[FIX] website: do not restore page views
[odoo/odoo.git] / addons / website / controllers / main.py
index aa214b8..4f2a2a3 100644 (file)
@@ -20,82 +20,96 @@ import openerp
 from openerp.osv import fields
 from openerp.addons.website.models import website
 from openerp.addons.web import http
-from openerp.addons.web.http import request
+from openerp.addons.web.http import request, LazyResponse
 
 logger = logging.getLogger(__name__)
 
-
-def auth_method_public():
-    registry = openerp.modules.registry.RegistryManager.get(request.db)
-    if not request.session.uid:
-        request.uid = registry['website'].get_public_user(request.cr, openerp.SUPERUSER_ID, request.context).id
-    else:
-        request.uid = request.session.uid
-http.auth_methods['public'] = auth_method_public
-
-NOPE = object()
 # Completely arbitrary limits
 MAX_IMAGE_WIDTH, MAX_IMAGE_HEIGHT = IMAGE_LIMITS = (1024, 768)
+
 class Website(openerp.addons.web.controllers.main.Home):
-    @website.route('/', type='http', auth="public", multilang=True)
+    #------------------------------------------------------
+    # View
+    #------------------------------------------------------
+    @http.route('/', type='http', auth="public", website=True, multilang=True)
     def index(self, **kw):
-        # TODO: check if plain SQL is needed
-        menu = request.registry['website.menu']
-        root_domain = [('parent_id', '=', False)] # TODO: multiwebsite ('website_id', '=', request.website.id),
-        root_id = menu.search(request.cr, request.uid, root_domain, limit=1, context=request.context)[0]
-        first_menu = menu.search_read(
-            request.cr, request.uid, [('parent_id', '=', root_id)], ['url'],
-            limit=1, order='sequence', context=request.context)
-        if first_menu:
-            first_menu = first_menu[0]['url']
-        if first_menu and first_menu != '/':
-            return request.redirect(first_menu)
-        else:
-            return self.page("website.homepage")
+        try:
+            main_menu = request.registry['ir.model.data'].get_object(request.cr, request.uid, 'website', 'main_menu')
+            first_menu = main_menu.child_id and main_menu.child_id[0]
+            # Dont 302 loop on /
+            if first_menu and not ((first_menu.url == '/') or first_menu.url.startswith('/#') or first_menu.url.startswith('/?')):
+                return request.redirect(first_menu.url)
+        except:
+            pass
+        return self.page("website.homepage")
+
+    @http.route(website=True, auth="public", multilang=True)
+    def web_login(self, *args, **kw):
+        response = super(Website, self).web_login(*args, **kw)
+        if isinstance(response, LazyResponse):
+            values = dict(response.params['values'], disable_footer=True)
+            response = request.website.render(response.params['template'], values)
+        return response
 
-    @website.route('/pagenew/<path:path>', type='http', auth="user")
-    def pagenew(self, path, noredirect=NOPE):
-        module = 'website'
-        # completely arbitrary max_length
-        idname = http.slugify(path, max_length=50)
+    @http.route('/page/<page:page>', type='http', auth="public", website=True, multilang=True)
+    def page(self, page, **opt):
+        values = {
+            'path': page,
+        }
+        # allow shortcut for /page/<website_xml_id>
+        if '.' not in page:
+            page = 'website.%s' % page
 
