* blacklist all fields by default
* don't use blacklist in get_authorized_fields which is called to see if
a field can be added to a form, instead only use it afterwards to see
if the field can be written to by the formbuilder. That way
formbuilder can whitelist fields which are actually added to forms
on-demand resulting in a more secure interaction
In noupdate, the opt-in setting is ignored by migrations and breaks the
corresponding feature. If the feature is undesirable, don't install the
module.
In the top menu bar, the `active` class is set when the
menu url matches the page url (the url in the browser url bar)
A while ago, we made so all urls
`/page/website.***'
were automatically redirected to
`/page/****`
Therefore, if the menu url still contains this `website.` prefix,
the active class wasn't set on it, while it should.
Fixes#3059Closes#3070
Models renamings:
- crm.case.stage becomes crm.stage
- crm.case.section becomes crm.team
Model split:
crm.case.categ has been splitted into:
- crm.phonecall.tag
- crm.lead tag
- crm.claim.tag
- crm.helpdesk.tag
Models removal:
- crm.payment.mode
- crm.segmentation
- report.crm.case
Removal of the crm_profiling module
(all these refactorings have been done in order to ease new API
migrations)