Daily updates from Odoo
Saturday, August 2, 2025
3 changes · master
New functionality added to Odoo
Documents can now be automatically sorted into folders using AI, helping teams reduce manual filing work and keep incoming documents organized faster. The update also improves AI prompt handling so files can be included safely and adds safeguards to avoid sorting loops and delayed email processing.
Original PR description
Purpose ======= Allow sorting documents that created / move in a folder with AI. Specification ============= To achieve that result, we need to create a new type of server actions, "AI". This type of…
Purpose
=======
Allow sorting documents that created / move in a folder with AI.
Specification
=============
To achieve that result, we need to create a new type of server actions,
"AI". This type of server action can use other server action marked
as "Use with AI". We call the "Use with AI" server action "tools".
The LLM can ask to execute a tool with some parameter. That allow it
to move documents in a given folder, to rename a document,
log a note, etc.
We also need to be able to add binary file in the prompt,
for that purpose, we stop using QWeb, and we render ourselves the prompt with LXML.
Various fixes were applied along the way.
See underlying commits for more details about each of the changes.
Technical
=========
Mail alias: To not block the email CRON, when documents are sent to a
folder with AI sorting enable, we delay the sorting (they will be
sorted in a different CRON, and a ribbon message will be shown
in the kanban view while they are waiting to be sorted)
Loop: We need to prevent loop in case the target folder is also marked
as "AI sorted".
Prompt injection: The new server action code is vulnerable to prompt injection.
An attacker could try to retrieve the information from the prompt
by fooling the LLM into inserting those information in the result
of the server action.
Most obvious example is writing an unlimited free text into a readable record.
Several measures are available to limit this when creating AI server actions:
- End users should make careful use of the '/record' command to specify the
possible "winner candidates" records of the server action.
- The 'ai_tool_schema' can be used to limit the available outputs of the LLM
(for example by truncating text to a certain limit)
- The LLM can only execute a set of manually selected AI tools, these have to
be carefully chosen to avoid unwanted side-effects as the LLM could be fooled
into executing any of these tools with any arguments
- Dynamic information inside the prompt is added using '/field', those values
should be reviewed to make sure they do not contain sensitive information
The AI server actions & tools provided as data in this PR have been reviewed
by Odoo to make sure they follow these criteria.
Number of API calls: OpenAI always answer `"status": "completed"` after
executing a tool (even if it's not finished) so even if the LLM
will execute one action and stop, it will require 2 API calls
(to be sure it's finished and that nothing else will be executed).
In the last call, to specify it's done, there's no more tool call,
and the LLM send eg `The documents has been moved to...`.
Even if we say `When you are done, sent DONE`, it sends it in the
last call. We could have limited the tools call to 1 for documents,
to improve performance, but then we will restrict the feature.
AI module: The code is done in the `ai` module, because it's meant to
replace `ai.tool`. For now, we keep the `ai_server_actions` module
but it's only used for "update with AI" action, and will be merged
with AI in the future.
Access check: We only check that we can execute the AI action, we skip
all check on the tools. The reason is that it can be executed in a
CRON on most cases anyway, so it's better for it to be explicit
(and to have something consistent). If a tool has a group, then a
warning will be shown to explain to the user that the LLM can skip
the access check for this action.
Default folders: For other models, if we didn't insert records in the
prompt, then we add the most used records. But for documents, they
inherit from the accesses of the parent folder, and so it has
security impact, so we don't insert the most used folders (if the
user does not do /record in the prompt, then the LLM won't be able
to move the documents).
Folders values: When inserting a record in the prompt, by default we
just insert its display name. We want the LLM to have more
information for the auto-sort, for example, if we have a folder
"Belgium" inside "Finance", the LLM should be able to know that
the Belgium folder is related to Finance.
Task-4915266A new Accounting and Knowledge integration lets users create polished audit reports directly in Knowledge, edit them collaboratively, and export them as professional PDFs. The update adds ready-made templates, embedded accounting reports, dynamic audit data, attachments, foldable sections, and electronic signature support to make audit reporting faster and more complete.
Original PR description
This PR introduces a new bridge module that connects the Knowledge and Accounting modules, enabling users to seamlessly create audit reports directly within Knowledge. Thanks to this integration, users can now generate professional-grade audit reports with just a few clicks, and continue editing them inside the Knowledge interface. See underlying commits for more details. COM: https://github.com/odoo/odoo/pull/214712 Task-4840940
Website live chat can now be powered by AI agents instead of only scripted chatbot flows. This lets businesses offer more flexible, question-and-answer style support conversations through a new AI Livechat website snippet.
Original PR description
- Previously, livechat channel rules could only be configured using scripted chatbots(chatbots that rely on pre-defined steps and answers). This commit gives the ability to configure livechat channel rules using AI Agents (LLMs). - Introduce AI Livechat website snippet. Community PR: https://github.com/odoo/odoo/pull/221008 task-4825509