Commit Graph
885 Commits
Author SHA1 Message Date
Olivier Dony b02dea7688 [IMP] config: allow blocking access to db manager
- The `--no-database-list` option will now also block access to database
  management functions and screens.
  Presumably this flag should only be used in production when all
  databases have been provisioned, so the admin should like to block
  access to the db manager at the same time.

- If no `--database` or `-d` parameter is provided, the system will be
  unable to fetch a list of databases at all, so users will be blocked
  with an error message.

- Hide the link on the login screen to the DB manager when it is
  disabled, to prevent sending users to an error page.

- Weak attempt at updating the documentation

Note: the security check for RPC methods could have been done in the RPC
dispatcher, however that would not have protected service methods when
called directly, e.g. by a controller (e.g. the dump method).
2017-10-03 12:46:03 +02:00
Olivier Dony 7d16769263 [IMP] config: support hashed master passwords
- Add support for hashed master passwords (super-admin password) using a
  strong scheme (PBKDF2_SHA512).

- Replace the password with a hash in memory (tools.config map), after
  verifying it

- Automatically replace the plaintext master password with a hash when
  saving it after a password change

- Preserve support for setting/using plaintext passwords when necessary
  (e.g. as a temporary deployment thing)
2017-10-03 12:45:22 +02:00
Jeremy Kersten 1b52b00d2a [IMP] website*: clean sitemap + add method to declare sitemap function.
Don't add useless routes or route that will return 404.
Improve generate function from ModelConverter to have a better management of
query_string.

Now we have an helper sitemap_qs2dom that will analyse the current route and
check if query string is plausible and if yes, generate a domain, when the
query_string don't seems to match the route, we return a Falsy domain.

Before this commit, if qs was /product/ipad, enumerate_page check for each
modelconverter of the route a name ilike '/product/ipad'.

Now we check all routes that contains product and one converter that match ipad
or routes that contains ipad and one converter that match product.

This commit a new way to declare the sitemap for a route.
    def sitemap_xx(env, rule, query_string):
        yield {'loc': '/my_url'}
    @http.route(..., sitemap=sitemap_xx)

    In this case, only the loc returned by this function will be in the sitemap
    for all rules.

    You can pass sitempa=False, if you don't want that route are into the sitemap
2017-09-27 21:33:49 +02:00
Olivier Dony 2257583bb5 [ADD] ir.attachment: add token field for external access
Introduce a new attachment field (access_token) to allow external
unauthenticated access. This will be an opaque unique number
(typically a UUID) that should be provided via an appropriate
controller, for unauthenticated display.

The field is intended to be NULL unless unauthenticated access has been
allowed, in which case a value will be set for the access_token.

This could be used e.g. for allowing access to images within mailings,
even when the recipient is not logged in (which is sometimes entirely
impossible, when email providers use restricted proxy servers to
load images)

Note 1: this is still a work-in-progress, but serves to freeze the API.
The implementation of the access check and provisioning of the new
field will be added later.

Note 2: namimg collisions with the file download token prevent the use
of a shorter 'token' parameter for download routes.

Apologies for the late (and incomplete) addition in saas-18 :-/
2017-09-21 23:48:36 +02:00
Yannick Tivisse 2e3848b394 [IMP] web: Add the possibility to crop an image in web/image controller
Purpose
=======

Could be useful if you want to load a preview of an image as a thumbnail
2017-09-05 15:52:15 +02:00
Christophe Simonis 4879ce0407 [MERGE] forward port branch saas-17 up to fe77df3ba4 2017-08-31 12:55:41 +02:00
Christophe Simonis 71f370903c [MERGE] forward port branch saas-16 up to 600d015938 2017-08-30 18:18:59 +02:00
Christophe Simonis 600d015938 [MERGE] forward port branch saas-15 up to cb4dbfb7b7 2017-08-30 18:04:40 +02:00
Christophe Simonis cb4dbfb7b7 [MERGE] forward port branch saas-14 up to 583fcf0a67 2017-08-30 16:13:19 +02:00
Christophe Simonis 583fcf0a67 [MERGE] forward port branch 10.0 up to 1b7e31f341 2017-08-30 15:34:58 +02:00
Christophe Simonis 792204ae9e [MERGE] forward port branch saas-11 up to dce35ca44b 2017-08-30 14:15:32 +02:00
Christophe Simonis 6c6ba6c78a [MERGE] forward port branch 9.0 up to 81908899fc 2017-08-29 16:07:03 +02:00
Lucas Perais (lpe) f32a79dd82 [FIX] web: limit amount of rows for excel export
Before this commit, when the amount of rows was above xls format threshold (>65535), the xlwt library threw an obscure Traceback to the user.

