[FIX] website_slides: only allow for a single review per user

Once a user posts a review, they are able to edit this single review
and not create any new ones. However if the user had multiple tabs open
of the same course, then they can still access the "Add a review"
functionality.

This fix enforces the single review per user per course policy.

Task-3721958

closes odoo/odoo#156411

X-original-commit: 61a95ad41e0b0c72554a491c555ddd33d8588566
Signed-off-by: Stéphane Debauche (std) <std@odoo.com>
Signed-off-by: Bram Van Gaal (brvg) <brvg@odoo.com>
This commit is contained in:
bram1000
2024-03-05 16:48:20 +00:00
parent 967e0f7982
commit 85232e56e6
3 changed files with 55 additions and 3 deletions
+9 -2
View File
@@ -4,8 +4,9 @@
import werkzeug
from werkzeug.exceptions import NotFound, Forbidden
from odoo.exceptions import ValidationError
from odoo import http, _
from odoo import _, http
from odoo.http import request
from odoo.addons.portal.controllers.mail import _check_special_access, PortalChatter
from odoo.tools import plaintext2html, html2plaintext
@@ -22,12 +23,18 @@ class SlidesPortalChatter(PortalChatter):
@http.route()
def portal_chatter_post(self, res_model, res_id, message, **kw):
previous_post = request.env['mail.message'].search([('res_id', '=', res_id),
('author_id', '=', request.env.user.partner_id.id),
('model', '=', 'slide.channel'),
('subtype_id', '=', request.env.ref('mail.mt_comment').id)])
if previous_post:
raise ValidationError(_("Only a single review can be posted per course."))
result = super(SlidesPortalChatter, self).portal_chatter_post(res_model, res_id, message, **kw)
if result and res_model == 'slide.channel':
rating_value = kw.get('rating_value', False)
slide_channel = request.env[res_model].sudo().browse(int(res_id))
if rating_value and slide_channel and request.env.user.partner_id.id == int(kw.get('pid')):
# apply karma gain rule only once
request.env.user._add_karma(slide_channel.karma_gen_channel_rank, slide_channel, _('Course Ranked'))
result.update({
'default_rating_value': rating_value,
@@ -4412,6 +4412,12 @@ msgstr ""
msgid "Operation not supported"
msgstr ""
#. module: website_slides
#: code:addons/website_slides/controllers/mail.py:0
#, python-format
msgid "Only a single review can be posted per course."
msgstr ""
#. module: website_slides
#: model:ir.model.fields,help:website_slides.field_slide_channel_invite__lang
msgid ""
+40 -1
View File
@@ -2,10 +2,11 @@
# Part of Odoo. See LICENSE file for full copyright and licensing details.
import base64
from odoo import http
from odoo.addons.mail.tests.common import mail_new_test_user
from odoo.addons.website_slides.tests import common
from odoo.exceptions import AccessError
from odoo.tests import tagged
from odoo.tests import tagged, HttpCase
from odoo.tools import mute_logger
@@ -528,3 +529,41 @@ class TestAccessFeatures(common.SlidesCase):
resource2.with_user(self.user_manager).write({'name': 'Another name'})
resource2.with_user(self.user_manager).unlink()
self.env['slide.slide.resource'].with_user(self.user_manager).create(resource_values)
@tagged('functional')
class TestReview(common.SlidesCase, HttpCase):
@mute_logger('odoo.addons.http_routing.models.ir_http', 'odoo.http')
def test_channel_multiple_reviews(self):
self.authenticate("admin", "admin")
res1 = self.opener.post(
url='%s/mail/chatter_post' % self.base_url(),
json={
'params': {
'res_id': self.channel.id,
'res_model': 'slide.channel',
'message': 'My first review :)',
'rating_value': '2',
'pid': self.env.user.partner_id.id,
'csrf_token': http.Request.csrf_token(self),
},
},
)
self.assertIn("My first review :)", res1.text)
res2 = self.opener.post(
url='%s/mail/chatter_post' % self.base_url(),
json={
'params': {
'res_id': self.channel.id,
'res_model': 'slide.channel',
'message': 'My second review :)',
'rating_value': '2',
'pid': self.env.user.partner_id.id,
'csrf_token': http.Request.csrf_token(self),
},
},
)
self.assertIn("odoo.exceptions.ValidationError", res2.text)