[IMP] website_profile,*: specify reason for profile access denial

*: website_forum, website_slides

Purpose
=======

Website profiles of users like Mitchell Admin, which are set as "public",
are also rendered as "Private". In Fact, users can be denied access to
the public profile of other users for different reasons. In such
situations, users should get a more accurate feedback on the reason of
the access denial.

Specifications
==============

On profile access denial, give users a more accurate reason:

- "This profile is private!" when the profile is indeed private
or the karma of the user profile is equal to 0.

-"Not have enough karma to view other users' profile." when the profile
is public but the requesting user has insufficient karma rights.

Also:
- Redirect to the 404 page users trying to access a non-existing
profile.

Note: the minimum level of karma required to access a public profile is
now editable. See odoo/odoo#123411

Task-3360050

closes odoo/odoo#128686

Related: odoo/upgrade#4955
Signed-off-by: Stéphane Debauche (std) <std@odoo.com>
This commit is contained in:
Lopes Marc (loma)
2023-09-28 10:22:05 +00:00
parent c31c6f5de5
commit 2e5175919c
4 changed files with 29 additions and 21 deletions
+19 -11
View File
@@ -11,7 +11,7 @@ import math
from dateutil.relativedelta import relativedelta
from operator import itemgetter
from odoo import fields, http, modules, tools
from odoo import _, fields, http, tools
from odoo.http import request
from odoo.osv import expression
@@ -36,14 +36,22 @@ class WebsiteProfile(http.Controller):
return False
def _check_user_profile_access(self, user_id):
""" Takes a user_id and returns:
- (user record, False) when the user is granted access
- (False, str) when the user is denied access
Raises a Not Found Exception when the profile does not exist
"""
user_sudo = request.env['res.users'].sudo().browse(user_id)
# User can access - no matter what - his own profile
if user_sudo.id == request.env.user.id:
return user_sudo
if user_sudo.karma == 0 or not user_sudo.website_published or \
(user_sudo.id != request.session.uid and request.env.user.karma < request.website.karma_profile_min):
return False
return user_sudo
return user_sudo, False
if request.env.user.karma < request.website.karma_profile_min:
return False, _("Not have enough karma to view other users' profile.")
elif not user_sudo.exists():
raise request.not_found()
elif user_sudo.karma == 0 or not user_sudo.website_published:
return False, _('This profile is private!')
return user_sudo, False
def _prepare_user_values(self, **kwargs):
kwargs.pop('edit_translations', None) # avoid nuking edit_translations
@@ -84,14 +92,14 @@ class WebsiteProfile(http.Controller):
field_name=field, width=int(width), height=int(height), crop=crop
).get_response()
@http.route(['/profile/user/<int:user_id>'], type='http', auth="public", website=True)
@http.route('/profile/user/<int:user_id>', type='http', auth='public', website=True)
def view_user_profile(self, user_id, **post):
user = self._check_user_profile_access(user_id)
if not user:
return request.render("website_profile.private_profile")
user_sudo, denial_reason = self._check_user_profile_access(user_id)
if denial_reason:
return request.render('website_profile.profile_access_denied', {'denial_reason': denial_reason})
values = self._prepare_user_values(**post)
params = self._prepare_user_profile_parameters(**post)
values.update(self._prepare_user_profile_values(user, **params))
values.update(self._prepare_user_profile_values(user_sudo, **params))
return request.render("website_profile.user_profile_main", values)
# Edit Profile
@@ -508,12 +508,12 @@
<h6 t-else="" t-field="badge.name" class="d-inline my-0"/>
</template>
<!--Private profile-->
<template id="private_profile" name="Private Profile Page">
<!--Access Denied - Profile Page-->
<template id="profile_access_denied" name="Access Denied - Profile Page">
<t t-call="website.layout">
<div class="container mb32 mt48">
<h1 class="mt32">This profile is private!</h1>
<div id="private_profile_return_link_container">
<h1 class="mt32" t-out="denial_reason"/>
<div id="profile_access_denied_return_link_container">
<p><a t-attf-href="/">Return to the website.</a></p>
</div>
</div>