*: barcodes, mail, mass_mailing, note, test_website, web, web_tour,
website, website_blog, website_event, website_form, website_forum,
website_mail_channel, website_mass_mailing, website_profile,
website_sale, website_twitter, doc
New solutions are being investigated in master. For the moment, it seems
better to remove Jabberwock to unlock difficult forward-port between
14.0 and 14.1/master, until we decide what to do once and for all in
a later master. We may un-revert this later but that would be way easier
than reverting Jabberwock in a few months.
This was done as safely as possible by removing any commit related to
Jabberwock, then resolving conflicts, then reforcing commits from 14.0
that were hugely adapted for 14.1/master, then forcing the whole diff
over a rebased 14.1/master. The only possible miss (other than me making
a mistake) would be commits that were not forward-ported to 14.1 thanks
to Jabberwock handling the issue on its own (I know we had such commits
in website, which I manually included in this revert, see below).
For reference:
Commits which were reforced to their 14.0 version:
- https://github.com/odoo/odoo/commit/1a916fc2362c0b006460d94a219366ade1cce058
- https://github.com/odoo/odoo/commit/fd9e58a675bb7ec1bf97cb77b21b3c65369d51fe
- https://github.com/odoo/odoo/commit/bdfddace29b16404c06a7ebfc0cc242463a0e768
- https://github.com/odoo/odoo/commit/42b3ad10e0b32b7fc72f801e2c67d6baf938c566
- https://github.com/odoo/odoo/commit/710784da1f02d45cbe898da426ba7e2ac63dc711
- https://github.com/odoo/odoo/commit/597585c9b8b1350bcfd84e8433ea6c82060bcc3d
- https://github.com/odoo/odoo/commit/333a9124608ff655bd9ad5e63044a5cb7ef9c636
Commits that were not forward-ported to 14.1/master and now are:
- https://github.com/odoo/odoo/commit/55ff2d971b672dec5f103215be39101c88856b6c
- https://github.com/odoo/odoo/commit/ebbb3de1e5f363689a5ba1647bb4c26416e42d5b
+ Adapt this forward-port: https://github.com/odoo/odoo/pull/60976 (as
it was simplified for non-stable master version relying to the
Jabberwock implementation and now needed to be adapted to the
summernote implementation).
See `!$el.data('oe-expression') && $el.data('oe-xpath')`
+ Revert https://github.com/odoo/odoo/pull/60477 and reforce original
14.0 fix https://github.com/odoo/odoo/commit/746bf53b4aecfc601f0581a948d7cb7153812c82
Note: this also means that any good refactoring that was done by the
Jabberwock-related commits is lost for now. Once the revert reaches
master, I'll try and restore what we want from those commits. Here
are their references (but obviously they have the opposite conflicts
than those resolved during this revert):
e766842a92b6 [REM] web_editor,website: empty summernote files
08c94c986e09 [REF] web_editor,web: adapt to new jabberwock editor
1546c1b74713 [REF] mass_mailing: adapt to new jabberwock editor
fd0b963c6028 [REF] website: adapt to new jabberwock editor
0113d05c6c94 [ADD] web_editor: add new Jabberwock editor lib
d0c88a396493 [FIX] web_editor: don't change background color out of the website editor
d52d3d67d4e1 [FIX] web_editor : better icon in text style dropdown
61cb2f0d21da [FIX] web_editor: should not ask if want to leave the page twice
c42012b863b5 [FIX] web_editor: trigger a resize when use the mobile preview
d934d05d6e39 [FIX] web_editor: need to build the snippet before commit it into vDom
495bea924745 [FIX] web_editor: remove box shadow on the #wrap container
bffb5612e689 [ADD] field_html: add resizer in most field_html
f3c94e40cccf [IMP] web_editor: update Jabberwock library to commit 41e4063
cc87dea3ef32 [FIX] web_editor: update header change position to work with JW
5d9b25f66704 [FIX] web_editor: do not insert chars around step icon on click
70d3f0e4630c [IMP] web_editor: update Jabberwock library to commit 0bd94881
a57f13891f82 [FIX] web_editor: open media modal in appropriate tab on dblclick media
5b7537397e08 [IMP] web_editor: update Jabberwock library to commit a7ba7c34
a8d7ec235eeb [FIX] web_editor: adapt iframe Qunit test to new editor
5f794eac7209 [FIX] mass_mailing: hide all panels on show themes
