Commit Graph
4952 Commits
Author SHA1 Message Date
Benoit Socias fb9efde4f3 [FIX] *: replace werkzeug's Response by odoo's Response
*: base, http_routing, mass_mailing, web, web_editor, website_slides

In some situations `werkzeug.wrappers.Response` are used instead of
`odoo.http.Reponse` that extends it.
This is a problem because since [1] the calls to `set_cookie` expect it
to accept the `cookie_type` parameter, which is not the case in the base
werkzeug implementation.

This commit replaces the `werkzeug.wrappers.Response` by
`odoo.http.Response`.

[1]: https://github.com/odoo/odoo/commit/2cbda6c98ee947cea1d06c09880eee8c758304a8

closes odoo/odoo#112827

X-original-commit: 28da08292b7028575e628c5ad846fc05d30498f2
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
2023-02-16 09:01:07 +01:00
Xavier-Do f8adfe72dd [FIX] base, website: remove dead code
Looks like this is not useful since #66169
This cleanup was initially in #97879

closes odoo/odoo#112685

Signed-off-by: Vincent Schippefilt (vsc) <vsc@odoo.com>
2023-02-15 10:14:45 +01:00
Dani Baumann 70aecd60b2 [IMP] add Swiss states
closes odoo/odoo#112670

X-original-commit: 57874beb5d0c2e2605f33d34ff19e78536a2b748
Signed-off-by: William André (wan) <wan@odoo.com>
2023-02-14 17:09:59 +01:00
Thomas Lefebvre (thle) 7708b6b5ca [FIX] base: add space between two fields
Steps to reproduce:
Add a record in the "Contacts & Addresses" tab of a contact.

Issue:
There are missing spaces in the information display.

Cause:
The kanban view compilation removes the spaces
(and line breaks) between the different tags.

Solution:
Add spaces on the template.

opw-3131806

closes odoo/odoo#112667

X-original-commit: 7bada7fc942cee0bcfd6447665640ee29a4b5752
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
Signed-off-by: Lefebvre Thomas (thle) <thle@odoo.com>
2023-02-14 17:09:52 +01:00
Aaron Bohy dad8de3863 [REF] base: remove checks on non existent context keys
Those keys have no match in the codebase.

closes odoo/odoo#112613

Signed-off-by: Vincent Schippefilt (vsc) <vsc@odoo.com>
2023-02-14 13:14:01 +01:00
Jordan D. (Joda) b12e8fd338 [FIX] base: fix write deny while creating new contact
How to reproduce
================

1. Create a user with lower privileges then admin
2. Add a new company and a new contact of that company in the contact
   app at the sametime
3. Manually save

This will result in a write access denied

opw-3127591

closes odoo/odoo#112595

X-original-commit: 93a37df79fc30c2f9ac31d60dc897452851fd5bd
Signed-off-by: John Laterre (jol) <jol@odoo.com>
2023-02-14 10:02:30 +01:00
Christophe Monniez 56bb6d5b32 [FIX] base: allow patching of config.options for 3.11
Since python/cpython#18544, unittest mock is not able to properly find
the "odoo.tools.config".

When trying to patch the `options` dictionnary, it leads to
`AttributeError: module 'odoo.tools.config' has no attribute 'options'`

In order to have the tests
working in python <= 3.11, we have to import the config module and patch
the options in place.

Part-of: odoo/odoo#112450
2023-02-14 08:03:23 +01:00
Christophe Monniez a3dffa86f5 [FIX] base, tools: use getlocale vs deprecated getdefaultlocale
As getdefaultlocale is deprecated in 3.11 in favor of getlocale which is
available since at least 3.0.

Part-of: odoo/odoo#112450
2023-02-14 08:03:23 +01:00
Pierre Masereel 1e35315399 [FIX] odoo,base: new Python 3.11 opcodes
When python expression is evaluated in odoo form an action or qweb, we
are checking the opcodes generated by the evaluation of this code. We do
such a verification, because the code from actions and templates can be
written by someone having not access to the server and we don't want to
let them perform actions out of the scope of their database.

