:00
Christophe Simonis c8d7ad9a6b [MERGE] forward port branch saas-12.2 up to 995aa1685e 2019-06-03 15:49:31 +02:00
Christophe Simonis d785adba6c [MERGE] forward port branch 12.0 up to c545783b95 2019-05-17 15:50:59 +02:00
Christophe Simonis d8c0826b07 [MERGE] forward port branch saas-11.3 up to 37bca6ae50 2019-05-17 12:19:55 +02:00
Christophe Simonis 5f17daae40 [MERGE] forward report branch 11.0 up to daf9763e6e 2019-05-17 10:00:11 +02:00
Christophe Simonis 7b9aa21576 [MERGE] forward port branch saas-15 up to cecb1ec77d 2019-05-16 18:19:49 +02:00
Christophe Simonis 556b59bce1 [MERGE] forward port branch 10.0 up to 90d86e07dd 2019-05-16 18:10:33 +02:00
Mohammed ShekhaandDhaval Limbuwala 90d86e07dd [FIX] tools: allow using datetime in function call
Traceback generated when trying to pass a datetime object into a function tag
in xml.

<function name="action_name" model="model_name" eval="datetime.date.today"/>

Used to fail.

With this commit now one can pass time, datetime, timedelta, relativedelta,
version, ref, pytz in function tag in xml

Task-id: 1772614
Closes odoo/odoo#29212

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>


Co-authored-by: Dhaval Limbuwala <dli@odoo.com>
2019-05-16 14:42:41 +00:00
Xavier Morel 16cd987a53 [IMP] validation error messages through optional use of jing
A long-standing issue with data files is that lxml (libxml2) has
trouble reporting useful errors, often going no further than "the file
is not valid" (libxml2 apparently has issues reporting useful errors
within non-trivial <choice>, which Odoo's data file schema makes
extensive use of) e.g. if a data file has some stray text in an
unexpected place (in this case, after a `</field>` tag in a
`<record>`), libxml2 will report:

ERROR:RELAXNGV:RELAXNG_ERR_EXTRACONTENT: Element odoo has extra content: data

Jing (the reference implementation) provides significantly better
error reporting:

error: text not allowed here; expected the element end-tag or element "field"

It's in java which is inconvenient and expensive for baseline
validation (and as a hard dependency), but there's now a "jingtrang"
package which bundles the relevant jars & invocation on
pypi (https://pypi.org/project/jingtrang/), making for a convenient
optional dependency for better development experience.

closes odoo/odoo#33666

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2019-05-27 06:58:48 +00:00
Xavier Morel 10f1a1a0c4 [REM] multi from ir.actions.act_window
Task 1843603

* src_model is redundant with binding_model_id
* multi -> binding_view_types (if empty => all views) (maybe should be
empty by default yo?)
* in convert, type => rec.get(type) but no @type possible on <act_window>...
* removed deprecated auto_refresh & auto_search (not used anywhere (?))

closes odoo/odoo#24738

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2019-05-27 12:00:39 +00:00
Raphael Collet d87443a213 [FIX] convert: enable kwargs in tag <function>
closes odoo/odoo#31417

Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2019-03-22 16:42:14 +00:00
Xavier Morel 4d7aa97da3 [FIX] core: fixup of convert cleanup
_tag_delete was not properly converted when the _tag_ calling
convention was modified in 4d581e26c2,
so <delete> tags would all blow up if encountered.

closes odoo/odoo#29149
2018-11-29 13:46:14 +00:00
Adrian Torres 52f5528cfb [REF] *: replace deprecated pycompat helpers for builtins
This commit replaces calls to pycompat helpers that were intended for
python 2 <-> python 3 interoperability for python 3 builtins, as python
2 is no longer officially supported by Odoo.

This includes:
    * calls to imap/izip/ifilter replaced by map/zip/filter
    * uses of text_type replaced by str
    * uses of unichr replaced by chr
    * calls to implements_to_string, implements_iterator removed
    * string_types and integer_types replaced by str, int respectively
    * calls to to_native replaced by calls to to_text

This is done in preparation to the removal of these deprecated helpers
in the following commit.
2018-11-29 09:28:17 +00:00
Christophe Simonis c9356a1096 [FIX] core: adapt forward-ported code after 4d581e26c2 2018-10-22 19:26:18 +02:00
Christophe Simonis 9dbb7d199c [MERGE] forward port branch 12.0 up to b81c2bce84 2018-10-22 17:57:08 +02:00
Martin Trigaux 933165ec3a [FIX] models: restore warning on wrong record
Was lost during d5b687a48f

Set the module name in the context to be able to detect errors in xml and csv import

closes odoo/odoo#27680
2018-10-21 08:41:22 +00:00
Christophe Simonis 1810f6be4c [FIX] core: early fail on missing foreign records
When installing/updating a module, verify existence of foreign records
before updating them.  Also handle forcecreate=False records.

