*: hr_presence, web_editor.
This commit is part of the websocket integration in Odoo.
It focuses on adapting the bus to support websockets:
- last notification id is now kept on the server
- channel list is built by overriding the `_build_bus_channel_list`
method of the `ir_websocket` model instead of overriding the `_poll`
method of the bus controller.
- The bus presence was updated during polls, since there is no more poll,
bus presence update will be the responsability of the client.
- The `/websocket/peek_notifications`, `/websocket/update_bus_presence`
routes will be available so that odoo sh can access notifications/update presence
from http requests.
- /longpolling routes are now prefixed with /bus thus won't be redirected to the
gevent worker anymore except for `/longpolling/health` which is the
health check route of the gevent server.
Since websocket now handle incoming messages, a way to manage authentication
have been introduced :
- The session is retrieved from the HTTP handshake.
- When a websocket message comes/leaves the session is retrieved
on the file system so that we're sure it still exists and that
it is up to date.
- The session is checked
- If no session is found on the file system or `check_session`
fails, the websocket connection is closed with the `SESSION_EXPIRED`
close code (which is a custom close code: 4001).
- Note that websocket connections are closed every `KEEP_ALIVE_TIMEOUT`
seconds to ensure no websocket connection will stay open if the user
clears its cookies.
- Note that a wsrequest object is available when processing incoming
messages. It is similar to the http request and contains various
useful informations (session, env, ...).
Part-of: odoo/odoo#75510
40 lines
1.6 KiB
Python
40 lines
1.6 KiB
Python
# -*- coding: utf-8 -*-
|
|
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
|
|
|
import re
|
|
|
|
from odoo import models
|
|
from odoo.exceptions import AccessDenied
|
|
|
|
|
|
class IrWebsocket(models.AbstractModel):
|
|
_inherit = 'ir.websocket'
|
|
|
|
def _build_bus_channel_list(self, channels):
|
|
if self.env.uid:
|
|
# Do not alter original list.
|
|
channels = list(channels)
|
|
for channel in channels:
|
|
if isinstance(channel, str):
|
|
match = re.match(r'editor_collaboration:(\w+(?:\.\w+)*):(\w+):(\d+)', channel)
|
|
if match:
|
|
model_name = match[1]
|
|
field_name = match[2]
|
|
res_id = int(match[3])
|
|
|
|
# Verify access to the edition channel.
|
|
if not self.env.user._is_internal():
|
|
raise AccessDenied()
|
|
|
|
document = self.env[model_name].browse([res_id])
|
|
|
|
document.check_access_rights('read')
|
|
document.check_field_access_rights('read', [field_name])
|
|
document.check_access_rule('read')
|
|
document.check_access_rights('write')
|
|
document.check_field_access_rights('write', [field_name])
|
|
document.check_access_rule('write')
|
|
|
|
channels.append((self.env.registry.db_name, 'editor_collaboration', model_name, field_name, res_id))
|
|
return super()._build_bus_channel_list(channels)
|