In python 3.11, some opcodes from previous versions of Python have been
renamed, grouped or sepcified. There are also new ones that have been
introduce.

In this PR, we are whitelisting the new ones that are needed by odoo to
properly work in this version of Python.

Part-of: odoo/odoo#112450
2023-02-14 08:03:23 +01:00
Dylan Kiss (dyki) 8095e3f1e2 [FIX] base: change US tax id label
Since 16.0 the `Tax ID` field label is dependant on the company country.
For the US we chose `EIN` as the label.
Since there are multiple sources of tax ids in the US, it is better to leave it as the default: `Tax ID`.

task-3162675

closes odoo/odoo#112561

X-original-commit: f6846f5b9dcae6a0a9e26f3b847593a2e8a3222b
Signed-off-by: William André (wan) <wan@odoo.com>
2023-02-14 00:43:00 +01:00
Christophe Monniez 9df3110cc7 [FIX] core: fix import from werkzeug 2.2.2
In werkzeug 2.2.2, the NumberConverter class was moved in routing.
Needed as Debian Bookworm provides werkzeug 2.2.2.

See https://github.com/pallets/werkzeug/pull/2433

Part-of: odoo/odoo#112298
2023-02-10 14:37:30 +01:00
Achraf 74b14b5d02 [FIX] base: Prevent traceback on rate creation
Steps:
 - Create new rate in random currency (for example USD)
 - Try to put 0 in USD per Unit
 - Try to put 0 in Unit per USD

Two errors are raised: ZeroDivisionError and Expected singleton

sentry-3916858495
sentry-3767286632

closes odoo/odoo#112348

X-original-commit: 3a320f5ec2c772a33dc905ed5b717adb9f134800
Signed-off-by: Quentin De Paoli <qdp@odoo.com>
Signed-off-by: Achraf <abz@odoo.com>
2023-02-09 20:04:07 +01:00
Alvaro Fuentes cec6e163c1 [FIX] base: don't fail on empty groups attribute
In 15.0 this was supported. It may be also handy when editing views to
momentarily set the groups to `""`.

Steps to reproduce:
1. Install Odoo 15 locally
2. Edit or create a view with `groups=""` for some component
3. Upgrade to 16.
It fails.

Empty groups was allowed in 15.0 we want to ensure this is not broken
unintentionally anymore, such a new test was added.

Muted logged to hide the warning (also present in 15.0):
```
2023-02-08 11:09:18,697 506777 WARNING test_16_gr odoo.addons.base.models.ir_ui_view: The group '' defined in view does not exist!
View error context:
{'file': None,
 'line': 3,
 'name': 'foo',
 'view': ir.ui.view(242,),
 'view.model': 'res.partner',
 'view.parent': ir.ui.view(),
 'xmlid': ''}
 ```

closes odoo/odoo#112246

X-original-commit: 4379dce95edcc34a8e97e73a3bdaa2e20fdc79a8
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
2023-02-09 10:49:06 +01:00
sofiagvaladze 14d97ec28a [IMP] base,auth_password_policy: add form view for changing password
Purpose: The form view is more intuitive then list view in case
user wants to change the password only for one user.

task - 3105178

closes odoo/odoo#109869

Signed-off-by: Kevin Baptiste <kba@odoo.com>
2023-02-07 14:35:33 +01:00
Martin Trigaux 8872acaede [IMP] base: clarify groups_id label
Using the word "Security" as a label may bring some wrong expectations
on what the value does.
Only on server action does this value is actually enforced at run
time. For window actions and menu, it is only for UX purpose.

closes odoo/odoo#111954

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-02-07 10:39:42 +01:00
Raphael Collet 206525658b [IMP] core: add a class for trigger trees
The class is a simple extension of dict, and adds an explicit attribute
for the content of the root node of a tree.  It makes the code much more
readable with very small performance overhead.

closes odoo/odoo#111946

X-original-commit: 8a01d74e5f7d035cfd05bc02596f075270e0fcf8
Signed-off-by: Raphael Collet <rco@odoo.com>
2023-02-04 22:39:45 +01:00
Raphael Collet 161e5fad3b [REF] core: make APIs on registry for computation triggers
Those APIs are aimed at hiding the implementation of trigger trees,
dependent fields and fields modifying relations.  Explicit APIs simplify
the profiling of executions and comparison of implementations for
building trigger trees.

