Commit Graph
176 Commits
Author SHA1 Message Date
Christophe Monniez fab86bbf8b [FIX] web: adapt test for werkzeug >= 2.2.2
In werkzeug 2.2.2, the following characters "$!'()*+,;" are now
considered as safe by url_quote. This makes the filename_secure test
fail with the hard coded expected string containing a single quote as
'%27'.

This commit adapt the filename_secure test in order to work with all
versions of werkzeug.

closes odoo/odoo#112298

Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2023-02-10 14:37:31 +01:00
Florian VranckxandJulien Castiaux 8c30699f2a [FIX] http: no rotate sid for unidentified user
This commit fixes a change in behavior between 15.2 and 15.3.

Previously, if an unidentified user tried to reach a route that had auth='user', it would simply redirect to the login page.

Currently, it redirects and invalidates the session_id.

This is an issue in the latest version of master after this PR https://github.com/odoo/enterprise/pull/36521
This commit changes the route of service-worker.js to auth='user'.

This route is called on the login page, which rotates the sid and therefore invalidates the csrf token. Making it impossible for a user to log in.

This is a race condition, meaning it would only appear if the user stayed on the login page for a few seconds, hence why the automated testing did not block the commit.

closes odoo/odoo#112239

X-original-commit: d5d80d172616afe02bd41934930ea18dc273c739
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
Co-authored-by: Julien Castiaux <juc@odoo.com>
2023-02-08 21:45:53 +01:00
Laurent Smet d724f69a1d [FIX] web: Fix useless search_count with count_limit
When count_limit is set and lower than the current number of fetched records, making an extra search_count is useless.

closes odoo/odoo#111895

X-original-commit: 6f90d6924e24e700694111732ee85465f802b22f
Signed-off-by: Rémy Voet <ryv@odoo.com>
2023-02-03 17:41:15 +01:00
Jeremy Kersten fb8765b494 [FIX] base: ir.binary - return valid filename in Stream
Before this commit, if you have some special char like a return line \n,
or \r the get_stream_from method will crash with exception:

```
File "/home/odoo/src/odoo/odoo/addons/web/controllers/binary.py", line 163, in content_image
  return stream.get_response(**send_file_kwargs)
File "/home/odoo/src/odoo/odoo/odoo/http.py", line 578, in get_response
  res = _send_file(self.path, **send_file_kwargs)
File "/home/odoo/src/odoo/odoo/odoo/tools/_vendor/send_file.py", line 156, in send_file
  headers.set("Content-Disposition", value, **names)
File "/usr/local/lib/python3.9/dist-packages/werkzeug/datastructures.py", line 1218, in set
  self._validate_value(_value)
File "/usr/local/lib/python3.9/dist-packages/werkzeug/datastructures.py", line 1182, in _validate_value
  raise ValueError(

ValueError: Detected newline in header value.  This is a potential security problem
```

Now we replace `\n` `\r` by `_` before to serve the stream to avoid this
security exception from a safe way.
We decided to not use secure_filename from werzkeug because we want to
continue the support of non ascii char.

closes odoo/odoo#111851

X-original-commit: 95584e71a898017a92112f89e8a94315dd9235ac
Signed-off-by: Jérémy Kersten <jke@odoo.com>
2023-02-03 16:32:24 +01:00
Xavier-Do 503ed05029 [IMP] tests: add generic Basecase.start for patch
Using patcher.start() can easily lead to incorrect cleanup.
-> after a copy paste, patcher is working, but stop is forgotten
-> stop is present, but won't be called if something fails during the
test

This commit add an utility `start(patcher)` to always have the add
cleanup.

Using a standard way to start the patcher with an automated addCleanup
should prevent this kind of mistake. This is why this commit also
replaces all valid patch.start() (followed immediately by a addCleanup)

closes odoo/odoo#102873

X-original-commit: 7d5a193d86316965a0908c65cfacfb607dc3f3ad
Related: odoo/enterprise#32618
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2022-10-10 16:11:01 +02:00
Jeremy Kersten 5490fcc27f [FIX] http: convert DEFAULT_SESSION as a function get_default_session
This commit avoid to have a dict by reference that will be global.
Now get_default_session return a new dict each time for the context key.
From this way the session.context['lang'] is not shared between several
users on the same worker.

To reproduce the bug, restart the server with 2 workers, make request in
lang A on these 2 workers. DEFAULT_SESSION['context']['lang'] now is set
to this lang A.
Now, make request to an url without lang in path and without cookies and
withtout session, you should be redirected to lang B (preferred lang
from the request header) but you will be redirect to lang A due to the
dict session.context that is shared for the worker...
When we initialize the new Session, we get the wrong lang A as value for
context.lang, so we don't recompute the expected lang for the end user.