551d45641d19 [IMP] website: remove unused reference
10580e1c102f [IMP] wesbite: add comment in tour
c17049f6b764 [FIX] web_editor: Fix description toggle in pricelist snippet
18a428e854b1 [IMP] web_editor: update Jabberwock library to commit 43a10003
58a161c645a5 [REF] web_editor, website: use editor helper setClass
62dd0bd3bc66 [FIX] web_editor: properly deactivate snippets and reactivate the last
99eebcaa34cb [FIX] web_editor: disable snippet in preview mode on mouse leave options
a84216932958 [FIX] web_editor: fix the image gallery snippet
f8dd4ea3e7d5 [FIX] web_editor: fix shadow selector for Safari
e50a4f3a16de [IMP] web_editor: update Jabberwock library to commit de13ed7e
4a2718f7a5ba [FIX] web_editor: ensure dom is properly cleaned at end of save test
03684c004a4e [FIX] website: ensure reset of bg-image on add bg-video
d63397159708 [FIX] web_editor: fix image remove from images wall
82fa5142f1a5 [IMP] note: restyle note without sheet or resizer
8b9f1ce603d5 [FIX] web_editor: properly mock createWysiwygIntance (sic) in tests
fc2183b66305 [FIX] web_editor: image overlay did not update with changes
cd0d2f5791cd [FIX] web_editor: add color preview to color picker
28a168172454 [FIX] web_editor: restore removal of spinner
67c90dd3b946 [FIX] website_forum: properly initialize editor
920dfe2a430a [FIX] website_forum: better css in the JW toolbar
43f33fd651af [IMP] web_editor: update Jabberwock library to commit 6853b60
71246c92f8de [FIX] Web_editor: table options button should be inside the toolbar
12b9e5916692 [FIX] web_editor: properly update the image options on replace image
e889cf8583da [FIX] website, website_sale: properly save filter id of dynamic snippets
e0fd11e36e45 [IMP] web_editor: update Jabberwock library to commit 4b2c903b
8f2b7ba35614 [FIX] web_editor: properly stop snippet option changed event propagation
a30c2c4105c7 [FIX] website: fix megamenu snippet editor behavior
312091cf822b [FIX] web_editor: fix overlay that is not reappearing
9f1d03dda613 [FIX] web_editor: table picker not fully displayed
814ddada6124 [IMP] web_editor: remove message before leaving page if editor is destro
4f38e26af7da [FIX] web: allow saving copyright footer
01e947b6123b [FIX] web_editor: only save translations that changed
103676072c50 [FIX] web_editor: prevent traceback on open crop dialog
5844ff66d4a0 [FIX] web_editor: apply image crop in jw on save dialog
1b435652e4a0 [FIX] website_forum: ensure media modal opens on click button
4f4a6ca0b8ac [FIX] web_editor: ensure valid default html value
51e22026ac7b [IMP] web_editor: update Jabberwock library to commit ab1184f8
2413fa19be0e [FIX] web_editor: Qunit test properly wait for editor stop
aa89e1ea3e97 [FIX] web_editor: properly save view blocks with an id
e2e90b53992e [FIX] web_editor: ensure language selector is non editable
0efd72089d5c [IMP] web_editor: clean useless lines
f54dfc7631f9 [IMP] web_editor: remove useless comment
3995ab1b84f2 [IMP] web_editor: update Jabberwock library to commit b8d73691
0834b1e5740a [IMP] web_editor: withDomMutations
f1459fb7b45c [FIX] web_editor: fix non-deterministic error in QUnit wysiwyg tests
6e8acc6c8cc7 [IMP] web_editor: update Jabberwock library to commit 3bbb175c
18a0c95d51cb [FIX] website, web_editor: #wrapwrap in body
4686a92e742c [FIX] website_form: allow edition of success message
78cc4da075cc [FIX] web_editor: allow edition of branded nodes only
bcffa7353448 [FIX] web: dialog should not use field value footer items
67ff56e14746 [FIX] web_editor,website_mass_mailing: display the popup preview
3cb9bea50c20 [IMP] web_editor: update Jabberwock library to commit a20492ea
518f03e6f1c9 [FIX] web_editor: use withIntangibles to find ZoneNode
d0ad6a568f49 [FIX] website: move sidebar out of theme
d690f5da13ea [FIX] website: properly save popup id
43b3433df3e6 [FIX] web_editor: fix non-deterministic error in QUnit wysiwyg tests
4ee8f4dedc30 [FIX] web_editor: prevent deadlock when removing child snippet of popup
850be198ef6d [FIX] web_editor: prevent traceback on reposition background image
4c3eaba41f5d [FIX] mass_mailing: adapt tour to the new editor design.
