[FIX] base: allow user to modify its own preferences

The res.users model functions a bit uniquely since it should allow a user to
modify their own parameters but turns off model edition priviledges by default.
See "SELF_WRITEABLE_FIELDS".

This implies that ir_ui_view#_postprocess_access_rights method will by default
turn off record edition, by automatically adding a 'edit="false"' attribute on
the form node when the frontend calls 'get_views'.

This will in turn prevent the user from modifying its preferences as it will
set the form view in readonly mode.
(It was apparently ignored pre-OWL, hence why we only have this issue now).

To fix the issue, we force the edition by manually setting 'edit="1"' on our
"view_users_form_simple_modif" form.
Allowing the end-user to modify their own settings again.

A tour was added to ensure this behavior.
Note that tour steps need to be adapted in the 'hr' module, as this module
changes the flow of modifying user preferences.

Task-3067001

closes odoo/odoo#106440

X-original-commit: 490d480458590c205962c3f9b95a63790a59f4d3
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Signed-off-by: Warnon Aurélien (awa) <awa@odoo.com>
This commit is contained in:
Aurélien Warnon
2022-11-24 19:25:16 +01:00
parent d49200feca
commit bb58fdacba
6 changed files with 63 additions and 1 deletions
+1
View File
@@ -70,6 +70,7 @@
],
'web.assets_tests': [
'hr/static/tests/tours/hr_employee_flow.js',
'hr/static/tests/tours/user_modify_own_profile_tour.js',
],
},
'license': 'LGPL-3',
@@ -0,0 +1,19 @@
/** @odoo-module **/
import tour from 'web_tour.tour';
/**
* As 'hr' changes the flow a bit and displays the user preferences form in a full view instead of
* a modal, we adapt the steps of the original tour accordingly.
*/
tour.tours['mail/static/tests/tours/user_modify_own_profile_tour.js'].steps = [{
content: 'Open user account menu',
trigger: '.o_user_menu button',
}, {
content: "Open preferences / profile screen",
trigger: '[data-menu=settings]',
}, {
content: "Update the email address",
trigger: 'div[name="email"] input',
run: 'text updatedemail@example.com',
}, ...tour.stepUtils.saveForm()];
@@ -0,0 +1,26 @@
/** @odoo-module **/
import tour from 'web_tour.tour';
/**
* Verify that a user can modify their own profile information.
*/
tour.register('mail/static/tests/tours/user_modify_own_profile_tour.js', {
test: true,
}, [{
content: 'Open user account menu',
trigger: '.o_user_menu button',
}, {
content: "Open preferences / profile screen",
trigger: '[data-menu=settings]',
}, {
content: "Update the email address",
trigger: 'div[name="email"] input',
run: 'text updatedemail@example.com',
}, {
content: "Save the form",
trigger: 'button[name="preference_save"]',
}, {
content: "Wait until the modal is closed",
trigger: 'body:not(.modal-open)',
}]);
+1
View File
@@ -16,3 +16,4 @@ from . import test_res_users_settings
from . import test_rtc
from . import test_uninstall
from . import test_update_notification
from . import test_user_modify_own_profile
@@ -0,0 +1,15 @@
# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
from odoo.tests import HttpCase, tagged
@tagged('-at_install', 'post_install')
class TestUserModifyOwnProfile(HttpCase):
def test_user_modify_own_profile(self):
"""" A user should be able to modify their own profile.
Even if that user does not have access rights to write on the res.users model. """
self.start_tour("/web", "mail/static/tests/tours/user_modify_own_profile_tour.js", login="demo")
self.assertEqual(self.env.ref('base.user_demo').email, "updatedemail@example.com")
+1 -1
View File
@@ -449,7 +449,7 @@
<field name="model">res.users</field>
<field eval="18" name="priority"/>
<field name="arch" type="xml">
<form string="Users">
<form string="Users" edit="1">
<widget name="notification_alert"/>
<field name="avatar_128" invisible="1"/>
<field name="image_1920" readonly="0" widget='image' class="oe_right oe_avatar" options='{"preview_image": "avatar_128"}'/>