X-original-commit: d12b9270375634e738f5288d0c523ac0eec2fa18
Part-of: odoo/odoo#111946
2023-02-04 22:39:45 +01:00
Raphael Collet 42b1faf328 [FIX] base: remove circular dependency between fields
The field ir.rule.global depends on ir.rule.groups, and its inverse
field res.group.rule_groups depends on ir.rule.global because of a
domain on the field.  As the domain is only useful client-side, turn the
domain into a string, so that it is only valid client-side.

X-original-commit: ef55c87f6ca7c6bed99cd975ab7dbffb618d2584
Part-of: odoo/odoo#111946
2023-02-04 22:39:45 +01:00
Raphael Collet ed762a3cef [FIX] core: field recomputed on more records than expected
The issue occurs when a computed field depends on a many2many field with
a corresponding inverse field on its comodel.  Consider two models like

class User(models.Model):
    _name = _description = 'test_new_api.user'

    group_ids = fields.Many2many('test_new_api.group')
    group_count = fields.Integer(compute='_compute_group_count', store=True)

    @api.depends('group_ids')
    def _compute_group_count(self):
        for user in self:
            user.group_count = len(user.group_ids)

class Group(models.Model):
    _name = _description = 'test_new_api.group'

    user_ids = fields.Many2many('test_new_api.user')

When a user is added to a group with

    group.write({'user_ids': [Command.link(user.id)]})

we expect the field `group_count` to be recomputed on `user` only, but
it is actually triggered on *all* the records in `group.user_ids`.  This
is a real performance issue when there are many records in the relation.

The explanation comes from the fact that
 - the framework considers the field `user_ids` is modified on `group`;
 - the field `group_count` implicitly depends on `group_ids.user_ids`,
   which makes it triggered on the users `u` such that `u.group_ids`
   intersects `group`.

The solution consists in handling the dependencies on inverse many2many
field in the field itself.  The field no longer adds the implicit
dependency on its inverse field in the trigger tree, but instead
determines which records in the comodel are actually impacted by the
relation change in the method field.write().

closes odoo/odoo#111943

X-original-commit: bb3a6e378b5f6b2e14b74ce4efb6d749ad54cb1e
Signed-off-by: Raphael Collet <rco@odoo.com>
2023-02-04 18:48:07 +01:00
gawa-odoo 29a8d65013 [FIX] base: add German states
We need German states when formatting the 'SteurNummer'.
So we provide it so the user can select his, instead of having to
 create them by hand.

task-3056694
opw-2974560

closes odoo/odoo#111932

X-original-commit: 6c8f3dc4fdffa167680f3a234a13b028c2f54a3b
Related: odoo/enterprise#36703
Signed-off-by: William André (wan) <wan@odoo.com>
2023-02-03 22:52:14 +01:00
Thibault Libioulle c13735bde9 [FIX] base: add cumulated to rng graph file
This commit adds cumulated optional attribute to the graph view rng
definition.

`cumulated` graph attribute is used, defined and tested in PR #97394.

closes odoo/odoo#111880

X-original-commit: 5be91c78c687cc2ac8fd3f9a94e4e8ef2b951efa
Signed-off-by: Dardenne Florent (dafl) <dafl@odoo.com>
2023-02-03 16:32:48 +01:00
Chong Wang (cwg) 4e282f10fc [IMP] core: void model translation
Before this commit, there is no way to "void" model translations, i.e.,
discard a translation and let the value fall back on the 'en_US' value.
The API of methods write() and update_field_translations() can only
overwrite the translations for the specified languages.

After this commit, calling update_field_translations() with a falsy
value except the empty string discards the corresponding translation
value, and let the value of the field in the given language fall back on
the 'en_US' value of the field.

