diff --git a/report_qweb_encrypt/README.rst b/report_qweb_encrypt/README.rst new file mode 100644 index 0000000000..626cb0723a --- /dev/null +++ b/report_qweb_encrypt/README.rst @@ -0,0 +1,100 @@ +.. image:: https://odoo-community.org/readme-banner-image + :target: https://odoo-community.org/get-involved?utm_source=readme + :alt: Odoo Community Association + +=================== +Report Qweb Encrypt +=================== + +.. + !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! + !! This file is generated by oca-gen-addon-readme !! + !! changes will be overwritten. !! + !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! + !! source digest: sha256:0b14a10714ea2e18453d7f01d8a6803ea6ebbc0a1cd46892aa0a05e1aeef5fbc + !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! + +.. |badge1| image:: https://img.shields.io/badge/maturity-Beta-yellow.png + :target: https://odoo-community.org/page/development-status + :alt: Beta +.. |badge2| image:: https://img.shields.io/badge/license-AGPL--3-blue.png + :target: http://www.gnu.org/licenses/agpl-3.0-standalone.html + :alt: License: AGPL-3 +.. |badge3| image:: https://img.shields.io/badge/github-OCA%2Freporting--engine-lightgray.png?logo=github + :target: https://github.com/OCA/reporting-engine/tree/19.0/report_qweb_encrypt + :alt: OCA/reporting-engine +.. |badge4| image:: https://img.shields.io/badge/weblate-Translate%20me-F47D42.png + :target: https://translation.odoo-community.org/projects/reporting-engine-19-0/reporting-engine-19-0-report_qweb_encrypt + :alt: Translate me on Weblate +.. |badge5| image:: https://img.shields.io/badge/runboat-Try%20me-875A7B.png + :target: https://runboat.odoo-community.org/builds?repo=OCA/reporting-engine&target_branch=19.0 + :alt: Try me on Runboat + +|badge1| |badge2| |badge3| |badge4| |badge5| + +This module allow you to encrypt PDF with a password seting option, + +- Manually keyin password (only applicable for record print action) +- Auto generated password based on object data (python) + +**Table of contents** + +.. contents:: + :local: + +Usage +===== + +To make a report encryptable mark the field Encryption in the report +record. + +Bug Tracker +=========== + +Bugs are tracked on `GitHub Issues `_. +In case of trouble, please check there if your issue has already been reported. +If you spotted it first, help us to smash it by providing a detailed and welcomed +`feedback `_. + +Do not contact contributors directly about support or help with technical issues. + +Credits +======= + +Authors +------- + +* Creu Blanca +* Ecosoft + +Contributors +------------ + +- Enric Tobella +- Jaime Arroyo +- Kitti U. + +Maintainers +----------- + +This module is maintained by the OCA. + +.. image:: https://odoo-community.org/logo.png + :alt: Odoo Community Association + :target: https://odoo-community.org + +OCA, or the Odoo Community Association, is a nonprofit organization whose +mission is to support the collaborative development of Odoo features and +promote its widespread use. + +.. |maintainer-kittiu| image:: https://github.com/kittiu.png?size=40px + :target: https://github.com/kittiu + :alt: kittiu + +Current `maintainer `__: + +|maintainer-kittiu| + +This module is part of the `OCA/reporting-engine `_ project on GitHub. + +You are welcome to contribute. To learn how please visit https://odoo-community.org/page/Contribute. diff --git a/report_qweb_encrypt/__init__.py b/report_qweb_encrypt/__init__.py new file mode 100644 index 0000000000..91c5580fed --- /dev/null +++ b/report_qweb_encrypt/__init__.py @@ -0,0 +1,2 @@ +from . import controllers +from . import models diff --git a/report_qweb_encrypt/__manifest__.py b/report_qweb_encrypt/__manifest__.py new file mode 100644 index 0000000000..36e760df33 --- /dev/null +++ b/report_qweb_encrypt/__manifest__.py @@ -0,0 +1,26 @@ +# Copyright 2020 Creu Blanca +# Copyright 2020 Ecosoft Co., Ltd. +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl). + +{ + "name": "Report Qweb Encrypt", + "summary": "Allow to encrypt qweb pdfs", + "version": "19.0.1.0.0", + "license": "AGPL-3", + "author": "Creu Blanca,Ecosoft,Odoo Community Association (OCA)", + "website": "https://github.com/OCA/reporting-engine", + "depends": [ + "web", + ], + "data": [ + "views/ir_actions_report.xml", + ], + "assets": { + "web.assets_backend": [ + "report_qweb_encrypt/static/src/report/action_manager_report.esm.js", + "report_qweb_encrypt/static/src/report/encrypt_dialog.xml", + ], + }, + "installable": True, + "maintainers": ["kittiu"], +} diff --git a/report_qweb_encrypt/controllers/__init__.py b/report_qweb_encrypt/controllers/__init__.py new file mode 100644 index 0000000000..12a7e529b6 --- /dev/null +++ b/report_qweb_encrypt/controllers/__init__.py @@ -0,0 +1 @@ +from . import main diff --git a/report_qweb_encrypt/controllers/main.py b/report_qweb_encrypt/controllers/main.py new file mode 100644 index 0000000000..962d33165d --- /dev/null +++ b/report_qweb_encrypt/controllers/main.py @@ -0,0 +1,39 @@ +# Copyright 2020 Creu Blanca +# Copyright 2020 Ecosoft Co., Ltd. +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl). +import json + +from werkzeug.urls import url_decode + +from odoo.http import request, route + +from odoo.addons.web.controllers.report import ReportController + + +class ReportControllerEncrypt(ReportController): + @route() + def report_download(self, data, context=None, token=None, readonly=True): + result = super().report_download( + data, context=context, token=token, readonly=readonly + ) + # When report is downloaded from print action, this function is called, + # but this function cannot pass context (manually entered password) to + # report.render_qweb_pdf(), encrypton for manual password is done here. + if result.headers.get("Content-Type") != "application/pdf": + return result + request_content = json.loads(data) + url, ttype = request_content[0], request_content[1] + if ttype != "qweb-pdf" or "?" not in url: + return result + args = dict( + url_decode(url.split("?", 1)[1]) + ) # decoding the args represented in JSON + data_context = json.loads(args.get("context", "{}")) + encrypt_password = data_context.get("encrypt_password") + if not encrypt_password: + return result + encrypted_data = request.env["ir.actions.report"]._encrypt_pdf( + result.get_data(), encrypt_password + ) + result.set_data(encrypted_data) + return result diff --git a/report_qweb_encrypt/i18n/es.po b/report_qweb_encrypt/i18n/es.po new file mode 100644 index 0000000000..79431f7665 --- /dev/null +++ b/report_qweb_encrypt/i18n/es.po @@ -0,0 +1,99 @@ +# Translation of Odoo Server. +# This file contains the translation of the following modules: +# * report_qweb_encrypt +# +msgid "" +msgstr "" +"Project-Id-Version: Odoo Server 14.0\n" +"Report-Msgid-Bugs-To: \n" +"PO-Revision-Date: 2023-07-13 20:08+0000\n" +"Last-Translator: Ivorra78 \n" +"Language-Team: none\n" +"Language: es\n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: \n" +"Plural-Forms: nplurals=2; plural=n != 1;\n" +"X-Generator: Weblate 4.17\n" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,help:report_qweb_encrypt.field_ir_actions_report__encrypt +#: model:ir.model.fields,help:report_qweb_encrypt.field_report_pdf_form__encrypt +msgid "" +"* Manual Input Password: allow user to key in password on the fly. This " +"option available only on document print action.\n" +"* Auto Generated Password: system will auto encrypt password when PDF " +"created, based on provided python syntax." +msgstr "" +"* Contraseña de entrada manual: permite al usuario introducir la contraseña " +"sobre la marcha. Esta opción sólo está disponible en la acción de impresión " +"de documentos.\n" +"* Contraseña generada automáticamente: el sistema cifrará automáticamente la " +"contraseña cuando se cree el PDF, basándose en la sintaxis python " +"proporcionada." + +#. module: report_qweb_encrypt +#: model:ir.model.fields.selection,name:report_qweb_encrypt.selection__ir_actions_report__encrypt__auto +msgid "Auto Generated Password" +msgstr "Contraseña generada automáticamente" + +#. module: report_qweb_encrypt +#. odoo-javascript +#: code:addons/report_qweb_encrypt/static/src/report/encrypt_dialog.xml:0 +msgid "Cancel" +msgstr "Cancelar" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_ir_actions_report__encrypt_password +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_report_pdf_form__encrypt_password +msgid "Encrypt Password" +msgstr "Encriptar contraseña" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_ir_actions_report__encrypt +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_report_pdf_form__encrypt +msgid "Encryption" +msgstr "Encriptación" + +#. module: report_qweb_encrypt +#. odoo-javascript +#: code:addons/report_qweb_encrypt/static/src/report/encrypt_dialog.xml:0 +msgid "Enter password" +msgstr "" + +#. module: report_qweb_encrypt +#: