Commit Graph
28 Commits
Author SHA1 Message Date
Julien (jula) 926d8c6c5d [FIX] web, stock: escape JSON error when downloading report
__Description of the issue:__

When something goes wrong while downloading a report file, a 500 error
is sent as JSON. However the frontend interprets this response as HTML
and then try to parse the text content as JSON.

Most of the time this works, but if the response contains any HTML tags,
like `<lambda>` from a Python stacktrace, the JSON response will get
misinterpreted as HTML instead of regular text, causing the subsequent
JSON interpretation to fail.

The end result for the user is that empty tracebacks will be displayed
instead of User Errors or actual tracebacks.

__Desired behavior:__

The JSON response is HTML escaped before being sent and will therefore
be correctly parsed and displayed to the user.

This basically restore what was done prior of #104594.

Enterprise: odoo/enterprise#36523
X-original-commit: 5999a7d336553053c5638f69344cdfbc84a8c681
Part-of: odoo/odoo#112453
2023-02-12 14:14:41 +01:00
Victor Piryns (pivi) 21f78b1ae0 [FIX] web, stock: rollback database when crashing on report generation
Current behaviour:
When we are printing a report and then the report fails to generate
(for ex. wkhtmltopdf memory limit/timeout),
the incorrect state is committed to the database.

Expected behaviour:
We should rollback when generating reports fails, since it is an error state.

Steps to reproduce:
To reproduce the behaviour, we need to force an error state.
- In odoo/addons/base/models/ir_actions_report.py:`_run_wkhtmltopdf()`,
raise an exception before spawning the subprocess (for ex. adding a 1/0).
- In addons/web/controllers/main.py:`report_download()`#L2126,
add this little code snippet:
```python
ids = [int(x) for x in docids.split(",")]
report = request.env['ir.actions.report']._get_report_from_name(reportname)
obj = request.env[report.model].browse(ids)
if getattr(obj, 'message_post'):
    obj.message_post(body='This report was committed!')
```
- Install Inventory
- Pick a delivery order and try to print it, there should be an error
(whatever exception you decided to raise in `_run_wkhtmltopdf()`)
- See that in the message board we got a message that the report has been committed,
which isn't the case, it failed to generate.

Reason for the problem:
Controllers are catching the exception when generating reports,
but never reset the state of the database.

Fix:
Raise an InternalServerError with an error code of 500 to trigger
a database rollback.

Affected versions:
- 14.0
- 15.0
- saas-15.2
- saas-15.3
- 16.0
- master

opw-3001950

closes odoo/odoo#106172

X-original-commit: ec185fcf7f32da05c83733af36bebe10ac22e2ad
Related: odoo/enterprise#34193
Signed-off-by: Julien Castiaux <juc@odoo.com>
Signed-off-by: Piryns Victor (pivi) <pivi@odoo.com>
2022-11-21 15:57:11 +01:00
Julien Castiaux c0647b5c52 [REF] core: HTTPocalypse (14) changes all addons
This commit is the 14th commit of a comprehensive refactor of our HTTP
framework. See odoo/odoo#78857 for complete historic, discussions and
rationnals.

* `request.uid = x` => `request.update_env(user=x)`.
* `request.context = x` => `request.update_env(context=x)`.
* `request.context = dict(request.context, x=y)`
   => `request.update_context(x=y)`.
* `request.cr = None` => `request.cr.close()`.
* `http.mono_db()` => `request.db`.
* `http.dispatch_rpc()` => `service.dispatch_rpc()`.
* `@service.model.check` => `service.model.retrying()`.
* `request.endpoint`
   => `env['ir.http']._match(request.httprequest.path)[0].endpoint`.
* `request.routing_iteration `=> `removed`.
* `request.jsonrequest` => `request.dispatcher.jsonrequest`.

Note that `request.params` is now set much later in the process. If you
are in a situation where you values from the query string or the
http body you can use `request.get_http_params()`.

Note that using the new `request.future_response`, it is possible to
add headers and cookies on the response object before the response
object is initialized. Please note that headers/cookies saved on
the future response will NOT be injected in case of error.