X-original-commit: 5434fb845c393327db377abf872c448f4860a7d3
Part-of: odoo/odoo#111869
2023-02-03 16:32:34 +01:00
Jeremy Kersten fb8765b494 [FIX] base: ir.binary - return valid filename in Stream
Before this commit, if you have some special char like a return line \n,
or \r the get_stream_from method will crash with exception:

```
File "/home/odoo/src/odoo/odoo/addons/web/controllers/binary.py", line 163, in content_image
  return stream.get_response(**send_file_kwargs)
File "/home/odoo/src/odoo/odoo/odoo/http.py", line 578, in get_response
  res = _send_file(self.path, **send_file_kwargs)
File "/home/odoo/src/odoo/odoo/odoo/tools/_vendor/send_file.py", line 156, in send_file
  headers.set("Content-Disposition", value, **names)
File "/usr/local/lib/python3.9/dist-packages/werkzeug/datastructures.py", line 1218, in set
  self._validate_value(_value)
File "/usr/local/lib/python3.9/dist-packages/werkzeug/datastructures.py", line 1182, in _validate_value
  raise ValueError(

ValueError: Detected newline in header value.  This is a potential security problem
```

Now we replace `\n` `\r` by `_` before to serve the stream to avoid this
security exception from a safe way.
We decided to not use secure_filename from werzkeug because we want to
continue the support of non ascii char.

closes odoo/odoo#111851

X-original-commit: 95584e71a898017a92112f89e8a94315dd9235ac
Signed-off-by: Jérémy Kersten <jke@odoo.com>
2023-02-03 16:32:24 +01:00
Jeremy Kersten 3c939ada28 [FIX] base: remove autofocus on help tab from action server
It is only useful the first time to see the help tab.
And the content is already as docstring of the action.

closes odoo/odoo#111838

X-original-commit: 89f92d46e15aed91c535f78d2ec5f32ce11142c5
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Signed-off-by: Jérémy Kersten <jke@odoo.com>
2023-02-03 15:28:04 +01:00
Martin Trigaux a349b0a89b [IMP] test_new_api: move logger to top level
closes odoo/odoo#111764

X-original-commit: ca83a7879aed132ad2ff216405f745b5bd2ebb80
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-02-03 09:28:38 +01:00
Aaron Bohy c1ddd1c29f [FIX] base: no crash when leaving contact with empty name
Go to Contacts, click Create, leave the name empty, click on a
stat button (e.g. Meetings). Before this commit, there's a crash.

It happens because the `name` field is present twice in the view,
with different `required` attrs. Only one of them is visible,
depending on the `is_company` field.

Commit [1] introduced a sub part to the required domains to fix an
issue with the way the legacy form view handled required fields
(basically, the field `name` was displayed twice in the notification
indicating that there were invalid fields), thus making those two
domains different.

With wowl views, this patch is no longer necessary, as the required
attrs is evaluated in the model, so once for each field. Thus,
having two different required domain doesn't make sense anymore
(the last one wins).

This commit fixes the issue by removing the domain sub parts added
by [1].

[1] 8143a641a2

Task 3086014

closes odoo/odoo#111711

X-original-commit: a1ed27352f393b8fff8c4f8985e3f503a07e6e37
Signed-off-by: Géry Debongnie <ged@odoo.com>
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
2023-02-03 06:06:04 +01:00
Xavier Morel a6d601dc4e [FIX] test_lint: deprecation warnings in pylint 3
Runbot currently doesn't use Pylint 3 in order to still have "style"
lints (since removed), however compatibility with pylint 3 is useful
to run tests / lints locally (and possibly eventually in future python
versions for which 2 might not be compatible).

Fix a few deprecation warnings:

- the `__implements__` magic thing has been deprecated
- `check_messages` has been renamed to
  `only_required_for_messages` (better explains the purpose)

Also remove second parameter of `is_message_enabled` call, if
specified it's supposed to be a `Confidence` value, not a
number. Recent pylints changed the way it's checked, so it now errors
even if not using the confidence system (or something like that).

closes odoo/odoo#107960

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2023-02-03 05:09:22 +01:00
Denis Ledoux f498ab4b13 [IMP] base: remove unused check_group methods on ir.model.access
It looks like these methods where an alternative to `has_groups`,
but not used since a while.

