Commit Graph
1083 Commits
Author SHA1 Message Date
Jeremy Kersten 2cab9a8341 [FIX] website: clean sitemap
followup of 8a0fc6476c70a4126043de3b3efbd1096e41f968

task-2065018

closes odoo/odoo#39211

X-original-commit: bfa239b59c4d02c2b03ab8a84b52bc8f77704e41
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-22 16:36:37 +00:00
Lucas Lefèvre 2bc060d13b [FIX] web: Avoid variable name confusion
The attribute `self._fields` is not well named. This is not a list of instances
of the Field class.
It is a list of field names to export.
e.g. 'journal_id', 'account_id/name'

X-original-commit: 6225ce60082d5d2b5fec0e678fe2a1f3f9b93668
2019-10-16 15:49:49 +00:00
Lucas Lefèvre 645ae69bb9 [FIX] web: Correctly aggregate values in exported parent groups
When exporting a grouped list view with some nested groups, the aggregate value
of parent groups are not correct. It always sums aggregated values of children
whether the group operator is 'sum' or not (could be 'max', 'avg', ...).

This behavior is wrong and can even lead to a crash if the aggregated field is a
date field (e.g. with group_operator='max'). (Try two sum two dates...)

The quick fix 85cf47f was merged just before OXP to avoid any crash. This fix
limited the support of aggregates to only int and float fields.
This commit remove this limitation.

This commit correclty implements the aggregation for parent group for all
field types and all group_operator.

This commit also improves the export feature tests.

X-original-commit: 5e7e4fa98698967e3c4fd0903f4aa8e91981a6cd
2019-10-16 15:49:49 +00:00
jbm-odoo e76c65e8b4 [FIX] web: Manage False in groupby title
Before this commit, when we export a list with a groupby on
boolean, the groupby title 'False' is replaced by 'Undefined'
in xls document.

After this commit, with an export and groupby on a boolean, we
will have correct title: True and False.

X-original-commit: 7e2c7bc35f2a5b3bc22e0e6c9d3b38279cda9367
2019-10-16 15:49:49 +00:00
Romain Derie 9bbf57f915 [REM] web: remove unused controller /apps/<app>
This controller never really worked in the last 3 versions.
It was fixed in 11.3 with e9350993ca but broken with refactoring in 12.0 at a
higher level with 19eacf7d23.

It was even worse in 13.0 as it was leading to a traceback: `view_type` field
got removed with 3cd7ed07a2 but this controller was still reading that
field.

closes odoo/odoo#38355

X-original-commit: a5c4e262449fef03d05d5250e4523832db5fbf00
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-10 08:56:22 +00:00
Christophe Simonis d74b451805 [MERGE] forward port branch 13.0 up to f4105eb9c7 2019-10-09 02:08:17 +02:00
Swapnesh Shah db1c909f33 [FIX] web: Support integer group name
Fixes https://github.com/odoo/odoo/issues/37998
Follow up on https://github.com/odoo/odoo/commit/5c4544fb2943e63fc1e0f5ae1e7e250a5a2b2cf1
As Integer fields are Supported for "Group By", they should be used as Group name

closes odoo/odoo#38007

Signed-off-by: lul-odoo <LucasLefevre@users.noreply.github.com>
2019-10-07 16:32:01 +00:00
Xavier Morel 0c7f7b186d [FIX] web, mail: move admin login warning to mail
Fixes #33254:

* was in mail despite using mail.channel (which breaks if mail is not
  installed, and web doesn't depend on mail)
* changes to sudo() broke previous behaviour (of having odoobot
  message the admin, we ended up with the admin messaging themselves)
  so fix that
* also get the channel and message with the user's context, otherwise
  since we're during the login procedure the context could be as
  little as just the lang from the browser and apparently channel_get
  automatically creates a translation which would break if the
  browser's lang is not installed in Odoo

closes odoo/odoo#37580

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2019-09-30 10:34:42 +00:00
Florian Gilbert 85cf47fc92 [FIX] Web controllers: quick fix for just keep number in aggregated_values 2019-09-27 09:19:38 +00:00
qsm-odoo cf27ff8fd3 [IMP] http, *: review cache TTL values
* base, web

Google now recommends a TTL of one year for static contents. We used to
use 1 week in almost every case. This commit increases that value to one
year for safe resources, like assets bundles which contain a specific
hash in the URL which changes if the bundle is recomputed anyway.

