*: base, http_routing, mass_mailing, web, web_editor, website_slides
In some situations `werkzeug.wrappers.Response` are used instead of
`odoo.http.Reponse` that extends it.
This is a problem because since [1] the calls to `set_cookie` expect it
to accept the `cookie_type` parameter, which is not the case in the base
werkzeug implementation.
This commit replaces the `werkzeug.wrappers.Response` by
`odoo.http.Response`.
[1]: https://github.com/odoo/odoo/commit/2cbda6c98ee947cea1d06c09880eee8c758304a8closesodoo/odoo#112827
X-original-commit: 28da08292b7028575e628c5ad846fc05d30498f2
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
Steps to reproduce:
Add a record in the "Contacts & Addresses" tab of a contact.
Issue:
There are missing spaces in the information display.
Cause:
The kanban view compilation removes the spaces
(and line breaks) between the different tags.
Solution:
Add spaces on the template.
opw-3131806
closesodoo/odoo#112667
X-original-commit: 7bada7fc942cee0bcfd6447665640ee29a4b5752
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
Signed-off-by: Lefebvre Thomas (thle) <thle@odoo.com>
How to reproduce
================
1. Create a user with lower privileges then admin
2. Add a new company and a new contact of that company in the contact
app at the sametime
3. Manually save
This will result in a write access denied
opw-3127591
closesodoo/odoo#112595
X-original-commit: 93a37df79fc30c2f9ac31d60dc897452851fd5bd
Signed-off-by: John Laterre (jol) <jol@odoo.com>
Since python/cpython#18544, unittest mock is not able to properly find
the "odoo.tools.config".
When trying to patch the `options` dictionnary, it leads to
`AttributeError: module 'odoo.tools.config' has no attribute 'options'`
In order to have the tests
working in python <= 3.11, we have to import the config module and patch
the options in place.
Part-of: odoo/odoo#112450
When python expression is evaluated in odoo form an action or qweb, we
are checking the opcodes generated by the evaluation of this code. We do
such a verification, because the code from actions and templates can be
written by someone having not access to the server and we don't want to
let them perform actions out of the scope of their database.
In python 3.11, some opcodes from previous versions of Python have been
renamed, grouped or sepcified. There are also new ones that have been
introduce.
In this PR, we are whitelisting the new ones that are needed by odoo to
properly work in this version of Python.
Part-of: odoo/odoo#112450
Since 16.0 the `Tax ID` field label is dependant on the company country.
For the US we chose `EIN` as the label.
Since there are multiple sources of tax ids in the US, it is better to leave it as the default: `Tax ID`.
task-3162675
closesodoo/odoo#112561
X-original-commit: f6846f5b9dcae6a0a9e26f3b847593a2e8a3222b
Signed-off-by: William André (wan) <wan@odoo.com>
Steps:
- Create new rate in random currency (for example USD)
- Try to put 0 in USD per Unit
- Try to put 0 in Unit per USD
Two errors are raised: ZeroDivisionError and Expected singleton
sentry-3916858495
sentry-3767286632
closesodoo/odoo#112348
X-original-commit: 3a320f5ec2c772a33dc905ed5b717adb9f134800
Signed-off-by: Quentin De Paoli <qdp@odoo.com>
Signed-off-by: Achraf <abz@odoo.com>
In 15.0 this was supported. It may be also handy when editing views to
momentarily set the groups to `""`.
Steps to reproduce:
1. Install Odoo 15 locally
2. Edit or create a view with `groups=""` for some component
3. Upgrade to 16.
It fails.
Empty groups was allowed in 15.0 we want to ensure this is not broken
unintentionally anymore, such a new test was added.
Muted logged to hide the warning (also present in 15.0):
```
2023-02-08 11:09:18,697 506777 WARNING test_16_gr odoo.addons.base.models.ir_ui_view: The group '' defined in view does not exist!
View error context:
{'file': None,
'line': 3,
'name': 'foo',
'view': ir.ui.view(242,),
'view.model': 'res.partner',
'view.parent': ir.ui.view(),
'xmlid': ''}
```
closesodoo/odoo#112246
X-original-commit: 4379dce95edcc34a8e97e73a3bdaa2e20fdc79a8
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
Purpose: The form view is more intuitive then list view in case
user wants to change the password only for one user.
task - 3105178
closesodoo/odoo#109869
Signed-off-by: Kevin Baptiste <kba@odoo.com>
Using the word "Security" as a label may bring some wrong expectations
on what the value does.
