From 91ba3463543b5085347118d69723b232847602a2 Mon Sep 17 00:00:00 2001 From: Rushabh Mehta Date: Fri, 13 Jul 2012 14:54:40 +0530 Subject: [PATCH 1/4] profile cleanup start and new auth table for better security --- erpnext/patches/patch_list.py | 4 ++++ erpnext/startup/event_handlers.py | 3 ++- erpnext/utilities/page/users/users.py | 8 +++++-- erpnext/website/templates/js/login.js | 1 + public/js/all-app.js | 33 ++++++++++++++------------- public/js/all-web.js | 2 +- public/js/fields.js | 7 +++--- 7 files changed, 35 insertions(+), 23 deletions(-) diff --git a/erpnext/patches/patch_list.py b/erpnext/patches/patch_list.py index 32e1a6ef6e5..2392fd5a652 100644 --- a/erpnext/patches/patch_list.py +++ b/erpnext/patches/patch_list.py @@ -496,4 +496,8 @@ patch_list = [ 'patch_file': 'cms2', 'description': 'cms2 release patches' }, + { 'patch_module': 'patches.july_2012', + 'patch_file': 'auth_table', + 'description': 'create new __Auth table' + }, ] \ No newline at end of file diff --git a/erpnext/startup/event_handlers.py b/erpnext/startup/event_handlers.py index 0c5eae18921..d05b2ec8d33 100644 --- a/erpnext/startup/event_handlers.py +++ b/erpnext/startup/event_handlers.py @@ -40,8 +40,9 @@ def on_login_post_session(login_manager): if webnotes.session['user'] not in ('Guest', 'demo@webnotestech.com'): # create feed from webnotes.utils import nowtime + from webnotes.profile import get_user_fullname home.make_feed('Login', 'Profile', login_manager.user, login_manager.user, - '%s logged in at %s' % (login_manager.user_fullname, nowtime()), + '%s logged in at %s' % (get_user_fullname, nowtime()), login_manager.user=='Administrator' and '#8CA2B3' or '#1B750D') diff --git a/erpnext/utilities/page/users/users.py b/erpnext/utilities/page/users/users.py index 07504a80779..336282bace2 100644 --- a/erpnext/utilities/page/users/users.py +++ b/erpnext/utilities/page/users/users.py @@ -30,9 +30,13 @@ def get(arg=None): @webnotes.whitelist() def get_roles(arg=None): - """return all roles""" + """return all roles except standard""" + return _get_roles(webnotes.form_dict['uid']) + +def _get_roles(user): + """return all roles except standard""" return [r[0] for r in webnotes.conn.sql("""select name from tabRole - where name not in ('Administrator', 'Guest', 'All') order by name""")] + where name not in ('Administrator', 'Guest', 'All') order by name""", user)] @webnotes.whitelist() def get_user_roles(arg=None): diff --git a/erpnext/website/templates/js/login.js b/erpnext/website/templates/js/login.js index 29e49226fcc..4ca18c94527 100644 --- a/erpnext/website/templates/js/login.js +++ b/erpnext/website/templates/js/login.js @@ -59,6 +59,7 @@ erpnext.login.doLogin = function(){ args['remember_me'] = 1; $('#login_btn').set_working(); + $('#login_message').empty(); $c("login", args, erpnext.login.onLoginReply); diff --git a/public/js/all-app.js b/public/js/all-app.js index ef3b4e38e4d..ee120300fd7 100644 --- a/public/js/all-app.js +++ b/public/js/all-app.js @@ -678,7 +678,8 @@ this.set_input(_f.get_value(this.doctype,this.docname,this.df.fieldname));this.r Field.prototype.refresh_label_icon=function(){if(this.df.reqd){if(this.get_value&&is_null(this.get_value())){if(this.label_icon)$ds(this.label_icon);$(this.txt?this.txt:this.input).addClass('field-to-update')}else{if(this.label_icon)$dh(this.label_icon);$(this.txt?this.txt:this.input).removeClass('field-to-update')}}} Field.prototype.set=function(val){if(this.not_in_form) return;if((!this.docname)&&this.grid){this.docname=this.grid.add_newrow();} -var