X-original-commit: 62179de74862210fe2a055d15b367b1850c24263

fwd-port of #100102

closes odoo/odoo#100910

X-original-commit: 42e46b2d89dde276f796b980f29e33cc216e7cb2
Signed-off-by: Jérémy Kersten <jke@odoo.com>
2022-09-23 09:21:38 +02:00
John Laterre (jol) 78789cfc28 [FIX] account,base,web: fix "Send & Print" on invoices
The purpose of the task is twofold:

1. Remove empty lines in the company address.

Until now, the address format was fixed, which could
lead to empty lines if one or more field(s) were missing.
We are now removing empty fields to avoid that.

2. Make sure the external report layout is configured
before generating the PDF.

This will ensure that the company data will appear
in the file. If no layout is defined,
it would not be shown.

task-2834517

closes odoo/odoo#100936

X-original-commit: f36bb6acdacaaba26afdd8f62c48fd2c8784d1e1
Signed-off-by: Olivier Colson (oco) <oco@odoo.com>
Signed-off-by: John Laterre (jol) <jol@odoo.com>
2022-09-23 07:21:43 +02:00
Xavier-Do 395b30e39d [IMP] tests, web: improve test_js end catching
Since #99912 logging an error message doesn't always end qunit tests.
This was mainly to allow to failfast logging qunit errors earlier
without stopping the tests in order to test all qunit anyway.

The logic was to have an end message that stops the test.

Unfortunately some errors will prevent the qunit suite to start
and the test will wait a 1800 long timer. An example was because of
a Missing dependencies. https://runbot.odoo.com/runbot/build/19306352

This new approach will avoid to stop only if the message looks like a
qunit failure and the final message is not there (to be sure).

closes odoo/odoo#100238

Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2022-09-16 20:52:08 +02:00
Gorash 5410b7c238 [IMP] base/web: XML templates are added into the asset bundles.
XML files are now declared in python module manifests. During the qweb
't-call-asset' directive, assetbundle will fetch the declared xml files,
apply the inheritance (t-inherit) and create a javascript service (for
eg: 'web.assets_backend.bundle.xml') which is added at the end of the
*.js mimifier file.

When the debug mode is activated, comments are added in the template
indicating which file the template comes from as well as the
inheritances applied to it.

****

JavaScript:

assets.js (module @web/core/assets) takes care of loading libraries,
javascripts and styles.
`loadJS(url)` (loads the javascript and returns a resolved promise when
the templates are also loaded via the '*.bundle.xml' service)
`loadCSS(url)` (loads the style a resolved promise when the file is
loaded)
`loadXML(xml, app=assets.defaultApp)` (load template into
application/owl, used by the `*.bundle.xml` services)
`getBundle(bundleName)` (get the bundle descriptor)
`loadBundle(desc)` (load the files and bundle from a descriptor)

templates (XML element content all owl templates)

A new `ready(serviceName)` method on boot.js lets you know when a
service is loaded are the require.

The xmlDependencies attribute no longer exists.

Python:

The xmls taken into account by assetbundle.py, applying `t-inherit`
inheritances and adding an `name_of_the_bundle.bundle.xml` service in
the generated JavaScript file.

****

Every manifest changes is into the next commit, except 'web_tour' in
this current commit as example.

Part-of: odoo/odoo#95500
2022-09-14 20:25:01 +02:00
Xavier-Do c764c38d7c [IMP] website: pregenerate frontend assets
closes odoo/odoo#99176

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2022-09-12 13:49:00 +02:00
Xavier-Do ae3e68c1f4 [IMP] web: add tests for bundle pregeneration.
Since bundle generations should be generated before post install tests,
a loading of a /web shouldn't try to save a new version

This is currently breaking for / because of the website_id added in the
extra part of the attachement. Even if the content is the same.

Part-of: odoo/odoo#99176
2022-09-12 13:48:59 +02:00
Xavier-Do 0a695ab6b2 [IMP] web: one log per qunit module.
Right now the qunit will log all results at the end.

This means that the runbot may wait for all qunit before detecting the
failure.

This also mean that all failure are in one ir.logging on runbot, making
the automated parsing difficult if multiple modules fails during the
same build.

We could also log all failure immediately, but grouping them my qunit
module will avoid duplicating logs for linked causes (one failure
leading to a `Expected %s assertions, but %s were run` message)

closes odoo/odoo#99912

Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2022-09-10 01:54:12 +02:00
Xavier-Do e82c75c28b [FIX] web: static template performance test
Time comparison can always be slightly random (this is why this test
is a nightly one). The 20% margin left by the 12 ratio is not enough
in all cases. This test was sometime breaking with a
12.944994188420822 not less than or equal to 12

This is one of the max value found by quickly checking the builds.
A ratio of 14 should be hopefully enough.

closes odoo/odoo#99156

X-original-commit: cc86b80342d38913f7af79474c41f8764c8b2dd2
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2022-09-05 14:50:39 +02:00
std-odoo a740989ba5 [MOV] web: move the domain selector component to web
Purpose
=======

For security reason access on ir.model is not granted to internal suers. Due
to this constraint a component exists in spreadsheet to be able to select
the models for which we have a read access on the records of this model.

