Files
odoo_source/addons/web_editor/tests/test_controller.py
T
Romain DerieandMerlin e104937118 [FIX] web_editor, web_unsplash, *: allow portal user to upload images
* website_forum

Portal users cannot insert images in the WYSIWYG, eg in a forum post.

Steps to reproduce:
- Install website_forum
- Connect as portal
- Go to the forum and create a new post
- Type '/image' and try to insert an image
- An Access Error is raised preventing the portal user from inserting an
image

History:
- It was possible in version earlier than 15.0 before the new editor, as
  it was using a base64 inplace image upload to bypass the access rights
  and avoid creating an attachment.
- It was broken in 15.0 with the new editor which doesn't have such a
  mechanism. The image upload was then disabled for those users in 15.0
  with [1] to avoid that bad UX with those errors/tracebacks.
- It was decided to implement a clean solution in master and see from
  there was will be done with 15.0 (as being able to upload an image on
  a forum seems quite critical).

Solution here in master to be able to use the media dialog:
- First issue, about opening the media dialog:
  It fetches attachments, which is raising some access errors. We now
  catch the error silently and return an empty list.
- Second issue, about upload an image (and thus creating an attachment):
  We now create attachments with sudo to allow access to portal users,
  but only if he has write access on the model.

[1]: https://github.com/odoo/odoo/commit/e453d4c119a69f285d9a014babe485492bbe9c40

opw-2648770
task-2811325

closes odoo/odoo#82612

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Co-authored-by: Merlin (megu) <megu@odoo.com>
2022-07-08 14:33:43 +02:00

153 lines
6.7 KiB
Python

# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
import binascii
import json
import odoo.tests
from odoo.tests.common import HttpCase, new_test_user
from odoo.tools.json import scriptsafe as json_safe
from odoo.addons.http_routing.models.ir_http import slug
@odoo.tests.tagged('-at_install', 'post_install')
class TestController(HttpCase):
@classmethod
def setUpClass(cls):
super().setUpClass()
portal_user = new_test_user(cls.env, login='portal_user', groups='base.group_portal')
cls.portal = portal_user.login
admin_user = new_test_user(cls.env, login='admin_user', groups='base.group_user,base.group_system')
cls.admin = admin_user.login
cls.headers = {"Content-Type": "application/json"}
cls.pixel = 'R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs='
def _build_payload(self, params=None):
"""
Helper to properly build jsonrpc payload
"""
return {
"jsonrpc": "2.0",
"method": "call",
"id": 0,
"params": params or {},
}
def test_01_upload_document(self):
self.authenticate('admin', 'admin')
# Upload document.
response = self.url_open(
'/web_editor/attachment/add_data',
headers={'Content-Type': 'application/json'},
data=json_safe.dumps({'params': {
'name': 'test.txt',
'data': 'SGVsbG8gd29ybGQ=', # base64 Hello world
'is_image': False,
}})
).json()
self.assertFalse('error' in response, 'Upload failed: %s' % response.get('error', {}).get('message'))
attachment_id = response['result']['id']
checksum = response['result']['checksum']
# Download document and check content.
response = self.url_open(
'/web/content/%s?unique=%s&download=true' % (attachment_id, checksum)
)
self.assertEqual(200, response.status_code, 'Expect response')
self.assertEqual(b'Hello world', response.content, 'Expect raw content')
def test_02_illustration_shape(self):
self.authenticate('admin', 'admin')
# SVG with all replaceable colors.
svg = b"""
<svg viewBox="0 0 400 400">
<rect width="300" height="300" style="fill:#3AADAA;" />
<rect x="20" y="20" width="300" height="300" style="fill:#7C6576;" />
<rect x="40" y="40" width="300" height="300" style="fill:#F6F6F6;" />
<rect x="60" y="60" width="300" height="300" style="fill:#FFFFFF;" />
<rect x="80" y="80" width="300" height="300" style="fill:#383E45;" />
</svg>
"""
# Need to bypass security check to write image with mimetype image/svg+xml
context = {'binary_field_real_user': self.env['res.users'].sudo().browse([1])}
attachment = self.env['ir.attachment'].sudo().with_context(context).create({
'name': 'test.svg',
'mimetype': 'image/svg+xml',
'datas': binascii.b2a_base64(svg, newline=False),
'public': True,
'res_model': 'ir.ui.view',
'res_id': 0,
})
# Shape illustration with slug.
url = '/web_editor/shape/illustration/%s' % slug(attachment)
palette = 'c1=%233AADAA&c2=%237C6576&&c3=%23F6F6F6&&c4=%23FFFFFF&&c5=%23383E45'
attachment['url'] = '%s?%s' % (url, palette)
response = self.url_open(url)
self.assertEqual(200, response.status_code, 'Expect response')
self.assertEqual(svg, response.content, 'Expect unchanged SVG')
response = self.url_open(url + '?c1=%23ABCDEF')
self.assertEqual(200, response.status_code, 'Expect response')
self.assertEqual(len(svg), len(response.content), 'Expect same length as original')
self.assertTrue('ABCDEF' in str(response.content), 'Expect patched c1')
self.assertTrue('3AADAA' not in str(response.content), 'Old c1 should not be there anymore')
# Shape illustration without slug.
url = '/web_editor/shape/illustration/noslug'
attachment['url'] = url
response = self.url_open(url)
self.assertEqual(200, response.status_code, 'Expect response')
self.assertEqual(svg, response.content, 'Expect unchanged SVG')
response = self.url_open(url + '?c1=%23ABCDEF')
self.assertEqual(200, response.status_code, 'Expect response')
self.assertEqual(len(svg), len(response.content), 'Expect same length as original')
self.assertTrue('ABCDEF' in str(response.content), 'Expect patched c1')
self.assertTrue('3AADAA' not in str(response.content), 'Old c1 should not be there anymore')
def test_03_get_image_info(self):
gif_base64 = "R0lGODdhAQABAIAAAP///////ywAAAAAAQABAAACAkQBADs="
self.authenticate('admin', 'admin')
# Upload document.
response = self.url_open(
'/web_editor/attachment/add_data',
headers={'Content-Type': 'application/json'},
data=json_safe.dumps({'params': {
'name': 'test.gif',
'data': gif_base64,
'is_image': True,
}})
).json()
self.assertFalse('error' in response, 'Upload failed: %s' % response.get('error', {}).get('message'))
attachment_id = response['result']['id']
image_src = response['result']['image_src']
mimetype = response['result']['mimetype']
self.assertEqual('image/gif', mimetype, "Wrong mimetype")
# Ensure image info can be retrieved.
response = self.url_open('/web_editor/get_image_info',
headers={'Content-Type': 'application/json'},
data=json_safe.dumps({
"params": {
"src": image_src,
}
}),
).json()
self.assertEqual(attachment_id, response['result']['original']['id'], "Wrong id")
self.assertEqual(image_src, response['result']['original']['image_src'], "Wrong image_src")
self.assertEqual(mimetype, response['result']['original']['mimetype'], "Wrong mimetype")
def test_04_admin_attachment(self):
self.authenticate(self.admin, self.admin)
payload = self._build_payload({"name": "pixel", "data": self.pixel, "is_image": True})
response = self.url_open('/web_editor/attachment/add_data', data=json.dumps(payload), headers=self.headers)
self.assertEqual(200, response.status_code)
attachment = self.env['ir.attachment'].search([('name', '=', 'pixel')])
self.assertTrue(attachment)
domain = [('name', '=', 'pixel')]
result = attachment.search_read(domain)
self.assertTrue(len(result), "No attachment fetched")
self.assertEqual(result[0]['id'], attachment.id)