-        request.cr.execute('SAVEPOINT pagenew')
-        imd = request.registry['ir.model.data']
-        view = request.registry['ir.ui.view']
-        view_model, view_id = imd.get_object_reference(
-            request.cr, request.uid, 'website', 'default_page')
-        newview_id = view.copy(
-            request.cr, request.uid, view_id, context=request.context)
-        newview = view.browse(
-            request.cr, request.uid, newview_id, context=request.context)
-        newview.write({
-            'arch': newview.arch.replace("website.default_page",
-                                         "%s.%s" % (module, idname)),
-            'name': path,
-            'page': True,
-        })
-        # Fuck it, we're doing it live
         try:
-            imd.create(request.cr, request.uid, {
-                'name': idname,
-                'module': module,
-                'model': 'ir.ui.view',
-                'res_id': newview_id,
-                'noupdate': True
-            }, context=request.context)
-        except psycopg2.IntegrityError:
-            logger.exception('Unable to create ir_model_data for page %s', path)
-            request.cr.execute('ROLLBACK TO SAVEPOINT pagenew')
-            return werkzeug.exceptions.InternalServerError()
-        else:
-            request.cr.execute('RELEASE SAVEPOINT pagenew')
+            request.website.get_template(page)
+        except ValueError, e:
+            # page not found
+            if request.context['editable']:
+                page = 'website.page_404'
+            else:
+                return request.registry['ir.http']._handle_exception(e, 404)
+
+        return request.website.render(page, values)
+
+    @http.route(['/robots.txt'], type='http', auth="public", website=True)
+    def robots(self):
+        response = request.website.render('website.robots', {'url_root': request.httprequest.url_root})
+        response.mimetype = 'text/plain'
+        return response
+
+    @http.route('/sitemap', type='http', auth='public', website=True, multilang=True)
+    def sitemap(self):
+        return request.website.render('website.sitemap', {
+            'pages': request.website.enumerate_pages()
+        })
 
-        url = "/page/%s" % idname
-        if noredirect is not NOPE:
+    @http.route('/sitemap.xml', type='http', auth="public", website=True)
+    def sitemap_xml(self):
+        response = request.website.render('website.sitemap_xml', {
+            'pages': request.website.enumerate_pages()
+        })
+        response.headers['Content-Type'] = 'application/xml;charset=utf-8'
+        return response
+
+    #------------------------------------------------------
+    # Edit
+    #------------------------------------------------------
+    @http.route('/website/add/<path:path>', type='http', auth="user", website=True)
+    def pagenew(self, path, noredirect=False, add_menu=None):
+        xml_id = request.registry['website'].new_page(request.cr, request.uid, path, context=request.context)
+        if add_menu:
+            model, id  = request.registry["ir.model.data"].get_object_reference(request.cr, request.uid, 'website', 'main_menu')
+            request.registry['website.menu'].create(request.cr, request.uid, {
+                    'name': path,
+                    'url': "/page/" + xml_id,
+                    'parent_id': id,
+                }, context=request.context)
+        url = "/page/" + xml_id
+        if noredirect:
             return werkzeug.wrappers.Response(url, mimetype='text/plain')
         return werkzeug.utils.redirect(url)
 
-    @website.route('/website/theme_change', type='http', auth="admin")
+    @http.route('/website/theme_change', type='http', auth="user", website=True)
     def theme_change(self, theme_id=False, **kwargs):
         imd = request.registry['ir.model.data']
         view = request.registry['ir.ui.view']
@@ -117,19 +131,32 @@ class Website(openerp.addons.web.controllers.main.Home):
 
         return request.website.render('website.themes', {'theme_changed': True})
 
-    @website.route(['/website/snippets'], type='json', auth="public")
+    @http.route(['/website/snippets'], type='json', auth="public", website=True)
     def snippets(self):
-        return request.website.render('website.snippets')
-
-    @website.route('/page/<path:path>', type='http', auth="public", multilang=True)
-    def page(self, path, **kwargs):
-        values = {
-            'path': path,
-        }
+        return request.website._render('website.snippets')
+
+    @http.route('/website/reset_templates', type='http', auth='user', methods=['POST'], website=True)
+    def reset_template(self, templates, redirect='/'):
+        templates = request.httprequest.form.getlist('templates')
+        modules_to_update = []
+        for temp_id in templates:
+            view = request.registry['ir.ui.view'].browse(request.cr, request.uid, int(temp_id), context=request.context)
+            if view.page:
+                continue
+            view.model_data_id.write({
+                'noupdate': False
+            })
+            if view.model_data_id.module not in modules_to_update:
+                modules_to_update.append(view.model_data_id.module)
 