This is required for the properties fields feature, hence moving its code
to web.

Some renaming is performed to make it generic. This generates some changes
in other addons, notably some class renaming.el.

Task-2852259

Part-of: odoo/odoo#95184
2022-08-29 23:46:07 +02:00
Stanislas Sobieski 31de6e8454 [FIX] web: fix database manager test
Skip test on database manager rendered page when option
--no-database-list is used

closes odoo/odoo#98771

Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2022-08-25 03:12:01 +02:00
Christophe Monniez c754838489 [FIX] web: fix clickbot click timeout inconsistency
The clickbot click default timeout was increased in #98495, but missed
the fact that the default was overridden for the "Settings" menu to a
lower value.

With this commit, the "Settings" exception is completely removed as the
default timeout is higher. Also, checking that the text contains
"Settings" was a bit weak.

While at it, the timeout for the global testing of an app is also
increased to 10 minutes instead of 5 as this limit is reached by the
Field Service app.

closes odoo/odoo#98617

X-original-commit: 0247e6f4abef4121b451c1373ae3c1ce184451c0
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2022-08-23 08:50:01 +02:00
Romeo Fragomeli a5d6b3cafd [FIX] project,web: 'bg-muted' doesn't exist anymore
`bg-muted` as been replaced by `bg-200` in odoo/odoo#97051, but there
are still non-converted ones.

closes odoo/odoo#98555

Related: odoo/enterprise#30635
Signed-off-by: Adrien Dieudonné (adr) <adr@odoo.com>
2022-08-22 16:48:57 +02:00
Xavier Morel d22cd89a60 [FIX] web: opt clickall out of form edition check
We can't really know where the clickall tour will end, and if it ends
on the settings action things are rather difficult as saving or
discarding the settings form returns to the edition mode.

Part-of: odoo/odoo#96517
2022-08-04 09:14:09 +02:00
Xavier-Do 555ef06fa5 [IMP] tests: allow to disable auto retry
Auto retry can be usefull to avoid breaking a build because of a
small tour or query count, but for long tests like qunit, this can be
painfull when a real error is triggered.

This commit proposes to disable autoretry on demand for some tests
to solve this issue.

This may be applied on all tests longer than a few seconds.

closes odoo/odoo#95440

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-07-27 16:33:56 +02:00
Pierre Paridans 69f047c26d [IMP] web,tests,test_main_flows: Chrome headless touch option
Before this commit Chrome's "touch mode" was enabled in both desktop and
mobile-like tests suite (when run headless).

To better match real usecases, this commit adds an option to
enable "touch mode" only in mobile tests suites; keeping it disabled in
desktop ones.

Part-of: odoo/odoo#95924
2022-07-19 11:50:51 +02:00
Julien Castiaux d28feaa5a6 [FIX] web: session cookie lost between requests
Each cookie binds to a domain name, multiple cookies can be set for the
same name if they are for different domain name. In this case, two
`session_id` cookies were set: (1) the first set right on the opener at
`opener.cookies[...] = ...`, (2) the second set upon inside of
`http.Request._save_session` because the session was rotated upon login.
The problem is that the former cookie (the one set on the opener, the
one *not* rotated) was used instead of the second cookie (the one
holding the registered user) in the subsequent queries. There is a long
comment explaining the same problem inside of
`odoo.tests.common.HttpCase.authenticate`, we used the same solution as
they did inside of `authenticate`: we diched the previous opener.

closes odoo/odoo#94773

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2022-07-07 16:06:55 +02:00
Florian Charlier b5f3433adc [IMP] auth_signup,portal,web: welcome external users w/o portal
When portal is not installed and `auth_signup.invitation_scope` is "b2c",
visitors can create an account, leading to a blank page. Still, accounts can be
required for several use cases in apps that do not require portal (such as
survey).

We here add a landing page for users that created an account but have no
requested redirections and cannot be redirected to a customer portal either.

auth_signup_uninvited is also updated in model to be consistent with config
data.

Tests are added to check this behavior.

Task-2762102

Part-of: odoo/odoo#85703
2022-06-14 09:35:57 +02:00
Julien Castiaux da8def8e41 [IMP] core, web: Delegate delivery of static files
Rationnals
----------

Web servers can serve some resources (e.g. static files) right away
without any interaction with the web application. The network model of
most web servers makes them capable of handling thousands of
simultaneous requests when it comes to intensive IO operations such as
streaming data from a file. The network model of Odoo is different: it
is capable of a lot of processing power but can only serve a handful of
requests at a time, i.e. Odoo (with some help from postgres) is
optimized for CPU operations, not IO.