496d3ea272ed [FIX] web_editor: properly position sidebar scrollbar
5be4de703074 [FIX] web_editor: Show the toolbar when select the text in forum edition
closesodoo/odoo#63768
Related: odoo/enterprise#15458
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
1) Replace editor function that change the editor internal structure
with a new mechansim that does it automatically by observing dom
mutations. Welcome wysiwyg.withDomMutations.
2) Add a mechanism to reuse the active editor execution context
when a wysiwyg.execCommand or wysiwyg.withDomMutations is called
inside itself.
Example:
await wysiwyg.execCommand(async ()=> {
...
await wysiwyg.execCommand(()=>{...})
await wysiwyg.withDomMutations(()=>{...})
})
closesodoo/odoo#63237
X-original-commit: fe7056ccb450c9767693671e8d980a6aebacd6ab
Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
These functions convert plain text links into clickable hyperlinks.
These open in new tabs but did not have the "noreferrer noopener" rel
attributes, which made them susceptible to reverse tabnabbing.
A lot of attack vectors were available to unregistered, uninvited
anonymous users and presented a significant phishing threat (such as
posting links in the instant-chat, through a mail-alias, in a forum post
or in a twitter post) and leading the operator to believe he had been
disconnected from odoo in the original tab, prompting them to enter
their credentials.
while these three places will add the noreferrer and noopener attributes
on the anchor tags generated by them, there are still many places that
create hyperlinks without the use of these functions, although most of
them are static links, they still represent a transitive security
vulnerability to the linked sites.
There are also a few modules and widgets that roll out their own links
or open new tabs unsafely using window.open(), these will need to be
patched separately.
closesodoo/odoo#37591
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Animations (now public widgets) are now disabled by default in edit
mode. It is opt-in. That one should have been enabled and was left
disabled by mistake.
task-2070930
closesodoo/odoo#36807
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
* web, website_blog, website_sale, website_twitter
Before this PR, all website widgets were named 'Animation'. Now that
they are 'Public Widgets', we can at last stop using the confusing
'animation' name.
Part of https://github.com/odoo/odoo/pull/29442
task-1932066
* website_blog, website_crm_partner_assign, website_event,
website_event_track, website_form, website_forum, website_links,
website_mail, website_mail_channel, website_mass_mailing,
website_sale, website_sale_comparison, website_sale_delivery,
website_sale_stock, website_sale_wishlist, website_slides,
website_twitter
While using the 'Animation' class of website instead of the frontend
'Widget' class leads to the same behaviors, this refactoring is done for
two reasons:
- Stop using the confusing 'Animation' name for non-animated behaviors
- Instantiation of 'Widget' is slightly faster than 'Animation'
Part of https://github.com/odoo/odoo/pull/29442
task-1932066
The system completely changed. I also had to adapt classes to new
screen breakpoints.
hidden/hide -> d-none
show -> d-block
hidden-xs -> d-none d-md-(block/inline/...)
hidden-sm -> d-md-none d-lg-(block/inline/...)
hidden-md -> d-lg-none d-xl-(block/inline/...)
hidden-lg -> d-xl-none
visible-xs-* -> d-* d-md-none
visible-sm-* -> d-none d-md-* d-lg-none
visible-md-* -> d-none d-lg-* d-xl-none
visible-lg-* -> d-none d-xl-*
hidden-print -> d-print-none
visible-print-* -> d-none d-print-*
...
and all possible combination of those had to be handled too.