model:ir.model.fields.selection,name:report_qweb_encrypt.selection__ir_actions_report__encrypt__manual +msgid "Manual Input Password" +msgstr "Contraseña de entrada manual" + +#. module: report_qweb_encrypt +#. odoo-javascript +#: code:addons/report_qweb_encrypt/static/src/report/encrypt_dialog.xml:0 +msgid "Ok" +msgstr "Aceptar" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,help:report_qweb_encrypt.field_ir_actions_report__encrypt_password +#: model:ir.model.fields,help:report_qweb_encrypt.field_report_pdf_form__encrypt_password +msgid "Python code syntax to gnerate password." +msgstr "Sintaxis del código Python para generar la contraseña." + +#. module: report_qweb_encrypt +#. odoo-python +#: code:addons/report_qweb_encrypt/models/ir_actions_report.py:0 +msgid "" +"Python code used for encryption password is invalid.\n" +"%s" +msgstr "" +"El código Python utilizado para cifrar la contraseña no es válido.\n" +"%s" + +#. module: report_qweb_encrypt +#: model:ir.model,name:report_qweb_encrypt.model_ir_actions_report +msgid "Report Action" +msgstr "Informar Acción" + +#. module: report_qweb_encrypt +#: model_terms:ir.ui.view,arch_db:report_qweb_encrypt.ir_actions_report_form_view +msgid "python syntax, i.e., (object.default_code or 'secretcode')" +msgstr "sintaxis python, es decir, (object.default_code o 'secretcode')" diff --git a/report_qweb_encrypt/i18n/it.po b/report_qweb_encrypt/i18n/it.po new file mode 100644 index 0000000000..651dd924ef --- /dev/null +++ b/report_qweb_encrypt/i18n/it.po @@ -0,0 +1,97 @@ +# Translation of Odoo Server. +# This file contains the translation of the following modules: +# * report_qweb_encrypt +# +msgid "" +msgstr "" +"Project-Id-Version: Odoo Server 16.0\n" +"Report-Msgid-Bugs-To: \n" +"PO-Revision-Date: 2025-12-17 10:42+0000\n" +"Last-Translator: mymage \n" +"Language-Team: none\n" +"Language: it\n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: \n" +"Plural-Forms: nplurals=2; plural=n != 1;\n" +"X-Generator: Weblate 5.10.4\n" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,help:report_qweb_encrypt.field_ir_actions_report__encrypt +#: model:ir.model.fields,help:report_qweb_encrypt.field_report_pdf_form__encrypt +msgid "" +"* Manual Input Password: allow user to key in password on the fly. This " +"option available only on document print action.\n" +"* Auto Generated Password: system will auto encrypt password when PDF " +"created, based on provided python syntax." +msgstr "" +"* Inserimento manuale password: consente all'utente di inserire la password " +"al volo. Questa opzione è disponibile solo nell'azione stampa documento.\n" +"* Password auto generata: il sistema cripterà automaticamente la password " +"quando viene creato il PDF, in base alla sintassi Pythn fornita." + +#. module: report_qweb_encrypt +#: model:ir.model.fields.selection,name:report_qweb_encrypt.selection__ir_actions_report__encrypt__auto +msgid "Auto Generated Password" +msgstr "Password generata automaticamente" + +#. module: report_qweb_encrypt +#. odoo-javascript +#: code:addons/report_qweb_encrypt/static/src/report/encrypt_dialog.xml:0 +msgid "Cancel" +msgstr "Annulla" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_ir_actions_report__encrypt_password +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_report_pdf_form__encrypt_password +msgid "Encrypt Password" +msgstr "Cripta password" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_ir_actions_report__encrypt +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_report_pdf_form__encrypt +msgid "Encryption" +msgstr "Criptazione" + +#. module: report_qweb_encrypt +#. odoo-javascript +#: code:addons/report_qweb_encrypt/static/src/report/encrypt_dialog.xml:0 +msgid "Enter password" +msgstr "Inserire password" + +#. module: report_qweb_encrypt +#: model:ir.model.fields.selection,name:report_qweb_encrypt.selection__ir_actions_report__encrypt__manual +msgid "Manual Input Password" +msgstr "Password inserita manualmente" + +#. module: report_qweb_encrypt +#. odoo-javascript +#: code:addons/report_qweb_encrypt/static/src/report/encrypt_dialog.xml:0 +msgid "Ok" +msgstr "Ok" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,help:report_qweb_encrypt.field_ir_actions_report__encrypt_password +#: model:ir.model.fields,help:report_qweb_encrypt.field_report_pdf_form__encrypt_password +msgid "Python code syntax to gnerate password." +msgstr "Sintassi codice Python per generazione password." + +#. module: report_qweb_encrypt +#. odoo-python +#: code:addons/report_qweb_encrypt/models/ir_actions_report.py:0 +msgid "" +"Python code used for encryption password is invalid.