Note: this commit refactors the code so that both the one week and one
year durations are defined in http.py and used by others apps. Loading
the library "locale" file used to be done with 10-hours-cache, this has
been increased to 1-week-cache by using the http.py STATIC_CACHE var.

closes odoo/odoo#37402

Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2019-09-25 11:55:30 +00:00
Odoo's Mergebot f1aa96b0a8 [MERGE] web: Re-implement the XLS grouped export
Purpose
=======

The commit 2849b5c introduces a new export mechanism of grouped
list views to xls files.

The issue with this development is mainly that the displayed records
are exported, instead of all the records that match the search
parameters.

To export all the records we cannot rely on the data from the web
client. This implies to revert 2849b5c, and implement it in a better
way.

Functional Spec
===============

Add the support of grouped exports.
Allow the user to export all records in one click from
the listview, without having to go through the export modal,
taking into account the domain, groupbys, and visible fields.

Technical Spec
==============

When exporting (whether it is from the modal or from the shortcut),
any groupby(s) set on the listview should be taken into account (all unfolded)
- UNLESS the export is import-compatible
- each subgroup header has an indentation compared to its parent
- the 'group headers' in the exported file should contain the
  same info (label, field aggregates) as it has in the listview.

New secondary button on the tree view with label 'EXPORT' (to be confirmed...)
- the export shortcut disregard the selected records, it exports all records
  according to the domain.
- the button is visible even if there is no selected records.
- essentially the export shortcut does the same thing as the following:
    - select all records
    - hit 'action' then 'export'
    - hit 'export'

Define a boolean attribute on <tree> to specify whether or not the export
shortcut should be displayed

Task 2072910

closes odoo/odoo#37087

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-09-20 17:13:47 +02:00
Lucas Lefèvre 5c4544fb29 [IMP] web: Export grouped list view in xls file
PURPOSE
=======

Add the support of grouped exports.
Allow the user to export all records in one click from
the listview, without having to go through the export modal,
taking into account the domain, groupbys, and visible fields.

SPECIFICATION
=============

When exporting (whether it is from the modal or from the shortcut),
any groupby(s) set on the listview should be taken into account (all unfolded)
- UNLESS the export is import-compatible
- each subgroup header has an indentation compared to its parent
- the 'group headers' in the exported file should contain the
  same info (label, field aggregates) as it has in the listview.

New secondary button on the tree view with label 'EXPORT' (to be confirmed...)
- the export shortcut disregard the selected records, it exports all records
  according to the domain.
- the button is visible even if there is no selected records.
- essentially the export shortcut does the same thing as the following:
    - select all records
    - hit 'action' then 'export'
    - hit 'export'

Define a boolean attribute on <tree> to specify whether or not the export shortcut should be displayed

Task 2072910
2019-09-20 16:18:35 +02:00
Lucas Lefèvre 2849b5cb39 Revert "[IMP] web: Export list view as XLS file"
This reverts commit ac00548b28.
2019-09-19 14:00:49 +02:00
Sébastien Theys b6288e5446 [IMP] *: remove image_64 and clean views
There are too many image sizes. Since they are stored resized this takes time to
generate when saving a new image, it's more rows on the attachment table, more
files on the disk, ...

64px is close enough to 128px that it can be removed without a big impact on
download size.

It will even reduce download and number of requests when both images are
displayed because now only one has to be downloaded and then benefit from cache.

The difference between the two is typically around 1.5kB which is negligible
these days, especially when the request overhead is around 0.5kB already, not
even taking into account other factors such as latency.

If a 64px image must absolutely be returned, it is still possible to pass the
size parameters to the image route. But the current guideline is to handle
resizing in the views when necessary.

