From 8e38d97f6901fb5dc27be7da61a22f6b67eb8e2a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thibault=20Delavall=C3=A9e?= Date: Thu, 29 Nov 2018 14:18:15 +0000 Subject: [PATCH] [FIX] survey: make a specific route for testing surveys Purpose of this commit is to clean a bit the test mode of surveys before working a bit on ACLs and survey access. Currently when taking a survey with a magic 'phantom' token it generates a test answer allowing to go through the survey process. However it has several drawbacks : * 'phantom' is not a real token. Token parameter should be used only for real tokens and avoid having corner case when managing simple parameter; * token should only be used to ensure people have been granted access to answering surveys; * it is currently available for every users; * it is pure unwanted magic; In this commit we add a separate route for testing surveys that create the test answer and then redirects to the survey with this answer. It is now also limited to survey managers or survey officers testing their own surveys. Survey JS tour now uses the standard URL and not the testing one. Indeed as testing is now limited to survey officers and managers tour should test real life use cases. This commit is linked to task ID 1916034 and PR #29339. --- addons/survey/controllers/main.py | 27 ++++++++++--------- addons/survey/models/survey_survey.py | 5 ++-- .../survey/static/src/js/tour_test_survey.js | 2 +- 3 files changed, 18 insertions(+), 16 deletions(-) diff --git a/addons/survey/controllers/main.py b/addons/survey/controllers/main.py index 379359086b6..65e4cd370fc 100644 --- a/addons/survey/controllers/main.py +++ b/addons/survey/controllers/main.py @@ -15,7 +15,6 @@ _logger = logging.getLogger(__name__) class Survey(http.Controller): - # HELPER METHODS # def _check_bad_cases(self, survey, token=None): # In case of bad survey, redirect to surveys list @@ -49,23 +48,27 @@ class Survey(http.Controller): return request.render("survey.notopen") return None - ## ROUTES HANDLERS ## + @http.route('/survey/test/', type='http', auth='user', website=True) + def survey_test(self, survey, token=None): + """ Test mode for surveys: create a test answer, only for managers or officers + testing their surveys """ + if request.env.user.has_group('survey.group_survey_manager') or \ + request.env.user.has_group('survey.group_survey_user') and survey.create_uid == request.env.user: + user_input = request.env['survey.user_input'].create({ + 'survey_id': survey.id, + 'test_entry': True + }) + return request.redirect('/survey/start/%s/%s' % survey.id, user_input.token) + return werkzeug.utils.redirect('/') - # Survey start @http.route(['/survey/start/', '/survey/start//'], type='http', auth='public', website=True) - def start_survey(self, survey, token=None, **post): + def survey_start(self, survey, token=None, **post): + """ Start a survey by providing a token linked to an answer or generate + a new token if access is allowed """ UserInput = request.env['survey.user_input'] - # Test mode - if token and token == "phantom": - _logger.info("[survey] Phantom mode") - user_input = UserInput.create({'survey_id': survey.id, 'test_entry': True}) - data = {'survey': survey, 'page': None, 'token': user_input.token} - return request.render('survey.survey_init', data) - # END Test mode - # Controls if the survey can be displayed errpage = self._check_bad_cases(survey, token=token) if errpage: diff --git a/addons/survey/models/survey_survey.py b/addons/survey/models/survey_survey.py index b78f947aeef..01e0b7b8eec 100644 --- a/addons/survey/models/survey_survey.py +++ b/addons/survey/models/survey_survey.py @@ -337,9 +337,9 @@ class Survey(models.Model): self.ensure_one() return { 'type': 'ir.actions.act_url', - 'name': "Results of the Survey", + 'name': "Test Survey", 'target': 'self', - 'url': self.with_context(relative_url=True).public_url + "/phantom" + 'url': '/survey/test/%s' % self.id, } @api.multi @@ -351,4 +351,3 @@ class Survey(models.Model): 'search_default_completed': 1}) action['context'] = ctx return action - diff --git a/addons/survey/static/src/js/tour_test_survey.js b/addons/survey/static/src/js/tour_test_survey.js index c051c766ba0..9a9cac10001 100644 --- a/addons/survey/static/src/js/tour_test_survey.js +++ b/addons/survey/static/src/js/tour_test_survey.js @@ -6,7 +6,7 @@ var base = require("web_editor.base"); tour.register('test_survey', { test: true, - url: '/survey/start/user-feedback-form-1', + url: '/survey/start/1', wait_for: base.ready() }, [ // Page-1