Reported: clicking "Post a Listing" on /classifieds while logged out threw a raw 500 instead of prompting login. Root cause is upstream, in this Odoo 19 build's own http.py: when auth='user' raises SessionExpiredException for an anonymous visitor, Request._serve_db's `finally: self.env = None` clears the request env before the exception reaches the website error handler, which then tries to build the login redirect via self.env['ir.http']._redirect(...) and crashes with TypeError: 'NoneType' object is not subscriptable. This isn't specific to any one route - it reproduces on every auth='user' + website=True page hit anonymously, including stock Odoo's own /my (traced this back to the true cause rather than continuing to treat it as an unrelated environment quirk, since it now has a real reported symptom). Since core can't be patched here, worked around it at the route level across all 9 affected pages (classifieds new/my/renew, membership my/renew/card, benefits my, school attendance, portal my/school, event checkin): switched from auth='user' to auth='public' and added an explicit `if request.env.user._is_public(): return request.redirect(...)` check at the top of each handler, before Odoo's own auth layer ever gets a chance to raise. The jsonrpc AJAX endpoints (attendance save, checkin scan/dashboard) were left on auth='user' since they return a JSON error rather than attempting an HTML redirect, so they don't hit this path. Verified against a live Odoo 19 + Postgres 16 container: reproduced the original crash pre-fix, then confirmed all 9 previously-broken routes now 303-redirect to /web/login?redirect=<path> when hit anonymously, that the login page carries the redirect target, that logged-in access is unaffected (200), and that the separate "logged in but lacking a required group" case (event check-in without Registration Desk) still degrades gracefully to a clean 403 rather than a crash. Full regression: 48/48 tests pass across the six touched modules. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
85 lines
3.5 KiB
Python
85 lines
3.5 KiB
Python
from odoo import fields, http
|
|
from odoo.exceptions import AccessDenied
|
|
from odoo.http import request
|
|
|
|
|
|
def _redirect_to_login_if_public(path):
|
|
"""Manual login-required redirect - see community_classifieds for why this
|
|
is needed instead of auth='user' (a bug in this Odoo version's own
|
|
SessionExpiredException -> login-redirect handling)."""
|
|
if request.env.user._is_public():
|
|
return request.redirect(f'/web/login?redirect={path}')
|
|
return None
|
|
|
|
|
|
class SchoolAttendanceController(http.Controller):
|
|
|
|
def _get_teacher_classes(self):
|
|
partner = request.env.user.partner_id
|
|
return request.env['community.school.class'].sudo().search([('teacher_id', '=', partner.id)])
|
|
|
|
@http.route(['/school/attendance'], type='http', auth='public', website=True)
|
|
def attendance_home(self, class_id=None, date=None, **kwargs):
|
|
redirect = _redirect_to_login_if_public('/school/attendance')
|
|
if redirect:
|
|
return redirect
|
|
classes = self._get_teacher_classes()
|
|
if not classes:
|
|
return request.render('community_school.portal_no_classes', {})
|
|
|
|
selected_class = classes.filtered(lambda c: c.id == int(class_id)) if class_id else classes[:1]
|
|
if not selected_class:
|
|
selected_class = classes[:1]
|
|
selected_date = date or fields.Date.context_today(request.env.user).isoformat()
|
|
|
|
Enrollment = request.env['community.school.enrollment'].sudo()
|
|
enrollments = Enrollment.search([
|
|
('class_id', '=', selected_class.id), ('state', '=', 'enrolled'),
|
|
])
|
|
existing_by_enrollment = {
|
|
attendance.enrollment_id.id: attendance
|
|
for attendance in request.env['community.school.attendance'].sudo().search([
|
|
('class_id', '=', selected_class.id), ('date', '=', selected_date),
|
|
])
|
|
}
|
|
roster = [
|
|
{'enrollment': enrollment, 'attendance': existing_by_enrollment.get(enrollment.id)}
|
|
for enrollment in enrollments
|
|
]
|
|
|
|
return request.render('community_school.portal_attendance', {
|
|
'classes': classes,
|
|
'selected_class': selected_class,
|
|
'selected_date': selected_date,
|
|
'roster': roster,
|
|
})
|
|
|
|
@http.route(['/school/attendance/save'], type='jsonrpc', auth='user', website=True)
|
|
def attendance_save(self, class_id=None, date=None, lines=None, **kwargs):
|
|
classes = self._get_teacher_classes()
|
|
klass = classes.filtered(lambda c: c.id == int(class_id))
|
|
if not klass:
|
|
raise AccessDenied()
|
|
|
|
Attendance = request.env['community.school.attendance'].sudo()
|
|
Enrollment = request.env['community.school.enrollment'].sudo()
|
|
saved = 0
|
|
for line in (lines or []):
|
|
enrollment = Enrollment.browse(int(line.get('enrollment_id', 0)))
|
|
if not enrollment.exists() or enrollment.class_id.id != klass.id:
|
|
continue
|
|
vals = {'state': line.get('state', 'present'), 'notes': line.get('notes') or False}
|
|
record = Attendance.search([
|
|
('enrollment_id', '=', enrollment.id), ('date', '=', date),
|
|
], limit=1)
|
|
if record:
|
|
record.write(vals)
|
|
else:
|
|
vals.update({'enrollment_id': enrollment.id, 'date': date})
|
|
record = Attendance.create(vals)
|
|
saved += 1
|
|
if record.state == 'absent':
|
|
record._send_absence_notice()
|
|
|
|
return {'status': 'ok', 'saved': saved}
|