[FIX] calendar: private events
By default, an event can be modified by any employee. This is also the case for private events, displayed as "Busy" to other users. However, since any user can modify an event, nothing prevents him to change the privacy setting in order to be able to see the content. This commit introduces a global record rule which only allows the followers of an event to modify it. opw-705079
This commit is contained in:
@@ -23,5 +23,15 @@
|
||||
<field name="groups" eval="[(4, ref('base.group_portal'))]"/>
|
||||
</record>
|
||||
|
||||
<record id="calendar_event_rule_private" model="ir.rule">
|
||||
<field ref="model_calendar_event" name="model_id"/>
|
||||
<field name="name">Private events</field>
|
||||
<field name="domain_force">['|', ('class', '!=', 'private'), '&', ('class', '=', 'private'), ('partner_ids', 'in', user.partner_id.id)]</field>
|
||||
<field name="perm_read" eval="False"/>
|
||||
<field name="perm_write" eval="True"/>
|
||||
<field name="perm_create" eval="True"/>
|
||||
<field name="perm_unlink" eval="True"/>
|
||||
</record>
|
||||
|
||||
</data>
|
||||
</openerp>
|
||||
|
||||
Reference in New Issue
Block a user