Some users don't configure their web server, they use a basic
configuration that relay all requests to Odoo. The result is that many
Odoo HTTP Workers can be busy streaming static files instead of
processing other requests. This can lead to a worker starvation, i.e.
all workers are busy streaming files and cannot process new requests.

X-Sendfile
----------

In this work, we add the support for the [X-Sendfile] header family,
they are multiples http headers that can be used by the web application
to communicate with the web server in order to delegate the delivery of
files stored on the file system. Odoo still receives the request but it
does no more stream the file content from within its HTTP worker,
instead it skips the response body altogether and sets the `X-Sendfile`
special header with the path of the file on the filesystem. The web
server intercepts that special header, open the file and stream it.

Using those headers, we can use the best of both the web application and
the web server. The web application is still responsible to locate the
resource and verify the access rights, the web server is still
responsible of streaming the content.

Using X-Sendfile is opt-in via the `--x-sendfile` CLI flag. We set both
`X-Sendfile` (apache) and `X-Accel-Redirect` (nginx). If you are using
apache, make sure `mod_xsendfile` is enabled. If you are using NGINX
you have to add the following location block:

    location /web/filestore {  # custom path, hardcoded within Odoo
        # Prevent access from the outside world, i.e. makes this
        # route only accessible via X-Accel. MANDATORY!!!
        internal;

        # Give access to the filestore using this server's
        # permissions. Odoo is in charge of verifying the access
        # rights.
        alias /path/to/odoo/data-dir/filestore;
    }

The Odoo [deployment documentation] has been updated accordingly.

[X-Sendfile]: https://www.nginx.com/resources/wiki/start/topics/examples/xsendfile/
[deployment documentation]: https://www.odoo.com/documentation/master/administration/install/deploy.html#serving-static-files-and-attachments

Changes to the API
------------------

To benefit most from X-Sendfile, all APIs related to streaming content
over HTTP has to be adapted. They are: (1) `request._serve_static`,
(2) `ir.http._serve_fallback`, (3) `/web/content` and (4) `/web/image`.

Each used it own way to deliver content: (1) `_serve_static` was using
`send_file` (flask's send_file that as been vendored with odoo 10
years ago and not maintenained since then), (2) _serve_fallback was
handcrafting a `werkzeug.wrappers.Response`, (3) /web/content-image were
using the "binary server" `ir.http.binary_content` API.

I has been decided to remove all 3 APIs and to merge the code inside of
the new `http.Stream` object and the `ir.binary` helper model.

A Stream wraps what is going to be sent to the browser, it can be a path
to a file on the locale filesystem, a blob of raw data or an URL to an
external resource. The Stream also holds various metadata that are
mainly used for caching. The preferred way to create a Stream is via one
of its three factories so that all the metadata are set. The factories
are: `from_path`, `from_attachment` and `from_binary_field`. A stream
instance exposes a single method `get_response()` used to create the
corresponding HTTP response object out of the stream.

Inside of `ir.http` were a few methods that were not related to the http
routing and formed what was called the "binary server". All those
methods have been removed and the feature have been refactored inside of
the new `ir.binary` model. The removed methods are:

- `_xmlid_to_obj`
- `_get_record_and_check`
- `_binary_ir_attachment_redirect_content`
- `_binary_record_content`
- `_binary_set_headers`
- `binary_content`
- `_response_by_status`
- `_get_content_common`
- `_content_image`
- `_content_image_get_response`
- `_placeholder_image_get_response`

The new `ir.binary` abstract model exposes the following utilities:

**`_find_record`**

Find an attachment or a record with a binary-field out of an xmlid or
out of a pair record-model/record-id. Check the access rights and the
access token.

**`_get_stream_from`**

Create a Stream from an attachment or a record with a binary-field.

**`_get_image_stream_from`**

Same as `_get_stream_from` but adapted for images. It sets a sensible
ETag on the stream and has image resizing support.

**`_placeholder`**

Get the image placeholder blob.

Testing
-------

It is possible to test the web server configuration using the
`test_http` module. Install the module then run the unittest using the
`webserver` test-tag. By default it attempts to connect to a web-server
running on `http://localhost:80`, you can change this URL by setting the
`WEB_SERVER_URL` environment variable.

    odoo-bin -i test_http --stop-after-init
    WEB_SERVER_URL='http://localhost:80' odoo-bin --test-tags webserver --stop-after-init

closes odoo/odoo#88134

Task: 2801675
Related: odoo/documentation#2083
Related: odoo/enterprise#26191
Signed-off-by: Julien Castiaux <juc@odoo.com>
2022-06-01 02:53:59 +02:00
Mathieu Walravens ae95a1025e [FIX] base: shadowed attachment filename
When a filename is given to the function binary_content it was shadowed
by _binary_ir_attachment_redirect_content if it is an ir.attachment.

