Step to reproduce:
- Be sure to have `sale_quotation_builder` installed
- Drag & drop the "Steps" snippet on a product in edit mode
- Add this product on a SO in the backend
- Click on Customer Preview
-> The step snippet will not have the connector lines anymore
This is because in Odoo 16, the step snippet connectors are now `svg`
element (see [1]) which are removed by the sanitizer.
```py
from lxml.html import clean
svg='<svg><path/></svg>'
clean.Cleaner().clean_html(svg)
```
It's not the case in the `website_description` field of the product
template as this field is defined with `sanitize_overridable=True` [2]
which make it so the users with the right to do so can bypass the
sanitation and use the Step snippet in this field.
Since the quotation description can be a copy of that field, but without
the same sanitize behavior, the connectors are lost.
Note that most of the `sale_quotation_builder` description HTML fields
were already set as `sanitize_overridable=True` with [2] and [3] but
those ones were not.
[1]: https://github.com/odoo/odoo/commit/aba31e9f2d8a44ce1586403f2a621a6caeed57b4
[2]: https://github.com/odoo/odoo/commit/44ae3f38da07c2215b1547d992f053a11829a8ac
[3]: https://github.com/odoo/odoo/commit/811cf78ee1e63a7c41efe578fb64ee2deeca1dde
opw-3380346
closesodoo/odoo#129690
X-original-commit: 7a928c92136400454e7ed53326f2cdc9173fa1b3
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Current behaviour:
If we add a blockquote in the `website_description` of a product on
the e-shop, we cannot checkout the product. Silent HTTP 400 error
code, due to an exception raised by
https://github.com/odoo/odoo/blob/bf772181933ce5334da35c8368455963b2478399/odoo/fields.py#L1987-L1993
Expected behaviour:
You should be able to checkout products even if they have blockquote
in their `website_description`.
Steps to reproduce:
- Install eCommerce, sale_quotation_builder (issue is present only
after installing sale_quotation_builder)
- On a product, with the website editor, add a `blockquote` to the
description of the product > Save
- In a private browser window, as public user, visit the product on
the e-shop and try to checkout with it.
- Observe there is no visible error, and we do not proceed in the
checkout process.
Reason for the problem:
The exception mentioned above is triggered when there is a
difference between the html content that is saved in the DB and after
sanitization, meaning that someone with escalated privilege saved
the HTML content by overriding the sanitization with
`sanitize_overridable`. In our use case the only diff is the
presence of the attribute `data-o-mail-quote-node` which is removed
after the sanitization.
Fix:
This issue can be resolved two ways:
1) Adding `data-o-mail-quote-node` to the list of save attributes,
meaning it will not be removed during the sanitization process.
Since this is an attribute that we add on `<blockquote>` nodes,
it can be considered safe, just like `data-o-mail-quote`.
2) Remove the attribute sanitization of the `website_description`,
just like it is done in the website_sale module.
Since the `website_description` and `quotation_description` are both
computed from one-another, they should have the same sanitization
level.
I am implementing both solutions, 1) because adding the attribute to
the safe list seems safe in general, and may prevent future
issues of this sort. 2) because it is the root cause of the issue,
since the bug is present only after installation of the
`sale_quotation_builder` module.
Affected versions:
- 16.0
- saas-16.1
- saas-16.2
- master
opw-3297237
closesodoo/odoo#122154
X-original-commit: 23022144cb1a338db05870b28f17360b92c46a9c
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Signed-off-by: Piryns Victor (pivi) <pivi@odoo.com>
Currently, only stable releases see their translations updated. This has
resulted in master accumulating outdated stuff for years, which can be
confusing for users testing master on runbot.
This one-shot commit resynchronizes master translations based on the
content from 16.0 and removes empty PO files (i.e. no longer containing
translations).
closesodoo/odoo#121629
Related: odoo/enterprise#41171
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
This commit put the same field description between 'sale.order.template.line'
and "sale.order.line"
closesodoo/odoo#119576
X-original-commit: 811cf78ee1e63a7c41efe578fb64ee2deeca1dde
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Signed-off-by: Vranckx Florian (flvr) <flvr@odoo.com>
This commit reworks the display of the default SO values
in the settings to make it clear to the users what those
settings impact and that they are overridden by the quotation
template when specified.
task-2880950
Part-of: odoo/odoo#97565
This is mostly a cleaning/refactoring change.
The current API for init hooks (pre, post, uninstall) is to pass
`cr, registry`.
But the first thing which was done by most
post init and uninstall hooks was to create an env using
the cr passed
e.g.
`env = api.Environment(cr, SUPERUSER_ID, {})`
and the `registry` argument was unused in all these hooks,
completely.
By changing the API of hooks to pass `env` instead
of `cr, registry`, we gain in average two lines in every
hooks:
- the line creating the env `env = api.Environment(cr, SUPERUSER_ID, {})`
- the line importing `api` and `SUPERUSER_ID`
Therefore removing ~250 lines of repeated code lines accross odoo/odoo and
odoo/enterprise.