set_val=val;if(this.validate)set_val=this.validate(val);_f.set_value(this.doctype,this.docname,this.df.fieldname,set_val);this.value=val;} +if(this.validate) +val=this.validate(val);cur_frm.set_value_in_locals(this.doctype,this.docname,this.df.fieldname,val);this.value=val;} Field.prototype.set_input=function(val){this.value=val;if(this.input&&this.input.set_input){if(val==null)this.input.set_input('');else this.input.set_input(val);} var disp_val=val;if(val==null)disp_val='';this.set_disp(disp_val);} Field.prototype.run_trigger=function(){this.refresh_label_icon();if(this.df.reqd&&this.get_value&&!is_null(this.get_value())&&this.set_as_error) @@ -713,9 +714,9 @@ return v;}else{return v;}} DataField.prototype.onrefresh=function(){if(this.input&&this.df.colour){var col='#'+this.df.colour.split(':')[1];$bg(this.input,col);}} function ReadOnlyField(){} ReadOnlyField.prototype=new Field();function HTMLField(){} -HTMLField.prototype=new Field();HTMLField.prototype.with_label=0;HTMLField.prototype.set_disp=function(val){this.disp_area.innerHTML=val;} +HTMLField.prototype=new Field();HTMLField.prototype.with_label=0;HTMLField.prototype.set_disp=function(val){if(this.disp_area)this.disp_area.innerHTML=val;} HTMLField.prototype.set_input=function(val){if(val)this.set_disp(val);} -HTMLField.prototype.onrefresh=function(){this.set_disp(this.df.options?this.df.options:'');} +HTMLField.prototype.onrefresh=function(){if(this.df.options)this.set_disp(this.df.options);} var datepicker_active=0;function DateField(){}DateField.prototype=new Field();DateField.prototype.make_input=function(){var me=this;this.user_fmt=wn.control_panel.date_format;if(!this.user_fmt)this.user_fmt='dd-mm-yy';this.input=$a(this.input_area,'input');$(this.input).datepicker({dateFormat:me.user_fmt.replace('yyyy','yy'),altFormat:'yy-mm-dd',changeYear:true,beforeShow:function(input,inst){datepicker_active=1},onClose:function(dateText,inst){datepicker_active=0;if(_f.cur_grid_cell) _f.cur_grid_cell.grid.cell_deselect();}});var me=this;me.input.onchange=function(){if(this.value==null)this.value='';if(!this.not_in_form) me.set(dateutil.user_to_str(me.input.value));me.run_trigger();} @@ -1359,7 +1360,7 @@ var getchildren=LocalDB.getchildren;var get_field=Meta.get_field;var createLocal /* * lib/js/legacy/model/doclist.js */ -function compress_doclist(list){var kl={};var vl=[];var flx={};for(var i=0;i Date: Fri, 13 Jul 2012 15:07:07 +0530 Subject: [PATCH 2/4] added auth_table patch file: --- erpnext/patches/july_2012/auth_table.py | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 erpnext/patches/july_2012/auth_table.py diff --git a/erpnext/patches/july_2012/auth_table.py b/erpnext/patches/july_2012/auth_table.py new file mode 100644 index 00000000000..db087414415 --- /dev/null +++ b/erpnext/patches/july_2012/auth_table.py @@ -0,0 +1,12 @@ +import webnotes +def execute(): + webnotes.conn.commit() + + from webnotes.install_lib.install import Installer + Installer(None, None).create_auth_table() + + webnotes.conn.begin() + + for user, password in webnotes.conn.sql("""select name, password from tabProfile"""): + webnotes.conn.sql("""insert into __Auth (user, `password`) values (%s, %s)""", + (user, password)) From 9ec8024db7ff1632a6b2ec9f9cfa8efb08872214 Mon Sep 17 00:00:00 2001 From: Anand Doshi Date: Fri, 13 Jul 2012 16:46:12 +0530 Subject: [PATCH 3/4] show order type icon in sales order list view --- .../selling/doctype/sales_order/listview.js | 28 ++- public/css/all-app.css | 27 ++- public/css/all-web.css | 22 ++- public/js/all-app.js | 165 ++++++++---------- public/js/all-web.js | 19 +- public/js/fields.js | 9 +- public/js/report-legacy.js | 2 +- 7 files changed, 152 insertions(+), 120 deletions(-) diff --git a/erpnext/selling/doctype/sales_order/listview.js b/erpnext/selling/doctype/sales_order/listview.js index