[FIX] base: allow user to modify its own preferences
The res.users model functions a bit uniquely since it should allow a user to modify their own parameters but turns off model edition priviledges by default. See "SELF_WRITEABLE_FIELDS". This implies that ir_ui_view#_postprocess_access_rights method will by default turn off record edition, by automatically adding a 'edit="false"' attribute on the form node when the frontend calls 'get_views'. This will in turn prevent the user from modifying its preferences as it will set the form view in readonly mode. (It was apparently ignored pre-OWL, hence why we only have this issue now). To fix the issue, we force the edition by manually setting 'edit="1"' on our "view_users_form_simple_modif" form. Allowing the end-user to modify their own settings again. A tour was added to ensure this behavior. Note that tour steps need to be adapted in the 'hr' module, as this module changes the flow of modifying user preferences. Task-3067001 closes odoo/odoo#106440 X-original-commit: 490d480458590c205962c3f9b95a63790a59f4d3 Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com> Signed-off-by: Warnon Aurélien (awa) <awa@odoo.com>
This commit is contained in:
@@ -70,6 +70,7 @@
|
||||
],
|
||||
'web.assets_tests': [
|
||||
'hr/static/tests/tours/hr_employee_flow.js',
|
||||
'hr/static/tests/tours/user_modify_own_profile_tour.js',
|
||||
],
|
||||
},
|
||||
'license': 'LGPL-3',
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
/** @odoo-module **/
|
||||
|
||||
import tour from 'web_tour.tour';
|
||||
|
||||
/**
|
||||
* As 'hr' changes the flow a bit and displays the user preferences form in a full view instead of
|
||||
* a modal, we adapt the steps of the original tour accordingly.
|
||||
*/
|
||||
tour.tours['mail/static/tests/tours/user_modify_own_profile_tour.js'].steps = [{
|
||||
content: 'Open user account menu',
|
||||
trigger: '.o_user_menu button',
|
||||
}, {
|
||||
content: "Open preferences / profile screen",
|
||||
trigger: '[data-menu=settings]',
|
||||
}, {
|
||||
content: "Update the email address",
|
||||
trigger: 'div[name="email"] input',
|
||||
run: 'text updatedemail@example.com',
|
||||
}, ...tour.stepUtils.saveForm()];
|
||||
@@ -0,0 +1,26 @@
|
||||
/** @odoo-module **/
|
||||
|
||||
import tour from 'web_tour.tour';
|
||||
|
||||
/**
|
||||
* Verify that a user can modify their own profile information.
|
||||
*/
|
||||
tour.register('mail/static/tests/tours/user_modify_own_profile_tour.js', {
|
||||
test: true,
|
||||
}, [{
|
||||
content: 'Open user account menu',
|
||||
trigger: '.o_user_menu button',
|
||||
}, {
|
||||
content: "Open preferences / profile screen",
|
||||
trigger: '[data-menu=settings]',
|
||||
}, {
|
||||
content: "Update the email address",
|
||||
trigger: 'div[name="email"] input',
|
||||
run: 'text updatedemail@example.com',
|
||||
}, {
|
||||
content: "Save the form",
|
||||
trigger: 'button[name="preference_save"]',
|
||||
}, {
|
||||
content: "Wait until the modal is closed",
|
||||
trigger: 'body:not(.modal-open)',
|
||||
}]);
|
||||
@@ -16,3 +16,4 @@ from . import test_res_users_settings
|
||||
from . import test_rtc
|
||||
from . import test_uninstall
|
||||
from . import test_update_notification
|
||||
from . import test_user_modify_own_profile
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
||||
|
||||
from odoo.tests import HttpCase, tagged
|
||||
|
||||
|
||||
@tagged('-at_install', 'post_install')
|
||||
class TestUserModifyOwnProfile(HttpCase):
|
||||
|
||||
def test_user_modify_own_profile(self):
|
||||
"""" A user should be able to modify their own profile.
|
||||
Even if that user does not have access rights to write on the res.users model. """
|
||||
|
||||
self.start_tour("/web", "mail/static/tests/tours/user_modify_own_profile_tour.js", login="demo")
|
||||
self.assertEqual(self.env.ref('base.user_demo').email, "updatedemail@example.com")
|
||||
@@ -449,7 +449,7 @@
|
||||
<field name="model">res.users</field>
|
||||
<field eval="18" name="priority"/>
|
||||
<field name="arch" type="xml">
|
||||
<form string="Users">
|
||||
<form string="Users" edit="1">
|
||||
<widget name="notification_alert"/>
|
||||
<field name="avatar_128" invisible="1"/>
|
||||
<field name="image_1920" readonly="0" widget='image' class="oe_right oe_avatar" options='{"preview_image": "avatar_128"}'/>
|
||||
|
||||
Reference in New Issue
Block a user