In addition to these lines removed,
it also ease the API of init hooks for Odoo developers,
who are used to that `env` and not so much how to create an `env`
from a cursor.
Part-of: odoo/odoo#108254
The aim of this commit is to simplify and standardize the settings archs.
To do this, a small DSL exclusively for the settings was created. This
new DSL introduces 3 tags: `app`, `block` and `setting`.
The `app` tag is used to declare the application on the settings view.
It creates an entry with its logo on the sidebar of the view. It also
acts as delimiter when searching.
```xml
<app string="CRM" name="crm">
...
</app>
```
- `string` : The "display" name of the application.
- `name` : The technical name of the application (the name of the module).
- `logo` *optional* : The relative path to the logo. If not set, the
logo is created using the `name` parameter :
`/{name}/static/description/icon.png`.
The `block` tag is used to declare a group of settings. This group can
have a title and a description/help.
```xml
<block title="Title of group Bar">
...
</block>
```
- `title` *optional* : The title of the block of settings (the old h2),
you can perform research on its text.
- `help` *optional* : The description/help of the block of settings
(the old h3), you can perform research on its text.
The `setting` tag is used to declare the setting itself. The first field
in the setting is used as the main field (optional). This field is
placed on the left panel (if it's a boolean field) or on the top of the
right panel (otherwise). The field is also used to create the setting
label if a `string` is not defined. The `setting` tag can also contain
more elements (e.g. html), all of these elements are rendered in the
right panel.
```xml
<setting string="this is bar">
<field name="bar"/>
...More elements
</setting>
```
- `type` *optional* : By default, a setting is visually separated on two
panels (left and right), and is used to edit a given field. By
defining `type='header'`, a special kind of setting is rendered
instead. This setting is used to modify the scope of the other
settings. For example, on the website application, this setting
is used to indicate to which website the other settings apply.
The header setting is visually represented as a yellow banner on
the top of the screen.
- `string` *optional* : The text used as label of the setting. If it's
not defined, the first field is used as label.
- `title` *optional* : The text used as tooltip.
- `help` *optional* : The help/description of the setting. This text is
displayed just below the setting label (with classname
`text-muted`).
- `company_dependent` *optional* : If this attribute is set to "1" an
icon is displayed next to the setting label to explicit that
this setting is company-specific.
- `documentation` *optional* : If this attribute is set, an icon is
added next to the setting label, this icon is a link to the
documentation. Note that you can use relative or absolute path.
The relative path is relative to
`https://www.odoo.com/documentation/server_version`, so it's not
necessary to hard-code the server version on the arch anymore.
closesodoo/odoo#106425
Task-id: 3081367
Related: odoo/enterprise#34337
Signed-off-by: Aaron Bohy (aab) <aab@odoo.com>
Co-authored-by: "Michael Mattiello (mcm)" <mcm@odoo.com>
The quotation templates got a button to design them, which lands on
their website/frontend preview.
The goal is to then be able to enter edit mode and customize it.
But since we merged frontend > backend with [1] (and multiple iterations
since then), landing on the frontend is not a good idea to do that as
you would then need to click on the "Editor" button to go back to the
backend and be able to enter edit mode. Now we reach the iframe preview
directly.
Note: this will be improved in a further update to not require a reload
of the backend when clicking on the button.
[1]: https://github.com/odoo/odoo/commit/31cc10b91dc7762e23b4bde9b945be0c4ce3fe3b
X-original-commit: a98ea96b52f6ccfd43e364720001ed4c4bcbcb4e
Part-of: odoo/odoo#102787
t-esc directive has been deprecated.
This commit replaces remaining occurrences in the modules under our
responsiblity.
Was only noticed recently during runs in dev mode because the
deprecation warnings are only posted when odoo is launched in dev mode.
"Found deprecated directive @t-esc=%r in template %r. Replace by @t-out"
in base/models/ir_qweb.py
X-original-commit: 7083b65e31626acc826c47d1d450f12b7d1c2d4a
Part-of: odoo/odoo#102245
The previous commit allows the sanitizer to be bypassed by some users if
those users are part of one of the `base.group_sanitize_override` group
and if the HTML field is declared as `sanitize_overridable`.
This commit flag frontend HTML fields as `sanitize_overridable`.
See the main commit of this PR for more details.
It also gives the `base.group_sanitize_override` group to the "Editor &
Designer" group.
Part-of: odoo/odoo#97398
When a record is created through xml data, its HTML fields should
receive a `type="html"` attribute, not a `type="xml"` attribute.
When important XML data with XML type instead of HTML type will have 2
differences:
- The field value will be prefixed by `<?xml version="1.0"/>`
- If the HTML contains multiple root nodes, the value will be wrapped in
a `<data/>` tag.
See `_fix_multiple_roots()` and the `xml_import` class for more details.
closesodoo/odoo#98239
Related: odoo/enterprise#30491
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
That way, the method overrides are grouped with the new fields to
propagate between template lines/options and order lines/options.