Views
=====

- remove width and height attributes when existing CSS rules are overriding them
  (eg. `.oe_kanban_avatar` in the right context)
- add CSS rules instead of width and height attributes when possible
- use `object-fit: cover;` where width and height are forced to avoid distortion
  of non-square images
- for products, use `object-fit: contain;` instead, keep ratio but without crop
- add new CSS rules where the expected size was max 64px*64px before due to the
  image size itself
- remove `img-fluid` where using size classes to avoid conflicting rules

task-2060865

closes odoo/odoo#36147

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2019-09-19 10:23:39 +00:00
RomainLibert dde0746725 [FIX] web: avoid having context twice
In case the context was manually passed to report_download, #36839
would pass the context keyword argument twice to report_routes.

That is not allowed in python so we update the current context with the
custom context from the report and pop the custom context from the
arguments

closes odoo/odoo#36989

Signed-off-by: Romain Libert (rli) <rli@odoo.com>
2019-09-17 08:52:56 +00:00
Lucas Lefèvre ac00548b28 [IMP] web: Export list view as XLS file
Purpose
=======

Have a quick export feature.

The current export wizard is quite complex.
We want to be able to quickly export a tree view,
with the group by correctly represented, depending on the fields
visible in the list view.

Specification
=============

Add an "EXPORT (XLS)" button in the list view (a little download icon)
- export only columns visible in list view
- export all the records
- while respecting the group by

This should be a generic feature but should be applied to all
the account.move.lines list views.
account.view_move_line_tree_grouped_sales_purchases
account.view_move_line_tree_grouped_bank_cash
account.view_move_line_tree_grouped_misc

Task 2031835

closes odoo/odoo#36943

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-09-16 13:57:40 +00:00
Julien Castiaux 7c47eb1854 [IMP] module.py: deprecate openerp
[PEP-594] is deprecating the `imp` module, that module is used in
`module.py` in order to dynamically import addons using any of the
`odoo.addons` or `openerp.addons` import anchor.

We are deprecating `openerp` module/addons imports in v13 in order to
remove the support in v14 and greatly simplify how modules/addons are
loaded. If you are still using the old `import openerp` or `import
openerp.addons`, `import odoo` and `import odoo.addons` are drop-in
replacements.

The `odoo.modules.module.ad_paths` addon paths list has been deprecated
too. The list is now accessible on `odoo.addons.__path__` where they
are now directly loaded [2].

See also:

[PEP-594]: https://python.org/dev/peps/pep-0594/
[2]: https://packaging.python.org/guides/packaging-namespace-packages/

closes odoo/odoo#36597

Task: 2003936
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2019-09-16 09:31:38 +00:00
fja-odoo 424adb63e3 [IMP] gamification, *: remove KarmaError
* = stock, test_website, web, website_forum, website_slides, base

Replace KarmaError with AccessError and remove the related override made
on crash_manager and ir_http.

task-2069890

closes odoo/odoo#36655

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-09-12 13:49:02 +00:00
RomainLibert 4c9624db9d [FIX] web: add context to /report/download
This commit fixes the /report/download route in multicompany

Since the multi company revamp (a5b6f31cf2)
the multi company rules depend on the context.

However the route /report/download was not forwarding any context, this meant
that when trying to read some fields on a record in a company that is different
than the default one, it would crash with the multi company ir.rule

Forwarding the context from the session in the Javascript call is quite simple
however since (521f7d36c1) it also requires to change
the signature of the `report_download` method in order to pass the context to the final
method.

As there was already some code allowing the adding of some context in `report_routes`
this PR reuses this code by simply passing the context as a kwargs.

closes odoo/odoo#36839

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-09-13 10:00:34 +00:00
Christophe Simonis 64e43808b7 [MERGE] forward port branch saas-12.5 up to 58a83d1222 2019-09-20 17:34:45 +02:00
Julien Castiaux b96e633b0b [IMP] web: upgrade the cache to use SHA2 over SHA1
SHA-1 is a cryptographic hash function that have weaknesses known since
2005, it has been deprecated by the NIST [1] about 10 years ago in 2011
and Google [2] have been able to perform a collision attack in 2017.