PR: odoo#78857
Task: 2571224
2022-02-24 13:30:51 +00:00
Quentin Wolfs e2f59a6dd1 [IMP] stock: traceability report origin
Add reference of the traceability report's origin (production.lot,
manufacturing order, picking, ...) to the end of the
report.
Change the layout a bit so the data isn't squashed by
the border.

Task-2467686

closes odoo/odoo#74120

Signed-off-by: William Henrotin <Whenrow@users.noreply.github.com>
2021-08-16 08:14:09 +00:00
Jeremy Kersten 926af37343 [REF] *: remove unused fileToken cookies
This cookies is not more used since 35d452cffb

closes odoo/odoo#72079

Related: odoo/enterprise#18967
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-06-14 07:32:18 +00:00
Simon Lejeune 09f66f4885 [REM] stock: unused controller
This was a remnant of the old old barcode client action.
2019-11-20 08:35:31 +00:00
fja-odoo 424adb63e3 [IMP] gamification, *: remove KarmaError
* = stock, test_website, web, website_forum, website_slides, base

Replace KarmaError with AccessError and remove the related override made
on crash_manager and ir_http.

task-2069890

closes odoo/odoo#36655

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-09-12 13:49:02 +00:00
Raphael Collet b7fd679a6c [FIX] *: sudo() -> with_user() 2019-07-04 11:32:22 +00:00
fja-odoo 0d1407a715 [IMP] base, web, *: make KarmaError an except_orm
* = gamification, test_website, stock

- KarmaError is now handled as a 400 exception.
- test_website has been updated.
- NO_POSTMORTEM is now clean it was referencing duplicates as most the
  exceptions inherit from except_orm.
- serialize_exception from http.py has been moved to ir_http
  to take advantage of the odoo inheritance system. We can then
  extend ir_http serialize_exception method to add the KarmaError
  logic if and only if gamification is installed.
  Places where serialize_exception was previously used are updated.

Part of https://github.com/odoo/odoo/pull/32132
task-1894820
2019-06-28 08:53:53 +00:00
Romain Derie d7cd97a9be [IMP] *: new asset for test files, new debug mode (stored in session)
This commit goal is to encapsulate every tour-test into a separate assets
bundle that would be called only during tests (command line) or by URL
(debug=tests). That way, a lot of .js files would not be loaded anymore
uselessly outside test mode and will speed up the page loads (especially in the
frontend as the backend do not reload the page anyway).

In order to do that, we needed to propagate the `debug` state from page to
page.
Otherwise, every page change during a test would simply lose the debug mode and
the test would stop as the test assets would not be loaded.
As we could not add the `&debug=tests` on every link (either hardcoded or
preprocess during the rendering), it has been decided to store it in session.

Technical summary:
1. `debug` state (currently only stored in URL) will be stored in session.
   Either when adding the `debug` param in URL (handled with _dispatch) or by
   starting Odoo with `test-enable` or `test-file` (handled by session init).
2. Once activated (and so set in session), debug mode will remain activated
   even if not visible in URL (after a page navigation eg).
   To deactivate it, set its value to nothing, `debug=`. That will exit debug mode
   (whatever mode it is: debug, assets, tests).
3. As tour-test files are now in a separate bundle, every layout (when needed)
   should `t-call="web.conditional_assets_tests"`.
   As it would be redundant and verbose, no `t-if` is needed on the t-call to
   load it only in test debug mode. That will be handled by
   `compiled_assets_tests` that will actually do the conditionnal t-call-assets
   to web.assets_tests, if tests debug mode is activated.
4. In addition to separating the tour-tests files in a separate bundle, we also
   moved those files to a specific folder under /static/tests/tours next to
   QUnit tests.
5. Also, tour files will be moved in a specific folder /static/src/js/tours for
   cleanness purpose (those files will still be kept in their 'normal' assets
   as needed outside test mode since it is tours).
   This will be done in the next commit.
6. It is possible to enable multiple debug mode, such as 'tests' and 'assets'
   together. Simply separate debug modes with a comma, eg '?debug=assets,tests'