\n" +"%s" +msgstr "" +"Il codice Python usato per la criptazione password non è valido.\n" +"%s" + +#. module: report_qweb_encrypt +#: model:ir.model,name:report_qweb_encrypt.model_ir_actions_report +msgid "Report Action" +msgstr "Azione resoconto" + +#. module: report_qweb_encrypt +#: model_terms:ir.ui.view,arch_db:report_qweb_encrypt.ir_actions_report_form_view +msgid "python syntax, i.e., (object.default_code or 'secretcode')" +msgstr "Sintassi Python, es., (object.default_code o 'secretcode')" diff --git a/report_qweb_encrypt/i18n/report_qweb_encrypt.pot b/report_qweb_encrypt/i18n/report_qweb_encrypt.pot new file mode 100644 index 0000000000..fe42382a3f --- /dev/null +++ b/report_qweb_encrypt/i18n/report_qweb_encrypt.pot @@ -0,0 +1,86 @@ +# Translation of Odoo Server. +# This file contains the translation of the following modules: +# * report_qweb_encrypt +# +msgid "" +msgstr "" +"Project-Id-Version: Odoo Server 18.0\n" +"Report-Msgid-Bugs-To: \n" +"Last-Translator: \n" +"Language-Team: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: \n" +"Plural-Forms: \n" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,help:report_qweb_encrypt.field_ir_actions_report__encrypt +#: model:ir.model.fields,help:report_qweb_encrypt.field_report_pdf_form__encrypt +msgid "" +"* Manual Input Password: allow user to key in password on the fly. This option available only on document print action.\n" +"* Auto Generated Password: system will auto encrypt password when PDF created, based on provided python syntax." +msgstr "" + +#. module: report_qweb_encrypt +#: model:ir.model.fields.selection,name:report_qweb_encrypt.selection__ir_actions_report__encrypt__auto +msgid "Auto Generated Password" +msgstr "" + +#. module: report_qweb_encrypt +#. odoo-javascript +#: code:addons/report_qweb_encrypt/static/src/report/encrypt_dialog.xml:0 +msgid "Cancel" +msgstr "" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_ir_actions_report__encrypt_password +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_report_pdf_form__encrypt_password +msgid "Encrypt Password" +msgstr "" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_ir_actions_report__encrypt +#: model:ir.model.fields,field_description:report_qweb_encrypt.field_report_pdf_form__encrypt +msgid "Encryption" +msgstr "" + +#. module: report_qweb_encrypt +#. odoo-javascript +#: code:addons/report_qweb_encrypt/static/src/report/encrypt_dialog.xml:0 +msgid "Enter password" +msgstr "" + +#. module: report_qweb_encrypt +#: model:ir.model.fields.selection,name:report_qweb_encrypt.selection__ir_actions_report__encrypt__manual +msgid "Manual Input Password" +msgstr "" + +#. module: report_qweb_encrypt +#. odoo-javascript +#: code:addons/report_qweb_encrypt/static/src/report/encrypt_dialog.xml:0 +msgid "Ok" +msgstr "" + +#. module: report_qweb_encrypt +#: model:ir.model.fields,help:report_qweb_encrypt.field_ir_actions_report__encrypt_password +#: model:ir.model.fields,help:report_qweb_encrypt.field_report_pdf_form__encrypt_password +msgid "Python code syntax to gnerate password." +msgstr "" + +#. module: report_qweb_encrypt +#. odoo-python +#: code:addons/report_qweb_encrypt/models/ir_actions_report.py:0 +msgid "" +"Python code used for encryption password is invalid.\n" +"%s" +msgstr "" + +#. module: report_qweb_encrypt +#: model:ir.model,name:report_qweb_encrypt.model_ir_actions_report +msgid "Report Action" +msgstr "" + +#. module: report_qweb_encrypt +#: model_terms:ir.ui.view,arch_db:report_qweb_encrypt.ir_actions_report_form_view +msgid "python syntax, i.e., (object.default_code or 'secretcode')" +msgstr "" diff --git a/report_qweb_encrypt/models/__init__.py b/report_qweb_encrypt/models/__init__.py new file mode 100644 index 0000000000..a248cf2162 --- /dev/null +++ b/report_qweb_encrypt/models/__init__.py @@ -0,0 +1 @@ +from . import ir_actions_report diff --git a/report_qweb_encrypt/models/ir_actions_report.py b/report_qweb_encrypt/models/ir_actions_report.py new file mode 100644 index 0000000000..8114c7f0b8 --- /dev/null +++ b/report_qweb_encrypt/models/ir_actions_report.py @@ -0,0 +1,82 @@ +# Copyright 2020 Creu Blanca +# Copyright 2020 Ecosoft Co., Ltd. +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl). +from io import BytesIO + +from odoo import fields, models +from odoo.exceptions import ValidationError +from odoo.tools.pdf import PdfReader, PdfWriter +from odoo.tools.safe_eval import safe_eval + + +class IrActionsReport(models.Model): + _inherit = "ir.actions.report" + + encrypt = fields.Selection( + selection=[ + ("manual", "Manual Input Password"), + ("auto", "Auto Generated Password"), + ], + string="Encryption", + help="* Manual Input Password: allow user to key in password on the fly. " + "This option available only on document print action.