[FIX] calendar: private events

By default, an event can be modified by any employee. This is also the
case for private events, displayed as "Busy" to other users. However,
since any user can modify an event, nothing prevents him to change the
privacy setting in order to be able to see the content.

This commit introduces a global record rule which only allows the
followers of an event to modify it.

opw-705079
This commit is contained in:
Nicolas Martinelli
2017-01-18 14:49:22 +01:00
parent f98a4d45af
commit 23b2bba925
@@ -23,5 +23,15 @@
<field name="groups" eval="[(4, ref('base.group_portal'))]"/>
</record>
<record id="calendar_event_rule_private" model="ir.rule">
<field ref="model_calendar_event" name="model_id"/>
<field name="name">Private events</field>
<field name="domain_force">['|', ('class', '!=', 'private'), '&amp;', ('class', '=', 'private'), ('partner_ids', 'in', user.partner_id.id)]</field>
<field name="perm_read" eval="False"/>
<field name="perm_write" eval="True"/>
<field name="perm_create" eval="True"/>
<field name="perm_unlink" eval="True"/>
</record>
</data>
</openerp>