In Odoo 10.0, there is only one hit, in point_of_sale,
which has been replaced by `user_has_groups`
in 11.0 with revision
34c661111b

In Odoo 9.0, there are a few more hits in base,
which have been replaced by `self.env.user.has_group`
in 11.0 with revision
4ddc323139

closes odoo/odoo#111622

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2023-02-02 21:25:12 +01:00
Mohammed Erradi (moer) 94d6e8b474 [FIX] l10n_ch: Correct export fiscal position for LI
The aim of this commit is to fix the export fiscal position for invoices between Switzerland and the Principality of Liechtenstein in the Swiss localization.

context:
This commit corrects the Swiss national fiscal position, in accordance with legislation that considers Switzerland and Liechtenstein to be a common fiscal territory of application for VAT.

Previous to this commit:
- When the use create an invoice with a customer from Liechtenstein, the correct VAT is not applied because transactions to Liechtenstein were considered as export transactions.

After this commit:
- When the use create an invoice with a customer from Liechtenstein, the correct VAT is applied because transactions to Liechtenstein are considered as domestic transactions.

closes odoo/odoo#111578

Task-id: 3151891
X-original-commit: 773ad35af4b4d6d8ec608875ded6b5f22ecad1dd
Signed-off-by: Erradi Mohammed (moer) <moer@odoo.com>
Signed-off-by: John Laterre (jol) <jol@odoo.com>
2023-02-01 14:38:18 +01:00
Denis Ledoux b4a7996e96 [IMP] base, *: change the API of init hooks to pass env
This is mostly a cleaning/refactoring change.

The current API for init hooks (pre, post, uninstall) is to pass
`cr, registry`.
But the first thing which was done by most
post init and uninstall hooks was to create an env using
the cr passed
e.g.
`env = api.Environment(cr, SUPERUSER_ID, {})`
and the `registry` argument was unused in all these hooks,
completely.

By changing the API of hooks to pass `env` instead
of `cr, registry`, we gain in average two lines in every
hooks:
- the line creating the env `env = api.Environment(cr, SUPERUSER_ID, {})`
- the line importing `api` and `SUPERUSER_ID`

Therefore removing ~250 lines of repeated code lines accross odoo/odoo and
odoo/enterprise.
In addition to these lines removed,
it also ease the API of init hooks for Odoo developers,
who are used to that `env` and not so much how to create an `env`
from a cursor.

Part-of: odoo/odoo#108254
2023-02-01 10:25:01 +01:00
Denis Ledoux 5bf1207c8c [IMP] base, *: re-use env during registry loading
The goal of this revision is to re-use the environment among the
different steps of the registry loading,
instead of creating a new environment for each step.

1. Simply To avoid to repeat the line
   `env = api.Environment(cr, SUPERUSER_ID, {})`
   multiple times in the code
2. This also allows to share the context among the different
   steps. This is not yet used in this revision, but it could
   be, for instance to avoid the current repetition to add the keys
   `install_module`, in `convert_csv_import` and `xml_import._tag_record`

Part-of: odoo/odoo#108254
2023-02-01 10:25:01 +01:00
niyasraphy 320b91372a [FIX] base: fix access right change warning when no category
Before this commit, if a user group has no category assigned for it, the
user group information message shows the group name in the format
False: Group name, where false is the category name.

To reproduce

  * open users form view
  * assign administrator role in sales and editor role in website
  * Access Rights Mismatch? Since Marc Demo is a/an "Website: Editor and
    Designer", they will at least obtain the right "False: Bypass HTML Field
    Sanitize"

After this commit, in the users form view, "Other" is displayed instead
of False.

closes odoo/odoo#111446

X-original-commit: 54cb5aa41d1a1f21ff5b60d92ee59c8df867f066
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2023-01-31 14:04:33 +01:00
Xavier Morel 98dd7aba2f [FIX] *: used-before-assignment pylint warnings
Warnings show up when using a recent pylint. It's only a fraction of
what e.g. pycharm flags as "local variable might be referenced before
assignment" but seems a good idea to fix anyway in prevision of
possibly eventually updating the reference pylint.

closes odoo/odoo#107968

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2023-01-31 12:55:49 +01:00
Sylvain LE GAL a3be1182af [FIX] base: add 'disable_shrinking' field in views
Add the field disable_shrinking in the report.paperformat form view. This
field has been added recently (see odoo/odoo@9e4c8d61ea / odoo/odoo#68188)
but only in the model.