\n" + "* Auto Generated Password: system will auto encrypt password when PDF " + "created, based on provided python syntax.", + ) + encrypt_password = fields.Char( + help="Python code syntax to gnerate password.", + ) + + def _render_qweb_pdf(self, report_ref, res_ids=None, data=None): + document, ttype = super()._render_qweb_pdf( + report_ref, res_ids=res_ids, data=data + ) + report_sudo = self._get_report(report_ref) + if res_ids: + encrypt_password = self.env.context.get("encrypt_password") + report = self._get_report_from_name(report_sudo.report_name).with_context( + encrypt_password=encrypt_password + ) + password = report._get_pdf_password(res_ids[:1]) + document = self._encrypt_pdf(document, password) + return document, ttype + + def _get_pdf_password(self, res_ids): + encrypt_password = False + if self.encrypt == "manual": + # If use document print action, report_download() is called, + # but that can't pass context (encrypt_password) here. + # As such, file will be encrypted by report_download() again. + # -- + # Following is used just in case when context is passed in. + encrypt_password = self.env.context.get("encrypt_password", False) + elif self.encrypt == "auto" and self.encrypt_password: + # access the report details with sudo() but evaluation context as + # sudo(False) + records = self.env[self.sudo().model].browse(res_ids).exists() + try: + encrypt_password = safe_eval(self.encrypt_password, {"object": records}) + except Exception as e: + raise ValidationError( + self.env._( + "Python code used for encryption password is invalid.\n%s", + self.encrypt_password, + ) + ) from e + return encrypt_password + + @staticmethod + def _encrypt_pdf(data, password): + if not password: + return data + output_pdf = PdfWriter() + in_buff = BytesIO(data) + pdf = PdfReader(in_buff) + output_pdf.appendPagesFromReader(pdf) + output_pdf.encrypt(password) + buff = BytesIO() + output_pdf.write(buff) + return buff.getvalue() + + def _get_readable_fields(self): + return super()._get_readable_fields() | {"encrypt"} diff --git a/report_qweb_encrypt/pyproject.toml b/report_qweb_encrypt/pyproject.toml new file mode 100644 index 0000000000..4231d0cccb --- /dev/null +++ b/report_qweb_encrypt/pyproject.toml @@ -0,0 +1,3 @@ +[build-system] +requires = ["whool"] +build-backend = "whool.buildapi" diff --git a/report_qweb_encrypt/readme/CONTRIBUTORS.md b/report_qweb_encrypt/readme/CONTRIBUTORS.md new file mode 100644 index 0000000000..bb221535fb --- /dev/null +++ b/report_qweb_encrypt/readme/CONTRIBUTORS.md @@ -0,0 +1,3 @@ +- Enric Tobella \ +- Jaime Arroyo \ +- Kitti U. \ diff --git a/report_qweb_encrypt/readme/DESCRIPTION.md b/report_qweb_encrypt/readme/DESCRIPTION.md new file mode 100644 index 0000000000..7db0f8f2e9 --- /dev/null +++ b/report_qweb_encrypt/readme/DESCRIPTION.md @@ -0,0 +1,4 @@ +This module allow you to encrypt PDF with a password seting option, + +- Manually keyin password (only applicable for record print action) +- Auto generated password based on object data (python) diff --git a/report_qweb_encrypt/readme/USAGE.md b/report_qweb_encrypt/readme/USAGE.md new file mode 100644 index 0000000000..053d5159a9 --- /dev/null +++ b/report_qweb_encrypt/readme/USAGE.md @@ -0,0 +1,2 @@ +To make a report encryptable mark the field Encryption in the report +record. diff --git a/report_qweb_encrypt/static/description/icon.png b/report_qweb_encrypt/static/description/icon.png new file mode 100644 index 0000000000..3a0328b516 Binary files /dev/null and b/report_qweb_encrypt/static/description/icon.png differ diff --git a/report_qweb_encrypt/static/description/index.html b/report_qweb_encrypt/static/description/index.html new file mode 100644 index 0000000000..fd9c1142bb --- /dev/null +++ b/report_qweb_encrypt/static/description/index.html @@ -0,0 +1,444 @@ + + + + + +README.rst + + + +
+ + + +Odoo Community Association + +
+