Description of the issue/feature this PR addresses:
Accessibility improvements forbids the use of the syntax
`<i class="fa fa-check"/> Some text`
to create a labelled icon. But, by this, some fonts are changed.
Desired behavior after PR is merged:
The old syntax can be used.
Today, Odoo is really tricky to use without seeing the screen, it must be improved to be usable.
This PR forbid to use labels without a "for" attribute, add some title, rule and aria attributes in HTML. With that, Odoo will be fully usable with a screen reader.
* [IMP] Labels must have a for attribute. Improve accessibility.
* [IMP] Better error message when trying to read a missing cached value
* [FIX] Add some aria-label and title attributes for screen readers.
* [FIX] Template name is not included in the error message in case of SyntaxError in QWeb
* [FIX] Improve the Tour failed at step error message to be more explicit.
* [IMP] Add aria-labels
* [FIX] Add missing aria-label on failing test
* [IMP] aria-hidden means hidden. Fix all bad aria-hidden and hide aria-hidden for all.
* [IMP] Color names on kanban views and many2many tags
* [IMP] Add some checks on views for accessibility.
* [IMP] Add `alt` attribute on `img` tags.
* [IMP] Add aria-label and title on non-described icons
* [IMP] Add button role to widgets with btn class
* [IMP] Translate aria and formatted attributes.
* [IMP] Remove wrong aria-labelledby
* [IMP] Add menu role on dropdowns
* [IMP] Buttons must be focusable
* [IMP] Add aria attributes on progress bars
* [IMP] Improve accessibility of basic widgets
* [IMP] Change main layout to more semantic tags
* [IMP] Add menuitem role when missing
* [IMP] Remove wrong role='presentation'
* [IMP] Improve accessibility of tab panels
* [IMP] Add aria-invalid on invalid fields
* [IMP] Add aria-sort on ordered columns
* [IMP] Add role on alerts
* [IMP] Use dialog role, header, main and footer tags for modals
* [IMP] Add labels on o_status
* [IMP] Improve accessibility of kanban view with feeds and articles
* [IMP] Add alerts in case of new messages
* [IMP] Add widget, navigation or img role to aria-labelled items
* web_editor, website_twitter
- There can now be multiple animation widget on the same element
- Animation are destroyed before saving the editor (allows to not be
forced to do that destruction / code duplication in many cleanForSave)
- .data('snippet-view') is definitely dead
+ Some layout fixes
+ Controllers routes renaming
+ SASS -> LESS
Note: animations and layout could be further improved but the goal of
this commit was to refresh the code to master's new conventions.
* mass_mailing, payment, point_of_sale, portal, survey, web, web_tour,
website_blog, website_crm_partner_assign, website_event,
website_event_questions, website_form, website_forum, website_gengo,
website_hr_recruitment, website_links, website_mail,
website_mail_channel, website_mass_mailing, website_quote,
website_sale, website_sale_options, website_slides, website_twitter
This commit reviews the whole "JS side" of the web_editor and website
apps. This is a first step to be able to improve them with new and
better functionnalities; this commit is not supposed to change any
visual behavior.
The main goal was to achieve a structure similar to the backend one.
Now, the frontend side also has a root widget (like the WebClient)
and all other widgets are attached to it one way or another. This allows
the benefits of using the 'trigger_up' functionnality for example.
As RPC are now mainly done with the `this._rpc` functionnality (being
possible thanks to the parent hierarchy), the frontend will also be
possible to test thanks to QUnit in a future update (besides the "text"
editor side which still requires a refactoring to be able to do that).
---
Here are some of the changes:
(-) conventions and documentation
The code has been updated to follow JS conventions and a lot of code has
been commented (around +2000 lines of comment). This also means that
lots of functions have been renamed to use camelCase or simply to make
their name understandable.
See https://github.com/odoo/odoo/wiki/Javascript-coding-guidelines.
