Behavior before the fix:
- When uploading an office 2007 attachment (.xlsx / .docx) as a regular
(non admin) user, the preview shows it as text, and the download option
by default saves it as a text document (in certain browsers, at least).
This stems from an over-aggressive check on mime type (anything that
contains 'xml' **anywhere** in the mime type is taken to be XML, but the
mime type for an Office document is
`application/vnd.openxmlformats-officedocument.wordprocessingml.document`
so it falls in the XML case.
Behavior after the fix:
- The mime type is preserved
- Mime type for XML-like documents (including HTML and SVG) continues to
be validated
opw-2352712
closesodoo/odoo#60164
X-original-commit: 2820ec7d5763a5856274709a4d2024267313106b
Related: odoo/enterprise#14168
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
Signed-off-by: Nicolas Galler <nicocrm@users.noreply.github.com>
How to reproduce:
- Open PLM app, open an Engineering Change Order;
- Click on "Update Documents";
- Try to upload a document -> Traceback.
As we did not cast res_id as integer, the check method of ir.attachment
crashes when accessing company_id on a malformed recordset of ECO
because the domain generated by _filter_access_rules_python is:
`['|', ('company_id', '=', False), ('company_id', 'in', [2, 1])]`
This route is also used when adding attachment to a `product.product`.
In this case the check didn't work either but somehow passed because no
domain is generated by `_filter_access_rules_python`.
The following snippet shows that if there was one, it would also crash:
```
In [16]: records
Out[16]: product.product('25',)
In [17]: records.stock_move_ids
Out[17]: stock.move()
In [18]: self.env['product.product'].browse(25)
Out[18]: product.product(25,)
In [19]: self.env['product.product'].browse(25).stock_move_ids
Out[19]: stock.move(41, 13)
```
task-2223153
closesodoo/odoo#48515
Signed-off-by: Simon Lejeune (sle) <sle@openerp.com>
Purpose:
Modernizes and facilitates files upload in manufacturing app.
In this Commit:
- Show the image in Kanban.
- Allow to access a preview of the file when clicking on it in the
Kanban view.
- Add a 'Edit', 'Delete' and 'Download' in kanban card dropdown menu.
- Add Upload button in control panel to upload document which will
create new record of `mrp.document` and also add a testcase for it.
task-1960733
closesodoo/odoo#42168
Related: odoo/enterprise#8977
Signed-off-by: Simon Lejeune (sle) <sle@openerp.com>