[FIX] survey: make a specific route for testing surveys
Purpose of this commit is to clean a bit the test mode of surveys before working a bit on ACLs and survey access. Currently when taking a survey with a magic 'phantom' token it generates a test answer allowing to go through the survey process. However it has several drawbacks : * 'phantom' is not a real token. Token parameter should be used only for real tokens and avoid having corner case when managing simple parameter; * token should only be used to ensure people have been granted access to answering surveys; * it is currently available for every users; * it is pure unwanted magic; In this commit we add a separate route for testing surveys that create the test answer and then redirects to the survey with this answer. It is now also limited to survey managers or survey officers testing their own surveys. Survey JS tour now uses the standard URL and not the testing one. Indeed as testing is now limited to survey officers and managers tour should test real life use cases. This commit is linked to task ID 1916034 and PR #29339.
This commit is contained in:
@@ -15,7 +15,6 @@ _logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
class Survey(http.Controller):
|
||||
# HELPER METHODS #
|
||||
|
||||
def _check_bad_cases(self, survey, token=None):
|
||||
# In case of bad survey, redirect to surveys list
|
||||
@@ -49,23 +48,27 @@ class Survey(http.Controller):
|
||||
return request.render("survey.notopen")
|
||||
return None
|
||||
|
||||
## ROUTES HANDLERS ##
|
||||
@http.route('/survey/test/<model("survey.survey"):survey>', type='http', auth='user', website=True)
|
||||
def survey_test(self, survey, token=None):
|
||||
""" Test mode for surveys: create a test answer, only for managers or officers
|
||||
testing their surveys """
|
||||
if request.env.user.has_group('survey.group_survey_manager') or \
|
||||
request.env.user.has_group('survey.group_survey_user') and survey.create_uid == request.env.user:
|
||||
user_input = request.env['survey.user_input'].create({
|
||||
'survey_id': survey.id,
|
||||
'test_entry': True
|
||||
})
|
||||
return request.redirect('/survey/start/%s/%s' % survey.id, user_input.token)
|
||||
return werkzeug.utils.redirect('/')
|
||||
|
||||
# Survey start
|
||||
@http.route(['/survey/start/<model("survey.survey"):survey>',
|
||||
'/survey/start/<model("survey.survey"):survey>/<string:token>'],
|
||||
type='http', auth='public', website=True)
|
||||
def start_survey(self, survey, token=None, **post):
|
||||
def survey_start(self, survey, token=None, **post):
|
||||
""" Start a survey by providing a token linked to an answer or generate
|
||||
a new token if access is allowed """
|
||||
UserInput = request.env['survey.user_input']
|
||||
|
||||
# Test mode
|
||||
if token and token == "phantom":
|
||||
_logger.info("[survey] Phantom mode")
|
||||
user_input = UserInput.create({'survey_id': survey.id, 'test_entry': True})
|
||||
data = {'survey': survey, 'page': None, 'token': user_input.token}
|
||||
return request.render('survey.survey_init', data)
|
||||
# END Test mode
|
||||
|
||||
# Controls if the survey can be displayed
|
||||
errpage = self._check_bad_cases(survey, token=token)
|
||||
if errpage:
|
||||
|
||||
@@ -337,9 +337,9 @@ class Survey(models.Model):
|
||||
self.ensure_one()
|
||||
return {
|
||||
'type': 'ir.actions.act_url',
|
||||
'name': "Results of the Survey",
|
||||
'name': "Test Survey",
|
||||
'target': 'self',
|
||||
'url': self.with_context(relative_url=True).public_url + "/phantom"
|
||||
'url': '/survey/test/%s' % self.id,
|
||||
}
|
||||
|
||||
@api.multi
|
||||
@@ -351,4 +351,3 @@ class Survey(models.Model):
|
||||
'search_default_completed': 1})
|
||||
action['context'] = ctx
|
||||
return action
|
||||
|
||||
|
||||
@@ -6,7 +6,7 @@ var base = require("web_editor.base");
|
||||
|
||||
tour.register('test_survey', {
|
||||
test: true,
|
||||
url: '/survey/start/user-feedback-form-1',
|
||||
url: '/survey/start/1',
|
||||
wait_for: base.ready()
|
||||
}, [
|
||||
// Page-1
|
||||
|
||||
Reference in New Issue
Block a user