We now test the amount of rows before even calling the library, raising a more helpful message to the user

OPW 767319

closes #19035
2017-08-28 14:22:47 +02:00
Raphael Collet 10cb1beead [REM] base: remove model ir.values 2017-08-28 09:53:23 +02:00
Christophe Simonis 017ee5eab3 [MERGE] forward port branch saas-17 up to 877e709871 2017-08-24 13:17:53 +02:00
Olivier Dony 695716efb0 [FIX] P3: remove pycompat.{keys,items,values} helpers
Now that we're closer to switching to P3 for good, these helpers have
outlived their usefulness, and mostly add noise.

All remaining dict.iter*() or dict.view*() must be converted to the
normal keys(), values() or items() calls.

Whenever the result is likely to be used for more than the scope of a
loop, or when the dict needs to be modified during iteration, the calls
must be wrapped in a ``list()``, to protect the new P3 semantics.
Those cases are very exceptional.

Also removed some dead code or improved the API to remove unnecessary
conversions.
2017-08-20 23:25:54 +02:00
Xavier Morel bc7dce254d [FIX] P3: text model, base_url is a string but query_string is bytes 2017-08-20 23:25:54 +02:00
Xavier Morel be7c5aefdf [FIX] P3: CSV reading & writing 2017-08-20 23:25:54 +02:00
Xavier Morel 7dd062f835 [FIX] P3: text model types
* remove references to basestring & unicode (use relevant pycompat
  helpers)
* remove some str calls (either entirely or replaced by relevant
  helper, either text or native)
* use better API to avoid unnecessary conversions
* remove some XML declarations in views
2017-08-20 23:25:54 +02:00
Xavier Morel 3824b5dcc1 [FIX] P3: fix base64 and StringIO uses
* StringIO removed from stdlib, replace with io
* try to correctly handle BytesIO/StringIO (one is for bytes the other
  is for text)
* fix base64: Python 3 removed bytes-encoding and bytes-bytes
  codecs (via #encode) so replace all calls to str.encode('base64'),
  also b64encode is a bytes->bytes conversion so attempt to properly
  handle that

issue #8530
2017-08-20 23:25:54 +02:00
Christophe Simonis 1fa8680286 [MERGE] forward port branch saas-17 up to 48b2ce60ed 2017-08-10 18:07:47 +02:00
Christophe Simonis 48b2ce60ed [MERGE] forward port branch saas-16 up to 85571bb78c 2017-08-10 17:01:05 +02:00
Christophe Simonis 85571bb78c [MERGE] forward port branch saas-15 up to dde62073ba 2017-08-10 16:22:36 +02:00
Christophe Simonis c3d710d2f6 [MERGE] forward port branch saas-14 up to 80ac087d6e 2017-08-09 17:11:10 +02:00
Christophe Simonis 80ac087d6e [MERGE] forward port branch 10.0 up to f69655829a 2017-08-09 15:53:37 +02:00
Jerther 64190abec5 [FIX] web: display full error message
Add missing parenthesis, fixes ebc23b5
2017-08-09 09:53:26 +02:00
Thibault Delavallée ea27c1b7a3 [MOV] website_portal, portal: move customer portal to portal module
This commit moves the whole customer portal to the portal module.
It now completely uses portal and http_routing features and is not
dependent on website anymore.

An override of web controller is added in portal in order to redirect
portal users to /my instead of /web. That way once having the customer
portal installed all share users are correctly redirected to their
account.

All modules defining customer portal templates and controllers are
updated accordingly.
2017-08-08 14:58:49 +02:00
Christophe Simonis f46a393602 [MERGE] forward port branch saas-16 up to 09d698d05f 2017-07-31 14:53:06 +02:00
Christophe Simonis 09d698d05f [MERGE] forward port branch saas-15 up to a6900c43b4 2017-07-31 14:09:34 +02:00
Christophe Simonis a6900c43b4 [MERGE] forward port branch saas-14 up to 9cae991345 2017-07-31 12:59:48 +02:00
Christophe Simonis 9cae991345 [MERGE] forward port branch 10.0 up to 1e64a88cd3 2017-07-31 11:45:29 +02:00
Jeremy Kersten f3f66d2b8e [FIX] web: avoid cast None in int
Some function send None instead of 0
2017-07-28 18:30:01 +02:00
Christophe Simonis bf51fe55a1 [MERGE] forward port branch saas-16 up to 0f2b2c4e2b 2017-07-07 14:30:30 +02:00
Denis Vermylen 6977a363e4 [IMP] web, auth_signup: add signup and login values to session
When you receive an url with parameters

