Commit Graph
720 Commits
Author SHA1 Message Date
Martin Trigaux 8c8c02598d [FIX] web: untranslated term 2016-01-20 16:41:58 +05:30
Martin Trigaux 8b4f052a38 [MERGE] Forwardport of branch saas-6 up to c649bb0df 2016-01-05 18:28:06 +01:00
Denis Ledoux aef8a4d618 [MERGE] forward port of branch 8.0 up to f9f7669 2015-12-21 18:24:22 +01:00
Holger Brunn f9f7669e60 [FIX] pass context as keyword argument to search()
closes #10080
2015-12-16 11:42:05 +01:00
Denis Ledoux 5cf29dcff2 [FIX] web, website: overrideable images controller
The `binay_image` and `content_disposition` are moved
from the web controller to the `ir.http` model,
to be able to override these methods.

This makes possible to browse the records images as sudo
when the record is published on the website.
e.g. to see the partner images on the website `/partners` page
from the `website_crm_partner_assign` module.

opw-659244
2015-12-11 13:58:49 +01:00
Olivier Dony 8955363808 [FIX] web: /web/image - backwards-compatibility
The QWeb image widget allows passing either
max_width, max_height or both, but the
controller required both.
We'll consider a 0px dimension request as
meaning: "appropriate value according to ratio".
2015-12-09 13:45:00 +01:00
qsm-odoo 8c0b755841 [IMP] web: return file content for url attachments
URL attachments are now returned as data and not redirection.
If the url does not match with a module file, the 301 status
(redirection) is still returned.

This allows to use the /web/image/<xmlid>/<dimension> route
and get an image attachment with correct dimensions.
2015-12-03 13:26:36 +01:00
qsm-odoo bbc67ec402 [FIX] web: export data according to domain
Some accounting model (i.e. account.tax) are redefining the ORM search
method, but with misordered arguments (placing count as fifth argument
instead of context).

For the export function, this lead to have the "context" variable
associated to the "count" function variable. As "count" is then
considered as True, the method returns the number of records instead
of the list of record ids. This then exported the last record (the
count'th one) instead of all the records that matched the domain.

The solution here is to explicitly give the context variable by name.
2015-11-26 15:57:17 +01:00
Damien Bouvy 0a6edac151 [FIX] web, openerp: make the webclient edition aware
- Differentiate between the Community and Enterprise editions
in the version number. By adding this attribute on the global
odoo JS object in the web client bootstrap controller /web,
we can differentiate between versions easily on the client
side without extra RPC calls.

- Remove a couple of version-related RPC calls in case
the global version info is present in the JS environment

- Update "About" panel to display the edition info

- This commit also reverts 07fe5afc87
which implemented the idea in a more limited way.

Closes #9625
2015-11-25 18:12:42 +01:00
Denis Ledoux c8d6b36632 [MERGE] forward port of branch saas-6 up to a0c64bebe6 2015-10-28 12:01:30 +01:00
Christophe Matthieu 63392cc239 [FIX] web: can use web/image controller for attachment type url
Attachment type url return a status 301 for response
2015-10-26 11:43:36 +01:00
Olivier Dony 807e776ac8 [FIX] web: /web/image: conforming HTTP status line
HTTP status lines are required to have both
a status code *and* a "reason phrase".

Some stricter HTTP clients / proxies choke
on status lines without "reason".

Technically, setting `response.status` is supposed
to set both at the same time, so we need to provide
both, or to set `status_code` only and let werkzeug
add the reason.  This patch does the latter.

Fixes #8924
2015-10-22 17:40:33 +02:00
Denis Ledoux a0c64bebe6 [MERGE] forward port of branch 8.0 up to 8209368 2015-10-14 12:28:22 +02:00
Denis Ledoux 8209368b02 [FIX] web: current transaction is aborted
This reverts commit bd9cbdfc41.

The above revision solved the SQL constraints not being
translated when raised. They were not translated because
the context, containing the lang, was not located as expected
in the `kwargs` dict.

While it solved this issue, it had as side-effect to raise
`current transaction is aborted,
commands ignored until end of transaction block` errors more
often when using the web client.

This can be explained by the double check, when the first
check raised this error
- which can happen, e.g. when the cursor is closed,
there is a retry mechanism in such cases -
and by the fact the transaction was not rollbacked.

This issue could have been solved as well by rollbacking
the transaction, but it is regarded as not-so-clean.

