TIP: You can type at any time to perform a new search.
Web
web · odoo/odoo
Security findings
Security warnings
/web/session/fingerprint/check— HTTP endpoint 'Session.session_fingerprint_check' disables CSRF protection for unsafe methods with session authentication. Restore CSRF or verify an independent request-authentication mechanism prevents cross-site actions. route-user-csrf-off · source
Found by automated static analysis: these patterns are usually risky, but only a manual review of the module can confirm a real issue.
- Repository
- odoo/odoo · module folder
- Module version
- 0.1.0
- Category
- Hidden
- Folder size
- 91.43 MB
- License
- LGPL-3
- Application
- No
- Auto-installable
- Yes
- Website
- None
- Last tracking update
- 2026-10-05 12:14:54
- Authors
- Odoo S.A.
- Maintainers
- Odoo S.A.
- Committers
- Xavier Morel, Xavier ALT, Raphael Collet, Thibault Delavallée, odoo, Odoo Translation Bot, Christophe Matthieu, Denis Ledoux, Aaron Bohy, Géry Debongnie, Lucas Perais (lpe), Yannick Tivisse, qsm-odoo, Pierre Masereel, Adrien Dieudonne, Jorge Pinna Puissant, Julien Castiaux, Aurélien Warnon, Xavier-Do, Romeo Fragomeli, Victor Feyens, Andrea Grazioso (agr-odoo), Adrien Dieudonné, Paul Morelle, William Henrotin, Sébastien Theys, Julien Mougenot, Katherine Zaoral, svs-odoo, Samuel Degueldre, std-odoo, Achraf (abz), Prakash Prajapati, Rémy Voet (ryv), Tiffany Chang (tic), Pierre Rousseau, Gorash, Mathieu Duckerts-Antoine, Pierre Paridans, abd-msyukyu-odoo, Arnaud Joset, Romain Estievenart, Benjamin Vray, Sylvain Francis, Stanislas Sobieski, william-andre, Florian Damhaut, JF Aubert, yhu-odoo, Didier (did), Florian Charlier, Louis Baudoux, Nicolas Bayet, Florian Gilbert, luvi, Hubert Van De Walle, adr, Renaud Thiry, Julien Banken, Vincent Larcin, David Monnom (moda), tsm-odoo, Louis Wicket (wil), Pedram (PEBR), Adrien Widart (awt), Julien (jula), Mahamadasif Ansari, amdi-odoo, Pierre-Yves Dufays, Robin Lejeune (role), Soukéina Bojabza, Louis (loco), Levi Siuzdak (sile), Dylan Kiss (dyki), Paolo Gatti, Antoine Boonen, FrancoisGe, Rahul Prajapati, Chong Wang (cwg), Simon Goffaux (sigo), bram1000, Xavier Bol (xbo), Brieuc-brd, micheledic, divy-odoo, Arnaud Sibille, omra-odoo, Zelong Lin, Walid (wasa), aktr-odoo, Maxime de Neuville, Mehdi Outagant (MOU), Sven Fuehr, vava-odoo, dhba, Julien Carion (juca), Bastien Fafchamps (bafa), adsh-odoo, Tanguy Quéguineur, Alex Kühn, SaddemAmine, Ritika Rathore, Lina (liew), nihp-odoo, adch-odoo, Adnan Saiyed, Chrysanthe (chgo), sami odoo, Sanjay Sharma, mano-odoo, Harsh Shah, manv-afk, Max Whale, parp-odoo, Loukas Wets (lowe), thle-odoo, Mathieu Coutant, Xavier Luyckx (xlu), Ahmad (alah), rame-odoo, kawkb, Claire (clbr), Antoine (anso), Abdo Mongy, Mohammed Basioni, Sébastien (blse), Hesham Saleh, ahta, Saif (segn), David Monnom, sben-odoo, abdelrahmanfawzy, David Van Droogenbroeck (DROD), Mohammad Abdulmoneim (abdu), djameltouati, khsr-odoo, Rémi Rahir (rar), Pierre Pulinckx, Bastien PIERRE, fdardenne, Michaël Mattiello, Corentin Heinix (cohe), Shrey Mehta, pish-odoo, Panagiotis Kyriakou, Thomas Josse (THJO), Krzysztof Magusiak (krma), Ajit Singh, nees-odoo, krip-odoo, Hazem Ibrahim, zadh-odoo, dhruv, kdes-odoo, Radu Macocian (admac), Sylvio Poliart (sypol), Harrison Hutton, Hadi El Yakhni, nsirjacobs, bhra-odoo, mojem, bhna-odoo, defl, K Theja (kthe@odoo.com), Dirk Douglas, Ayush Chauhan (aych), Giorgio Tocco (gito), akha, rare-odoo, sawer, Yassien Ghoniem, times-odoo, Mongy (abmn), Tudor-Calin Panzaru (tupan), Laurent Smet (LAS), Julien Launois (jula), Laetitia (ldau), rusp-odoo, adip-odoo, alap-odoo, Augustin (duau), Garvish Panchal, Parth Pujara, Serhii Rubanskyi, Alessandro Lupo, macs-odoo, Kai Chang (kacha), Jérôme Belpaire, Yagnik ✗ (yagp), suju-odoo, Waleed Elgamal, steji, h4818, Saurabh, Victor Decleire, Amr Elkhatieb, abdrahmanrashed, Yash Tiwari (Yatiw), Nisarg (nipl), Bruno BOI, assh-odoo, Robert Smith (rosm), Beekoan, Elliot ELCO, Lionel Piraux (lipi), Kevin Gerard (kege), Louis, pmah-odoo, nmak-odoo, Benoit Socias (bso), Ziri, Maxime de Neuville (mane), maap-odoo, Aurélien Bertrand, Mohamed Barakat, Soumya M, Omar Khalil (omkha), sbbh-odoo, Traina Ludo, Stephane Vanmeerhaeghe (stva), Léopold Cantraine, Eve Lin (evlin), lebm-odoo, Zachary (zavan), Youssef (abyo), alan-odoo, Kadam Darji, Julien (jdeh), Abo Taha, abmn-odoo, jowes-odoo, Farah (ahmfa), ksin-odoo, akth-odoo, MostafaTwfiq, Julien Carion, ELCO, Ricard Calvo, Thomas des Touches, jsum-odoo, karygauss03, Adham Abdeltawab, Guillaume Jacquet, Oussema Heni, stefanorigano (sri), hapt-odoo, mear-odoo, 3amo-magdy, Joseph Nechleba (jonec), Devendra Ladhani, hamza, Frantisek Binovsky, Kai (kache), Sreedev Kodichath (srkod), Dhrumit Parmar, jeanschoenlaub, apan-odoo, claireclan, FedericoBraidi, Louis Wicket, Léo Leclerc, Marceline (matho), Vedant Pandey (vpan-odoo), Julien Coppin (jucop), chga-odoo, Kevin, Liam Noonan, Cheng-Yan Wang, Erwan, Alex Kühn, Ayush Patel, Julien Piron, Lucas Gvasalia, nby, Jean Schoenlaub, Serhii Rubanksyi, Corentin Deruyck, pusu-odoo, Lou !, SebVrc, Mahiv Ram, pkhu-odoo, Ramez Ibrahim, Amine, Julien Coppin, Romain Fraiture, techbefore07-ops, Emmanuel Pire (empir)
- Odoo dependencies
-
odoo/odoo:- base
- Python dependencies
- None
- System dependencies