In this commit we add it in view so that it is controllable.

Followup of task-2483393

closes odoo/odoo#111393

X-original-commit: 6fdf517ea219a021521e3fbdad540d21b5e3ba76
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2023-01-31 00:52:10 +01:00
Nicolas (vin) af771e263c [FIX] base: partner view improvement
Improve the partner view by reorganising the city/state/zip row, making
the order of the fields dependant of the country address_format.
This is done to ease the use of these view for our users by displaying
a format they are already used to.

Task id #3138441

X-original-commit: c646f7bb80cb7f9af689082752608b554f1a648b
Part-of: odoo/odoo#111324
2023-01-30 22:27:15 +01:00
Nicolas (vin) 98a225f4d2 [FIX] base_vat: VIES check should not be blocking
To that end, we will now do the VIES and regular VAT
check separately.
The VAT check stays as a constrains, while the VIES
check will now be done in an onchange and simply
display a warning if it fails.

We will also now allow VAT with a single character to
ignore the checks. This will allow users to better
distinguish partners for which they didn't enter VAT
against partners which are not subject to VAT by setting
the later's VAT to '/' or any other characters.

Task id #3138441

X-original-commit: eff3b140cc88dd48b77948a577f195f2e1910fd8
Part-of: odoo/odoo#111324
2023-01-30 22:27:14 +01:00
Miquel Raïch 317463fb21 [IMP] *: Remove unnecessary view_type
closes odoo/odoo#110817

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2023-01-30 19:45:59 +01:00
Laurent SmetandAaron Bohy cf1bcb1851 [FIX] web,base: add 'count_limit' attrs in kanban and list
This commit adds an attribute in kanban and list archs that
fixes performance issues.

Some tables are very huge and depending of the searched domain,
the search_count made in web_search_read takes much more time
than the search_read. For 10M records, the search_count could take
more than 10x the time of search.

This commit allows to set the count_limit in the arch to override
the hardcoded 10k value.

closes odoo/odoo#111284

X-original-commit: 699215ec9a71b8c9b6a53fe96e924a400d216729
Related: odoo/enterprise#36431
Signed-off-by: Géry Debongnie <ged@odoo.com>
Co-authored-by: Aaron Bohy <aab@odoo.com>
2023-01-28 08:43:48 +01:00
Géry Debongnie b53f78e224 [REF] web_tour,*: use the registry in collecting the tours
This is a step closer to a goal of avoiding dependence on asynchronous
modules. Starting from this commit, new tour definition should be
registered to `registry.category("web_tour.tours")` registry.

So, instead of the following:

```js
import tour from "web_tour.tour";
tour.register(name, options, steps);
```

We now do:

```js
import { registry } from "@web/core/registry";
registry.category("web_tour.tours").add(name, optionsWithSteps);
```

Notice the `options` and `steps` params are merged when registering
the tour definition. It should look something like so:

```js
registry.category("web_tour.tours").add("account_tour", {
  test: true,
  steps: [ ... ],
});
```

And if the `TourManager` instance is needed, one can get it from the
registry like so `registry.get("tourManager")`. Note however that
this instance is only available when the `TourManager` has been
instantiated -- so it's not available at top level of the module.

closes odoo/odoo#111103

Related: odoo/enterprise#36335
Signed-off-by: Géry Debongnie <ged@odoo.com>
2023-01-27 23:17:35 +01:00
Chong Wang (cwg) 3a99c36ae9 [IMP] base: support batch for import_lang
Before this commit:
Importing multiple translations was failing due to concurrent update

After this commit:
1. `translation_importer.save` is moved out of the `try except` to prevent
`UserError` overriding `OperationalError`. So the service can retry the
transaction.
2. batch import is supported to allow RPC to import multiple translations at
once, which is faster and has lower chance to trigger OperationalError

closes odoo/odoo#111211

X-original-commit: 0545f323a67a3bf42d76c94c4d4c375245a69417
Signed-off-by: Raphael Collet <rco@odoo.com>
2023-01-27 14:03:40 +01:00
Florian Vranckxandxmo-odoo 7dc2190fa4 [IMP] test_lint, * : SQL injection detection
This commit brings a new way to detect sql injection.