We use SHA-1 in order to generate unique URL for resources that can be
cached by the browser: assets bundle, translations, qweb templates and
qweb images.

Although practical attacks still requires quite a lot of computational
resources, it is time to upgrade SHA-1 to SHA-2.

We have selected the SHA-512/256 variant of the SHA-2 algorithm as
replacement for SHA-1 for the following reasons:

* On 64 bits platform, SHA-512 is the fastest SHA-2 variant, it is only
  ~1.5x slower than SHA-1. [3]
* Keeping only the 256 foremost bits protects against both collision
  attacks and length extension attacks.
* The hexadecimal digest is only 24 chars longer than SHA-1 which is
  nice to have somewhat short URLs.

We have not used SHA-3 because:

* At the moment of writing, it is too slow (~3x slower than SHA-1) [3]
* It is not guaranteed to be available with the Python 3.5 `hashlib`
  module.
* One of the author of SHA-3 is Belgian.

[1] https://csrc.nist.gov/projects/hash-functions/nist-policy-on-hash-functions
[2] https://shattered.io/
[3] http://bench.cr.yp.to/results-hash.html
[4] http://www.commitstrip.com/en/2017/02/27/the-sha-1-alternative/
2019-09-04 09:52:01 +00:00
Julien Castiaux d47083e6d2 [IMP] module.py: deprecate openerp
[PEP-594] is deprecating the `imp` module, that module is used in
`module.py` in order to dynamically import addons using any of the
`odoo.addons` or `openerp.addons` import anchor.

We are deprecating `openerp` module/addons imports in v13 in order to
remove the support in v14 and greatly simplify how modules/addons are
loaded. If you are still using the old `import openerp` or `import
openerp.addons`, `import odoo` and `import odoo.addons` are drop-in
replacements.

The `odoo.modules.module.ad_paths` addon paths list has been deprecated
too. The list is now accessible on `odoo.addons.__path__` where they
are now directly loaded [2].

See also:

[PEP-594]: https://python.org/dev/peps/pep-0594/
[2]: https://packaging.python.org/guides/packaging-namespace-packages/

closes odoo/odoo#36597

Task: 2003936
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2019-09-20 05:58:16 +00:00
Julien Castiaux 4f03a5f136 [FIX] *: remove old deprecated modules/functions
PEP-594 is deprecating a bunch of modules. As part of the cleanup, we
are also dealing with long deprecated modules, functions and aliases.

* `assert_` -> `assertTrue`
* `assertEquals` -> `assertEqual`
* `assertNotEquals` -> `assertNotEqual`
* `assertAlmostEquals` -> `assertAlmostEqual`
* `assertRaisesRegexp` -> `assertRaisesRegex`
* `assertRegexpMatches` -> `assertRegex`
* `base64.encodestring` -> `base64.encodebytes`
* `base64.decodestring` -> `base64.decodebytes`
* `inspect.getargspec` -> `inspect.signature`
* `inspect.formatargspec` -> `inspect.signature`
* `logging.warn` -> `logging.warning`

closes odoo/odoo#36863

Task: 2003936
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2019-09-17 11:36:42 +00:00
Romain Derie 269aa59411 [IMP] http_routing, website: allow to customize the lang in URL
With this commit it is now possible to change the lang displayed in the URL.
Eg, you could use `/fr` instead of `/fr_BE`, or even a fancier `/french`.

Task-32838

Courtesy of pla@odoo.com

closes odoo/odoo#35135

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2019-08-26 16:35:19 +00:00
Christophe Simonis 140ee6b8f0 [MERGE] forward port branch saas-12.4 up to 98a55917a6 2019-08-14 16:48:10 +02:00
Martin Trigaux bdec8efabf [ADD] web: add the language code in the translation widget
The planet icon is not very clear for translation feature.
Replace it with the code of the current language.