cbe35daae1d..3fa63a5d7f8 100644 --- a/erpnext/selling/doctype/sales_order/listview.js +++ b/erpnext/selling/doctype/sales_order/listview.js @@ -3,21 +3,23 @@ wn.doclistviews['Sales Order'] = wn.views.ListView.extend({ init: function(d) { this._super(d) this.fields = this.fields.concat([ - "`tabSales Order`.customer_name", + "`tabSales Order`.customer_name", + "`tabSales Order`.status", + "`tabSales Order`.order_type", "ifnull(`tabSales Order`.per_delivered,0) as per_delivered", "ifnull(`tabSales Order`.per_billed,0) as per_billed", "`tabSales Order`.currency", "ifnull(`tabSales Order`.grand_total_export,0) as grand_total_export" ]); - this.stats = this.stats.concat(['status', 'company']); + this.stats = this.stats.concat(['status', 'order_type', 'company']); }, columns: [ {width: '3%', content: 'check'}, - {width: '5%', content:'avatar'}, - {width: '3%', content:'docstatus'}, - {width: '15%', content:'name'}, - {width: '32%', content:'customer_name+tags', css: {color:'#222'}}, + {width: '5%', content: 'avatar'}, + {width: '3%', content: 'docstatus'}, + {width: '15%', content: 'name'}, + {width: '29%', content: 'customer_name+tags', css: {color:'#222'}}, { width: '18%', content: function(parent, data) { @@ -25,7 +27,19 @@ wn.doclistviews['Sales Order'] = wn.views.ListView.extend({ }, css: {'text-align':'right'} }, - {width: '8%', content: 'per_delivered', type:'bar-graph', label:'Delivered'}, + { + width: '11%', + content: function(parent, data, me) { + var order_type = data.order_type.toLowerCase(); + + if (order_type === 'sales') { + me.render_icon(parent, 'icon-tag', data.order_type); + me.render_bar_graph(parent, data, 'per_billed', 'Delivered'); + } else if (order_type === 'maintenance') { + me.render_icon(parent, 'icon-wrench', data.order_type); + } + }, + }, {width: '8%', content: 'per_billed', type:'bar-graph', label:'Billed'}, {width: '12%', content:'modified', css: {'text-align': 'right', 'color':'#777'}} ] diff --git a/public/css/all-app.css b/public/css/all-app.css index 84ac2758c38..ecdbe652f93 100644 --- a/public/css/all-app.css +++ b/public/css/all-app.css @@ -2314,6 +2314,11 @@ div.form-title { border-bottom: 1px solid #eee; } +.appframe-titlebar .label { + vertical-align: middle; + margin-right: 7px; +} + div.form-section-head { margin: 11px -15px 3px -15px; border-top: 1px solid #ccc; @@ -3214,6 +3219,8 @@ div.stat-item { height: 18px; border: 1px solid #aaa; border-radius: 9px; + -webkit-border-radius: 9px; + -moz-border-radius: 9px; overflow: hidden; } @@ -3222,6 +3229,10 @@ div.stat-bar { left: 0px; height: 100%; z-index: 0; + /* So that this div is also curved like the enclosing one */ + border-radius: 9px; + -webkit-border-radius: 9px; + -moz-border-radius: 9px; background: #e0ff84; /* Old browsers */ background: -moz-linear-gradient(top, #e0ff84 0%, #a4e567 100%); /* FF3.6+ */ @@ -3237,12 +3248,8 @@ div.stat-bar { * lib/css/ui/views.css */ -.breadcrumbs { - color: #000000; -} - -.breadcrumbs a { - color: #000000; +.breadcrumb-area, .breadcrumb-area span { + vertical-align: middle; } div.appframe-titlebar { @@ -3260,6 +3267,14 @@ div.appframe-titlebar { border-radius: 5px 5px 0px 0px; -webkit-border-radius: 5px 5px 0px 0px; -moz-border-radius: 5px 5px 0px 0px; + + text-shadow: 0px 1px 1px #fff; + color: #555; +} + +span.appframe-title { + font-size: 160%; + font-weight: bold; } div.appframe-toolbar { diff --git a/public/css/all-web.css b/public/css/all-web.css index ec2fbcd333f..332471b01b8 100644 --- a/public/css/all-web.css +++ b/public/css/all-web.css @@ -2470,6 +2470,8 @@ div.stat-item { height: 18px; border: 1px solid #aaa; border-radius: 9px; + -webkit-border-radius: 9px; + -moz-border-radius: 