- None
- Required by
- api_doc, attachment_indexation, auth_oauth, auth_passkey, auth_password_policy, auth_signup, auth_totp, barcodes, base_address_extended, base_import, base_import_module, base_rest, base_setup, bus, fs_image, google_address_autocomplete, html_editor, http_routing, iap, iot_webserial, mail_plugin, mysubscription, onboarding, portal, project, queue_job, resource, spreadsheet, test_http, test_import_export, test_tests, test_translation_mode, test_web, utm, web_hierarchy, web_tour, website
- Description
Odoo Web core module. ======================== This module provides the core of the Odoo Web Client.
Code Analysis
Views touched (45)
| XML ID | Name | Model | Type | Status |
|---|---|---|---|---|
address_layout |
address_layout | ir.ui.view | qweb | New |
basic_layout |
basic_layout | ir.ui.view | qweb | New |
brand_promotion |
Brand Promotion | ir.ui.view | qweb | New |
brand_promotion_message |
Brand Promotion Message | ir.ui.view | qweb | New |
company_address_list |
company_address_list | ir.ui.view | qweb | New |
conditional_assets_tests |
Tests Assets Bundle | ir.ui.view | qweb | New |
config_speedscope_index |
config_speedscope_index | ir.ui.view | qweb | New |
external_layout |
external_layout | ir.ui.view | qweb | New |
external_layout_body |
external_layout_body | ir.ui.view | qweb | New |
external_layout_bubble |
external_layout_bubble | ir.ui.view | qweb | New |
external_layout_center |
external_layout_center | ir.ui.view | qweb | New |
external_layout_compact |
external_layout_compact | ir.ui.view | qweb | New |
external_layout_dual |
external_layout_dual | ir.ui.view | qweb | New |
external_layout_folder |
external_layout_folder | ir.ui.view | qweb | New |
external_layout_footer_content |
external_layout_footer_content | ir.ui.view | qweb | New |
external_layout_lines |
external_layout_lines | ir.ui.view | qweb | New |
external_layout_standard |
external_layout_standard | ir.ui.view | qweb | New |
external_layout_wave |
external_layout_wave | ir.ui.view | qweb | New |
html_container |
html_container | ir.ui.view | qweb | New |
html_preview_container |
html_preview_container | ir.ui.view | qweb | New |
internal_layout |
internal_layout | ir.ui.view | qweb | New |
minimal_layout |
minimal_layout | ir.ui.view | qweb | New |
preview_externalreport |
preview_externalreport | ir.ui.view | qweb | New |
preview_internalreport |
preview_internalreport | ir.ui.view | qweb | New |
preview_layout_report |
preview_layout_report | ir.ui.view | qweb | New |
report_invoice_wizard_preview |
report_invoice_wizard_preview | ir.ui.view | qweb | New |
report_layout |
Report layout | ir.ui.view | qweb | New |
report_preview_layout |
Report layout | ir.ui.view | qweb | New |
styles_company_report |
styles_company_report | ir.ui.view | qweb | New |
view_base_document_layout |
Document Layout | base.document.layout | form | New |
view_memory |
view_memory | ir.ui.view | qweb | New |
view_speedscope_index |
view_speedscope_index | ir.ui.view | qweb | New |
view_view_form_inherit_view |
ir.ui.view.form.inherit | ir.ui.view | form | Inherits base.view_view_form |
web.check_identity |
Check Identity | ir.ui.view | qweb | New |
web.frontend_layout |
Frontend Layout | ir.ui.view | qweb | Inherits web.layout |
web.layout |
Web layout | ir.ui.view | qweb | New |
web.login |
Login | ir.ui.view | qweb | New |
web.login_layout |
Login Layout | ir.ui.view | qweb | New |
web.login_oauth |
Login OAuth | ir.ui.view | qweb | New |
web.login_successful |
Login successful | ir.ui.view | qweb | New |
web.neutralize_banner |
Neutralize Banner | ir.ui.view | qweb | Inherits web.layout |
web.unit_tests_suite |
web.unit_tests_suite | ir.ui.view | qweb | New |
web.webclient_bootstrap |
web.webclient_bootstrap | ir.ui.view | qweb | New |
webclient_offline |
webclient_offline | ir.ui.view | qweb | New |
webclient_scoped_app |
webclient_scoped_app | ir.ui.view | qweb | New |
HTTP endpoints (73)
| Route(s) | Handler | Auth | Type | Methods | Flags |
|---|---|---|---|---|---|
/web/action/load |
Action.load |
user | jsonrpc | ALL | sudo |
/web/action/load_breadcrumbs |
Action.load_breadcrumbs |
user | jsonrpc | ALL | |
/web/action/run |
Action.run |
user | jsonrpc | ALL | |
/web/binary/company_logo, /logo, /logo.png |
Binary.company_logo |
none | http | ALL | |
/web/assets/<string:unique>/<string:filename> |
Binary.content_assets |
public | http | ALL | sudo |
/web/content, /web/content/<string:xmlid>, /web/content/<string:xmlid>/<string:filename>, /web/content/<int:id>, /web/content/<int:id>/<string:filename>, /web/content/<string:model>/<int:id>/<string:field>, /web/content/<string:model>/<int:id>/<string:field>/<string:filename> |
Binary.content_common |
public | http | ALL | |
/web/filestore/<path:_path> |
Binary.content_filestore |
none | http | ALL | |