Task-id: 2028152
2019-08-13 14:12:17 +00:00
Christophe Simonis b792ba7d9a [MERGE] forward port branch saas-12.3 up to 752b2553c6 2019-08-08 11:52:13 +02:00
Christophe Simonis 7d04dc1c7c [MERGE] forward port branch saas-12.2 up to 9e74730a26 2019-08-06 18:48:24 +02:00
Christophe Simonis 0fadd586fa [MERGE] forward port branch 12.0 up to ff9ddfdacc 2019-08-06 15:57:57 +02:00
Christophe Simonis ff9ddfdacc [MERGE] forward port branch saas-11.3 up to 97d81f1220 2019-08-06 12:13:19 +02:00
Christophe Simonis 4ac13f85f4 [MERGE] forward port branch 11.0 up to 593f631e5e 2019-08-02 12:41:55 +02:00
Kishan Gajjar 22b598bc1b [IMP] web: export improvements
* remove center buttons, corresponding features either moved to fields
list (handle / bin on exported, etc...) or removed
entirely (e.g. clear)
* replace XLS to XLSX format, increases rows# to 1048579
* add FAYT filtering of available fields
* sort available fields alphabetically (CI) always
* change export templates UI: remove buttons

TaskID: 1910953

closes odoo/odoo#32339

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2019-08-12 13:38:31 +00:00
Mathieu Duckerts-AntoineandAaron Bohy 49a97305b1 [REF] *: pivot view refactoring
The main aim of the present refactoring is twofold:

- simplify the code that was largely complexified at the time of the
introduction of comparisons in the pivot view (Time Ranges menu),

- factorize the method expandHeader and _loadData that were too much complex.

Along the way, the pivot model structure has been simplified
and many tests have been added.
Performances in mobile mode have been improved by avoiding
unecessary operations due to useless column groupbys in that
mode.
It should now be easier to understand and modify the pivot view in future.

Co-Authored-By: Aaron Bohy <aab@odoo.com>

closes odoo/odoo#33615

Signed-off-by: Géry Debongnie (ged) <ged@openerp.com>
2019-08-02 18:34:18 +00:00
Sébastien Theys 58a2ffa26f [IMP] *: rename image fields
image_original => image_1920 (now resized to 1920)
image_big => image_1024
image_large => image_256
image_medium => image_128
image_small  => image_64
image replaced by image_1920 (when writing) or by image_1024 (when displaying
	what was previously the big size)

+ add new intermediate format:
image_512

PR: #34925
2019-08-02 16:47:58 +00:00
David Arnold a69b4653c5 [FIX] web: missed P3 text model change
concat_xml was apparently missed during the Python 3 text model fixes,
resuling in a function which usually returns ``(bytes, str)`` but in
the case of an empty or missing ``file_list`` would return ``(str,
str))` instead, leading to type errors in Python 3.

Fix the particular case so it properly returns bytes as the
"concatenation result" even when it did nothing. Fix the docstring so
it properly reflects expectations as well.

closes odoo/odoo#34751

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2019-07-30 06:41:09 +00:00
Christophe Simonis cf51b5f25d [MERGE] forward port branch saas-12.3 up to 793933a128 2019-06-25 14:23:48 +02:00
Christophe Simonis 78b2063b29 [MERGE] forward port branch saas-12.2 up to 8747d72f1e 2019-06-21 15:16:54 +02:00
Thanh Dodeur f3e10f6980 [FIX] base, web: set 304 status in binary_content
Before this commit, the No Change status wasn't properly set because
the `filehash` wasn't passed to `_binary_set_headers` and because
the status was not changed to 304 if it was already set to 200 earlier.

This commit fixes this issue and also prevents images to be processed
in `content_image` if the status is 304.

opw-2008426

closes odoo/odoo#34032

Signed-off-by: Christophe Simonis <chs@odoo.com>
2019-06-19 12:31:07 +00:00
Thanh Dodeur c212cfe899 [REF] *: removes datas_fname from ir.attachment
This commit removes the field `datas_fname` from `ir.attachment` as
it was unnecessary and most of the time the duplicate of `name` or
`url`.