To reproduce:
  1. Start a brand new database in V14, install any app on which you can add an attachment (like Project or CRM)
  2. Add a file as an attachment
  3. Try to call the route "/web/content/<string:model>/<int:id>/<string:field>/<string:filename>"

closes odoo/odoo#87879

Solution: Use another variable to store the return value of _binary_ir_attachment_redirect_content and use it if the filename is not provided.
X-original-commit: 55e6097502da6169b85056b4769f4bf7fd230968
Signed-off-by: Wanderscheid Mathieu (mawa) <wama@odoo.com>
Signed-off-by: Julien Castiaux <juc@odoo.com>
2022-04-04 14:45:15 +02:00
Julien Castiaux 1dd3865208 [IMP] *: odoo.addons.web.controllers.main splitted
The odoo.addons.web.controllers.main python module have been splitted
over multiple files on the basis 1 controller = 1 file. In this work we
adapt all modules to use the new imports.

A non-exhaustive list of where stuff have been moved:

* main.Home		--> home.Home
* main.Session		--> session.Session
* main.WebClient	--> webclient.WebClient
* main.clean_action	--> action.clean_action
* main.ensure_db	--> home.ensure_db

The complete list is accessible in odoo.addons.web.controllers.main.

closes odoo/odoo#87571

Related: odoo/enterprise#25746
Signed-off-by: Raphael Collet <rco@odoo.com>
2022-03-31 02:10:53 +02:00
Julien Castiaux 5ced646b3f [FIX] auth_signup: impossible to login
Install auth_signup, go to /web/login, 500 Internal Server Error.

auth_signup extends the /web/login template and in this extension calls
`keep_query()` which has been wrongly moved from base to http_routing in
commit 880954ebfc. Here, we restored `keep_query()` in the base module
but moved in ir_qweb.

closes odoo/odoo#87491

Related: odoo/enterprise#25754
Signed-off-by: Julien Castiaux <juc@odoo.com>
2022-03-30 17:35:06 +02:00
Julien Castiaux f04b90b6e8 [REF] core: HTTPocalypse (12) web ir.http & login
This commit is the 12th commit of a comprehensive refactor of our HTTP
framework. See odoo/odoo#78857 for complete historic, discussions and
rationnals.

The web module is twofold, on one side there are many controllers: /,
/web, /web/login, /web/database/selector, /web/dataset/call_kw, etc, on
the other side there is `session_info`: the method responsible to create
the web client's environ.

This module is kinda an exception as it is (with base) a server wide
module. In the case of the HTTP framework, it means that the controllers
of web are always accessible, i.e. going to / or /web/login will never
return a 404 Not Found even if the user is not connected to a database.

This is both a blessing and a curse. It is a blessing because the
controllers are always accessible it means that a new users can freely
access those routes. It is a curse because *any* user can access them,
even user who don't have a session yet thus who are not connected to a
database yet. From a developer standpoint, we have to put extra care to
correct serve users with and without a database. An example is the
/web/login route, the login/password pair is stored in a database,
without database it is impossible to validate a user login but users can
still access this route without db.

To solve this problem, there is the `ensure_db` function. This function
attempts to find a database using various sources (?db= query-string,
session db, mono db) and to save it on the user session. In case no db
is found, the user is redirected to the database selector. In a way,
this function grants a database to the user in a seamingly experience.
In a way, this function brings a welcome differentiation between
`auth='none'` with a database and `auth='none'` without a database. Such
differentiation only matters for the server wide modules as "regular"
module controllers are only accessible via the ir.http routing map, i.e.
it is not possible to declare a nodb controller outside of server wide
modules.

An important changement is the `session.authenticate` method, before it
was possible to call the method when the cursor was not yet initialized,
authenticate would open a cursor against the given database, setup a
registry and an environment and ultimately save everything on the
current request. Because the cursor is now greedily created, it is no
more possible to update the request environment when authenticating on
another database.

PR: odoo#78857
Task: 2571224
2022-02-24 13:30:50 +00:00
Julien Mougenot 0dc347370f [FIX] web: Allow XML template attachments
Before this commit: static XML templates could only be defined on the
file system, and called by manifest assets or ir.asset records.
Attachments were not taken into account when evaluating static
templates.

Now, if a given path does not match a file on the system, an
additional check is run on ir.attachment records instead of failing
directly.