Only on server action does this value is actually enforced at run
time. For window actions and menu, it is only for UX purpose.
closesodoo/odoo#111954
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
The class is a simple extension of dict, and adds an explicit attribute
for the content of the root node of a tree. It makes the code much more
readable with very small performance overhead.
closesodoo/odoo#111946
X-original-commit: 8a01d74e5f7d035cfd05bc02596f075270e0fcf8
Signed-off-by: Raphael Collet <rco@odoo.com>
Those APIs are aimed at hiding the implementation of trigger trees,
dependent fields and fields modifying relations. Explicit APIs simplify
the profiling of executions and comparison of implementations for
building trigger trees.
X-original-commit: d12b9270375634e738f5288d0c523ac0eec2fa18
Part-of: odoo/odoo#111946
The field ir.rule.global depends on ir.rule.groups, and its inverse
field res.group.rule_groups depends on ir.rule.global because of a
domain on the field. As the domain is only useful client-side, turn the
domain into a string, so that it is only valid client-side.
X-original-commit: ef55c87f6ca7c6bed99cd975ab7dbffb618d2584
Part-of: odoo/odoo#111946
The issue occurs when a computed field depends on a many2many field with
a corresponding inverse field on its comodel. Consider two models like
class User(models.Model):
_name = _description = 'test_new_api.user'
group_ids = fields.Many2many('test_new_api.group')
group_count = fields.Integer(compute='_compute_group_count', store=True)
@api.depends('group_ids')
def _compute_group_count(self):
for user in self:
user.group_count = len(user.group_ids)
class Group(models.Model):
_name = _description = 'test_new_api.group'
user_ids = fields.Many2many('test_new_api.user')
When a user is added to a group with
group.write({'user_ids': [Command.link(user.id)]})
we expect the field `group_count` to be recomputed on `user` only, but
it is actually triggered on *all* the records in `group.user_ids`. This
is a real performance issue when there are many records in the relation.
The explanation comes from the fact that
- the framework considers the field `user_ids` is modified on `group`;
- the field `group_count` implicitly depends on `group_ids.user_ids`,
which makes it triggered on the users `u` such that `u.group_ids`
intersects `group`.
The solution consists in handling the dependencies on inverse many2many
field in the field itself. The field no longer adds the implicit
dependency on its inverse field in the trigger tree, but instead
determines which records in the comodel are actually impacted by the
relation change in the method field.write().
closesodoo/odoo#111943
X-original-commit: bb3a6e378b5f6b2e14b74ce4efb6d749ad54cb1e
Signed-off-by: Raphael Collet <rco@odoo.com>
We need German states when formatting the 'SteurNummer'.
So we provide it so the user can select his, instead of having to
create them by hand.
task-3056694
opw-2974560
closesodoo/odoo#111932
X-original-commit: 6c8f3dc4fdffa167680f3a234a13b028c2f54a3b
Related: odoo/enterprise#36703
Signed-off-by: William André (wan) <wan@odoo.com>
This commit adds cumulated optional attribute to the graph view rng
definition.
`cumulated` graph attribute is used, defined and tested in PR #97394.
closesodoo/odoo#111880
X-original-commit: 5be91c78c687cc2ac8fd3f9a94e4e8ef2b951efa
Signed-off-by: Dardenne Florent (dafl) <dafl@odoo.com>
Before this commit, there is no way to "void" model translations, i.e.,
discard a translation and let the value fall back on the 'en_US' value.
The API of methods write() and update_field_translations() can only
overwrite the translations for the specified languages.
After this commit, calling update_field_translations() with a falsy
value except the empty string discards the corresponding translation
value, and let the value of the field in the given language fall back on
the 'en_US' value of the field.