Task #1909865

closes odoo/odoo#32976

Signed-off-by: Martin Geubelle (mge) <mge@openerp.com>
2019-06-05 09:12:13 +00:00
Romain Derie d7cd97a9be [IMP] *: new asset for test files, new debug mode (stored in session)
This commit goal is to encapsulate every tour-test into a separate assets
bundle that would be called only during tests (command line) or by URL
(debug=tests). That way, a lot of .js files would not be loaded anymore
uselessly outside test mode and will speed up the page loads (especially in the
frontend as the backend do not reload the page anyway).

In order to do that, we needed to propagate the `debug` state from page to
page.
Otherwise, every page change during a test would simply lose the debug mode and
the test would stop as the test assets would not be loaded.
As we could not add the `&debug=tests` on every link (either hardcoded or
preprocess during the rendering), it has been decided to store it in session.

Technical summary:
1. `debug` state (currently only stored in URL) will be stored in session.
   Either when adding the `debug` param in URL (handled with _dispatch) or by
   starting Odoo with `test-enable` or `test-file` (handled by session init).
2. Once activated (and so set in session), debug mode will remain activated
   even if not visible in URL (after a page navigation eg).
   To deactivate it, set its value to nothing, `debug=`. That will exit debug mode
   (whatever mode it is: debug, assets, tests).
3. As tour-test files are now in a separate bundle, every layout (when needed)
   should `t-call="web.conditional_assets_tests"`.
   As it would be redundant and verbose, no `t-if` is needed on the t-call to
   load it only in test debug mode. That will be handled by
   `compiled_assets_tests` that will actually do the conditionnal t-call-assets
   to web.assets_tests, if tests debug mode is activated.
4. In addition to separating the tour-tests files in a separate bundle, we also
   moved those files to a specific folder under /static/tests/tours next to
   QUnit tests.
5. Also, tour files will be moved in a specific folder /static/src/js/tours for
   cleanness purpose (those files will still be kept in their 'normal' assets
   as needed outside test mode since it is tours).
   This will be done in the next commit.
6. It is possible to enable multiple debug mode, such as 'tests' and 'assets'
   together. Simply separate debug modes with a comma, eg '?debug=assets,tests'

task-1934445
Comes with https://github.com/odoo/enterprise/pull/4281
Closes #33213
2019-06-05 05:56:33 +00:00
Sébastien Theys 87a35d4263 [IMP] web, web_editor, *: add media image optimize dialog
* = website, website_blog

The goal is to give the user an opportunity to optimize his images before using
them.

For this we introduce a preview/configuration dialog after every image upload,
where appropriate default values are filled for the quality and resolution,
based on where the image is going to be used. Since this is not going to be
perfect all the time, we still allow the user to configure them, and we display
a preview to ease this process.

Indeed it is important for SEO and for usability in general that the images are
as light as possible in size.

Technically the original image is uploaded and saved first, and then it can be
optimized. This way the upload only happens once, and the preview can be
computed from the already saved image.

task-1930726
PR: #31208
2019-06-04 22:14:13 +02:00
Martin Trigaux 66dea8bb7b [REF] web: remove raw_mode flag on export
The export is now always in raw_mode
Adapt the tests

Fixes odoo/odoo#18798

closes odoo/odoo#26724

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2019-08-02 08:53:24 +00:00
Arnold Moyaux caf6cb929b [IMP] base, web: barcode drawer remove margins
The purpose of quiet parameter is to return a barcode image
without left and right margins.
It could be usefull on report where the barcode size should be
minize or align to another element.

closes odoo/odoo#29209

Signed-off-by: Simon Lejeune (sle) <sle@openerp.com>
2019-07-31 08:04:38 +00:00
Lucas Perais (lpe)andJulien Mougenot fc5878ecc6 [IMP] base, web: static xml templates support serverside inheritance
QWeb templates that show up in the 'qweb' key of a module's manifest
now support server side inheritance and xpath evaluation

