[IMP] mail, website_mail, base: extra info on error messages

Display extra information on error messages:
- Access error based on ACLs: user, fields (if applies)
- Access error based on record rules: user, ids
- Missing error: model, operation, user, ids

closes odoo/odoo#33942

Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>


Co-authored-by: jev-odoo <jev@odoo.com>
This commit is contained in:
Nicolas Martinelli
2019-06-07 06:38:06 +00:00
co-authored by jev-odoo
parent b4337f57d7
commit b5a04fd29f
6 changed files with 46 additions and 18 deletions
+3 -2
View File
@@ -178,8 +178,9 @@ class MailActivity(models.Model):
self.env[model].browse(res_ids).check_access_rule(doc_operation)
except exceptions.AccessError:
raise exceptions.AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') %
(self._description, operation))
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('Records:'), res_ids[:6], _('User:'), self._uid)
)
@api.model
def create(self, values):
+6 -4
View File
@@ -595,8 +595,9 @@ class Message(models.Model):
WHERE message.message_type = %%s AND (message.subtype_id IS NULL OR subtype.internal IS TRUE) AND message.id = ANY (%%s)''' % (self._table), ('comment', self.ids,))
if self._cr.fetchall():
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') %
(self._description, operation))
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
)
# Read mail_message.ids to have their values
message_values = dict((res_id, {}) for res_id in self.ids)
@@ -695,8 +696,9 @@ class Message(models.Model):
if not (other_ids and self.browse(other_ids).exists()):
return
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') %
(self._description, operation))
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('Records:'), list(other_ids)[:6], _('User:'), self._uid)
)
@api.model
def _get_record_name(self, values):
+4 -1
View File
@@ -54,7 +54,10 @@ class MailMessage(models.Model):
if self.user_has_groups('base.group_public'):
self.env.cr.execute('SELECT id FROM "%s" WHERE website_published IS FALSE AND id = ANY (%%s)' % (self._table), (self.ids,))
if self.env.cr.fetchall():
raise AccessError(_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation))
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
)
return super(MailMessage, self).check_access_rule(operation=operation)
@api.multi
+4 -1
View File
@@ -240,7 +240,10 @@ class IrActionsActWindow(models.Model):
existing = self.filtered(lambda rec: rec.id in ids)
if len(existing) < len(self):
# mark missing records in cache with a failed value
exc = MissingError(_("Record does not exist or has been deleted."))
exc = MissingError(
_("Record does not exist or has been deleted.")
+ '\n\n({} {}, {} {})'.format(_('Records:'), (self - existing).ids[:6], _('User:'), self._uid)
)
for record in (self - existing):
record._cache.set_failed(self._fields, exc)
return existing
+1
View File
@@ -1212,6 +1212,7 @@ class IrModelAccess(models.Model):
else:
msg_tail = _("Please contact your system administrator if you think this is an error.") + "\n\n(" + _("Document model") + ": %s)"
msg_params = (model,)
msg_tail += ' - ({} {}, {} {})'.format(_('Operation:'), mode, _('User:'), self._uid)
_logger.info('Access Denied by ACLs for operation: %s, uid: %s, model: %s', mode, self._uid, model)
msg = '%s %s' % (msg_heads[mode], msg_tail)
raise AccessError(msg % msg_params)
+28 -10
View File
@@ -2549,9 +2549,13 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
if invalid_fields:
_logger.info('Access Denied by ACLs for operation: %s, uid: %s, model: %s, fields: %s',
operation, self._uid, self._name, ', '.join(invalid_fields))
raise AccessError(_('The requested operation cannot be completed due to security restrictions. '
'Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
(self._description, operation))
raise AccessError(
_(
'The requested operation cannot be completed due to security restrictions. '
'Please contact your system administrator.\n\n(Document type: %s, Operation: %s)'
) % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('User:'), self._uid, _('Fields:'), ', '.join(invalid_fields))
)
return fields
@@ -2774,8 +2778,8 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
(self._name, 'read', ','.join([str(r.id) for r in self][:6]), self._uid))
# store an access error exception in existing records
exc = AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
(self._name, 'read')
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, 'read')
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
)
self.env.cache.set_failed(forbidden, self._fields.values(), exc)
@@ -2859,8 +2863,10 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
if self._uid == SUPERUSER_ID:
return
_logger.info('Access Denied by record rules for operation: %s on record ids: %r, uid: %s, model: %s', operation, forbidden_ids, self._uid, self._name)
raise AccessError(_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
(self._description, operation))
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {}, {})'.format(_('Records:'), forbidden_ids[:6], _('User:'), self._uid)
)
else:
# If we get here, the missing_ids are not in the database
if operation in ('read','unlink'):
@@ -2869,7 +2875,13 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
# errors for non-transactional search/read sequences coming from clients
return
_logger.info('Failed operation on deleted record(s): %s, uid: %s, model: %s', operation, self._uid, self._name)
raise MissingError(_('Missing document(s)') + ':' + _('One of the documents you are trying to access has been deleted, please try again after refreshing.'))
raise MissingError(
_('Missing document(s)') + ':' + _('One of the documents you are trying to access has been deleted, please try again after refreshing.')
+ '\n\n({} {}, {} {}, {} {}, {} {})'.format(
_('Document type:'), self._description, _('Operation:'), operation,
_('Records:'), missing_ids[:6], _('User:'), self._uid,
)
)
@api.model
def check_access_rights(self, operation, raise_exception=True):
@@ -3211,7 +3223,10 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
for sub_ids in cr.split_for_in_conditions(set(self.ids)):
cr.execute(query, params + (sub_ids,))
if cr.rowcount != len(sub_ids):
raise MissingError(_('One of the records you are trying to modify has already been deleted (Document type: %s).') % self._description)
raise MissingError(
_('One of the records you are trying to modify has already been deleted (Document type: %s).') % self._description
+ '\n\n({} {}, {} {})'.format(_('Records:'), sub_ids[:6], _('User:'), self._uid)
)
# TODO: optimize
for name in direct:
@@ -3993,7 +4008,10 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
existing = self.browse(ids + new_ids)
if len(existing) < len(self):
# mark missing records in cache with a failed value
exc = MissingError(_("Record does not exist or has been deleted."))
exc = MissingError(
_("Record does not exist or has been deleted.")
+ '\n\n({} {}, {} {})'.format(_('Records:'), (self - existing).ids[:6], _('User:'), self._uid)
)
self.env.cache.set_failed(self - existing, self._fields.values(), exc)
return existing