-        return request.website.render(path, values)
+        if modules_to_update:
+            module_obj = request.registry['ir.module.module']
+            module_ids = module_obj.search(request.cr, request.uid, [('name', 'in', modules_to_update)], context=request.context)
+            if module_ids:
+                module_obj.button_immediate_upgrade(request.cr, request.uid, module_ids, context=request.context)
+        return request.redirect(redirect)
 
-    @website.route('/website/customize_template_toggle', type='json', auth='user')
+    @http.route('/website/customize_template_toggle', type='json', auth='user', website=True)
     def customize_template_set(self, view_id):
         view_obj = request.registry.get("ir.ui.view")
         view = view_obj.browse(request.cr, request.uid, int(view_id),
@@ -143,22 +170,29 @@ class Website(openerp.addons.web.controllers.main.Home):
         }, context=request.context)
         return True
 
-    @website.route('/website/customize_template_get', type='json', auth='user')
+    @http.route('/website/customize_template_get', type='json', auth='user', website=True)
     def customize_template_get(self, xml_id, optional=True):
         imd = request.registry['ir.model.data']
         view_model, view_theme_id = imd.get_object_reference(
             request.cr, request.uid, 'website', 'theme')
 
+        user = request.registry['res.users'].browse(request.cr, request.uid, request.uid, request.context)
+        group_ids = [g.id for g in user.groups_id]
+
         view = request.registry.get("ir.ui.view")
-        views = view._views_get(request.cr, request.uid, xml_id, request.context)
+        views = view._views_get(request.cr, request.uid, xml_id, context=request.context)
         done = {}
         result = []
         for v in views:
+            if v.groups_id and [g for g in v.groups_id if g.id not in group_ids]:
+                continue
             if v.inherit_option_id and v.inherit_option_id.id != view_theme_id or not optional:
                 if v.inherit_option_id.id not in done:
                     result.append({
                         'name': v.inherit_option_id.name,
                         'id': v.id,
+                        'xml_id': v.xml_id,
+                        'inherit_id': v.inherit_id.id,
                         'header': True,
                         'active': False
                     })
@@ -166,12 +200,14 @@ class Website(openerp.addons.web.controllers.main.Home):
                 result.append({
                     'name': v.name,
                     'id': v.id,
+                    'xml_id': v.xml_id,
+                    'inherit_id': v.inherit_id.id,
                     'header': False,
                     'active': (v.inherit_id.id == v.inherit_option_id.id) or (not optional and v.inherit_id.id)
                 })
         return result
 
-    @website.route('/website/get_view_translations', type='json', auth='admin')
+    @http.route('/website/get_view_translations', type='json', auth='public', website=True)
     def get_view_translations(self, xml_id, lang=None):
         lang = lang or request.context.get('lang')
         views = self.customize_template_get(xml_id, optional=False)
@@ -180,7 +216,7 @@ class Website(openerp.addons.web.controllers.main.Home):
         irt = request.registry.get('ir.translation')
         return irt.search_read(request.cr, request.uid, domain, ['id', 'res_id', 'value'], context=request.context)
 
-    @website.route('/website/set_translations', type='json', auth='admin')
+    @http.route('/website/set_translations', type='json', auth='public', website=True)
     def set_translations(self, data, lang):
         irt = request.registry.get('ir.translation')
         for view_id, trans in data.items():
@@ -215,37 +251,40 @@ class Website(openerp.addons.web.controllers.main.Home):
                     irt.create(request.cr, request.uid, new_trans)
         return True
 
-    @website.route('/website/attach', type='http', auth='user')
+    @http.route('/website/attach', type='http', auth='user', methods=['POST'], website=True)
     def attach(self, func, upload):
-        req = request.httprequest
-        if req.method != 'POST':
-            return werkzeug.exceptions.MethodNotAllowed(valid_methods=['POST'])
 
         url = message = None
         try:
-            attachment_id = request.registry['ir.attachment'].create(request.cr, request.uid, {
+            image_data = upload.read()
+            image = Image.open(cStringIO.StringIO(image_data))
+            w, h = image.size
+            if w*h > 42e6: # Nokia Lumia 1020 photo resolution
+                raise ValueError(
+                    u"Image size excessive, uploaded images must be smaller "
+                    u"than 42 million pixel")
+
+            Attachments = request.registry['ir.attachment']
+            attachment_id = Attachments.create(request.cr, request.uid, {
                 'name': upload.filename,
-                'datas': upload.read().encode('base64'),
+                'datas': image_data.encode('base64'),
                 'datas_fname': upload.filename,
                 'res_model': 'ir.ui.view',
             }, request.context)
 