/web/image, /web/image/<string:xmlid>, /web/image/<string:xmlid>/<string:filename>, /web/image/<string:xmlid>/<int:width>x<int:height>, /web/image/<string:xmlid>/<int:width>x<int:height>/<string:filename>, /web/image/<string:model>/<int:id>/<string:field>, /web/image/<string:model>/<int:id>/<string:field>/<string:filename>, /web/image/<string:model>/<int:id>/<string:field>/<int:width>x<int:height>, /web/image/<string:model>/<int:id>/<string:field>/<int:width>x<int:height>/<string:filename>, /web/image/<int:id>, /web/image/<int:id>/<string:filename>, /web/image/<int:id>/<int:width>x<int:height>, /web/image/<int:id>/<int:width>x<int:height>/<string:filename>, /web/image/<int:id>-<string:unique>, /web/image/<int:id>-<string:unique>/<string:filename>, /web/image/<int:id>-<string:unique>/<int:width>x<int:height>, /web/image/<int:id>-<string:unique>/<int:width>x<int:height>/<string:filename> |
Binary.content_image |
public | http | ALL | sudo |
/web/sign/get_fonts, /web/sign/get_fonts/<string:fontname> |
Binary.get_fonts |
none | jsonrpc | ALL | |
/web/binary/upload_attachment |
Binary.upload_attachment |
user | http | ALL | |
/web/export/csv |
CSVExport.web_export_csv |
user | http | ALL | |
/web/dataset/call_button, /web/dataset/call_button/<path:path> |
DataSet.call_button |
user | jsonrpc | ALL | |
/web/dataset/call_kw, /web/dataset/call_kw/<path:path> |
DataSet.call_kw |
user | jsonrpc | ALL | |
/web/database/backup |
Database.backup |
none | http | POST | csrf off |
/web/database/change_password |
Database.change_password |
none | http | POST | csrf off |
/web/database/create |
Database.create |
none | http | POST | csrf off |
/web/database/drop |
Database.drop |
none | http | POST | csrf off |
/web/database/duplicate |
Database.duplicate |
none | http | POST | csrf off |
/web/database/list |
Database.list |
none | jsonrpc | ALL | |
/web/database/manager |
Database.manager |
none | http | ALL | |
/web/database/rename |
Database.rename |
none | http | POST | csrf off |
/web/database/restore |
Database.restore |
none | http | POST | csrf off |
/web/database/selector |
Database.selector |
none | http | ALL | |
/web/domain/validate |
DomainController.validate |
user | jsonrpc | ALL | sudo |
/web/export/xlsx |
ExcelExport.web_export_xlsx |
user | http | ALL | |
/web/export/formats |
Export.formats |
user | jsonrpc | ALL | |
/web/export/get_fields |
Export.get_fields |
user | jsonrpc | ALL | |
/web/export/namelist |
Export.namelist |
user | jsonrpc | ALL | |
/web/cloc |
Home.cloc_report |
user | jsonrpc | ALL | |
/web/health |
Home.health |
none | http | ALL | |
/ |
Home.index |
none | http | ALL | |
/web/login_successful |
Home.login_successful_external_user |
user | http | ALL | website |
/robots.txt |
Home.robots |
none | http | ALL | |
/web/become |
Home.switch_to_admin |
user | http | ALL | |
/web, /odoo, /odoo/<path:subpath>, /scoped_app/<path:subpath> |
Home.web_client |
none | http | ALL | |
/web/webclient/load_menus |
Home.web_load_menus |
user | http | GET | |
/web/login |
Home.web_login |
none | http | ALL | |
/web/model/get_definitions |
Model.get_model_definitions |
user | http | POST | |
/web/translations/get_translation_for_field |
ModelTranslations.get_translation_for_field |
user | jsonrpc | POST | sudo |
/web/translations/save_translation_for_field |
ModelTranslations.save_translation_for_field |
user | jsonrpc | POST | sudo |
/web_enterprise/partner/<model("res.partner"):partner>/vcard, /web/partner/vcard |
Partner.download_vcard |
user | http | ALL | |
/web/set_profiling |
Profiling.profile |
public | http | ALL | |
/web/profile_config/<profile> |
Profiling.profile_config |
user | http | ALL | |
/web/speedscope/<profile> |
Profiling.speedscope |
user | http | ALL | sudo |
/report/get_pdf_engine_state |
ReportController.get_pdf_engine_state |
user | jsonrpc | ALL | |
/report/barcode, /report/barcode/<barcode_type>/<path:value> |
ReportController.report_barcode |
public | http | ALL | |
/report/download |
ReportController.report_download |
user | http | ALL | |
/report/<converter>/<reportname>, /report/<converter>/<reportname>/<docids> |
ReportController.report_routes |
user | http | ALL | website |
/web/session/account |
Session.account |
user | jsonrpc | ALL | sudo |
/web/session/authenticate |
Session.authenticate |
none | jsonrpc | ALL | |
/web/session/check |
Session.check |
user | jsonrpc | ALL | |
/web/session/destroy |
Session.destroy |
user | jsonrpc | ALL | |
/web/session/get_session_info |
Session.get_session_info |
user | jsonrpc | ALL | |
/web/session/logout |
Session.logout |
none | http | POST | |
/web/session/modules |
Session.modules |
user | jsonrpc | ALL | |
/web/session/fingerprint/check |
Session.session_fingerprint_check |
user | http | POST | csrf off |
/web/session/identity |
Session.session_identity |
user | http | GET | |
/web/session/identity/check |
Session.session_identity_check |
user | jsonrpc | POST | |
/web/pivot/export_xlsx |
TableExporter.export_xlsx |
user | http | ALL | |
/web/view/edit_custom |
View.edit_custom |
user | jsonrpc | ALL | sudo |
/web/webclient/bootstrap_translations |
WebClient.bootstrap_translations |
none | jsonrpc | ALL | |
/web/bundle/<string:bundle_name> |
WebClient.bundle |
public | http | GET | |
/web/webclient/translations |
WebClient.translations |
public | http | ALL | sudo |
/web/tests |
WebClient.unit_tests_suite |
user | http | ALL | |
/web/webclient/version_info |
WebClient.version_info |
none | jsonrpc | ALL | |
/json/<path:subpath> |
WebJsonController.web_json |
user | http | ALL | |
/json/1/<path:subpath> |
WebJsonController.web_json_1 |
bearer | http | ALL | |
/odoo/offline |
WebManifest.offline |
public | http | GET | |
