The CDN domain will typically be different from the main
website domain, so session cookies cannot be shared.
This means that assets that require elevated privileges
(such as the website editor rights) will not be reachable
from the CDN's proxy server.
This could cause random problems with CSS/JS/images not
being accessible.
The benefits of the CDN are mostly meant for the masses
of new visitors (less workload and less bandwidth consumed
for the main domain) anyway.
Authenticated users are also returning users that have most
of the resources in the browser cache anyway (assets bundles
and images, typically).
Escape text nodes changed via the web editor before sending the content
it to the server controller.
It is done since the content is unescaped one time when being displayed,
and it is not done for inline style and script tags (which may be
injected by dropping a snippet) since that would break them.
replacing the solution in cdb900044.
Replace deprecate controllers like /web/binary/image, /web/binary/saveas...
Use ETag for all content with 'unique' option to cache the content if the content is never changed.
When saving a template in version 8.0, html would be saved as it should
be displayed once on the site. In particular, if some text should be
escaped once send to the browser, it will be saved as such.
But when rendering, a text node content is unescaped two times:
* for translation which seems wrong since we already use .text of a node
which already escaped it, doing it one more time is bad,
* when rendering the template, since the html template is stored in xml,
This commit remove superfluous unescaping for translation, and add an
escaping when saving the changed template content.
closes#7967
opw-646889
to mail. The only use was to update a method of publisher_warranty.contract
model that is defined in mail.
This code has been moved to the bridge module between website and mail
aka website_mail.
Dependency to share has also been removed.
When clicking on the publish/unpublish button in a form view, if the
user does not belong to the `base.group_website_publisher` group,
fallback to a simple toggling behavior.
This fixes a bug on some methods. Because `ormcache` uses the decorator
`decorator`, the `context` argument is passed positionally to the decorated
lookup method, instead of being passed as a keyword argument. As a
consequence, the context dictionary is included in the cache key, which makes
the cache lookup fail all the time.
Using the new API of `ormcache` gracefully fixes this issue.
- remove useless cache clear_prefix
- add a route cache attribute when used it will save the rendered page into the
ormcache for the specified time, this is only enabled if the user is public
and reponse code is 200
- enable it on /page controller for 5min
This commit impact crm, website, website_sale and web_planner modules because it
- add planner for website and website_sale
- improve planner notebook by setting texterea and input size to 100% and using col-md-* class
- split js code into common part (used in backend and frontend) and backend part (only for backend)
- adapt some tour, since every page will have the planner modal in its DOM, the tour selectors msut be more accurate
- introduce some style fixes and adaptations
- ...
Improves aea358ca67 and avoid spurious
redirects for URLs that do not match a controller but do not
have a valid language.
When the URL does not match any controller, the language
matcher tried to strip the leading path component, treating
it as a language code. For example:
/fr_BE/page/homepage
would not match any route, so it would be rerouted internally
as /page/homepage, after setting `request.lang` to fr_BE.
This breaks the magical 404 handler that allows ir.attachment
entries to be mapped to static URLs. Due to the internal rerouting,
the mapping of e.g. /website_mycompany/static/src/image/logo.png
would be rerouted to /static/src/image/logo.png and not match
the mapped URL anymore.
Now the stripping of the path component will only occur if
that path component matches an installed language code.
The consequence is that URLs containing uninstalled language codes
will now lead to 404 errors - an acceptable trade-off (e.g.
when an older version of the website is still indexed by a search
engine)
Redirect odoo.com/page//contactus ==> odoo.com/page/contactus
(only for get method)
Apache don't redirect but search for route with only one slash...
For SEO optimization, Odoo force a redirect permanently
The extra auth blows an environment and causes an extra query
of ``website`` before calling the controller.
The preceding two SQL queries likely can't be avoided: one uses uid1 to fetch
the current website's public user in order to set it, the other one
fetches the current website using the user set beforehand
Detect most of bots/crawlers to avoid auto redirect. Most bots fetch
with lang en_US, so even if default website lang was not in en_US,
googlebot was redirected to en_US page.
Now we keep also the language selected by user into a cookie.
If cookie exists but lang not in url, we redirect the user into
his preferred language.
Manage special case to allow to change the lang in url to set the
default lang at fly in url and set the cookie...
Many routes are not specified as multilang=False but should be.
With the auto redirection, we need to update these routes to avoid
useless redirects !
Code from delete_page has been spliited (functions, templates, ...)
to be re-usable by rename_page
Change default input type from website.prompt.
Old default value 'text' had no sense, there are no tag <text>.
The implementation of ormcache does not work on methods that take a context
parameter. Because of the decorator decorator, the arguments of the call are
passed positionally to the method ormcache.lookup, and positional arguments
are used in the cache key.
The fix consists in removing the context parameter from the faulty methods,
either directly, or by caching a private method called by the public method.
Commit 540b753bf8 introduced
support for resources stored as ir.attachment records in
asset bundles too.
This is specifically useful for customizations.
However the HTTP route for reaching those resources
when they are *not* in a bundle was originally created
in the `website` module (as a special handling for
404 requests)
This means that these dynamic resources would only
be partially supported when `website` is not installed,
causing various problems:
- missing resources in debug mode where bundles are skipped
- errors when trying to define new client-side Qweb templates
via XML resources - which are loaded with a direct request
- ...
This commit moves back the supporting code to the web module.
The `mimetype` column is not present in ir.attachment without
the `website` module, but sniffing it based on the attachment
name works fine at serving time too.
Closes#6002
The implementation of `ormcache` does not work on methods that take a `context`
parameter. Because of the decorator `decorator`, the arguments of the call are
passed positionally to the method `ormcache.lookup`, and positional arguments
are used in the cache key.
The fix consists in removing the `context` parameter from the faulty methods,
either directly, or by caching a private method called by the public method.