Report Qweb Encrypt

+ +

Beta License: AGPL-3 OCA/reporting-engine Translate me on Weblate Try me on Runboat

+

This module allow you to encrypt PDF with a password seting option,

+
    +
  • Manually keyin password (only applicable for record print action)
  • +
  • Auto generated password based on object data (python)
  • +
+

Table of contents

+ +
+

Usage

+

To make a report encryptable mark the field Encryption in the report +record.

+
+
+

Bug Tracker

+

Bugs are tracked on GitHub Issues. +In case of trouble, please check there if your issue has already been reported. +If you spotted it first, help us to smash it by providing a detailed and welcomed +feedback.

+

Do not contact contributors directly about support or help with technical issues.

+
+
+

Credits

+
+

Authors

+
    +
  • Creu Blanca
  • +
  • Ecosoft
  • +
+
+
+

Contributors

+ +
+
+

Maintainers

+

This module is maintained by the OCA.

+ +Odoo Community Association + +

OCA, or the Odoo Community Association, is a nonprofit organization whose +mission is to support the collaborative development of Odoo features and +promote its widespread use.

+

Current maintainer:

+

kittiu

+

This module is part of the OCA/reporting-engine project on GitHub.

+

You are welcome to contribute. To learn how please visit https://odoo-community.org/page/Contribute.