X-original-commit: 5434fb845c393327db377abf872c448f4860a7d3
Part-of: odoo/odoo#111869
Before this commit, if you have some special char like a return line \n,
or \r the get_stream_from method will crash with exception:
```
File "/home/odoo/src/odoo/odoo/addons/web/controllers/binary.py", line 163, in content_image
return stream.get_response(**send_file_kwargs)
File "/home/odoo/src/odoo/odoo/odoo/http.py", line 578, in get_response
res = _send_file(self.path, **send_file_kwargs)
File "/home/odoo/src/odoo/odoo/odoo/tools/_vendor/send_file.py", line 156, in send_file
headers.set("Content-Disposition", value, **names)
File "/usr/local/lib/python3.9/dist-packages/werkzeug/datastructures.py", line 1218, in set
self._validate_value(_value)
File "/usr/local/lib/python3.9/dist-packages/werkzeug/datastructures.py", line 1182, in _validate_value
raise ValueError(
ValueError: Detected newline in header value. This is a potential security problem
```
Now we replace `\n` `\r` by `_` before to serve the stream to avoid this
security exception from a safe way.
We decided to not use secure_filename from werzkeug because we want to
continue the support of non ascii char.
closesodoo/odoo#111851
X-original-commit: 95584e71a898017a92112f89e8a94315dd9235ac
Signed-off-by: Jérémy Kersten <jke@odoo.com>
It is only useful the first time to see the help tab.
And the content is already as docstring of the action.
closesodoo/odoo#111838
X-original-commit: 89f92d46e15aed91c535f78d2ec5f32ce11142c5
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Signed-off-by: Jérémy Kersten <jke@odoo.com>
Go to Contacts, click Create, leave the name empty, click on a
stat button (e.g. Meetings). Before this commit, there's a crash.
It happens because the `name` field is present twice in the view,
with different `required` attrs. Only one of them is visible,
depending on the `is_company` field.
Commit [1] introduced a sub part to the required domains to fix an
issue with the way the legacy form view handled required fields
(basically, the field `name` was displayed twice in the notification
indicating that there were invalid fields), thus making those two
domains different.
With wowl views, this patch is no longer necessary, as the required
attrs is evaluated in the model, so once for each field. Thus,
having two different required domain doesn't make sense anymore
(the last one wins).
This commit fixes the issue by removing the domain sub parts added
by [1].
[1] 8143a641a2
Task 3086014
closesodoo/odoo#111711
X-original-commit: a1ed27352f393b8fff8c4f8985e3f503a07e6e37
Signed-off-by: Géry Debongnie <ged@odoo.com>
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
Runbot currently doesn't use Pylint 3 in order to still have "style"
lints (since removed), however compatibility with pylint 3 is useful
to run tests / lints locally (and possibly eventually in future python
versions for which 2 might not be compatible).
Fix a few deprecation warnings:
- the `__implements__` magic thing has been deprecated
- `check_messages` has been renamed to
`only_required_for_messages` (better explains the purpose)
Also remove second parameter of `is_message_enabled` call, if
specified it's supposed to be a `Confidence` value, not a
number. Recent pylints changed the way it's checked, so it now errors
even if not using the confidence system (or something like that).
closesodoo/odoo#107960
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
It looks like these methods where an alternative to `has_groups`,
but not used since a while.
In Odoo 10.0, there is only one hit, in point_of_sale,
which has been replaced by `user_has_groups`
in 11.0 with revision
34c661111b
In Odoo 9.0, there are a few more hits in base,
which have been replaced by `self.env.user.has_group`
in 11.0 with revision
4ddc323139closesodoo/odoo#111622
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
The aim of this commit is to fix the export fiscal position for invoices between Switzerland and the Principality of Liechtenstein in the Swiss localization.
context:
This commit corrects the Swiss national fiscal position, in accordance with legislation that considers Switzerland and Liechtenstein to be a common fiscal territory of application for VAT.
Previous to this commit:
- When the use create an invoice with a customer from Liechtenstein, the correct VAT is not applied because transactions to Liechtenstein were considered as export transactions.
After this commit:
- When the use create an invoice with a customer from Liechtenstein, the correct VAT is applied because transactions to Liechtenstein are considered as domestic transactions.
closesodoo/odoo#111578
Task-id: 3151891
X-original-commit: 773ad35af4b4d6d8ec608875ded6b5f22ecad1dd
Signed-off-by: Erradi Mohammed (moer) <moer@odoo.com>
Signed-off-by: John Laterre (jol) <jol@odoo.com>
This is mostly a cleaning/refactoring change.
The current API for init hooks (pre, post, uninstall) is to pass
`cr, registry`.
But the first thing which was done by most
post init and uninstall hooks was to create an env using
the cr passed
e.g.