Task 2715333

closes odoo/odoo#83438

X-original-commit: e022c4bfafa77f1a3433c3b980631510af696ade
Signed-off-by: Lucas Perais (lpe) <lpe@odoo.com>
Signed-off-by: Julien Mougenot (jum) <jum@odoo.com>
2022-01-26 19:22:57 +00:00
Xavier-Do b1efacf417 [FIX] web: fix tests for runbot
On runbot database can be create concurently by other builds, meaning
that the teardown may fail randomly if a database is create between
setup and teardown. Filtering on the dbfilter in all case may miss some
errors but will be enough in this case.

closes odoo/odoo#83414

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2022-01-26 14:09:06 +00:00
Achraf (abz) 5cd61fc810 [FIX] web_studio: add background image in the cache hashes
When changing the background image with studio the image does not update.
It works in debug=assets mode.
This is due to the fact that the caching system is not aware of the presence of a possible background image

opw-2696786

closes odoo/odoo#83374

X-original-commit: 184029e3e1e8907e25dd712dd87afd65885695bb
Related: odoo/enterprise#23744
Signed-off-by: Achraf <abz@odoo.com>
2022-01-26 10:15:59 +00:00
Xavier-Do 3c58197d81 [IMP] web: add tests for database manager
Database manager may easily be broken since it wasn't tested and is a
special case (can be rendered without databases).  This commit adds a
basic test to check that the database manager is rendered as expected.

Testing database rendering is not enough, in some cases the database
operations may be broken.  Another test will be executed on runbot to
test basic create/duplicate/delete operations.  The test is tagged as
"-standard" since it can be a risk to execute such operation
automatically with other tests.

closes odoo/odoo#82874

Signed-off-by: Raphael Collet <rco@odoo.com>
2022-01-24 11:09:56 +00:00
Christophe Monniez 8b295ad968 [FIX] tests: bump allowed assets generation time
As this test is always red, notably because of the qunit asset bundle, the
threshold is raised for some bundles based on runbot builds
observations.

closes odoo/odoo#82972

X-original-commit: ab8350b5432a6a6d671bcc76413815274f7daaca
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2022-01-18 13:40:47 +00:00
Laurent Stukkens (LTU) 9ffb0143d0 [FIX] web: order company by their sequence in the company switcher
As JS is not taking the properties in the order they are written,
the order in the rendering was always following the property name
sorting order (=id).

Previous to this commit:

    - The companies were ordered by their id in the company switcher as
      JS is not tacking the object properties order into account.

After this commit:

    - The companies will be sorted by their sequence prior to be used in the
      rendering.

task-2722235

closes odoo/odoo#81893

X-original-commit: 39c678a1ccb50d3a1871a4049a8df26427b27a3c
Signed-off-by: Laurent Stukkens (ltu) <ltu@odoo.com>
2021-12-24 12:25:01 +00:00
Julien Castiaux 2e29a93503 [REF] core: remove http.addons_manifest
The http.addons_manifest is a map {module: manifest_dict} that is
populated upon the first http request. This map is basically a module
manifest cache with an extra `addons_path` key, the path of the module
on the file-system. This cache is eagerly populated upon the first http
request, the map is empty in non-http contextes (e.g. cron) which have
been a source of bugs (e.g. 50c8eb1).

A manifest cache is necessary because reading and parsing python files
from the file-system is not that cheap but there is no reason that cache
is located in `odoo.http`. A thin cache layer now wraps
`load_information_from_description_file()`/`load_manifest()` and is
lazily populated.

The `http.addons_manifest` have been removed. The extra `addons_path`
key is now present in the "normal" manifest. The `read_manifest()` was
hardly used so it has been deprecated. The only way to retrieve a
manifest is now `load_information_from_description_file()` which was
renamed `load_manifest()` (no cache) and `get_manifest()` (cache).

Side note about performances, the cache is necessary. Addons manifest
are read-only and reading + parsing python files from the file system is
not a cheap operation. Running the e-commerce tour
`@website_sale.test_04_admin_website_sale_tour` without cache on
`load_manifest()` requires 68,29 secs to complete on my laptop,
exceeding the default 1-minute time frame allowed in tests. Using a
cache the time is down to 36,53 secs. The performance impact is huge.

Part-of: odoo/odoo#79977
2021-12-14 12:39:54 +00:00
Xavier Morel 52b2edf623 [IMP] point_of_sale: cleanup unnecessary testing content
* remove `component_extension_tests`, that's a test from web and
  already tested by web, no idea why it's rerunning in POS
* remove all failfast specs, after discussion with ged, seb, and
  xdo it was considered not useful: it's mostly for the runbot but
  turns out to be pretty minor as far as positives go, and it makes
  fixing errors much harder

Part-of: odoo/odoo#77735
2021-10-25 09:53:11 +00:00
Xavier-Do 68ea460f3f [IMP] profiling, base: add enable profiling wizard
When using profiling on a fresh test database, it can be tedious to
access settings to enable the feature. This commit adds a wizard to help
enabling profiling without accessing the settings when trying to
activate profiling on a administrator session.

closes odoo/odoo#75967

Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2021-09-06 12:03:27 +00:00
Adrian Torres e2f3ac24d0 [IMP] web: allow read_progress_bar to group by m2m fields
The value returned by the search_read in read_progress_bar when passing
a m2m field is a list of ids, which then read_progress_bar tries to use
in a dictionary, list is not a hashable type thus it crashes.