+
+
+
+
+ + diff --git a/report_qweb_encrypt/static/src/report/action_manager_report.esm.js b/report_qweb_encrypt/static/src/report/action_manager_report.esm.js new file mode 100644 index 0000000000..f4b5d9550f --- /dev/null +++ b/report_qweb_encrypt/static/src/report/action_manager_report.esm.js @@ -0,0 +1,84 @@ +import {Dialog} from "@web/core/dialog/dialog"; +import {download} from "@web/core/network/download"; +import {registry} from "@web/core/registry"; +import {useRef} from "@odoo/owl"; +import {user} from "@web/core/user"; + +const {Component} = owl; + +function buildReportUrl(action, type, userContext) { + let url = `/report/${type}/${action.report_name}`; + const actionContext = action.context || {}; + if (action.data && Object.keys(action.data).length) { + // Build a query string with `action.data` (it's the place where reports + // using a wizard to customize the output traditionally put their options) + url += `?options=${encodeURIComponent(JSON.stringify(action.data))}`; + url += `&context=${encodeURIComponent(JSON.stringify(actionContext))}`; + } else { + if (actionContext.active_ids) { + url += `/${actionContext.active_ids.join(",")}`; + } + if (type === "html") { + url += `?context=${encodeURIComponent(JSON.stringify(userContext))}`; + } + } + return url; +} + +async function download_function(action, options, env) { + const type = action.report_type === "qweb-pdf" ? "pdf" : action.report_type; + const userContext = { + ...user.context, + encrypt_password: action.context?.encrypt_password, + }; + const url = buildReportUrl(action, type, userContext); + env.services.ui.block(); + try { + await download({ + url: "/report/download", + data: { + data: JSON.stringify([url, action.report_type]), + context: JSON.stringify(userContext), + }, + }); + } finally { + env.services.ui.unblock(); + } + if (action.close_on_report_download) { + return env.services.action.doAction( + {type: "ir.actions.act_window_close"}, + {onClose: options.onClose} + ); + } + options.onClose?.(); + return true; +} + +class EncryptDialog extends Component { + setup() { + this.passwordRef = useRef("password"); + } + onClick() { + const password = this.passwordRef.el?.value || false; + const action = { + ...this.props.action, + context: { + ...this.props.action.context, + encrypt_password: password, + }, + }; + return download_function(action, this.props.options, this.props.env); + } +} + +EncryptDialog.components = {Dialog}; +EncryptDialog.template = "report_qweb_encrypt.EncryptDialogBody"; + +registry + .category("ir.actions.report handlers") + .add("qweb-pdf-password", async (action, options, env) => { + if (action.encrypt === "manual" && action.report_type === "qweb-pdf") { + return env.services.dialog.add(EncryptDialog, {action, options, env}); + } + return false; + }); diff --git a/report_qweb_encrypt/static/src/report/encrypt_dialog.xml b/report_qweb_encrypt/static/src/report/encrypt_dialog.xml new file mode 100644 index 0000000000..5bc967ea0f --- /dev/null +++ b/report_qweb_encrypt/static/src/report/encrypt_dialog.xml @@ -0,0 +1,21 @@ + + + + + +
+ +
+ + + + +
+
+ +
diff --git a/report_qweb_encrypt/tests/__init__.py b/report_qweb_encrypt/tests/__init__.py new file mode 100644 index 0000000000..a822879c19 --- /dev/null +++ b/report_qweb_encrypt/tests/__init__.py @@ -0,0 +1,2 @@ +from . import test_report_qweb_encrypt +from . import test_report_download diff --git a/report_qweb_encrypt/tests/test_report_download.py b/report_qweb_encrypt/tests/test_report_download.py new file mode 100644 index 0000000000..3664d6526a --- /dev/null +++ b/report_qweb_encrypt/tests/test_report_download.py @@ -0,0 +1,90 @@ +# Copyright 2026 Vauxoo +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl). +import json +from urllib.parse import quote, urlencode + +from odoo.tests.common import tagged + +from odoo.addons.web.tests.test_reports import TestReports + + +@tagged("-at_install", "post_install") +class TestReportQwebEncryptDownload(TestReports): + """Cover the /report/download override. + + It inherits the core TestReports so its report regression tests also run + with this module installed. Core has no test hitting /report/download + itself, so the cases below are new. + """ + + @classmethod + def setUpClass(cls): + super().setUpClass() + cls.encrypt_report = cls.env.ref("web.action_report_internalpreview") + # The controller encrypts on its own, using the password found in the + # url. Keep the model side disabled so each assertion below can only + # be explained by the controller. + cls.encrypt_report.encrypt = False + cls.encrypt_company = cls.env.ref("base.main_company") + + def _report_url(self, context=None): + """Url of the report as action_manager_report.esm.js builds it""" + url = f"/report/pdf/{self.encrypt_report.report_name}/{self.encrypt_company.id}" + if