`env = api.Environment(cr, SUPERUSER_ID, {})`
and the `registry` argument was unused in all these hooks,
completely.
By changing the API of hooks to pass `env` instead
of `cr, registry`, we gain in average two lines in every
hooks:
- the line creating the env `env = api.Environment(cr, SUPERUSER_ID, {})`
- the line importing `api` and `SUPERUSER_ID`
Therefore removing ~250 lines of repeated code lines accross odoo/odoo and
odoo/enterprise.
In addition to these lines removed,
it also ease the API of init hooks for Odoo developers,
who are used to that `env` and not so much how to create an `env`
from a cursor.
Part-of: odoo/odoo#108254
The goal of this revision is to re-use the environment among the
different steps of the registry loading,
instead of creating a new environment for each step.
1. Simply To avoid to repeat the line
`env = api.Environment(cr, SUPERUSER_ID, {})`
multiple times in the code
2. This also allows to share the context among the different
steps. This is not yet used in this revision, but it could
be, for instance to avoid the current repetition to add the keys
`install_module`, in `convert_csv_import` and `xml_import._tag_record`
Part-of: odoo/odoo#108254
Before this commit, if a user group has no category assigned for it, the
user group information message shows the group name in the format
False: Group name, where false is the category name.
To reproduce
* open users form view
* assign administrator role in sales and editor role in website
* Access Rights Mismatch? Since Marc Demo is a/an "Website: Editor and
Designer", they will at least obtain the right "False: Bypass HTML Field
Sanitize"
After this commit, in the users form view, "Other" is displayed instead
of False.
closesodoo/odoo#111446
X-original-commit: 54cb5aa41d1a1f21ff5b60d92ee59c8df867f066
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Warnings show up when using a recent pylint. It's only a fraction of
what e.g. pycharm flags as "local variable might be referenced before
assignment" but seems a good idea to fix anyway in prevision of
possibly eventually updating the reference pylint.
closesodoo/odoo#107968
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Add the field disable_shrinking in the report.paperformat form view. This
field has been added recently (see odoo/odoo@9e4c8d61ea / odoo/odoo#68188)
but only in the model.
In this commit we add it in view so that it is controllable.
Followup of task-2483393
closesodoo/odoo#111393
X-original-commit: 6fdf517ea219a021521e3fbdad540d21b5e3ba76
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Improve the partner view by reorganising the city/state/zip row, making
the order of the fields dependant of the country address_format.
This is done to ease the use of these view for our users by displaying
a format they are already used to.
Task id #3138441
X-original-commit: c646f7bb80cb7f9af689082752608b554f1a648b
Part-of: odoo/odoo#111324
To that end, we will now do the VIES and regular VAT
check separately.
The VAT check stays as a constrains, while the VIES
check will now be done in an onchange and simply
display a warning if it fails.
We will also now allow VAT with a single character to
ignore the checks. This will allow users to better
distinguish partners for which they didn't enter VAT
against partners which are not subject to VAT by setting
the later's VAT to '/' or any other characters.
Task id #3138441
X-original-commit: eff3b140cc88dd48b77948a577f195f2e1910fd8
Part-of: odoo/odoo#111324
This commit adds an attribute in kanban and list archs that
fixes performance issues.
Some tables are very huge and depending of the searched domain,
the search_count made in web_search_read takes much more time
than the search_read. For 10M records, the search_count could take
more than 10x the time of search.
This commit allows to set the count_limit in the arch to override
the hardcoded 10k value.
closesodoo/odoo#111284
X-original-commit: 699215ec9a71b8c9b6a53fe96e924a400d216729
Related: odoo/enterprise#36431
Signed-off-by: Géry Debongnie <ged@odoo.com>
Co-authored-by: Aaron Bohy <aab@odoo.com>
This is a step closer to a goal of avoiding dependence on asynchronous
modules. Starting from this commit, new tour definition should be
registered to `registry.category("web_tour.tours")` registry.