Previously, this test was meant to push developers to use the second argument of cr.execute(query,args) for parameters.

However, this also meant that the test will always be green as soon as the second argument is used.

This commit aims to change that by tracking the source of information of all variables used to build a query. Parsing of the AST in reverse, starting from the query variable itself.

However these are some current limitations:
  -The hierarchy of Odoo modules is currently not taken into account. If two functions have the same name, they will both be evaluated to find if their return value is part of the query
  -Object mutation is not supported and is not evaluated
  -Whitelisted values are too wide in order to reduce the amount of false positives.

Even if this test is blocking, it can be disabled by adding #pylint: disable=sql-injection at the end of the line.

closes odoo/odoo#101237

Related: odoo/enterprise#35697
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Co-authored-by: xmo-odoo <xmo@odoo.com>
2023-01-26 14:19:00 +01:00
Dylan Kiss (dyki) 8889a896f3 [FIX] base: update Spanish address format
Currently the Spanish address format does not include the province/state.

This change adds the province between parentheses after the zip code and city.

task-3147965

closes odoo/odoo#111012

X-original-commit: 2c31ad84137b3a764116bea6a6d765a2c7d03eb7
Signed-off-by: Nicolas Viseur (vin) <vin@odoo.com>
Signed-off-by: Dylan Kiss (dyki) <dyki@odoo.com>
2023-01-25 19:52:43 +01:00
Laurent Smet 938efa80a0 [FIX] account_accountant: Fix dashboard default bank rec action
Open the kanban view by default when clicking on the journal name.

closes odoo/odoo#110964

Task: 3141127
X-original-commit: 05553202e0a4a59600214fcbf965cfb3c29afbc9
Related: odoo/enterprise#36271
Signed-off-by: Florian Gilbert (flg) <flg@odoo.com>
Signed-off-by: Laurent Smet <las@odoo.com>
2023-01-25 16:37:19 +01:00
Romain Derie fff31b316f [FIX] core: extract normalize from HTML sanitizer
Since [1], it's possible to conditionnally bypass the HTML sanitizer in field
definition with the `sanitize_overridable` attribute.
In a nutshell, when someone is part of the required group(s), it won't go
through the sanitizer, while the people not part of the group(s) will.

A behavior was thus introcuded to prevent a "restricted" user to wipe the
changes done previously by an "elevated" user (which bypassed the sanitizer).
But that behavior was not correct as there was unforeseen cases which led to
raise this error which are not due to the sanitizer but to normalization.

Indeed, while named `html_sanitize()`, it also does some normalize stuff on top
of the real sanitize part.
For instance, there is also (not exhaustive):
- some MAKO compatibility, replacing some chars
- special case for quotes, related to mail clients, which will add data
  attributes, add nodes in dom etc. This happen when the following are found:
  - `<blockquote/>` tag
  - text-based quotes (>, >>) and signatures (-- Signature)
  - html signature (-- <br />blah)
- some editor compatibility which removed the wrapping `<div/>` element
- `nbsp` handling..

See commit list below for detail about how/when/why those normalize cases where
introduced.

At the end, the issue was that the normalize part should not prevent a
"restricted" user to modify the content of an "elevated" user. Only the sanitize
part should.