Eases code comprehension and maintainability.
Part-of: odoo/odoo#91222
Harmonize backend & frontend behaviors
Avoid the overhead and additional stacktrace depth of write/create
overrides
Ligth cleanup of the fields & code as well.
Part-of: odoo/odoo#81818
quotation_description on the sale order is copied from the
product template, where it already is sanitize_attributes=False,
and it has to stay like that because otherwise widgets like
"tab" or "accordion" cannot be rendered correctly.
This is also linked to a bug in the ORM where the _related_attrs
weren't copied correctly.
Related ORM PR: https://github.com/odoo/odoo/pull/78687
Ticket link: https://www.odoo.com/web#id=2487749&model=project.task
opw-2487749
closesodoo/odoo#78836
X-original-commit: ee90f6bcea35350efa9eae8db749199b39ff5644
Signed-off-by: Paolo Gatti <lordkrandel@users.noreply.github.com>
The license is missing in most enterprise manifest so
the decision was taken to make it explicit in all cases.
When not defined, a warning will be triggered starting from
14.0 when falling back on the default LGPL-3.
closesodoo/odoo#74245
Related: odoo/design-themes#48
Related: odoo/enterprise#19862
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
It replace text fields to html fields as we have our own 'OdooEditor'.
Indeed, it gives more options to users in the way they format their
content without weighting too much on the UI
(tools appear on demand and not by default).
Models -> Fields
1) sale.order -> note
2) sale.order.template -> note
Task Id: 2499504
X-original-commit: 6a345c2695129a5cd907e5e23e057871ebf9ebfa
Fine-tuning of 0106fcd59c
Have a SO with a partner in another language
Apply a quote template to a SO
Customize the portal view to show website_description of a product on the template
Translate it
Show the SO on the portal
Before this commit, the description of the product was not translated
This was because the field was not included in the onchange of template_id
causing that field to never have changed, that is, it kept the description
done injected with the first write
After this commit, the description is changed according to the partner's lang
opw-2366738
closesodoo/odoo#63094
X-original-commit: b2b6fbef3a48249fef541e71c7f5b4745ef23d02
Signed-off-by: Jorge Pinna Puissant (jpp) <jpp@odoo.com>
Same change in several areas where translations existed:
- website editor notification popup
- elearning share popup
- forum remediation filter popup
- event registration attendees popup
- portal rating popup
- stripe payment error popup
And many other locations where there were no translations yet
"×" has been replaced by its UTF8 character.
Also introduced aria-label where missing.
Before this commit the close icon was included in translated resources.
For example, in Spanish the "×" had been turned into "&veces;"
thus not rendering an icon anymore
After this commit the close icon is not a translated text anymore and
remains an icon across all languages
https://github.com/odoo/odoo/pull/60186
task-2312878
closesodoo/odoo#62250
X-original-commit: 9896af94ebc887d98ccf44e6568ef7eeb5a27172
Related: odoo/enterprise#14937
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
This commit adapts the business code in which
class/module/function/method redefinition took place so that it no
longer happens and the pylint test passes.
The quotation template edition allows to save and use the description
of an optional product.
But when a quotation template is set, the description of optional
product is lost so we the optional product description was never used.
opw-2260457
closes#52133closesodoo/odoo#52167
X-original-commit: 81d13f4097e7fca9fbb623839a2c90b04bd9ec29
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
Purpose
=======
Having price and discount on quotation template is quite confusing
as it is more the job of pricelists.
In order to make it more simple for the user, we should remove the
fields price_unit and discount from quotation template.
Implementation
========
Now, the public price of a product is used instead of the price from
the quotation template. If a pricelist exists, it is taken into
account as before.
+ Add new tests to check the sale order template behavior.
closesodoo/odoo#47186
Taskid: 47186
Related: odoo/upgrade#972
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
* = event, website_event_track, website_sale, website_hr_recruitment,
website_livechat, website_sale, website_slides
The option to sanitize or not the forms was not available, this will
allow better flexibility on whether forms should be sanitized or not on
an HTML field.
Also we use this new param to allow forms to be added on some already
existing html fields where forms where sanitized out.
task-2209554
closesodoo/odoo#47318
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
- Create 2 companies A & B
- Set the website in A
- Set the user in both companies, main company being A
- Create a SO template in company B
- Click on "Design Template"
An AccessError is raised because:
- `slug` accesses the `display_name` of the template which is in company
B
- the `allowed_company_ids` is set to company A in [1]
A solution could be to always set:
```
context['allowed_company_ids'] = request.env.user.company_ids.ids
```
But the side-effects could cause other issues.
Therefore, we handle the `slug` manually.
[1] https://github.com/odoo/odoo/blob/af411b866aa2052c01168342f8f05ae3dabad83e/addons/website/models/ir_http.py#L203
opw-2194103
closesodoo/odoo#47249
X-original-commit: 0bcfffd291aceb74a5260a49d2fa3032f511dba1
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>