So, instead of the following:
```js
import tour from "web_tour.tour";
tour.register(name, options, steps);
```
We now do:
```js
import { registry } from "@web/core/registry";
registry.category("web_tour.tours").add(name, optionsWithSteps);
```
Notice the `options` and `steps` params are merged when registering
the tour definition. It should look something like so:
```js
registry.category("web_tour.tours").add("account_tour", {
test: true,
steps: [ ... ],
});
```
And if the `TourManager` instance is needed, one can get it from the
registry like so `registry.get("tourManager")`. Note however that
this instance is only available when the `TourManager` has been
instantiated -- so it's not available at top level of the module.
closesodoo/odoo#111103
Related: odoo/enterprise#36335
Signed-off-by: Géry Debongnie <ged@odoo.com>
Before this commit:
Importing multiple translations was failing due to concurrent update
After this commit:
1. `translation_importer.save` is moved out of the `try except` to prevent
`UserError` overriding `OperationalError`. So the service can retry the
transaction.
2. batch import is supported to allow RPC to import multiple translations at
once, which is faster and has lower chance to trigger OperationalError
closesodoo/odoo#111211
X-original-commit: 0545f323a67a3bf42d76c94c4d4c375245a69417
Signed-off-by: Raphael Collet <rco@odoo.com>
This commit brings a new way to detect sql injection.
Previously, this test was meant to push developers to use the second argument of cr.execute(query,args) for parameters.
However, this also meant that the test will always be green as soon as the second argument is used.
This commit aims to change that by tracking the source of information of all variables used to build a query. Parsing of the AST in reverse, starting from the query variable itself.
However these are some current limitations:
-The hierarchy of Odoo modules is currently not taken into account. If two functions have the same name, they will both be evaluated to find if their return value is part of the query
-Object mutation is not supported and is not evaluated
-Whitelisted values are too wide in order to reduce the amount of false positives.
Even if this test is blocking, it can be disabled by adding #pylint: disable=sql-injection at the end of the line.
closesodoo/odoo#101237
Related: odoo/enterprise#35697
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Co-authored-by: xmo-odoo <xmo@odoo.com>
Currently the Spanish address format does not include the province/state.
This change adds the province between parentheses after the zip code and city.
task-3147965
closesodoo/odoo#111012
X-original-commit: 2c31ad84137b3a764116bea6a6d765a2c7d03eb7
Signed-off-by: Nicolas Viseur (vin) <vin@odoo.com>
Signed-off-by: Dylan Kiss (dyki) <dyki@odoo.com>
Open the kanban view by default when clicking on the journal name.
closesodoo/odoo#110964
Task: 3141127
X-original-commit: 05553202e0a4a59600214fcbf965cfb3c29afbc9
Related: odoo/enterprise#36271
Signed-off-by: Florian Gilbert (flg) <flg@odoo.com>
Signed-off-by: Laurent Smet <las@odoo.com>
Extracted in its own commit to ease review of next one which is fixing
the sanitize_overide mechanism.
Note that 'Escalated' is meant to be used when talking about "Privilege
Escalation Attack". It's quite misleading when someone is reading this
"error". 'Elevated' is better (confusion brought by internal team).
Since the translation will be broken by this change anyway, the chance
is taken to make it cleaner and more helpful.
X-original-commit: 34235c48bd511d68f513e747dd3f50b9ea6f46d6
Part-of: odoo/odoo#110903
Purpose:
========
This commit removes the weird blank space at the edges of the merge contact
form (using custom css that will be removed in master), and displays the
info message and the associated action button shown when there are no more
contacts to merge inside two separate rows, instead of displaying them next
to each other (by adding `colspan="2"` on these elements).
Task-3112116
closesodoo/odoo#110887
X-original-commit: eb7e5de05a5b05054bffbcf3892cf2c432e3295a
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
before this commit, the sale_amazon module is not listed in community instance with upgrade button.
after this commit, the sale_amazon module will be listed in community apps list with upgrade button similar to sale_ebay module.
closesodoo/odoo#110447
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
The `ormcache` decorator fails to create the key method
(`determine_key`) when the method signature contains any annotation.
Fix it by removing annotation of the signature.
closesodoo/odoo#109777
Signed-off-by: Raphael Collet <rco@odoo.com>
Purpose
=======
On our saas, when users configure a mail server, they can't use anymore
the "odoo.com" configuration (which is stored in the odoo-bin argument).
To allow them to continue using the SMTP CLI configuration, we add a
new "smtp_authentication". When this authentication method is chosen,
all the "connection" fields of the mail server are ignored, and the
connection information are taken from the odoo-bin arguments. So they
can choose the from filter of this SMTP configuration, the priority...
Task-3061882
closesodoo/odoo#106297
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>