QWeb templates that show up in the xmlDependencies of a JS widget are not
impacted at all by theses changes, as they are served through the
Werkzeug sharedMiddleware

A similar syntax than ir.ui.view has been implemented in the QWeb templates
- each template must have a root node, whatever tag works

- the root node of a template must have a t-name containing the name of the template
The name -- without the module's name -- may contain dots pretty much anywhere
Though what is recommended is only underscores in template names

- if a template is to inherit from a parent, the root node has a t-inherit directive
containing either the full name of the template it inherits from which is module_name.template_name
or the name of the template, no module name necessary, if the parent template is in the same module

- there are 2 modes of inheriting
primary: copy the behavior of the parent into the template
extension: modifies the parent in place

Task: 1999528

closes odoo/odoo#33892

Signed-off-by: VincentSchippefilt <VincentSchippefilt@users.noreply.github.com>


Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Lucas Perais <lpe@odoo.com>
2019-07-24 12:21:59 +00:00
Raphael Collet caf900e89e [FIX] *: use auth='public' in controllers that use request.env
The following trick used to work, because `sudo()` was actually making
an environment for the superuser to operate upon:

request.env[...].sudo().method(...)

It no longer works in general, since `sudo()` now makes an environment
in superuser mode but with `uid=None`!  It may still work by accident
for operations that never use `env.uid`, but is broken in general.

Using `auth='public'` fixes the problem by using the public user when no
user is available.

closes odoo/odoo#34297

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2019-07-04 11:32:22 +00:00
Alexandre Kühn 893e07e590 [IMP] im_livechat,web: use nicer placeholders for livechat
In the context of a livechat session, a placeholder that looks like a
person is better than a generic "missing picture" one, when the user has
no public avatar.

In order to allow a different placeholder without exposing a public
placeholder parameter, a separate route is introduced for the
purpose of displaying user avatars:
/web/partner_image/<id>/<field>/<model>
and can be simplified to:
/web/partner_image/<id> for loading a partner avatar (`image_small`).

The common part of the /web/image route was moved into a helper
function that is not directly exposed.

Task-ID 1924666
Closes #32664

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2019-05-08 10:35:37 +00:00
Alexandre Kühn 9e067d7d9d [FIX] web: safe open image placeholder
Before allowing custom placeholders, make sure the placeholder images
are accessed safely, using the proper util methods.

Task-ID 1924666
Closes #32664
2019-05-08 10:35:37 +00:00
fja-odoo 0d1407a715 [IMP] base, web, *: make KarmaError an except_orm
* = gamification, test_website, stock

- KarmaError is now handled as a 400 exception.
- test_website has been updated.
- NO_POSTMORTEM is now clean it was referencing duplicates as most the
  exceptions inherit from except_orm.
- serialize_exception from http.py has been moved to ir_http
  to take advantage of the odoo inheritance system. We can then
  extend ir_http serialize_exception method to add the KarmaError
  logic if and only if gamification is installed.
  Places where serialize_exception was previously used are updated.

Part of https://github.com/odoo/odoo/pull/32132
task-1894820
2019-06-28 08:53:53 +00:00
Xavier Morel 0e1a471144 [IMP] web: warn admin on login if their password is "admin"
* We want to limit the obtrusiveness of the mechanism & at the same
time show the warning immediately, so send the warning through a
private channel between the superuser and the admin user rather than
the regular mail.thread's message_post which would likely send the
warning though email.
* Ignore issue when the request comes from a "private" IP (likely a
local dev box where it doesn't matter).
* Only check for "admin" on the admin user: passwords created manually
are already length-checked (required) and strength-checked (visual
indicator).

Task 31122

Supersedes #22428

closes odoo/odoo#33254

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2019-05-13 12:08:53 +00:00
Vincent Schippefilt 9d9a866cc3 [REF] web: remove hardcoding of maxage for load_menu
use CONTENT_MAXAGE to define the max-age instead

closes odoo/odoo#33634

Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2019-05-24 07:09:57 +00:00