task-1934445
Comes with https://github.com/odoo/enterprise/pull/4281
Closes #33213
2019-06-05 05:56:33 +00:00
Simon Lejeune fe20747ddc [REF] stock: adapt traceability to new implementation 2017-07-14 17:08:21 +02:00
Pierre Masereel 5fcdb06010 [MOV] stock: move traceability report from mrp_workorder 2017-07-14 17:08:21 +02:00
xmo-odoo b4429c2a91 [FIX] Various P3-related import changes
* LDAP import: python-ldap is not python3-compatible, pyldap is

  Warning: only supported from debian Stretch (current testing)?
  https://packages.debian.org/search?searchon=names&keywords=pyldap

* implicitly relative imports
* imports of moved or removed stdlib modules

issue #8530
2017-04-28 09:06:53 +02:00
Yenthe V.G d5a99319b0 [IMP] stock: remove unused logger import
The logger is imported but never used so let us remove it anyway.

Closes #14047
2016-12-05 16:45:35 +01:00
Thibault Delavallée 20223fe920 [MIGR] stock: reports and controllers 2016-04-29 12:18:49 +02:00
Fabien Meghazi dfa4d92eca [IMP] changed barcode start page url to /stock/barcode
As a convention we use the module name as first fragment of the url
2014-07-16 10:25:53 +02:00
Fabien Meghazi c0875efba1 [IMP] Improve stock's barcode start page
remove module_boot() usage
2014-07-15 17:18:47 +02:00
Simon Lejeune 10ce35040b [FIX] point of sale and barcode interface 'mini webclien' initialisation 2014-06-27 17:18:26 +02:00
Fabien Meghazi 863edbaaf2 Seperate assets_common from other bundles 2014-05-20 17:06:25 +02:00
Quentin (OpenERP) a029fb22d0 [FIX] stock: fixed error 'cannot import name html_template'
bzr revid: qdp-launchpad@openerp.com-20140508100856-jbitae0fzsdt7v78
2014-05-08 12:08:56 +02:00
Josse Colpaert d763f43878 [IMP] Correct js assets for barcode scanner
bzr revid: jco@openerp.com-20140505073931-mwikrhmngq1ju402
2014-05-05 09:39:31 +02:00
Cedric Snauwaert fd00c531d5 [FIX]barcode_interface: correct use of url hash in interface
bzr revid: csn@openerp.com-20140324155628-bojwf560y73s9pv7
2014-03-24 16:56:28 +01:00
Cedric Snauwaert 0d24796915 [FIX]barcode interface: take into account location filter when scanning a product
bzr revid: csn@openerp.com-20140324104621-xfah53qqwg06qcqe
2014-03-24 11:46:21 +01:00
Cedric Snauwaert 3e78262bb5 [WIP]barcode interface: add a modal window to change location
bzr revid: csn@openerp.com-20140320154056-137r0ts6umivzcrc
2014-03-20 16:40:56 +01:00
Cedric Snauwaert 05cd763da9 [WIP]add blink on line when scanning with barcode scanner and search is case insensitive
bzr revid: csn@openerp.com-20140319100758-u768tsufdgjig61r
2014-03-19 11:07:58 +01:00
Cedric Snauwaert cf5e42b568 [WIP]barcode interface: minor changes
bzr revid: csn@openerp.com-20140318155143-59lpf2jq7p8ivagb
2014-03-18 16:51:43 +01:00
Cedric Snauwaert fc27f33675 [FIX]barcode interface, redo of menu interface to use kanban view instead of table
bzr revid: csn@openerp.com-20140228105231-2wjgbri012wd4mna
2014-02-28 11:52:31 +01:00
Cedric Snauwaert 8e779fa761 [FIX]stock_barcode_interface: rework of the barcode interface to use bootstrap only
bzr revid: csn@openerp.com-20140226161003-kzgg5xfcrn8ucspx
2014-02-26 17:10:03 +01:00