The `session_info` dictionnary is used to bootstrap some JS code client side (usually in the backend). It includes relevant information, such as some parameters key for the OdooBot onboarding, the Enterprise subscription expiration alert, etc. to avoid triggering a lot of RPC calls upon webclient start. `session_info` is also called by the remote authentication mechanism located at `/web/session/authenticate`, which can be used by external mechanism to obtain a valid session remotely. Revision odoo/odoo@8a28cc2 introduced the concept of cache keys for some oft-requested data (such as menus, translations and dynamic qweb templates) to avoid requesting them on each webclient start, since they tend not to change often. Unfortunately, it introduced a read on the ir.ui.menu model that raised an `AccessError` if the authenticating user was not a member of the `base.group_user` group ('Internal' user type). While fixing that issue, it became apparent that `session_info` returns a whole lot of information through this remote connection route which is entirely unnecessary if not used in the context of a webclient start, such a currencies, the state of the enterprise subscription, etc. This commit fixes the access right issue by removing this non-relevant information from the returned dict (including cache keys) if the user is not an internal one. closes odoo/odoo#40770 X-original-commit: 6e99ac2c6cd5ca9af87b4fc7a3a1394359e30b02 Related: odoo/enterprise#6860 Signed-off-by: Damien Bouvy (dbo) <dbo@odoo.com>
91 lines
4.5 KiB
Python
91 lines
4.5 KiB
Python
# -*- coding: utf-8 -*-
|
|
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
|
import hashlib
|
|
import json
|
|
|
|
from odoo import api, models
|
|
from odoo.http import request
|
|
from odoo.tools import ustr
|
|
|
|
from odoo.addons.web.controllers.main import module_boot, HomeStaticTemplateHelpers
|
|
|
|
import odoo
|
|
|
|
|
|
class Http(models.AbstractModel):
|
|
_inherit = 'ir.http'
|
|
|
|
def webclient_rendering_context(self):
|
|
return {
|
|
'menu_data': request.env['ir.ui.menu'].load_menus(request.session.debug),
|
|
'session_info': self.session_info(),
|
|
}
|
|
|
|
def session_info(self):
|
|
user = request.env.user
|
|
version_info = odoo.service.common.exp_version()
|
|
|
|
user_context = request.session.get_context() if request.session.uid else {}
|
|
|
|
session_info = {
|
|
"uid": request.session.uid,
|
|
"is_system": user._is_system() if request.session.uid else False,
|
|
"is_admin": user._is_admin() if request.session.uid else False,
|
|
"user_context": request.session.get_context() if request.session.uid else {},
|
|
"db": request.session.db,
|
|
"server_version": version_info.get('server_version'),
|
|
"server_version_info": version_info.get('server_version_info'),
|
|
"name": user.name,
|
|
"username": user.login,
|
|
"partner_display_name": user.partner_id.display_name,
|
|
"company_id": user.company_id.id if request.session.uid else None, # YTI TODO: Remove this from the user context
|
|
"partner_id": user.partner_id.id if request.session.uid and user.partner_id else None,
|
|
"web.base.url": self.env['ir.config_parameter'].sudo().get_param('web.base.url', default=''),
|
|
}
|
|
if self.env.user.has_group('base.group_user'):
|
|
# the following is only useful in the context of a webclient bootstrapping
|
|
# but is still included in some other calls (e.g. '/web/session/authenticate')
|
|
# to avoid access errors and unnecessary information, it is only included for users
|
|
# with access to the backend ('internal'-type users)
|
|
mods = module_boot()
|
|
qweb_checksum = HomeStaticTemplateHelpers.get_qweb_templates_checksum(addons=mods, debug=request.session.debug)
|
|
lang = user_context.get("lang")
|
|
translations_per_module, lang_params = request.env['ir.translation'].get_translations_for_webclient(mods, lang)
|
|
translation_cache = {
|
|
'lang': lang,
|
|
'lang_parameters': lang_params,
|
|
'modules': translations_per_module,
|
|
'multi_lang': len(request.env['res.lang'].sudo().get_installed()) > 1,
|
|
}
|
|
menu_json_utf8 = json.dumps(request.env['ir.ui.menu'].load_menus(request.session.debug), default=ustr, sort_keys=True).encode()
|
|
translations_json_utf8 = json.dumps(translation_cache, sort_keys=True).encode()
|
|
cache_hashes = {
|
|
"load_menus": hashlib.sha512(menu_json_utf8).hexdigest()[:64], # sha512/256
|
|
"qweb": qweb_checksum,
|
|
"translations": hashlib.sha512(translations_json_utf8).hexdigest()[:64], # sha512/256
|
|
}
|
|
session_info.update({
|
|
# current_company should be default_company
|
|
"user_companies": {'current_company': (user.company_id.id, user.company_id.name), 'allowed_companies': [(comp.id, comp.name) for comp in user.company_ids]},
|
|
"currencies": self.get_currencies(),
|
|
"show_effect": True,
|
|
"display_switch_company_menu": user.has_group('base.group_multi_company') and len(user.company_ids) > 1,
|
|
"cache_hashes": cache_hashes,
|
|
})
|
|
return session_info
|
|
|
|
@api.model
|
|
def get_frontend_session_info(self):
|
|
return {
|
|
'is_admin': request.session.uid and self.env.user._is_admin() or False,
|
|
'is_system': request.session.uid and self.env.user._is_system() or False,
|
|
'is_website_user': request.session.uid and self.env.user._is_public() or False,
|
|
'user_id': request.session.uid and self.env.user.id or False,
|
|
'is_frontend': True,
|
|
}
|
|
|
|
def get_currencies(self):
|
|
Currency = request.env['res.currency']
|
|
currencies = Currency.search([]).read(['symbol', 'position', 'decimal_places'])
|
|
return {c['id']: {'symbol': c['symbol'], 'position': c['position'], 'digits': [69,c['decimal_places']]} for c in currencies}
|