/scoped_app |
WebManifest.scoped_app |
public | http | GET | |
/scoped_app_icon_png |
WebManifest.scoped_app_icon_png |
public | http | GET | |
/web/manifest.scoped_app_manifest |
WebManifest.scoped_app_manifest |
public | http | GET | |
/web/service-worker.js |
WebManifest.service_worker |
public | http | GET | |
/web/manifest.webmanifest |
WebManifest.webmanifest |
public | http | GET |
Models touched (16)
New fields (0)
No new fields.
Public methods (16)-
formatted_read_group(self, domain: DomainType, groupby: <expr>=(), aggregates: <expr>=(), having: DomainType=(), offset: int=0, limit: <expr>=None, order: <expr>=None) -> <expr>@api.model@api.readonlyA method similar to :meth:`_read_group` but with all the formatting needed by the webclient. :param domain: :ref:`A search domain <reference/orm/domains>`. Use an empty list to match all records. :param groupby: list of groupby descriptions by which the records will be grouped. A groupby description is either a field (then it will be grouped by that field) or a string ``'<field>:<granularity>'``. Right now, the only supported granularities are: * ``day`` * ``week`` * ``month`` * ``quarter`` * ``year`` and they only make sense for date/datetime fields. Additionally integer date parts are also supported: * ``year_number`` * ``quarter_number`` * ``month_number`` * ``iso_week_number`` * ``day_of_year`` * ``day_of_month`` * ``day_of_week`` * ``hour_number`` * ``minute_number`` * ``second_number`` :param aggregates: list of aggregates specification. Each element is ``'<field>:<agg>'`` (aggregate field with aggregation function ``agg``). The possible aggregation functions are the ones provided by `PostgreSQL <https://www.postgresql.org/docs/current/static/functions-aggregate.html>`_, except ``count_distinct`` and ``array_agg_distinct`` with the expected meaning. :param having: A domain where the valid "fields" are the aggregates. :param offset: optional number of groups to skip :param limit: optional max number of groups to return :param order: optional ``order by`` specification, for overriding the natural sort ordering of the groups, see :meth:`~.search`. :return: list of dict such as ``[{'groupy_spec': value, ...}, ...]`` containing: * the groupby values: ``{groupby[i]: <value>}`` * the aggregate values: ``{aggregates[i]: <value>}`` * ``'__extra_domain'``: list of tuples specifying the group search criteria * ``'__fold'``: boolean if a fold_name is set on the comodel and read_group_expand is activated :raise AccessError: if user is not allowed to access requested information -
formatted_read_grouping_sets(self, domain: DomainType, grouping_sets: <expr>, aggregates: <expr>=(), *, order: <expr>=None) -> <expr>@api.model@api.readonlyA method similar to :meth:`_read_grouping_set` but with all the formatting needed by the webclient. It is a multi groupby version of formatted_read_group allowing to have aggregates for different groupby specifications in a single SQL requests. :param domain: :ref:`A search domain <reference/orm/domains>`. Use an empty list to match all records. :param grouping_sets: list of list of groupby descriptions by which the records will be grouped. A groupby description is either a field (then it will be grouped by that field) or a string ``'<field>:<granularity>'``. Right now, the only supported granularities are: * ``day`` * ``week`` * ``month`` * ``quarter`` * ``year`` and they only make sense for date/datetime fields. Additionally integer date parts are also supported: * ``year_number`` * ``quarter_number`` * ``month_number`` * ``iso_week_number`` * ``day_of_year`` * ``day_of_month`` * ``day_of_week`` * ``hour_number`` * ``minute_number`` * ``second_number`` :param aggregates: list of aggregates specification. Each element is ``'<field>:<agg>'`` (aggregate field with aggregation function ``agg``). The possible aggregation functions are the ones provided by `PostgreSQL <https://www.postgresql.org/docs/current/static/functions-aggregate.html>`_, except ``count_distinct`` and ``array_agg_distinct`` with the expected meaning. :param order: optional ``order by`` specification, for overriding the natural sort ordering of the groups, see :meth:`~.search`. :return: list of list of dict such as ``[[{'groupy_spec': value, ...}, ...], ...]`` containing: * the groupby values: ``{groupby[i]: <value>}`` * the aggregate values: ``{aggregates[i]: <value>}`` * ``'__extra_domain'``: list of tuples specifying the group search criteria * ``'__fold'``: boolean if a fold_name is set on the comodel and read_group_expand is activated :raise AccessError: if user is not allowed to access requested information -