Therefore, to solve this issue, while still having
the SQL constraints translated, we apply the
second patch proposed in bd9cbdfc41
commit message, which is not-so-clean as well, but
which is a proper solution.

opw-651393
2015-10-13 17:12:34 +02:00
Xavier Morel afa9f4b5fd [REM] web: /login route
Only used by web tests (which rely on a module they don't depend on to
run, bad!) and altering the test session directly should work, so this
endpoint seems completely unnecessary.
2015-10-01 01:36:50 +02:00
Christophe Simonis 7636b510a2 [ADD] *: CSRF protection in forms and routes
* make CSRF protection the default on all non-SAFE methods
  note: there currently is no way to call a CSRF-protected endpoint
  without a form-encoded entity-body as that's the only place we get the
  CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
  generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
  the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
  the purpose of a CSRF token in the database manager screens.
  There is no request database to obtain the
  secret and generate a CSRF token.
2015-10-01 01:36:50 +02:00
Leonardo Rochael Almeida 60af7cac02 [IMP] replace simplejson with stdlib json
The stdlib version of the json library is more recent than the 3.5.3
version we are pinning in `requirements.txt`

There is no reason to use it.

Closes #6940
2015-09-28 10:53:32 +02:00
Christophe Simonis 57168a9e90 [MERGE] forward port of branch saas-6 up to a669433 2015-09-23 14:34:26 +02:00
Denis Ledoux a3648fd23a [MERGE] forward port of branch 8.0 up to aabbdc7 2015-09-21 16:01:58 +02:00
Denis Ledoux aabbdc7339 [FIX] web: Safari, download of attachments with accents
The structure `filename*=UTF-8` works in Safari, from
release 6.2 (which is set as version 537 in the user_agent version).

This structure has the advantage to handle the UTF-8 encoding,
and therefore special characters, such as accents.

Therefore, from this Safari release, we use the same format
than other browser. For older releases, we use the format
`filename=`, without UTF-8, ASCII encoded, replacing
special characters by `?`.

opw-649863
2015-09-21 15:30:05 +02:00
Christophe Simonis 3bb0cb2a50 [MERGE] forward port of branch 8.0 up to 9c8b99a 2015-09-04 18:30:48 +02:00
Denis Ledoux bd9cbdfc41 [FIX] web: sql constraint translation
The `check` decorator expects the context to be in the `kwargs`
or to be the last arguments of the method.

The `call_kw` route, which is decorated by the `check` decorator,
like every route,
expands its kwargs arguments.

Therefore, once in the `check` decorator,
the context is located in the `kwargs` key
of the kwargs.
(More simply, instead of
`kwargs.get('context', {})`
it's
`kwargs.get('kwargs', {}).get('context', {})`

As the context is not retrieved correctly,
the lang is not set correctly either,
and the sql constraints were not translated.

In 7.0, it worked, because there was a double
check, as the call_kw was called trough an rpc
(`dispatch_rpc`) call,
which was decorated by the `check` as well.

As a fix for 8.0, we apply the same logic,
we perform a double check, with an indirection.

The check decorator should probably be
refactored, but this cannot be done
in a stable release such as 8.0.

Closes #3634
2015-09-04 12:58:00 +02:00
Christophe Matthieu 522fcacb21 [IMP] base: assets now directly use /web/content url 2015-09-03 19:31:00 +02:00
Jérome Maes 275efedaad [IMP] web : add partner_id of the current in the webclient session 2015-09-01 20:05:00 +02:00
Ajay Javiya 31518bc09b [IMP] base: make group "Technical Features" effective in debug mode only
In method `user_has_groups`, make "Technical Features" effective in debug mode.
Make the group "Employees" inherit "Technical Features".
Make the group "Technical Features" invisible in the user form view.
Remove useless `ir.rule` attached on group "Technical Features".
Fix `test_acl` by avoiding the tricks around the group "Technical Features".
2015-08-28 14:51:09 +02:00
Aaron Bohy f3f56f6dc9 [FIX] web: typo introduced by 6baf611df1 2015-08-24 12:00:31 +02:00
Christophe Matthieu 6baf611df1 [IMP] web: create generic controller '/web/content' and '/web/image'
Replace deprecate controllers like /web/binary/image, /web/binary/saveas...
Use ETag for all content with 'unique' option to cache the content if the content is never changed.
2015-08-21 22:06:52 +02:00
Christophe Simonis b2062df319 [MERGE] forward port of branch 8.0 up to 86f98d5 2015-08-21 17:01:17 +02:00
Xavier Morel 2ea5c3aeef [IMP] restrict modules to system_group
* listing of modules in website already bypassed session user
* altered authenticated endpoint so it does the same
* sudoed a few read accesses & name_get in groups
* other accesses are list/form views, menu only accessible to
  system_user
* new-API-ified some calls & unified listing of installed modules
2015-08-21 12:59:06 +02:00
Nicolas Lempereur 0ea89c10b6 [FIX] web: keep hash when login redirect
The anchor part of the url should be kept when a login redirect is done.