9px; overflow: hidden; } @@ -2478,6 +2480,10 @@ div.stat-bar { left: 0px; height: 100%; z-index: 0; + /* So that this div is also curved like the enclosing one */ + border-radius: 9px; + -webkit-border-radius: 9px; + -moz-border-radius: 9px; background: #e0ff84; /* Old browsers */ background: -moz-linear-gradient(top, #e0ff84 0%, #a4e567 100%); /* FF3.6+ */ @@ -2493,12 +2499,8 @@ div.stat-bar { * lib/css/ui/views.css */ -.breadcrumbs { - color: #000000; -} - -.breadcrumbs a { - color: #000000; +.breadcrumb-area, .breadcrumb-area span { + vertical-align: middle; } div.appframe-titlebar { @@ -2516,6 +2518,14 @@ div.appframe-titlebar { border-radius: 5px 5px 0px 0px; -webkit-border-radius: 5px 5px 0px 0px; -moz-border-radius: 5px 5px 0px 0px; + + text-shadow: 0px 1px 1px #fff; + color: #555; +} + +span.appframe-title { + font-size: 160%; + font-weight: bold; } div.appframe-toolbar { diff --git a/public/js/all-app.js b/public/js/all-app.js index a9d1967b753..e8c3603fbb2 100644 --- a/public/js/all-app.js +++ b/public/js/all-app.js @@ -249,7 +249,7 @@ throw new SyntaxError('JSON.parse');};}}()); * lib/js/wn/router.js */ wn.re_route={} -wn.route=function(){if(wn.re_route[window.location.hash]){window.location.hash=wn.re_route[window.location.hash];} +wn.route=function(){if(wn.re_route[window.location.hash]){var re_route_val=wn.get_route_str(wn.re_route[window.location.hash]);var cur_route_val=wn.get_route_str(wn._cur_route);if(decodeURIComponent(re_route_val)===decodeURIComponent(cur_route_val)){window.history.back();return;}else{window.location.hash=wn.re_route[window.location.hash];}} wn._cur_route=window.location.hash;route=wn.get_route();switch(route[0]){case"List":wn.views.doclistview.show(route[1]);break;case"Form":if(route.length>3){route[2]=route.splice(2).join('/');} wn.views.formview.show(route[1],route[2]);break;case"Report":wn.views.reportview.show(route[1],route[2]);break;case"Report2":wn.views.reportview2.show();break;default:wn.views.pageview.show(route[0]);}} wn.get_route=function(route){return $.map(wn.get_route_str(route).split('/'),function(r){return decodeURIComponent(r);});} @@ -349,7 +349,8 @@ df.original_type=df.fieldtype;df.description='';df.reqd=0;if(fieldtype){df.field if(df.fieldtype=='Check'){df.fieldtype='Select';df.options='No\nYes';}else if(['Text','Text Editor','Code','Link'].indexOf(df.fieldtype)!=-1){df.fieldtype='Data';}},set_default_condition:function(df,fieldtype){if(!fieldtype){if(df.fieldtype=='Data'){this.$w.find('.condition').val('like');}else{this.$w.find('.condition').val('=');}}},get_value:function(){var me=this;var val=me.field.get_value();var cond=me.$w.find('.condition').val();if(me.field.df.original_type=='Check'){val=(val=='Yes'?1:0);} if(cond=='like'){val=val+'%';} return[me.fieldselect.$select.find('option:selected').attr('table'),me.field.df.fieldname,me.$w.find('.condition').val(),cstr(val)];}});wn.ui.FieldSelect=Class.extend({init:function(parent,doctype,filter_fields,with_blank){this.doctype=doctype;this.fields_by_name={};this.with_blank=with_blank;this.$select=$('').appendTo(parent);if(filter_fields){for(var i in filter_fields) -this.add_field_option(this.filter_fields[i])}else{this.build_options();}},build_options:function(){var me=this;me.table_fields=[];var std_filters=[{fieldname:'name',fieldtype:'Data',label:'ID',parent:me.doctype},{fieldname:'modified',fieldtype:'Date',label:'Last Modified',parent:me.doctype},{fieldname:'owner',fieldtype:'Data',label:'Created By',parent:me.doctype},{fieldname:'creation',fieldtype:'Date',label:'Created On',parent:me.doctype},{fieldname:'_user_tags',fieldtype:'Data',label:'Tags',parent:me.doctype}];if(this.with_blank){this.$select.append($('