onchange(self, values: dict, field_names: <expr>, fields_spec: dict)Perform an onchange on the given fields, and return the result. :param values: dictionary mapping field names to values on the form view, giving the current state of modification :param field_names: names of the modified fields :param fields_spec: dictionary specifying the fields in the view, just like the one used by :meth:`web_read`; it is used to format the resulting values When creating a record from scratch, the client should call this with an empty list as ``field_names``. In that case, the method first adds default values to ``values``, computes the remaining fields, applies onchange methods to them, and return all the fields in ``fields_spec``. The result is a dictionary with two optional keys. The key ``"value"`` is used to return field values that should be modified on the caller. The corresponding value is a dict mapping field names to their value, in the format of :meth:`web_read`, except for x2many fields, where the value is a list of commands to be applied on the caller's field value. The key ``"warning"`` provides a warning message to the caller. The corresponding value is a dictionary like:: { "title": "Be careful!", # subject of message "message": "Blah blah blah.", # full warning message "type": "dialog", # how to display the warning } -
onchange_batch(self, values_list: <expr>, field_names: <expr>, fields_spec: dict) -> <expr>@api.modelApply onchange to a batch of new records. This method only supports new records, so ``self`` must be empty. -
read_progress_bar(self, domain: DomainType, group_by: str, progress_bar: <expr>) -> <expr>@api.model@api.readonlyGet the data needed for all the kanban column progressbars. These are fetched alongside read_group operation. :param domain: the domain used in the kanban view to filter records :param group_by: the name of the field used to group records into kanban columns :param progress_bar: the ``<progressbar/>`` declaration attributes (field, colors, sum) :return: a dictionary mapping group_by values to dictionaries mapping progress bar field values to the related number of records -
search_panel_select_multi_range(self, field_name: str, **kwargs) -> <expr>@api.modelReturn possible values of the field field_name (case select="multi"), possibly with counters and groups. :param field_name: the name of a filter field; possible types are many2one, many2many, selection. :param kwargs: additional features :param category_domain: domain generated by categories. Default is ``[]``. :param comodel_domain: domain of field values (if relational) (this parameter is used in :meth:`_search_panel_range`). Default is ``[]``. :param enable_counters: whether to count records by value. Default is ``False``. :param expand: whether to return the full range of field values in ``comodel_domain`` or only the field image values. Default is ``False``. :param filter_domain: domain generated by filters. Default is ``[]``. :param group_by: extra field to read on comodel, to group comodel records. :param group_domain: dict, one domain for each activated group for the group_by (if any). Those domains are used to fech accurate counters for values in each group. Default is ``[]`` (many2one case) or ``None``. :param limit: integer, maximal number of values to fetch. Default is ``None`` (no limit). :param search_domain: base domain of search. Default is ``[]``. :return: :: { 'values': a list of possible values, each being a dict with keys 'id' (value), 'name' (value label), '__count' (how many records with that value), 'group_id' (value of group), set if a group_by has been provided, 'group_name' (label of group), set if a group_by has been provided } or an object with an error message when limit is defined and reached. -
search_panel_select_range(self, field_name: str, **kwargs) -> <expr>@api.modelReturn possible values of the field field_name (case select="one"), possibly with counters, and the parent field (if any and required) used to hierarchize them. :param field_name: the name of a field; of type many2one or selection. :param kwargs: additional features * category_domain: domain generated by categories. Default is ``[]``. * comodel_domain: domain of field values (if relational). Default is ``[]``. * enable_counters: whether to count records by value. Default is ``False``. * expand: whether to return the full range of field values in comodel_domain or only the field image values (possibly filtered and/or completed with parents if hierarchize is set). Default is ``False``. * filter_domain: domain generated by filters. Default is ``[]``. * hierarchize: determines if the categories must be displayed hierarchically (if possible). If set to true and ``_parent_name`` is set on the comodel field, the information necessary for the hierarchization will be returned. Default is ``True``. * limit: integer, maximal number of values to fetch. Default is ``None`` (no limit). * search_domain: base domain of search. Default is ``[]``. :return: :: { 'parent_field': parent field on the comodel of field, or False 'values': array of dictionaries containing some info on the records available on the comodel of the field 'field_name'. The display name, the __count (how many records with that value) and possibly parent_field are fetched. } or an object with an error message when limit is defined and is reached. -
