Private browsing in Safari doesn't allow to store anything in the localStorage,
and it throws an error when you try to do so. This new JS module is a connector
to the browser's localStorage if it is enabled, and if not, it simply keeps its
own storage in RAM.
All actions of the database manager redirect the user after an action except the
backup option which returns an octet stream.
Close the modal after form submission to mimic the same behaviour.
Do not close the modal for other actions than database manager to avoid waiting
time for create that may be long to process.
Add message to warn the user about backup waiting time after cliking on submit
to be less confusing for big databases that may take a lot of time to be ready.
Fixes#10803
Mobile virtual keyboards will often capitalize the first letter of
an input text field, which is annoying as odoo logins are case-sensitive.
This will no longer happen thanks to this new attribute.
X-port of commit odoo/enterprise@b8632f8bb6
This commit introduces a mechanism to add information into the session
from a different module, without having to fetch it manually with a rpc.
This is intended to be used with small pieces of info required at the
start of the web client, such as currency informations.
To add information to the session, one can simply inherit from ir.http
and modify the session_info method.
session_instance.js moved from framework/ to services/ and renamed into
session.js, which required to change the bundles in report and web_editor
addons.
A fonts.less file which contains the definition of Lato was created
in saas-11 and placed in the backend assets. It should have replaced
the lato/stylesheet.css in the common assets.
Also adapt point_of_sale assets to use the same file.
Add inputs e-mail address and country
when creating a newdatabase
This will provide the installation of the correct
chart of accounts at the installation of Accounting
Use the provided login as the admin login,
and set the email on the partner
if the login set is an email
Set the country on the company (and its partner)
The countries are parsed from XML country list
We take the opportunity to repair the `label for`
which bind the label with the input only if
the `id` attribute of the input is set with
what is set in the `for` attribute of the label
Avoid duplicating web addon in enterprise by extracting a common basis.
Enterprise features stay in enterprise, but use that common basis.
Mainly:
- JS refactoring and linting
- Conversion of .sass into .less split into multiple files
- Templates cleaning and DOM simplification
- Re-generation of web.pot, and update of .po files
Introduction of 'data_manager' service which handles meta-data related to
actions and views (fields_views, fields and filters). Ideally, all RPCs to
get that kind of information should go through data_manager, as it holds an
internal cache.
* Remove recursive assets inclusions (i.e. assets_editor was including
assets_common, summernote, ...)
* Better construct the assets (link, then script + type attribute)
* Better include the assets (split js / css, always use t-call-assets)
* Simplifies the number of assets
* Move bootstrap js to assets common
* assets_frontend is now created by web module to allow using it on the
connexion page but also in the web_editor, where colors have to be
bootstrap/theme ones. Note: if a module depends on website, then keep
using the inherit_id="WEBSITE.assets_frontend"
If the user has multicompany rights and more than one allowed
companies, the full company name is displayed in the topbar. When you
click on it, there is a dropdown with the name of the other companies.
Clicking on another company name makes you switch on it and reload the page
- Differentiate between the Community and Enterprise editions
in the version number. By adding this attribute on the global
odoo JS object in the web client bootstrap controller /web,
we can differentiate between versions easily on the client
side without extra RPC calls.
- Remove a couple of version-related RPC calls in case
the global version info is present in the JS environment
- Update "About" panel to display the edition info
- This commit also reverts 07fe5afc87
which implemented the idea in a more limited way.
Closes#9625
* add CSRF token as core.csrf_token
* add CSRF tokens to client-generated and/or JS-submitted forms
* remove broken "compatibility" mode of web.ajax.post
/cc @dmo-odoo I've no idea how that was supposed to work, from looking
things up all modern browsers seem to support FormData, and old IEs
which don't don't support fallbacks either and would require
submitting an actual form as fallback so...
* make CSRF protection the default on all non-SAFE methods
note: there currently is no way to call a CSRF-protected endpoint
without a form-encoded entity-body as that's the only place we get the
CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
the purpose of a CSRF token in the database manager screens.
There is no request database to obtain the
secret and generate a CSRF token.
Move the widget_x2many tour to web and call it from test_new_api as it needs
to be overrided for the new design, and it requires models and data from
test_new_api.
Clean other unnecessary stuff from web_tests, and thus remove the addon.
- fix html and css layout using only pure bootstrap
- replace db selection by a link to the database selector
- reorder templates
- remove unused templates