With this commit we convert the group_by_value from list to tuple,
which is hashable, if we're dealing with a many2many field.

task-2508608

Part-of: odoo/odoo#74985
2021-08-26 16:24:59 +00:00
Xavier-Do fdaee845d5 [FIX] base: remove options parameters
Regarding previous commit, the option parameter can be removed
from _get_asset_content api, followed by a nice snowball effect.

Part-of: odoo/odoo#75248
2021-08-26 10:21:10 +00:00
Xavier-Do b44345dd8d [IMP] web: split js and css assets generation in perfs test
The given time are currently quite high (arround 5 seconds for some
bundles) but it is difficult to know what kind of assets are taking so
much time. This commit will split js and css in order to track the
generation time separatelly.

closes odoo/odoo#75030

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2021-08-12 13:17:29 +00:00
Adam Heinz 542ed0e6cf [ADD] Health checks for load balancers.
https://tools.ietf.org/html/draft-inadarei-api-health-check-04

closes odoo/odoo#56522

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2021-08-11 14:01:02 +00:00
Christophe Monniez 9451489bfb [IMP] web: logs assets generation time
From time to time, the bundle generation duration may be unexpectedly
increased by assets modifications.

In order to avoid that, this commit adds two tests that generates all
the bundles. One of the test is only meant to log the duration in order
to monitor it. The other test is ensuring that a bundle generation does
not take more than 2 seconds.

Pay attention that the purpose is not to test the generation of the
bundle, any error during generation is logged as an information.
Also, warnings are silently ignored.

closes odoo/odoo#74746

Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2021-08-05 10:05:49 +00:00
Ivan YelizarievandRaphael Collet feecd15956 [FIX] web: speed up read_progress_bar
The method is used to get progress per column in kanban view
(green-yellow-red-red lines in Project, CRM etc).  There are two main
usages:

1. get statistics for ``kanban_state`` (red/green circles)
2. get statistics for ``activity_state`` (colored clock icon for overdue/today/planned)

Before this commit all cases were handled by calling search_read and then
counting records per group in a python script.  This is very inefficient,
especially for ``activity_state``.

This new implementation relies on ``read_group`` when possible, i.e.,
when both grouping fields (kanban column and progressbar field) are
stored (case 1).  It then falls back on a naive implementation inside
``_read_progress_bar``.  Cases like 2 above can be addressed by
overriding ``_read_progress_bar``.

We also added some minimal test to ensure that we don't break anything.

1. Performance test on 60 K project.task records (kanban_state):

With a filter for 6 records:

```
| measurement        | before | after |
|--------------------+--------+-------|
| number of queries  |      8 |     5 |
| query time, ms     |     11 |     7 |
| remaining time, ms |     21 |     9 |
```

All records:
```
| measurement        | before | after |
|--------------------+--------+-------|
| number of queries  |     67 |     5 |
| query time, ms     |    300 |    55 |
| remaining time, ms |   1780 |    12 |
```

---

opw-2346901
task-1915411

X-original-commit: 153621bdbab94a2a94a5bbfcabb4111cbc5970d8
Co-authored-by: Raphael Collet <rco@odoo.com>
2021-07-16 11:16:34 +00:00
Aaron Bohy e973e61c5f [FIX] web: click all as demo: load menus as demo user
Before this commit, the clickEverywhere test was run for the demo
user on all apps available for the admin. It thus crashed on the
apps that aren't available for the demo user.

closes odoo/odoo#72430

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2021-06-22 09:02:40 +00:00
Christophe Monniez 6a97f4a013 [FIX] web: fix clickEverywhere test
With the rewrite of the webclient in OWL 29731b404f, the load_menus
method now returns all menus instead of the root menu.

This commit adapts the click_everywhere tests to the change.

closes odoo/odoo#72405

Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2021-06-21 08:38:17 +00:00
+1 0573acae23 [REF] web: rewrite the webclient in OWL (phase 1)
This commit is the first phase of the conversion of the web/ JS
codebase to the owl framework. The impact of this commit is two-fold.

First, it rewrites the framework part of web with a new system of
services and registries. Services allow to execute code (e.g. do rpcs,
setup things) before launching the application. They can also expose
an API to be used by other parts of the application (e.g. a notification
service would expose a function to display notifications). Services are
often a good extension point for external modules that want to execute
code at webclient startup. Registries offer another way to extend the
application. They provide well designed extension points to add
elements/behaviors from the outside (for instance, to add a systray item,
an error handler...).

Second, this commit initiates the conversion of the webclient to owl
with a top-down approach, around those notions of services and registries.
The root of the web application is now an owl application. Among others,
the WebClient, ActionManager, Navbar, UserMenu, DebugManager, Dialogs,
services (e.g. notification, ajax...) have been converted to the new
framework/architecture.

Legacy views and client actions are still supported (and used). They
will be converted in the next months, and at some point, the support
will be dropped.