-            url = website.urlplus('/website/image', {
-                'model': 'ir.attachment',
-                'id': attachment_id,
-                'field': 'datas',
-                'max_height': MAX_IMAGE_HEIGHT,
-                'max_width': MAX_IMAGE_WIDTH,
-            })
+            [attachment] = Attachments.read(
+                request.cr, request.uid, [attachment_id], ['website_url'],
+                context=request.context)
+            url = attachment['website_url']
         except Exception, e:
             logger.exception("Failed to upload image to attachment")
-            message = str(e)
+            message = unicode(e)
 
         return """<script type='text/javascript'>
             window.parent['%s'](%s, %s);
         </script>""" % (func, json.dumps(url), json.dumps(message))
 
-    @website.route(['/website/publish'], type='json', auth="public")
+    @http.route(['/website/publish'], type='json', auth="public", website=True)
     def publish(self, id, object):
         _id = int(id)
         _object = request.registry[object]
@@ -260,44 +299,29 @@ class Website(openerp.addons.web.controllers.main.Home):
                       values, context=request.context)
 
         obj = _object.browse(request.cr, request.uid, _id)
-        return obj.website_published and True or False
+        return bool(obj.website_published)
 
-    @website.route(['/website/kanban/'], type='http', auth="public")
+    #------------------------------------------------------
+    # Helpers
+    #------------------------------------------------------
+    @http.route(['/website/kanban/'], type='http', auth="public", methods=['POST'], website=True)
     def kanban(self, **post):
         return request.website.kanban_col(**post)
 
-    @website.route(['/robots.txt'], type='http', auth="public")
-    def robots(self):
-        body = request.website.render('website.robots', {'url_root': request.httprequest.url_root})
-        return request.make_response(body, headers=[('Content-Type', 'text/plain')])
-
-    @website.route('/sitemap', type='http', auth='public', multilang=True)
-    def sitemap(self):
-        return request.website.render('website.sitemap', {'pages': request.website.list_pages()})
-
-    @website.route('/sitemap.xml', type='http', auth="public")
-    def sitemap_xml(self):
-        body = request.website.render('website.sitemap_xml', {
-            'pages': request.website.list_pages()
-        })
-
-        return request.make_response(body, [
-            ('Content-Type', 'application/xml;charset=utf-8')
-        ])
-
-
-class Images(http.Controller):
     def placeholder(self, response):
         # file_open may return a StringIO. StringIO can be closed but are
         # not context managers in Python 2 though that is fixed in 3
         with contextlib.closing(openerp.tools.misc.file_open(
                 os.path.join('web', 'static', 'src', 'img', 'placeholder.png'),
                 mode='rb')) as f:
-            response.set_data(f.read())
+            response.data = f.read()
             return response.make_conditional(request.httprequest)
 
-    @website.route('/website/image', auth="public")
-    def image(self, model, id, field, max_width=maxint, max_height=maxint):
+    @http.route([
+        '/website/image',
+        '/website/image/<model>/<id>/<field>'
+        ], auth="public", website=True)
+    def website_image(self, model, id, field, max_width=maxint, max_height=maxint):
         Model = request.registry[model]
 
         response = werkzeug.wrappers.Response()
@@ -351,7 +375,7 @@ class Images(http.Controller):
         max_w, max_h = fit
 
         if w < max_w and h < max_h:
-            response.set_data(data)
+            response.data = data
         else:
             image.thumbnail(fit, Image.ANTIALIAS)
             image.save(response.stream, image.format)