[IMP] website_profile,*: specify reason for profile access denial
*: website_forum, website_slides Purpose ======= Website profiles of users like Mitchell Admin, which are set as "public", are also rendered as "Private". In Fact, users can be denied access to the public profile of other users for different reasons. In such situations, users should get a more accurate feedback on the reason of the access denial. Specifications ============== On profile access denial, give users a more accurate reason: - "This profile is private!" when the profile is indeed private or the karma of the user profile is equal to 0. -"Not have enough karma to view other users' profile." when the profile is public but the requesting user has insufficient karma rights. Also: - Redirect to the 404 page users trying to access a non-existing profile. Note: the minimum level of karma required to access a public profile is now editable. See odoo/odoo#123411 Task-3360050 closes odoo/odoo#128686 Related: odoo/upgrade#4955 Signed-off-by: Stéphane Debauche (std) <std@odoo.com>
This commit is contained in:
@@ -1,8 +1,8 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<odoo><data>
|
||||
<!--Private profile-->
|
||||
<template id="private_profile" inherit_id="website_profile.private_profile">
|
||||
<xpath expr="//div[@id='private_profile_return_link_container']" position="inside">
|
||||
<!--Access Denied - Profile Page-->
|
||||
<template id="profile_access_denied" inherit_id="website_profile.profile_access_denied">
|
||||
<xpath expr="//div[@id='profile_access_denied_return_link_container']" position="inside">
|
||||
<t t-if="request.params.get('forum_id')">
|
||||
<a t-attf-href="/forum/#{request.params.get('forum_id')}" class="btn btn-primary">Return to the forum</a>
|
||||
</t>
|
||||
|
||||
@@ -11,7 +11,7 @@ import math
|
||||
from dateutil.relativedelta import relativedelta
|
||||
from operator import itemgetter
|
||||
|
||||
from odoo import fields, http, modules, tools
|
||||
from odoo import _, fields, http, tools
|
||||
from odoo.http import request
|
||||
from odoo.osv import expression
|
||||
|
||||
@@ -36,14 +36,22 @@ class WebsiteProfile(http.Controller):
|
||||
return False
|
||||
|
||||
def _check_user_profile_access(self, user_id):
|
||||
""" Takes a user_id and returns:
|
||||
- (user record, False) when the user is granted access
|
||||
- (False, str) when the user is denied access
|
||||
Raises a Not Found Exception when the profile does not exist
|
||||
"""
|
||||
user_sudo = request.env['res.users'].sudo().browse(user_id)
|
||||
# User can access - no matter what - his own profile
|
||||
if user_sudo.id == request.env.user.id:
|
||||
return user_sudo
|
||||
if user_sudo.karma == 0 or not user_sudo.website_published or \
|
||||
(user_sudo.id != request.session.uid and request.env.user.karma < request.website.karma_profile_min):
|
||||
return False
|
||||
return user_sudo
|
||||
return user_sudo, False
|
||||
if request.env.user.karma < request.website.karma_profile_min:
|
||||
return False, _("Not have enough karma to view other users' profile.")
|
||||
elif not user_sudo.exists():
|
||||
raise request.not_found()
|
||||
elif user_sudo.karma == 0 or not user_sudo.website_published:
|
||||
return False, _('This profile is private!')
|
||||
return user_sudo, False
|
||||
|
||||
def _prepare_user_values(self, **kwargs):
|
||||
kwargs.pop('edit_translations', None) # avoid nuking edit_translations
|
||||
@@ -84,14 +92,14 @@ class WebsiteProfile(http.Controller):
|
||||
field_name=field, width=int(width), height=int(height), crop=crop
|
||||
).get_response()
|
||||
|
||||
@http.route(['/profile/user/<int:user_id>'], type='http', auth="public", website=True)
|
||||
@http.route('/profile/user/<int:user_id>', type='http', auth='public', website=True)
|
||||
def view_user_profile(self, user_id, **post):
|
||||
user = self._check_user_profile_access(user_id)
|
||||
if not user:
|
||||
return request.render("website_profile.private_profile")
|
||||
user_sudo, denial_reason = self._check_user_profile_access(user_id)
|
||||
if denial_reason:
|
||||
return request.render('website_profile.profile_access_denied', {'denial_reason': denial_reason})
|
||||
values = self._prepare_user_values(**post)
|
||||
params = self._prepare_user_profile_parameters(**post)
|
||||
values.update(self._prepare_user_profile_values(user, **params))
|
||||
values.update(self._prepare_user_profile_values(user_sudo, **params))
|
||||
return request.render("website_profile.user_profile_main", values)
|
||||
|
||||
# Edit Profile
|
||||
|
||||
@@ -508,12 +508,12 @@
|
||||
<h6 t-else="" t-field="badge.name" class="d-inline my-0"/>
|
||||
</template>
|
||||
|
||||
<!--Private profile-->
|
||||
<template id="private_profile" name="Private Profile Page">
|
||||
<!--Access Denied - Profile Page-->
|
||||
<template id="profile_access_denied" name="Access Denied - Profile Page">
|
||||
<t t-call="website.layout">
|
||||
<div class="container mb32 mt48">
|
||||
<h1 class="mt32">This profile is private!</h1>
|
||||
<div id="private_profile_return_link_container">
|
||||
<h1 class="mt32" t-out="denial_reason"/>
|
||||
<div id="profile_access_denied_return_link_container">
|
||||
<p><a t-attf-href="/">Return to the website.</a></p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
<?xml version="1.0" ?>
|
||||
<odoo><data>
|
||||
<!--Private profile-->
|
||||
<template id="private_profile" inherit_id="website_profile.private_profile">
|
||||
<xpath expr="//div[@id='private_profile_return_link_container']" position="inside">
|
||||
<!--Access Denied - Profile Page-->
|
||||
<template id="profile_access_denied" inherit_id="website_profile.profile_access_denied">
|
||||
<xpath expr="//div[@id='profile_access_denied_return_link_container']" position="inside">
|
||||
<t t-if="request.params.get('channel_id')">
|
||||
<p><a t-attf-href="/slides/course-#{request.params.get('channel_id')}">Return to the course.</a></p>
|
||||
</t>
|
||||
|
||||
Reference in New Issue
Block a user