Bug
===
When an error occurs, the error received is wrongly stringified.
closesodoo/odoo#112504
X-original-commit: b0641c5e85bf9d2e2c64ba548f7243e0a4196602
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Signed-off-by: Stéphane Debauche (std) <std@odoo.com>
It allows to always have a OdooResponse Object and don't allow redirect
to external except when you allow it explicitly with local=False.
Always return to a local url:
/website/add
/slides/slide/<model("slide.slide"):slide>
/microsoft_outlook/confirm
Allow previously external redirect without reason, now blocked
/website/lang/<lang> -> open redirect
Allow external redirect for good reason and url is controlled by code.
/social_facebook/redirect_to_profile/
PS: HTTP Code 303 is a better default for generic redirects. It's not
historically the default for werkzeug.utils, but it is what we want in
general. Contrary to 302, there is no browser-dependent behavior, and
no risk of asking the user whether they want to accept the redirect if
the original method wasn't GET. It's always a non-permanent GET on the
target location.
closesodoo/odoo#95019
X-original-commit: 77f8d9c5d96a9274785ffc2ad83b95ea157d26ad
Related: odoo/enterprise#29000
Signed-off-by: Olivier Dony <odo@odoo.com>
Signed-off-by: Jérémy Kersten <jke@odoo.com>
Purpose
=======
The flow where we copy / paste the authorization code will be
depreciated. Because of that, we know use the newest authentication
system which use redirect URI.
Technical
=========
Now, the user is redirected to an Odoo endpoint "google_gmail/confirm"
and the access token / refresh token are automatically fetched.
Documentation
https://developers.google.com/identity/protocols/oauth2/native-app
Task-2852560
closesodoo/odoo#94476
X-original-commit: 69bd9bc6b36fdd55e8e859667bcddddad6db7d06
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>