context is not None: + url += "?context=" + quote(json.dumps(context)) + return url + + def _download(self, url): + """Call /report/download the way the web client does + + force_report_rendering is required because _render_qweb_pdf() falls + back to _render_qweb_html() while tests are running, and an html body + cannot be encrypted. + """ + params = { + "data": json.dumps([url, "qweb-pdf"]), + "context": json.dumps({"force_report_rendering": True}), + } + response = self.url_open("/report/download?" + urlencode(params)) + response.raise_for_status() + self.assertEqual(response.headers.get("Content-Type"), "application/pdf") + return response + + def test_download_encrypts_with_password_in_url(self): + """It should encrypt the pdf with the password given in the url""" + self.authenticate("admin", "admin") + response = self._download(self._report_url({"encrypt_password": "secretcode"})) + self.assertIn(b"/Encrypt", response.content) + + def test_download_without_query_string(self): + """It should return the pdf untouched when the url has no context""" + self.authenticate("admin", "admin") + response = self._download(self._report_url()) + self.assertNotIn(b"/Encrypt", response.content) + + def test_download_without_password_in_context(self): + """It should return the pdf untouched when no password is given""" + self.authenticate("admin", "admin") + response = self._download(self._report_url({"lang": "en_US"})) + self.assertNotIn(b"/Encrypt", response.content) + + def test_download_non_pdf_response_untouched(self): + """It should not touch a response that is not a pdf + + report_download() also serves qweb-text reports; the override has to + let anything that is not application/pdf go through untouched. + """ + self.authenticate("admin", "admin") + context = quote(json.dumps({"encrypt_password": "secretcode"})) + url = ( + f"/report/text/{self.encrypt_report.report_name}" + f"/{self.encrypt_company.id}?context={context}" + ) + params = { + "data": json.dumps([url, "qweb-text"]), + "context": json.dumps({"force_report_rendering": True}), + } + response = self.url_open("/report/download?" + urlencode(params)) + response.raise_for_status() + self.assertNotEqual(response.headers.get("Content-Type"), "application/pdf") + self.assertNotIn(b"/Encrypt", response.content) diff --git a/report_qweb_encrypt/tests/test_report_qweb_encrypt.py b/report_qweb_encrypt/tests/test_report_qweb_encrypt.py new file mode 100644 index 0000000000..2095531c1d --- /dev/null +++ b/report_qweb_encrypt/tests/test_report_qweb_encrypt.py @@ -0,0 +1,51 @@ +# © 2016 Therp BV +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl.html). +from odoo.exceptions import ValidationError +from odoo.tests.common import HttpCase + + +class TestReportQwebEncrypt(HttpCase): + def test_report_qweb_no_encrypt(self): + ctx = {"force_report_rendering": True} + report = self.env.ref("web.action_report_internalpreview") + report.encrypt = False + pdf, _ = report.with_context(**ctx)._render_qweb_pdf(report.report_name, [1]) + self.assertFalse(pdf.count(b"/Encrypt")) + + def test_report_qweb_auto_encrypt(self): + ctx = {"force_report_rendering": True} + report = self.env.ref("web.action_report_internalpreview") + report.encrypt = "auto" + report.encrypt_password = False + + # If no encrypt_password, still not encrypted + pdf, _ = report.with_context(**ctx)._render_qweb_pdf(report.report_name, [1]) + self.assertFalse(pdf.count(b"/Encrypt")) + + # If invalid encrypt_password, show error + report.encrypt_password = "invalid python syntax" + with self.assertRaises(ValidationError): + pdf, _ = report.with_context(**ctx)._render_qweb_pdf( + report.report_name, [1] + ) + + # Valid python string for password + report.encrypt_password = "'secretcode'" + pdf, _ = report.with_context(**ctx)._render_qweb_pdf(report.report_name, [1]) + self.assertTrue(pdf.count(b"/Encrypt")) + + def test_report_qweb_manual_encrypt(self): + ctx = {"force_report_rendering": True} + report = self.env.ref("web.action_report_internalpreview") + report.encrypt = "manual" + + # If no encrypt_password, still not encrypted + pdf, _ = report.with_context(**ctx)._render_qweb_pdf(report.report_name, [1]) + self.assertFalse(pdf.count(b"/Encrypt")) + + # Valid python string for password + ctx.update({"encrypt_password": "secretcode"}) + pdf, _ = report.with_context(**ctx)._render_qweb_pdf(report.report_name, [1]) + self.assertTrue(pdf.count(b"/Encrypt")) + + # TODO: test_report_qweb_manual_encrypt, require JS test? diff --git a/report_qweb_encrypt/views/ir_actions_report.xml b/report_qweb_encrypt/views/ir_actions_report.xml new file mode 100644 index 0000000000..e320b35081 --- /dev/null +++ b/report_qweb_encrypt/views/ir_actions_report.xml @@ -0,0 +1,30 @@ + + + + + ir.actions.report.form (in report_qweb_encrypt) + ir.actions.report + + + + + + +