introduced by 8f3f9ef46b

note: for 8.0 and saas-6
2015-08-20 11:09:23 +02:00
Christophe Simonis abb4b5d66a [FIX] web: force request.uid for /web route 2015-08-05 13:39:48 +02:00
Christophe Simonis 52f7f0b126 [FIX] web: /web route should be reachable in non-monodb mode 2015-08-05 13:01:33 +02:00
Christophe Simonis 498147fbbf [FIX] point_of_sale,web,website_{blog,forum,sale}: remove useless method login_redirect() 2015-08-05 12:01:12 +02:00
Christophe Simonis b13553d2b6 [FIX] web, base: POST requests handling
POST requests on routes with auth="user" are now correctly handled when
the user is not connected. Request data (form and files) are stored in
the session. Once the user is logged, redirect her to a specific route
that will reprocess the original POST request.
2015-08-05 12:01:12 +02:00
Antony Lesuisse 6933532778 [FIX] web: database manager create error
login was left out when refactoring the branch. It's has been hardcoded as
admin in the final version to minimize the number of inputs.
2015-08-01 19:39:48 +02:00
Antony Lesuisse cd5444a16d [IMP] web: login page cleanups
- fix html and css layout using only pure bootstrap
- replace db selection by a link to the database selector
- reorder templates
- remove unused templates
2015-08-01 18:06:45 +02:00
Antony Lesuisse 3cba55d7a7 [IMP] web: web 1.0 database manager
Implement the database manager with plain HTML forms and HTTP controllers.
2015-08-01 18:04:14 +02:00
Christophe Simonis 13468c271f [MERGE] forward port of branch 8.0 up to ed3065e 2015-06-18 19:41:31 +02:00
Nicolas Lempereur 3f1e99c4b9 [FIX] web, website_form_website_sale: form and login
Partial backport of commit 093e39bd.

When a flow is stopped by a login redirection, some data (e.g: a product
comment being posted) could be lost. This commit in this case convert
POST request data to GET data (so it is possible to add a GET controller
which after login will terminate the action).

closes #7100
opw-642350
2015-06-17 11:33:20 +02:00
Christophe Simonis 4647778758 [MERGE] forward port of branch 8.0 up to ea59856 2015-06-15 12:28:32 +02:00
Martin Trigaux 87d48b0859 [FIX] web: do not crash when select wrong db
When a user tries to log into a postgresql database with no view web.login (this
happens if the database is not an odoo database or using a previous version of
odoo), the rendering failed, producing a 500 error (with no detail for the user)
Instead, redirect to the database selector with an informative message.
Fixes #3443

The database selector page is a jinja template with no access to database
required so should be able to be displayed on any database.

Future improvement could verify the version of base module for even more precise
verification before login (but need to make sure it's always accurate).
2015-06-09 15:05:57 +02:00
Christophe Simonis 14a7d52307 [MERGE] forward port of branch 8.0 up to 327e471 2015-05-21 14:50:39 +02:00
Denis Ledoux db3e5716b3 [FIX] ir_attachment: write traceback to logs when upload fail
When the upload of an attachment failed,
e.g. for access rights reasons,
the traceback wasn't written or returned anywhere,
preventing the easy debugging.

opw-640242
2015-05-20 11:09:05 +02:00
Christophe Simonis 4a0241d6f6 [MERGE] forward port of branch 8.0 up to f722254 2015-05-18 17:35:24 +02:00
Christophe Simonis f722254018 [MERGE] forward port of branch saas-3 up to 0f5b6cf 2015-05-18 17:13:50 +02:00
Christophe Simonis 0f5b6cf60b [MERGE] forward port of branch 7.0 up to c435b84 2015-05-18 17:13:18 +02:00
Goffin Simon c435b8438e [FIX] web: With safari, UnicodeDecodeError
The headers returned by content_disposition must be either in Unicode or in ASCII.
The encode function expects a Unicode or ASCII string.
The quote function from urllib2 expects a UTF-8 string and retruns a ASCII string.

opw:634205
Fixes #6160, #6557
2015-05-13 16:56:12 +02:00
Christophe Simonis 0da722aa6a [MERGE] forward port of branch 8.0 up to bff6dff 2015-05-11 15:12:24 +02:00
Denis Ledoux 272e085df4 [MERGE] forward port of branch saas-3 up to da93981 2015-05-07 11:34:48 +02:00
Denis Ledoux da93981cb0 [MERGE] forward port of branch 7.0 up to f300d64 2015-05-07 11:33:59 +02:00