Commit graph

30 commits

Author SHA1 Message Date
22d30a1504 [FIX] security: redact the master password from every output
CodeQL raised seven high-severity alerts on this branch. Three were real,
and the same secret was behind all of them: the Odoo master password,
which db_restore appends to its command line as soon as the database
declares one.

The command itself was printed raw -- "print(arg)" -- so the password
reached stdout, and any terminal capture with it. The probe output was
logged raw too, and a refused attempt echoes the command it tried.

Wider than that: the runner filtered the command it was about to run, but
not what came back. A tool that reprints its own arguments -- "set -x", a
traceback, odoo_bin.sh -- put the secret straight back into the terminal
AND into the log file the sink writes. Every subprocess line now goes
through the same filter as the command.

The four remaining alerts sit on expressions already wrapped in
redact_secrets(). CodeQL does not cross re.sub, so it cannot see the
barrier; the mitigation is real and they are false positives.

--- FR ---

CodeQL a levé sept alertes de sévérité haute sur cette branche. Trois
étaient réelles, et le même secret était derrière : le mot de passe maître
d'Odoo, que db_restore ajoute à sa ligne de commande dès que la base en
exige un.

La commande elle-même était imprimée telle quelle — « print(arg) » — donc
le mot de passe atteignait la sortie standard, et toute capture de
terminal avec elle. La sortie de la sonde était journalisée brute
également, et un essai refusé réaffiche la commande tentée.

Plus large : le lanceur filtrait la commande qu'il allait exécuter, mais
pas ce qui en revenait. Un outil qui réaffiche ses propres arguments —
« set -x », une trace, odoo_bin.sh — remettait le secret dans le terminal
ET dans le fichier de journal. Chaque ligne du sous-processus passe
désormais par le même filtre que la commande.

Les quatre alertes restantes portent sur des expressions déjà entourées de
redact_secrets(). CodeQL ne franchit pas re.sub et ne voit donc pas la
barrière ; la mitigation est réelle, ce sont des faux positifs.

Assisted-by: Claude Opus 5
2026-08-23 02:11:50 -04:00
0ebdc0c710 [FIX] db_restore: ask the master password again instead of dying on a typo
It was asked once. Wrong, and Odoo raises AccessDenied, check_output
raises CalledProcessError, nothing catches it, and the migration dies on
a traceback. After an hour of version bumps that is a steep price for
one letter. Ten attempts now.

Only a refused PASSWORD is asked again. Any other failure stops and is
shown: asking ten times in front of an unreachable database would hide
the real fault behind a prompt, and one would hunt for a password.
AccessDenied is matched on the class, never on its message, which is
translated.

The attempt is probed with --list, which changes nothing. Validating
here avoids failing half-way, once the database has already been
dropped.

--- FR ---

Il était demandé une fois. Faux, et Odoo lève AccessDenied,
check_output lève CalledProcessError, rien ne l'attrape, la migration
meurt sur une trace. Après une heure de paliers, c'est cher payé pour
une lettre. Dix essais désormais.

Seul un MOT DE PASSE refusé fait reposer la question. Tout autre échec
arrête et s'affiche : dix invites devant une base injoignable
cacheraient la panne, et l'on chercherait un mot de passe. AccessDenied
se reconnaît à la CLASSE, jamais au message, qui est traduit.

L'essai est éprouvé sur --list, qui ne modifie rien. Valider là évite
d'échouer à mi-parcours, une fois la base déjà supprimée.

Assisted-by: Claude Opus 5
2026-08-23 02:09:59 -04:00
6339282668 [ADD] filestore: purge once at the end, tidy at the restore, see the 30 MB
Not between bumps, and the measurement says why: two to eleven fields
vanish at one step and COME BACK at the next -- hr.employee.phone,
account.move.statement_id. "The field is gone" is a transient state
while a migration runs. And there would be nothing to gain: 1881 dead
rows appear at the 13 bump and the count never moves again, so one
final pass takes them all.