web_name_search(self, name: str, specification: <expr>, domain: <expr>=None, operator: str='ilike', limit: int=100) -> <expr>@api.model@api.readonlySearch for records that have a display name matching the given ``name`` pattern when compared with the given ``operator``, while also matching the optional search domain (``domain``). The result is a dictionnary formatted according to the given ``specification``. Unlike the standard ``name_search()`` method, ``web_name_search()`` can traverse relational fields to fetch nested field values in a single call. Example:: records.web_name_search( name = "Note", operator = "ilike", specification = { 'display_name': {}, 'author_id': { 'fields': { 'display_name': {} } }, 'line_ids': { 'fields': { 'name': {} }, 'limit': 5, 'order': 'sequence asc' } } ) >>> [{ 'id': 1, 'display_name': 'Note G', 'author_id': { 'id': 42, 'display_name': 'Ada Lovelace' }, 'line_ids': [ {'id': 10, 'name': 'Intro'}, {'id': 11, 'name': 'Body'} ], '__formatted_display_name': "Note G" }] :param name: the name pattern to match :param domain: search domain specifying further restrictions :param operator: domain operator for matching ``name``, such as ``'like'`` or ``'='``. :param limit: max number of records to return :param specification: A dictionary defining the fields to read. The keys are field names, and the values are configuration dictionaries. Passing an empty dictionary as a value simply reads the field's value. Supported keys inside a field's configuration dictionary: * ``fields`` (dict): Nested specification for relational or property fields. * ``context`` (dict): Context to apply when evaluating the relational field. * ``limit`` (int): Maximum number of records to fetch (for x2many fields). * ``order`` (str): Sorting order to apply (for x2many fields). :return: A list of dictionaries representing the requested records. -
web_override_translations(self, values: <expr>) -> NoneThis method is used to override all the modal translations of the given fields with the provided value for each field. :param values: dictionary of the translations to apply for each field name ex: ``{ "field_name": "new_value" }`` -
web_read(self, specification: <expr>) -> <expr>@api.readonlyRead the requested fields for the records in ``self``, returning their values as a list of dicts according to the provided specification. Unlike the standard :meth:`read()` method, ``web_read()`` can traverse relational fields to fetch nested field values in a single call. Example:: records.web_read({ 'display_name': {}, 'author_id': { 'fields': { 'display_name': {} } }, 'line_ids': { 'fields': { 'name': {} }, 'limit': 5, 'order': 'sequence asc' } }) >>> [{ 'id': 1, 'display_name': 'Note G', 'author_id': { 'id': 42, 'display_name': 'Ada Lovelace' }, 'line_ids': [ {'id': 10, 'name': 'Intro'}, {'id': 11, 'name': 'Body'} ] }] :param specification: A dictionary defining the fields to read. The keys are field names, and the values are configuration dictionaries. Passing an empty dictionary as a value simply reads the field's value. Supported keys inside a field's configuration dictionary: * ``fields`` (dict): Nested specification for relational or property fields. * ``context`` (dict): Context to apply when evaluating the relational field. * ``limit`` (int): Maximum number of records to fetch (for x2many fields). * ``order`` (str): Sorting order to apply (for x2many fields). :return: A list of dictionaries representing the requested records. -
web_read_group(self, domain: DomainType, groupby: <expr>, aggregates: <expr>=(), limit: <expr>=None, offset: int=0, order: <expr>=None, *, auto_unfold: bool=False, opening_info: <expr>=None, unfold_read_specification: <expr>=None, unfold_read_default_limit: <expr>=80, groupby_read_specification: <expr>=None) -> <expr>@api.model@api.readonlyServe as the primary method for loading grouped data in list and kanban views. This method wraps :meth:`~.formatted_read_group` to return both the grouped data and the total number of groups matching the search domain. It also conditionally opens (unfolds) groups based on the `auto_unfold` parameter and the `__fold` key returned by :meth:`~.formatted_read_group`. A group is considered "open" if it contains a `__records` or `__groups` key. - `__records`: The result of a :meth:`~.web_search_read` call for the group. - `__groups`: The results of subgroupings. :param domain: :ref:`A search domain <reference/orm/domains>`. :param groupby: A list of groupby specification at each level, see :meth:`~.formatted_read_group`. :param aggregates: A list of aggregate specifications. see :meth:`~.formatted_read_group` :param limit: The maximum number of top-level groups to return. see :meth:`~.formatted_read_group` :param offset: The offset for the top-level groups. see :meth:`~.formatted_read_group` :param order: A sort string, as used in :meth:`~.search` :param auto_unfold: If `True`, automatically unfolds the first 10 groups according to their `__fold` key, if present; otherwise, it is unfolded by default. This is typically `True` for kanban views and `False` for list views. :param opening_info: The state of currently opened groups, used for reloading. :: opening_info = [{ "value": raw_value_groupby, "folded": True or False, ["offset": int,] # present if unfolded ["limit": int,] # present if unfolded ["progressbar_domain": progressbar_domain,] # present if unfolded, e.g., when clicking on a progress bar section ["groups": <opening_info>,] # present if unfolded }] :param unfold_read_specification: The read specification for :meth:`~.web_read` when unfolding a group. :param unfold_read_default_limit: The default record limit to apply when unfolding a group. :param groupby_read_specification: The :meth:`~.web_read` specification for reading the records that are being grouped on. This is mainly for list views with <groupby> leaves. {<groupby_spec>: <read_specification>} :return: A dictionary with the following structure: :: { 'groups': <groups>, 'length': <total_group_count>, } Where <groups> is the result of :meth:`~.formatted_read_group`, but with an added `__groups` key for subgroups or a `__records` key for the result of :meth:`~.web_read` for records within the group. -
