The `binay_image` and `content_disposition` are moved
from the web controller to the `ir.http` model,
to be able to override these methods.
This makes possible to browse the records images as sudo
when the record is published on the website.
e.g. to see the partner images on the website `/partners` page
from the `website_crm_partner_assign` module.
opw-659244
The QWeb image widget allows passing either
max_width, max_height or both, but the
controller required both.
We'll consider a 0px dimension request as
meaning: "appropriate value according to ratio".
URL attachments are now returned as data and not redirection.
If the url does not match with a module file, the 301 status
(redirection) is still returned.
This allows to use the /web/image/<xmlid>/<dimension> route
and get an image attachment with correct dimensions.
Some accounting model (i.e. account.tax) are redefining the ORM search
method, but with misordered arguments (placing count as fifth argument
instead of context).
For the export function, this lead to have the "context" variable
associated to the "count" function variable. As "count" is then
considered as True, the method returns the number of records instead
of the list of record ids. This then exported the last record (the
count'th one) instead of all the records that matched the domain.
The solution here is to explicitly give the context variable by name.
- Differentiate between the Community and Enterprise editions
in the version number. By adding this attribute on the global
odoo JS object in the web client bootstrap controller /web,
we can differentiate between versions easily on the client
side without extra RPC calls.
- Remove a couple of version-related RPC calls in case
the global version info is present in the JS environment
- Update "About" panel to display the edition info
- This commit also reverts 07fe5afc87
which implemented the idea in a more limited way.
Closes#9625
HTTP status lines are required to have both
a status code *and* a "reason phrase".
Some stricter HTTP clients / proxies choke
on status lines without "reason".
Technically, setting `response.status` is supposed
to set both at the same time, so we need to provide
both, or to set `status_code` only and let werkzeug
add the reason. This patch does the latter.
Fixes#8924
This reverts commit bd9cbdfc41.
The above revision solved the SQL constraints not being
translated when raised. They were not translated because
the context, containing the lang, was not located as expected
in the `kwargs` dict.
While it solved this issue, it had as side-effect to raise
`current transaction is aborted,
commands ignored until end of transaction block` errors more
often when using the web client.
This can be explained by the double check, when the first
check raised this error
- which can happen, e.g. when the cursor is closed,
there is a retry mechanism in such cases -
and by the fact the transaction was not rollbacked.
This issue could have been solved as well by rollbacking
the transaction, but it is regarded as not-so-clean.
Therefore, to solve this issue, while still having
the SQL constraints translated, we apply the
second patch proposed in bd9cbdfc41
commit message, which is not-so-clean as well, but
which is a proper solution.
opw-651393
Only used by web tests (which rely on a module they don't depend on to
run, bad!) and altering the test session directly should work, so this
endpoint seems completely unnecessary.
* make CSRF protection the default on all non-SAFE methods
note: there currently is no way to call a CSRF-protected endpoint
without a form-encoded entity-body as that's the only place we get the
CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
the purpose of a CSRF token in the database manager screens.
There is no request database to obtain the
secret and generate a CSRF token.
The stdlib version of the json library is more recent than the 3.5.3
version we are pinning in `requirements.txt`
There is no reason to use it.
Closes#6940
The structure `filename*=UTF-8` works in Safari, from
release 6.2 (which is set as version 537 in the user_agent version).
This structure has the advantage to handle the UTF-8 encoding,
and therefore special characters, such as accents.
Therefore, from this Safari release, we use the same format
than other browser. For older releases, we use the format
`filename=`, without UTF-8, ASCII encoded, replacing
special characters by `?`.
opw-649863
The `check` decorator expects the context to be in the `kwargs`
or to be the last arguments of the method.
The `call_kw` route, which is decorated by the `check` decorator,
like every route,
expands its kwargs arguments.
Therefore, once in the `check` decorator,
the context is located in the `kwargs` key
of the kwargs.
(More simply, instead of
`kwargs.get('context', {})`
it's
`kwargs.get('kwargs', {}).get('context', {})`
As the context is not retrieved correctly,
the lang is not set correctly either,
and the sql constraints were not translated.
In 7.0, it worked, because there was a double
check, as the call_kw was called trough an rpc
(`dispatch_rpc`) call,
which was decorated by the `check` as well.
As a fix for 8.0, we apply the same logic,
we perform a double check, with an indirection.
The check decorator should probably be
refactored, but this cannot be done
in a stable release such as 8.0.
Closes#3634
In method `user_has_groups`, make "Technical Features" effective in debug mode.
Make the group "Employees" inherit "Technical Features".
Make the group "Technical Features" invisible in the user form view.
Remove useless `ir.rule` attached on group "Technical Features".
Fix `test_acl` by avoiding the tricks around the group "Technical Features".
Replace deprecate controllers like /web/binary/image, /web/binary/saveas...
Use ETag for all content with 'unique' option to cache the content if the content is never changed.
* listing of modules in website already bypassed session user
* altered authenticated endpoint so it does the same
* sudoed a few read accesses & name_get in groups
* other accesses are list/form views, menu only accessible to
system_user
* new-API-ified some calls & unified listing of installed modules
POST requests on routes with auth="user" are now correctly handled when
the user is not connected. Request data (form and files) are stored in
the session. Once the user is logged, redirect her to a specific route
that will reprocess the original POST request.
- fix html and css layout using only pure bootstrap
- replace db selection by a link to the database selector
- reorder templates
- remove unused templates
Partial backport of commit 093e39bd.
When a flow is stopped by a login redirection, some data (e.g: a product
comment being posted) could be lost. This commit in this case convert
POST request data to GET data (so it is possible to add a GET controller
which after login will terminate the action).
closes#7100
opw-642350
When a user tries to log into a postgresql database with no view web.login (this
happens if the database is not an odoo database or using a previous version of
odoo), the rendering failed, producing a 500 error (with no detail for the user)
Instead, redirect to the database selector with an informative message.
Fixes#3443
The database selector page is a jinja template with no access to database
required so should be able to be displayed on any database.
Future improvement could verify the version of base module for even more precise
verification before login (but need to make sure it's always accurate).
When the upload of an attachment failed,
e.g. for access rights reasons,
the traceback wasn't written or returned anywhere,
preventing the easy debugging.
opw-640242
The headers returned by content_disposition must be either in Unicode or in ASCII.
The encode function expects a Unicode or ASCII string.
The quote function from urllib2 expects a UTF-8 string and retruns a ASCII string.
opw:634205
Fixes#6160, #6557