Also fix misprefixed XML id in sale_quotation_builder.

closes odoo/odoo#27659
2018-10-19 11:23:47 +00:00
Xavier Morel a8ee940e38 [REM] core: assert, ir_set and url tags from XML data files
* ir_set and url were accepted by the RNG despite ir_set having been
  removed back in 2015 or so and <url> having possibly never existed in
  the first place (could not find any reference to an <url> element
  outside of sitemap qweb templates)
* <assert> was essentially deprecated/removed in 2015 with the v9
  accounting having stopped running account_assert_test.xml, which was
  the last file using the tag so far as I can tell. The file itself
  remained as dead code until 2018
2018-10-11 15:01:59 +00:00
Xavier Morel 4d581e26c2 [REF] core: cleanup noupdate handling in XML import
Use the same pattern as for the envs: a stack of noupdate values pushed
and popped around data nodes.

Avoids re-parsing the same noupdate attribute on every node execution,
and completely removes the need to pass the nearest data node to every
_tag_ function.
2018-10-11 15:01:36 +00:00
Xavier Morel bf0ed03d0f [FIX] core: support for uid/context in XML data files
* add tests for uid/context on record & function & root nodes (odoo,
  data, openerp) "inherited" by record & function
* add rng validation to the test cases to ensure technical
  capabilities are matched by validation capabilities (which was not
  the case as we could validate nonsense and import stuff which didn't
  pass validation or something)
* extact uid/context into its own rng pattern
  - add uid support to record validation
  - add uid support to root nodes validation
  - fix uid support on function validation: was typoed to @id, which
    is not used anywhere in function tags loading & makes no sense
    as far as I can tell
* replace get_uid/get_context by get_env & reimplement the whole mess:
  build a stack of environments from the root nodes (each root node =
  one env in the stack, though the exact same env can be present
  multiple times if none of the root nodes has a @uid or @context) and
  leaves can build upon this "ready made" environment for their own
  uses or use it as-is.

  As a result, all uid/context should now properly transfer from the
  root nodes to the leaves needing them
* fix support for context on functions: was not actually implemented
  as the context was not propagated into the old-style API call
* add uid support to record & context is now inherited from env
2018-10-11 15:00:22 +00:00
Xavier Morel 77b5911137 [IMP] core: convert_xml refactorings to prepare for improvements
* add _tag_ methods for root nodes (remove some of the parse special
  casing)
* remove unnecessary/useless returns
* remove cr & uid (there's an env)
* remove mode argument from callbacks (redundant and confused with
  self.mode)
* try to cleanup menuitem callback a bit
* make second callback param not optional (because it's not)
2018-10-11 14:59:51 +00:00
Florent de Labarre c181033a6d [IMP] tools: replace SQL code
No need to construct the table name, can use the model name

Closes #25659
2018-08-20 16:58:38 +02:00
Jeremy KerstenandDerie Romain c0968e68ed [ADD] website_theme_install: try to make theme multi website compliant
From now, when you install a theme, it load the data from xml to template
table theme [ir.ui.view|ir.attachment|website.page|website.menu].

Data are only copied from this template table into the real table when you
choose a theme on a website; Making them website_specific and with a link
to the original to allow futur update.

A special case is done to create theme.ir.ui.view when you are installing
a theme, even if you continue to use template tag to create quick view.

Co-authored-by: Derie Romain <rde@odoo.com>
Co-authored-by: Kersten Jérémy <jke@odoo.com>
2018-08-13 20:16:34 +02:00
Raphael Collet d5b687a48f [REF] models: import records in batch
Create new methods on `BaseModel` to create records with given xml ids in
batch.  Those methods replace the methods `_update` and `_update_dummy` of
model 'ir.model.data', which are now deprecated.

Adapt XML and CSV import code to create records in batch.
2018-07-24 16:58:14 +02:00
Xavier Morel 93c0d7e811 [IMP] de-commit-ify db/module install
Try to remove cr.commit (and rollback) from module and db install:

* put a savepoint around test data loading
* remove a bunch of commits sprinkled throughout
* remove rollback on data loading failure (assuming it bubbles up, the
  entire module's installation should be rolled back)
* add commit right before the tests are run, so they can run isolated
  and still see whatever was done when installing their module
* convert a few explicit closing to context managers
2018-07-16 11:44:32 +02:00
Raphael Collet 627292f7f3 [IMP] convert: simplify context when creating records
The context was containing a dictionary under the key `install_mode_data`,
which was informing about the model, xml_id, module, filename.  Actually only
the module and filename were necessary, and the others were slowing down the
import because of generating artificially different environments.

The context now has two entries `install_module` and `install_filename`.
2018-06-01 13:30:28 +02:00
Christophe Simonis eeae2b80ea [MERGE] forward port branch 11.0 up to b793e23ae5 2018-05-09 13:55:27 +02:00