The nesting is born once, at the restore, and the clone copies it
identically into every step -- the six databases carried the same 1168
files. It is offered where it is born, never on a closed stdin.

Widened too: the tool was named after missing files and so looked only
at those. 1860 rows in 18 hold a live file for a field that is gone --
31 MB of res.partner.image and thumbnails from before Odoo 13 computed
them. Odoo's collector will never touch them while the row exists.

--- FR ---

Pas entre les paliers, et la mesure dit pourquoi : deux à onze champs
disparaissent à une étape et REVIENNENT à la suivante --
hr.employee.phone, account.move.statement_id. « Le champ n'existe plus »
est transitoire tant que la migration court. Et il n'y aurait rien à y
gagner : 1881 lignes mortes naissent au palier 13 et le compte ne bouge
plus, donc une passe finale les prend toutes.

Le nichage naît une fois, à la restauration, et le clone le recopie
partout — les six bases portaient les mêmes 1168 fichiers. Il se répare
là où il naît, jamais sur un stdin fermé.

Élargi aussi : l'outil portait le nom des fichiers absents et ne
regardait donc qu'eux. 1860 lignes en 18 retiennent un fichier bien
présent pour un champ disparu — 31 Mo d'images res.partner et de
vignettes d'avant qu'Odoo 13 ne les calcule.

Assisted-by: Claude Opus 5
2026-08-23 02:09:59 -04:00
d6a088e926 [ADD] db_restore: check the filestore landed, and open the tool from the menu
Odoo's shutil.move renames when the destination is absent and NESTS when
it exists, so a leftover filestore/<db>/ sends a whole backup into
filestore/<db>/filestore/, where Odoo never looks. That happened once
here and the clone copied it into all seven databases of the chain --
1168 files, 133 MB each, and nothing said a word.

The check runs after a real restore only. A clone copies its source as
it stands, faults included: checking the mirror would say the same thing
twice, and in the wrong place. It warns and names the fix rather than
aborting -- the database is restored and usable, it is the layout that
is wrong.

--- FR ---

Le shutil.move d'Odoo renomme quand la destination est absente et
IMBRIQUE quand elle existe : un filestore/<base>/ resté là envoie toute
une sauvegarde dans filestore/<base>/filestore/, où Odoo ne regarde
jamais. C'est arrivé une fois ici et le clone l'a recopié dans les sept
bases de la chaîne -- 1168 fichiers, 133 Mo chacune, sans un mot.

Le contrôle ne suit qu'une vraie restauration. Un clone recopie sa
source telle quelle, défauts compris : contrôler le miroir dirait deux
fois la même chose, au mauvais endroit. Il avertit et nomme la
correction plutôt que d'interrompre -- la base est restaurée et
utilisable, c'est la disposition qui cloche.

Assisted-by: Claude Opus 5
2026-08-23 02:09:59 -04:00
36ae1d9beb [UPD] script Format 2026-03-14 23:26:31 -04:00
1e731114f5 [IMP] script: update copyright year to 2026
Reflect the current year in all TechnoLibre
license headers across script/, test/, and docker/.