web_resequence(self, specification: <expr>, field_name: str='sequence', offset: int=0) -> <expr>Re-sequence a number of records in the model, by their ids. The re-sequencing starts at the first record of ``ids``, the sequence number starts at ``offset`` and is incremented by one after each record. The returning value is a read of the resequenced records with the specification given in the parameter. :param specification: specification for the read of the resequenced records :param field_name: field used for sequence specification, defaults to ``"sequence"`` :param offset: sequence number for first record in ``ids``, allows starting the resequencing from an arbitrary number, defaults to ``0`` -
web_save(self, vals: ValuesType, specification: <expr>, next_id=None) -> <expr>Save the provided values to the current recordset, either by updating existing records or creating a new one if the recordset is empty. After saving, fetch and return the requested fields based on the provided specification. :param vals: fields to update and the value to set on them :param specification: A dictionary defining the fields to read. The keys are field names, and the values are configuration dictionaries. Passing an empty dictionary as a value simply reads the field's value. Supported keys inside a field's configuration dictionary: * ``fields`` (dict): Nested specification for relational or property fields. * ``context`` (dict): Context to apply when evaluating the relational field. * ``limit`` (int): Maximum number of records to fetch (for x2many fields). * ``order`` (str): Sorting order to apply (for x2many fields). :param next_id: An optional record ID to browse and return instead of the currently saved record. :return: A list of dictionaries representing the requested records. -
web_save_multi(self, vals_list: <expr>, specification: <expr>) -> <expr>Save the provided list of values to the current recordset, either by updating existing records or creating a new one if the recordset is empty. After saving, fetch and return the requested fields based on the provided specification. :param vals_list: values for the model's fields, as a list of dictionaries :param specification: A dictionary defining the fields to read. The keys are field names, and the values are configuration dictionaries. Passing an empty dictionary as a value simply reads the field's value. Supported keys inside a field's configuration dictionary: * ``fields`` (dict): Nested specification for relational or property fields. * ``context`` (dict): Context to apply when evaluating the relational field. * ``limit`` (int): Maximum number of records to fetch (for x2many fields). * ``order`` (str): Sorting order to apply (for x2many fields). :return: A list of dictionaries representing the requested records. -
web_search_read(self, domain: DomainType, specification: <expr>, offset: int=0, limit: <expr>=None, order: <expr>=None, count_limit: <expr>=None) -> <expr>@api.model@api.readonlyPerform a search followed by a structured read. Unlike the standard :meth:`search_read()`, ``web_search_read()`` can traverse relational fields to fetch nested field values in a single call. :param domain: search domain specifying further restrictions :param offset: number of results to ignore (default: none) :param limit: maximum number of records to return (default: all) :param order: sort string :param specification: A dictionary defining the fields to read. The keys are field names, and the values are configuration dictionaries. Passing an empty dictionary as a value simply reads the field's value. Supported keys inside a field's configuration dictionary: * ``fields`` (dict): Nested specification for relational or property fields. * ``context`` (dict): Context to apply when evaluating the relational field. * ``limit`` (int): Maximum number of records to fetch (for x2many fields). * ``order`` (str): Sorting order to apply (for x2many fields). :return: A dictionary containing a 'length' key containing the number of records and a 'records' key containing a list of records. -
web_unlink(self) -> <expr>Delete the records in ``self``, the way the web client's own delete flows do it. This is deliberately a separate method from :meth:`~.unlink`, called only by the web client, so that the error-recovery below never runs for internal ``unlink()`` calls made by other server-side code. If deleting ``self`` in one go is blocked by a foreign key/RESTRICT violation, pinpoint exactly which records of ``self`` are the actual problem by retrying the deletion record by record (each attempt rolled back regardless of its outcome, so nothing is ever partially deleted), then raise a :class:`UnlinkBlockedError` enriched with that information - the blocking model's display name, whether the records can be archived instead, and which of them are actually blocked.