(-) deprecated: web_editor.base
The "web_editor.base" module has been split and does not force the
modules which require it to wait for DOM ready anymore. This was indeed
slowing loading times, but also prevented to use some modules in some
contexts (see the LESS editor use in web_studio which is the subject of
another task).
Now the "editor context" can be got thanks to the "web_editor.context"
JS module with its "get" function.
The "web_editor.base" module should probably not be used anymore (see
its code and recent updates).
(-) new: web.dom_ready
If a JS module should wait for the DOM to be ready to be executed, a
new JS module has been created: "web.dom_ready". This should always
be used in a module which only want to instantiate stuff. Do not
extend (or worst, include) classes after DOM ready.
(-) website.website
The "website.website" module has been split. "website.website" does not
return anything useful anymore, it just initialize some miscellaneous
stuff, without waiting for the DOM to be ready. You might want to check
"website.utils", "website.content.compatibility" or `WebsiteRoot`. Also
`website.form` has been deleted (use `this._rpc`), so has been
`website.error`. `website.prompt` will be removed in a future update to
be replaced by `Dialog.prompt`.
(-) widgets are great
Many classes which were not widgets are now widgets. This allows them to
use the 'events', the 'xmlDependencies' and the 'this._rpc' features for
example. Here are some of the main ones:
- Snippet options: these were classes with a `$el` for the menu element
and `$target` for the customized element. This is still the case
but following standard `Widget` structure (one exception: using
`this.$(...)` searches in the `$target` as before this update).
- Snippet animations: instead of class instances with a `$target`
element which can be `start` and `stop`, these are now standard
widgets which can be `start` and `destroy`. `this.$target` is
an alias to `this.$el` for ease of compatibility.
- Snippet editors: instead of class instances in charge of an editor
overlay, these are now widgets. Each "child" snippet editor is
properly attached as a "child", which allows editors to communicate
and to be properly destroyed.
(-) root widgets and website navbar
The frontend is different of the backend. In the backend, the page has
an empty <body/> element and all the components are instantiated from
parent to children (i.e. the `WebClient` is instantiated and is in
charge of instantiating the `ControlPanel`, etc). The frontend cannot
work like that on page loadings as they are way more frequent than in
the backend and we do not want them to flicker. A frontend page is
loaded as a <body/> element which already contains the website navbar
and its menus and the whole content page. JS code has to be "attached"
to these existing elements. This is possible thanks to the `RootWidget`
instances and the specialized `WebsiteRoot`, `IframeRoot` and
`WebsiteNavbar` (see code for details).
(-) lazy loading
No more (or at least a lot less) XML/JS has to be loaded on page
loading, thanks to the use of the `Widget.xmlDependencies` feature.
XML which have to be lazy loaded is loaded only on related Widget
instantiation if necessary, which allows to execute a lot of JS code
before the DOM is ready and to start many widgets on DOM ready (not
later). A visual benefit of this is clicking on the 'edit' button as
soon as it is possible: before this commit, this was sometimes not
doing anything as event handlers were not binded yet.
Still a possible exception: loading the session and locales. This may
be asynchronous stuff which is still required before widget
instantiations but this will be the subject of another task.
(-) deprecated code and code location
More than reviewing code and organizing it, many apparent dead code was
removed. More importantly, mislocated code was put in the right app.
This is the case for snippet animations which is a concept for website
apps but was defined in the web_editor app, or some translation concepts
which were part of website but should have been part of web_editor.
---
There are probably more things to say about this commit but I will let
the comments speak for those.
* mail_channel, mass_mailing, twitter, event
- t-install attribute holds the technical name of the module that
needs to be install to use a particular snippet.
- Disable the drag & drop feature for these dummy snippets.
- Move some images to website module.
- Installed snippets display at the top of the list.
- Hide not-installed module snippets if user don't have rights to install module.
The module system needs to know the dependencies of a given module
before executing the function. This is why the dependencies were
defined once in an array, and then were described one more times in the
call to require.
But a trick can simplify this: the boot function can parse the string
representation of the module and extract the calls to require from it.
It is more work for the processor, but it leads to simpler module
definitions.