Co-authored-by: Aaron Bohy <aab@odoo.com>
Co-authored-by: Bruno Boi <boi@odoo.com>
Co-authored-by: Géry Debongnie <ged@odoo.com>
Co-authored-by: Samuel Degueldre <sad@odoo.com>
Co-authored-by: Mathieu Duckerts-Antoine <dam@odoo.com>
Co-authored-by: Simon Genin (ges) <ges@odoo.com>
Co-authored-by: Francois (fge) <fge@odoo.com>
Co-authored-by: Michael Mattiello (mcm) <mcm@odoo.com>
Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Lucas Perais (lpe) <lpe@odoo.com>
Co-authored-by: Jorge Pinna Puissant <jpp@odoo.com>
2021-06-18 21:31:27 +02:00
Simon Genin (ges) 62f99565be [FIX] web: remove debug comment on qweb template extension
Owl 1 has some issues handling comments. So when people were in odoo
debug mode, inheriting in extension mode a t template, the comment
added from the server would throw a frontend error.
For now, we comment it, waiting for better comment handling in owl.

closes odoo/odoo#70227

Signed-off-by: Géry Debongnie (ged) <ged@openerp.com>
2021-06-03 14:30:51 +00:00
Xavier-Do 4c4a740e0a [IMP] web, base: add option to profile dispatch
The profiling tools can be useful to profile a test of some execution
point but this is not convenient to identify a problem on a running
instance.

With this commit, an option available in the debug menu allows to add a
flag on the user sessions to enable profiling of all requests. Each
request will be saved in a different 'ir.profile' entry, but will be
grouped under the same session.

The profiling can be activated on all sessions, even for a public user,
but only if profiling is enabled on the database globally.

This commits also adds a speedscope view to visualize saved results in
the web client.

closes odoo/odoo#66590

Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2021-06-02 11:46:28 +00:00
Aaron Bohy 30f52f3f8c [FIX] web: check QUnit.only: wrong bundle name
closes odoo/odoo#70685

X-original-commit: d38b5f9a69b3503c5f220bceddc4a924bf8c7c69
Signed-off-by: Lucas Perais (lpe) <lpe@odoo.com>
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2021-05-11 14:22:22 +00:00
Lucas Perais (lpe) f576c96a88 [FIX] web: route /web/session/modules returns a list
Since the changing of assets (8cc066173d)
the /web/session/modules route returned a stringified set instead of a list

After this commit, the route returns a list

closes odoo/odoo#70545

X-original-commit: 54e4a48996826dd8ea16a84517b46a847d6daf3f
Signed-off-by: Lucas Perais (lpe) <lpe@odoo.com>
2021-05-07 14:31:02 +00:00
abd-msyukyu-odoo a03c882a56 [FIX] web: fix kanban view progressbars related to records in another group (groupby:week)
* IMPACTED VERSIONS

  12.0+

* HOW TO REPRODUCE

locale :  Locale is en_US (or other SUNDAY based)
view:     CRM - My Pipeline - Kanban view
groupBy:  date_deadline:week (Expected closing)
records:  one record with a planned activity, on date_deadline = 2021-05-02 (SUNDAY)
          one record with no planned activity, on date_deadline = 2021-05-09 (SUNDAY)
remark:   don't keep any other record in MAY for better visibility

* PROBLEM

The progressbar of the week containing 2021-05-09 displays information about the record
from the week containing 2021-05-02

* CAUSE

1. PostgreSQL `date_trunc` function follows ISO8601 which essentially means that
  the start of a WEEK is always MONDAY. There is no argument to change this.

2. _read_group_format_result
  https://github.com/odoo/odoo/blob/27da86a138089c1838e4b94f8a6976995b9c1fff/odoo/models.py#L2210-L2219

  - Computes a label for a group of records.
  - Follows the locale for the label of the week, based on a date which is
    always a MONDAY because of `date_trunc`.

3. read_progress_bar
  https://github.com/odoo/odoo/blob/88957afca09662af7eaa19df1e40b3699e45e79e/addons/web/models/models.py#L167-L175

  - Associates a group label to a record.
  - Follows the locale for the label of the week, based on the date of a record
    which can be any day of the week. If the record is related to a SUNDAY and
    SUNDAY is the first day of the week, it would have been in a group with a
    different label in (2.) than in (3.) prior to this change.

* FIX

In 3., before associating a label to a record, we truncate the date to the
ISO start of the period, so that the label is determined for a record in the
same conditions than in 2. The locale is still used to get language-dependent
outputs with babel, but the grouping will always follows ISO8601 (date_trunc).

* TEST

Added a test for this problem case

TASK-ID : 2517848

closes odoo/odoo#70498

X-original-commit: 4560925b26fa79740b9618fd9241d3517b64f43f
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-05-06 17:56:20 +00:00