 * auth_signup_token: uuid
 * auth_login: login

those will be stored in the session and used

 * when the user will want to sign up in order to be linked to the right
   partner;
 * when he logs in so he's sure to log in with the right account +
   autofill is nice

This commit only adds the support, future commits will support its use.
2017-07-06 12:53:39 +02:00
Christophe Simonis 780ae8a808 [MERGE] forward port branch saas-15 up to 10cb34bcac 2017-07-04 18:14:13 +02:00
Christophe Simonis 10cb34bcac [MERGE] forward port branch saas-14 up to 97258040d8 2017-07-04 14:40:20 +02:00
Christophe Simonis 97258040d8 [MERGE] forward port branch 10.0 up to 657e328903 2017-07-04 13:17:16 +02:00
Jeremy Kersten 15da3356a0 [FIX] web: /web/image fix resize if only one limit (height or width)
The old code don't resize correctly if you use params in request.
because if '200' > 500 => return True

Now we force the casting to int to be sure to compare apple to apple.

before: /web/image/<id>?height=100 => don't return an image with height=100px
after: /web/image/<id>?height=100 => return now an image with height=100px
2017-07-03 10:56:31 +02:00
Christophe Simonis 99c34c4119 [MERGE] forward port branch saas-16 up to 6f3eada2c3 2017-06-06 19:38:29 +02:00
Christophe Simonis 6f3eada2c3 [MERGE] forward port branch saas-15 up to f687a27b79 2017-06-06 19:23:03 +02:00
Christophe Simonis f687a27b79 [MERGE] forward port branch saas-14 up to c0e7f9b0b1 2017-06-06 18:57:56 +02:00
Christophe Simonis c0e7f9b0b1 [MERGE] forward port branch 10.0 up to a85790be5c 2017-06-06 18:49:36 +02:00
Martin Trigaux ebc23b594a [FIX] web: display full error message
In case of a MemoryError, there is no error message, the user gets a
"Database restore error: "

without any details.

Instead fallback to the repr.

This way, a wrong password is
"Database restore error: Access denied"
and a memoryerror

"Database restore error: MemoryError()"

Closes #17393
2017-06-06 15:42:37 +02:00
Richard Mathot 04111cae39 [FIX] web: bad conversion to python3, el is an Etree, not a dict 2017-05-31 14:39:00 +02:00
Olivier Dony 5f4db9df66 [MERGE] Forward-port saas-16 up to 5afe894f44 2017-05-16 18:23:15 +02:00
Laurent Smet d5fa3232fe [FIX] base, report: fix some issues due to removed 'report' module.
fix related to task: https://www.odoo.com/web#id=31625&view_type=form&model=project.task&action=333&active_id=967&menu_id=4720

The 'report' module no longer exists but a dependency was still there in l10n_ca.

- fix dependency in l10n_ca
- fix broken company layout
- move layout templates from base to web
2017-05-16 15:37:15 +02:00
Géry Debongnie 15a227375a [ADD] web: add benchmark support
With this commit, we introduce a benchmarking infrastructure: a new
controller, accessible at the route /web/benchmarks which will render a
new template (web.benchmark_suite).

This template uses benchmark.js and qunit.js to display a list of
benchmarking informations.  For example, the number of op/s for
instantiating and destroying a list view.

I hope that this is the start of the beginning of taking the habit to
check our JS code performance sometimes, and making sure we do not have
large regression without a good reason.
2017-05-16 14:41:00 +02:00
Xavier Morel 07ab8b6cd2 [FIX] P3: Exception.message removed 2017-05-12 16:15:40 +02:00
xmo-odoo fffaf735f5 [FIX] P3: list -> iterable builtins (#16811)
In Python 3:

* various builtins and dict methods were changed to return
  view/iterable objects rather than lists
* and the separate Python 2 view/iterable builtins and methods were
  removed altogether

This is problematic when using these items as list (which the happens
repeatedly in Odoo), but more viciously when iterating *multiple times*
over them (which also happens, which I've messed up multiple times while
writing this, and which is a pain to debug even when you've just created
the issue).

Convert all code using these to semantics-matching cross-version
helper functions to get the LCD behaviour between P2 and P3, and
forbid the builtins via lint.

issue #8530
2017-05-10 09:39:55 +02:00
Laurent Smet e80238042c [REF] report: remove the report module
The content of the report module is now dispatched in
the 'base' and the 'web' modules.
2017-05-08 09:23:12 +02:00