Files
odoo_source/addons/web_editor
qsm-odoo e4a7103517 [FIX] web, web_editor: allow editor instantiation from public user
If for some reason someone wanted to develop a textarea using the
editor which is supposed to work as a public user (like we are trying
to do on Odoo.com), it was not possible. The code was "designed" to
allow it but there was one problem: the lazy loading of the editor
assets required a `render_template` call to the server... which cannot
be done from a public user.

This commit solves the issues by allowing the lazy loading of assets
to use a custom route if required. That route is then used by the editor
"root". That route performs the render_template as a superuser provided
that the view's xmlid is whitelisted.

Note: there was another unauthorized call for public user: the
colorpicker. This was solved by disabling the colorpicker template rpc
for public user, they will still get the default summernote one.

Part of https://github.com/odoo/odoo/pull/48981

closes odoo/odoo#48981

closes odoo/odoo#49398

X-original-commit: e84a0bfdc99c21406861b88c02b11c925d92f927
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
2020-04-10 11:54:03 +00:00
..
2020-02-13 11:45:39 +00:00