Generated by Claude Code 2.1.74 model claude-sonnet-4-6

Co-Authored-By: Mathieu Benoit <mathben@technolibre.ca>
2026-03-11 23:16:05 -04:00
a2d3aa2a78 [ADD] Multilingual translation of all documentation (EN/FR)
Added 30 .base.md files using the mmg (Multilingual Markdown Generator)
format to automatically generate English (.md) and French (.fr.md)
versions of all project documentation.
Updated conf/make.documentation.Makefile to process all .base.md files
via `make doc_markdown`.
2026-03-04 22:23:52 -05:00
facd1c928e [IMP] script update config from database and implement TODO configuration
- execute script remote endline from output
2026-02-13 04:07:53 -05:00
c580493099 [IMP] script repo change addons list from backup file
- check module to identify addons path
2026-02-13 04:07:48 -05:00
54f8ba0feb [UPD] script execute to share exec_command_live 2026-02-13 04:07:44 -05:00
e2125a7735 [IMP] script database restore: support neutralize 2025-12-20 03:15:51 -05:00
d1755f6683 [FIX] script db_drop_all.py fix execute_shell 2025-11-30 21:35:14 -05:00
5b87769e2e [UPD] script replace subprocess.check_output to subprocess.run 2025-11-27 00:43:22 -05:00
9ca904a2ec [FIX] script migrate process_backup_file.py permission 2025-11-26 03:32:18 -05:00
f1e1de2270 [IMP] script: migration database zip or prod to fix postgresql 18 module mail 2025-11-19 23:37:39 -05:00
c1b9a5fee4 [UPD] format and update license 2025-11-08 23:53:07 -05:00
cbc43fde3c [IMP] todo support odoo upgrade
- add example odoo test
- prevent delete production file with validation
- add makefile with selenium
- script prod to dev uninstall module after installation
- adapt todo with private directory
- script to download remote database
- TODO show documentation for migration
2025-10-31 01:43:26 -04:00
de9779cfc2 [IMP] refactoring .venv.erplibre
- erplibre separate venv erplibre and odoo
- rename python-version to python-odoo-version
- add conf/python-erplibre-version
- rename .venv to .venv.erplibre
- move .venv/repo to .venv.erplibre/bin/repo
- install pyenv into .venv.erplibre
- install poetry into .venv.odooVERSION

- first installation show odoo version to install
- can install erplibre without odoo
- update README.md information about installation with TODO
- change image from github to locally
- remove link creation .venv

- update version: remove code to force create symbolic link .venv
- use dynamic merge manifest, will be able to merge different odoo
version
- can add dev tools
- default manifest is empty to remove conflict
2025-10-31 01:34:26 -04:00
a1b9c98b5f [IMP] refactoring to support multiple version of Odoo
- change path odoo to support multiple
- conf pycharm exclude folder
- refactor run/test/coverage by use same script
2025-10-31 01:32:11 -04:00
c2850f4425 [FIX] test : restoring db use odoo12.0_base by default 2025-04-25 23:25:43 -04:00
12af324e5c [UPD] format script 2025-04-25 23:25:43 -04:00
e2e7a61ad6 [UPD] when using stop-after-init, enable no-http
- in many case, no need http when run with argument stop-after-init,
because we want to execute without gui
2024-12-03 23:10:16 -05:00
327870a175 Format 2024-12-01 04:49:34 -05:00
d91c3c2e95 [IMP] support change odoo and python version
- Makefile show version, switch version and install different version
- erplibre_version with odoo_version, poetry_version and python_version
- support multiple docker version
- support odoo 12, odoo 14, odoo 16
- bullseye, bookworm debian
- update latest version
- script update_env_version to detect actual version and refactor it
- adapt file path to support multiple version
- poetry with verbose by default, ignore python keyring
- python script to generate image db with parallel for all odoo version
- check_addons_exist before generate all image
- support delay to change queue parallel
- fix odoo 12 product configurator
- can show demo website
- swith odoo
- force create addons if missing
- update manifest, because gen config break with wrong manifest
2024-11-02 02:26:02 -04:00
5b103eb457 [UPD] script: format script and add licence technolibre 2024-11-02 02:26:02 -04:00
ba6ddee291 [FIX] script: migrate prod to test, new odoo break with --dev all 2023-07-06 16:39:47 -04:00
2732942633 [UPD] script db_restore: better description help
- show nothing when nothing to do
2023-01-17 21:44:30 -05:00
7ed6939907 [UPD] script: move script git, manifest, database, poetry, install
- refactor script emplacement
- update all reference
2023-01-02 21:54:20 -05:00
cf19262827 [ADD] script: db drop only test 2022-02-10 20:44:33 -05:00
24e5cba22b [UPD] makefile: improve test
- prevent makefile cache to ignore test
- update image_db_create_erplibre_base
- add mariadb migrator test
- add helloworld test
- fix other test
- add isort format
- add show log of test
- add clean to remove temporary file
2022-01-24 14:09:17 -05:00