[IMP] access error messages on fields with groups
This commit is contained in:
@@ -2,5 +2,8 @@
|
||||
'name': 'test of access rights and rules',
|
||||
'description': "Testing of access restrictions",
|
||||
'version': '0.0.1',
|
||||
'data': ['ir.model.access.csv'],
|
||||
'data': [
|
||||
'ir.model.access.csv',
|
||||
'data.xml',
|
||||
],
|
||||
}
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
<odoo>
|
||||
<record model="res.groups" id="test_group">
|
||||
<field name="name">Test Group</field>
|
||||
</record>
|
||||
</odoo>
|
||||
@@ -9,6 +9,11 @@ class SomeObj(models.Model):
|
||||
|
||||
val = fields.Integer()
|
||||
company_id = fields.Many2one('res.company')
|
||||
forbidden = fields.Integer(
|
||||
groups='test_access_rights.test_group,!base.group_no_one,base.group_user,!base.group_public',
|
||||
default=5
|
||||
)
|
||||
forbidden2 = fields.Integer(groups='test_access_rights.test_group')
|
||||
|
||||
class Container(models.Model):
|
||||
_name = 'test_access_right.container'
|
||||
|
||||
@@ -227,3 +227,46 @@ Note: this might be a multi-company issue.
|
||||
|
||||
(records: [%s], uid: %d)""" % (self.record.id, self.user.id)
|
||||
)
|
||||
|
||||
class TestFieldGroupFeedback(Feedback):
|
||||
|
||||
def setUp(self):
|
||||
super().setUp()
|
||||
self.record = self.env['test_access_right.some_obj'].create({
|
||||
'val': 0,
|
||||
}).sudo(self.user)
|
||||
|
||||
|
||||
def test_read(self):
|
||||
self.env.ref('base.group_no_one').write(
|
||||
{'users': [(4, self.user.id)]})
|
||||
with self.assertRaises(AccessError) as ctx:
|
||||
_ = self.record.forbidden
|
||||
|
||||
self.assertEqual(
|
||||
ctx.exception.args[0],
|
||||
"""The requested operation can not be completed due to security restrictions.
|
||||
|
||||
Document type: Object For Test Access Right (test_access_right.some_obj)
|
||||
Operation: read
|
||||
Fields:
|
||||
- forbidden (allowed for groups 'User types / Internal User', 'Test Group'; forbidden for groups 'Extra Rights / Technical Features', 'User types / Public')"""
|
||||
)
|
||||
|
||||
def test_write(self):
|
||||
self.env.ref('base.group_no_one').write(
|
||||
{'users': [(4, self.user.id)]})
|
||||
|
||||
with self.assertRaises(AccessError) as ctx:
|
||||
self.record.write({'forbidden': 1, 'forbidden2': 2})
|
||||
|
||||
self.assertEqual(
|
||||
ctx.exception.args[0],
|
||||
"""The requested operation can not be completed due to security restrictions.
|
||||
|
||||
Document type: Object For Test Access Right (test_access_right.some_obj)
|
||||
Operation: write
|
||||
Fields:
|
||||
- forbidden (allowed for groups 'User types / Internal User', 'Test Group'; forbidden for groups 'Extra Rights / Technical Features', 'User types / Public')
|
||||
- forbidden2 (allowed for groups 'Test Group')"""
|
||||
)
|
||||
|
||||
+47
-4
@@ -2734,10 +2734,53 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
|
||||
invalid_fields = {name for name in fields if not valid(name)}
|
||||
if invalid_fields:
|
||||
_logger.info('Access Denied by ACLs for operation: %s, uid: %s, model: %s, fields: %s',
|
||||
operation, self._uid, self._name, ', '.join(invalid_fields))
|
||||
raise AccessError(_('The requested operation cannot be completed due to security restrictions. '
|
||||
'Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
|
||||
(self._description, operation))
|
||||
operation, self._uid, self._name, ', '.join(invalid_fields))
|
||||
|
||||
description = self.env['ir.model']._get(self._name).name
|
||||
if not self.env.user.has_group('base.group_no_one'):
|
||||
raise AccessError(
|
||||
_('The requested operation cannot be completed due to security restrictions. '
|
||||
'Please contact your system administrator.\n\n(Document type: %(document_kind)s (%(document_model)s), Operation: %(operation)s)') % {
|
||||
'document_kind': description,
|
||||
'document_model': self._name,
|
||||
'operation': operation,
|
||||
})
|
||||
|
||||
def format_groups(field):
|
||||
anyof = self.env['res.groups']
|
||||
noneof = self.env['res.groups']
|
||||
for g in field.groups.split(','):
|
||||
if g.startswith('!'):
|
||||
noneof |= self.env.ref(g[1:])
|
||||
else:
|
||||
anyof |= self.env.ref(g)
|
||||
strs = []
|
||||
if anyof:
|
||||
strs.append(_("allowed for groups %s") % ', '.join(
|
||||
anyof.sorted(lambda g: g.id)
|
||||
.mapped(lambda g: repr(g.display_name))
|
||||
))
|
||||
if noneof:
|
||||
strs.append(_("forbidden for groups %s") % ', '.join(
|
||||
noneof.sorted(lambda g: g.id)
|
||||
.mapped(lambda g: repr(g.display_name))
|
||||
))
|
||||
return '; '.join(strs)
|
||||
|
||||
raise AccessError(_("""The requested operation can not be completed due to security restrictions.
|
||||
|
||||
Document type: %(document_kind)s (%(document_model)s)
|
||||
Operation: %(operation)s
|
||||
Fields:
|
||||
%(fields_list)s""") % {
|
||||
'document_model': self._name,
|
||||
'document_kind': description or self._name,
|
||||
'operation': operation,
|
||||
'fields_list': '\n'.join(
|
||||
'- %s (%s)' % (f, format_groups(self._fields[f]))
|
||||
for f in sorted(invalid_fields)
|
||||
)
|
||||
})
|
||||
|
||||
return fields
|
||||
|
||||
|
||||
Reference in New Issue
Block a user