For instance, the `Quotes` snippet dropped by an "elevated" user was preventing
further edition by a "restricted" user because there was a "false positive"
raised when checking if the save would wipe the existing changes.
Indeed, when the "elevated" user droped the snippet, it was saved as:
```html
<blockquote class=".." data-name="Blockquote">
```
But when the "restricted" user then wanted to do some changes, it would become:
```html
<blockquote class=".." data-name="Blockquote" data-o-mail-quote-node="1" data-o-mail-quote="1">
```

Same for `Share` snippet:
```html
<a href="https://www.facebook.com/sharer/sharer.php?u={url}">
<a href="https://www.facebook.com/sharer/sharer.php?u=%7Burl%7D">
```

[1]: https://github.com/odoo/odoo/commit/cf844e34dd0ce4830eb99fd0fa5b6b9cb58c867c

Normalize commit list:
https://github.com/odoo/odoo/commit/5f1ec49ecdac6d72cd42755c41fbe75d6a1f3587
https://github.com/odoo/odoo/commit/69af79ff3d705d19a71ba3ba7851b981cb301077
https://github.com/odoo/odoo/commit/2bcf4cca79a57dfba84d1f3e3fa7b8908bfe66e8
https://github.com/odoo/odoo/commit/f5688cd8fd515d1b668e8eb1d74de68faa681a01
https://github.com/odoo/odoo/commit/cb8c2d2b7e15c7c16e02d078767e27a07e5012c6
https://github.com/odoo/odoo/commit/275ee5825d38841a3eb21bb195722f3ceed09005
https://github.com/odoo/odoo/commit/b51d21c5b83b88e8d56dbbbb7600bcbe554d1b07

closes odoo/odoo#110903

X-original-commit: 3a2e82cf40f3265650b4f79f9ad5fe309906311d
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2023-01-25 05:06:02 +01:00
Romain Derie 8d3e917e31 [FIX] core: fix typo + improve variable name and comment placement
Extracted in its own commit to ease review of next one which is fixing
the sanitize_overide mechanism.

Note that 'Escalated' is meant to be used when talking about "Privilege
Escalation Attack". It's quite misleading when someone is reading this
"error". 'Elevated' is better (confusion brought by internal team).
Since the translation will be broken by this change anyway, the chance
is taken to make it cleaner and more helpful.

X-original-commit: 34235c48bd511d68f513e747dd3f50b9ea6f46d6
Part-of: odoo/odoo#110903
2023-01-25 05:06:02 +01:00
Adrien Schoffeniels 2be025dfa5 [FIX] base: fix merge contact form layout
Purpose:
========
This commit removes the weird blank space at the edges of the merge contact
form (using custom css that will be removed in master), and displays the
info message and the associated action button shown when there are no more
contacts to merge inside two separate rows, instead of displaying them next
to each other (by adding `colspan="2"` on these elements).

Task-3112116

closes odoo/odoo#110887

X-original-commit: eb7e5de05a5b05054bffbcf3892cf2c432e3295a
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2023-01-25 04:05:48 +01:00
niyasraphy 73c40e01a7 [IMP] base: list sale_amazon in community with upgrade
before this commit, the sale_amazon module is not listed in community instance with upgrade button.

after this commit, the sale_amazon module will be listed in community apps list with upgrade button similar to sale_ebay module.

closes odoo/odoo#110447

Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2023-01-24 13:47:04 +01:00
Martin Trigaux 776689b0f4 [I18N] *: export saas-16.1 source terms
closes odoo/odoo#110752

X-original-commit: 56b2b52287a8f2192d80ea417c7efac80a87c0a9
Related: odoo/enterprise#36173
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-01-24 10:20:30 +01:00
Rémy Voet (ryv) f6cf94d4bd [FIX] *: ormcache works with annotation
The `ormcache` decorator fails to create the key method
(`determine_key`) when the method signature contains any annotation.
Fix it by removing annotation of the signature.

closes odoo/odoo#109777

Signed-off-by: Raphael Collet <rco@odoo.com>
2023-01-23 14:25:14 +01:00
std-odoo 73ba81a8d1 [IMP] base: allow loading the SMTP CLI configuration in a mail server
Purpose
=======
On our saas, when users configure a mail server, they can't use anymore
the "odoo.com" configuration (which is stored in the odoo-bin argument).

To allow them to continue using the SMTP CLI configuration, we add a
new "smtp_authentication". When this authentication method is chosen,
all the "connection" fields of the mail server are ignored, and the
connection information are taken from the odoo-bin arguments. So they
can choose the from filter of this SMTP configuration, the priority...

Task-3061882

closes odoo/odoo#106297

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2023-01-23 11:19:50 +01:00