New fields (25)
-
company_detailsHtmldefault=_default_company_detailsreadonly=Falserelated='company_id.company_details' -
company_idMany2one → res.companydefault=<expr>required=True args: 'res.company' -
country_idMany2onereadonly=Truerelated='company_id.country_id' -
custom_colorsBooleancompute='_compute_custom_colors'readonly=False -
emailCharreadonly=Truerelated='company_id.email' -
external_report_layout_idMany2onereadonly=Falserelated='company_id.external_report_layout_id' -
fontSelectionreadonly=Falserelated='company_id.font' -
is_company_details_emptyBooleancompute='_compute_empty_company_details' -
logoBinaryreadonly=Falserelated='company_id.logo' -
logo_primary_colorCharcompute='_compute_logo_colors' -
logo_secondary_colorCharcompute='_compute_logo_colors' -
nameCharreadonly=Truerelated='company_id.name' -
paperformat_idMany2onereadonly=Falserelated='company_id.paperformat_id' -
partner_idMany2onereadonly=Truerelated='company_id.partner_id' -
phoneCharreadonly=Truerelated='company_id.phone' -
previewHtmlcompute='_compute_preview'sanitize=False -
preview_logoBinaryrelated='logo'string='Preview logo' -
primary_colorCharreadonly=Falserelated='company_id.primary_color' -
report_footerHtmldefault=_default_report_footerreadonly=Falserelated='company_id.report_footer' -
report_headerHtmlreadonly=Falserelated='company_id.report_header' -
report_layout_idMany2one → report.layoutargs: 'report.layout' -
report_tables_idSelectionreadonly=Falserelated='company_id.report_tables_id'required=True -
secondary_colorCharreadonly=Falserelated='company_id.secondary_color' -
vatCharreadonly=Truerelated='company_id.vat' -
websiteCharreadonly=Truerelated='company_id.website'
-
document_layout_save(self) -
extract_image_primary_secondary_colors(self, logo, white_threshold=225, mitigate=175)@api.modelIdentifies dominant colors First resizes the original image to improve performance, then discards transparent colors and white-ish colors, then calls the averaging method twice to evaluate both primary and secondary colors. :param logo: logo to process :param white_threshold: arbitrary value defining the maximum value a color can reach :param mitigate: arbitrary value defining the maximum value a band can reach :return: a 2-value tuple with hex values of primary and secondary colors
New fields (0)
No new fields.
Public methods (1)-
web_create_image_variants(self, variants)@api.modelCreate linked image variants in batch using `create_unique`.
New fields (0)
No new fields.
Public methods (7)-
color_scheme(self) -
get_currencies(self)@deprecated("Deprecated since 19.0, use get_all_currencies on 'res.currency'") -
get_frontend_session_info(self)@api.model -
is_a_bot(cls)@classmethod -
lazy_session_info(self)@api.model -
session_info(self) -
webclient_rendering_context(self)
New fields (0)
No new fields.
Public methods (2)-
display_name_for(self, models)@api.modelReturns the display names from provided models which the current user can access. The result is the same whether someone tries to access an inexistent model or a model they cannot access. :models list(str): list of technical model names to lookup (e.g. `["res.partner"]`) :return: list of dicts of the form `{ "model", "display_name" }` (e.g. `{ "model": "res_partner", "display_name": "Contact"}`) -
get_available_models(self)@api.modelReturn the list of models the current user has access to, with their corresponding display name.
New fields (0)
No new fields.
Public methods (1)-
record_to_html(self, record, field_name, options)@api.model
New fields (0)
No new fields.
Public methods (0)No public methods.
New fields (0)
No new fields.
Public methods (1)-
load_web_menus(self, debug)Loads all menu items (all applications and their sub-menus) and processes them to be used by the webclient. Mainly, it associates with each application (top level menu) the action of its first child menu that is associated with an action (recursively), i.e. with the action to execute when the opening the app. :return: the menus (including the images in Base64)
New fields (0)
No new fields.
Public methods (1)-
get_view_info(self)
New fields (0)
No new fields.
Public methods (1)-
get_properties_base_definition(self, model_name, field_name)@api.modelReturn the base properties definition if we can read the model.
New fields (0)
No new fields.
Public methods (2)-
create(self, vals_list)@api.model_create_multi -
write(self, vals)
New fields (1)
-
web_app_nameCharconfig_parameter='web.web_app_name' args: 'Web App Name'
No public methods.
New fields (0)
No new fields.
Public methods (0)No public methods.
New fields (0)
No new fields.
Public methods (1)-
name_search(self, name='', domain=None, operator='ilike', limit=100)@api.model
New fields (1)
-
embedded_actions_config_idsOne2many → res.users.settings.embedded.actionargs: 'res.users.settings.embedded.action', 'user_setting_id'
-
get_embedded_actions_settings(self) -
set_embedded_actions_setting(self, action_id, res_id, vals)
New fields (7)
-
action_idMany2one → ir.actions.act_windowexport_string_translation=Falseondelete='cascade'required=True args: 'ir.actions.act_window' -
embedded_actions_orderCharexport_string_translation=False args: 'List order of embedded action ids' -
embedded_actions_visibilityCharexport_string_translation=False args: 'List visibility of embedded actions ids' -
embedded_visibilityBooleanexport_string_translation=False args: 'Is top bar visible' -
res_idIntegerexport_string_translation=False -
res_modelCharexport_string_translation=Falserequired=True -
user_setting_idMany2one → res.users.settingsexport_string_translation=Falseindex='btree_not_null'ondelete='cascade'required=True args: 'res.users.settings'
No public methods.
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…