From bb58fdacba3075b9a0d0849d7ca63081594d0f81 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Aur=C3=A9lien=20Warnon?= Date: Mon, 21 Nov 2022 08:24:59 +0000 Subject: [PATCH] [FIX] base: allow user to modify its own preferences MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The res.users model functions a bit uniquely since it should allow a user to modify their own parameters but turns off model edition priviledges by default. See "SELF_WRITEABLE_FIELDS". This implies that ir_ui_view#_postprocess_access_rights method will by default turn off record edition, by automatically adding a 'edit="false"' attribute on the form node when the frontend calls 'get_views'. This will in turn prevent the user from modifying its preferences as it will set the form view in readonly mode. (It was apparently ignored pre-OWL, hence why we only have this issue now). To fix the issue, we force the edition by manually setting 'edit="1"' on our "view_users_form_simple_modif" form. Allowing the end-user to modify their own settings again. A tour was added to ensure this behavior. Note that tour steps need to be adapted in the 'hr' module, as this module changes the flow of modifying user preferences. Task-3067001 closes odoo/odoo#106440 X-original-commit: 490d480458590c205962c3f9b95a63790a59f4d3 Signed-off-by: Thibault Delavallee (tde) Signed-off-by: Warnon Aurélien (awa) --- addons/hr/__manifest__.py | 1 + .../tours/user_modify_own_profile_tour.js | 19 ++++++++++++++ .../tours/user_modify_own_profile_tour.js | 26 +++++++++++++++++++ addons/mail/tests/__init__.py | 1 + .../tests/test_user_modify_own_profile.py | 15 +++++++++++ odoo/addons/base/views/res_users_views.xml | 2 +- 6 files changed, 63 insertions(+), 1 deletion(-) create mode 100644 addons/hr/static/tests/tours/user_modify_own_profile_tour.js create mode 100644 addons/mail/static/tests/tours/user_modify_own_profile_tour.js create mode 100644 addons/mail/tests/test_user_modify_own_profile.py diff --git a/addons/hr/__manifest__.py b/addons/hr/__manifest__.py index 6180b6ddb88..599c49b168a 100644 --- a/addons/hr/__manifest__.py +++ b/addons/hr/__manifest__.py @@ -70,6 +70,7 @@ ], 'web.assets_tests': [ 'hr/static/tests/tours/hr_employee_flow.js', + 'hr/static/tests/tours/user_modify_own_profile_tour.js', ], }, 'license': 'LGPL-3', diff --git a/addons/hr/static/tests/tours/user_modify_own_profile_tour.js b/addons/hr/static/tests/tours/user_modify_own_profile_tour.js new file mode 100644 index 00000000000..e88659b0a7b --- /dev/null +++ b/addons/hr/static/tests/tours/user_modify_own_profile_tour.js @@ -0,0 +1,19 @@ +/** @odoo-module **/ + +import tour from 'web_tour.tour'; + +/** + * As 'hr' changes the flow a bit and displays the user preferences form in a full view instead of + * a modal, we adapt the steps of the original tour accordingly. + */ +tour.tours['mail/static/tests/tours/user_modify_own_profile_tour.js'].steps = [{ + content: 'Open user account menu', + trigger: '.o_user_menu button', +}, { + content: "Open preferences / profile screen", + trigger: '[data-menu=settings]', +}, { + content: "Update the email address", + trigger: 'div[name="email"] input', + run: 'text updatedemail@example.com', +}, ...tour.stepUtils.saveForm()]; diff --git a/addons/mail/static/tests/tours/user_modify_own_profile_tour.js b/addons/mail/static/tests/tours/user_modify_own_profile_tour.js new file mode 100644 index 00000000000..3b85bbd04cd --- /dev/null +++ b/addons/mail/static/tests/tours/user_modify_own_profile_tour.js @@ -0,0 +1,26 @@ +/** @odoo-module **/ + +import tour from 'web_tour.tour'; + +/** + * Verify that a user can modify their own profile information. + */ +tour.register('mail/static/tests/tours/user_modify_own_profile_tour.js', { + test: true, +}, [{ + content: 'Open user account menu', + trigger: '.o_user_menu button', +}, { + content: "Open preferences / profile screen", + trigger: '[data-menu=settings]', +}, { + content: "Update the email address", + trigger: 'div[name="email"] input', + run: 'text updatedemail@example.com', +}, { + content: "Save the form", + trigger: 'button[name="preference_save"]', +}, { + content: "Wait until the modal is closed", + trigger: 'body:not(.modal-open)', +}]); diff --git a/addons/mail/tests/__init__.py b/addons/mail/tests/__init__.py index 4f050f4c3cd..c492546effb 100644 --- a/addons/mail/tests/__init__.py +++ b/addons/mail/tests/__init__.py @@ -16,3 +16,4 @@ from . import test_res_users_settings from . import test_rtc from . import test_uninstall from . import test_update_notification +from . import test_user_modify_own_profile diff --git a/addons/mail/tests/test_user_modify_own_profile.py b/addons/mail/tests/test_user_modify_own_profile.py new file mode 100644 index 00000000000..3477cd9bfa5 --- /dev/null +++ b/addons/mail/tests/test_user_modify_own_profile.py @@ -0,0 +1,15 @@ +# -*- coding: utf-8 -*- +# Part of Odoo. See LICENSE file for full copyright and licensing details. + +from odoo.tests import HttpCase, tagged + + +@tagged('-at_install', 'post_install') +class TestUserModifyOwnProfile(HttpCase): + + def test_user_modify_own_profile(self): + """" A user should be able to modify their own profile. + Even if that user does not have access rights to write on the res.users model. """ + + self.start_tour("/web", "mail/static/tests/tours/user_modify_own_profile_tour.js", login="demo") + self.assertEqual(self.env.ref('base.user_demo').email, "updatedemail@example.com") diff --git a/odoo/addons/base/views/res_users_views.xml b/odoo/addons/base/views/res_users_views.xml index 6e13d34ad6c..31f3feb34ac 100644 --- a/odoo/addons/base/views/res_users_views.xml +++ b/odoo/addons/base/views/res_users_views.xml @@ -449,7 +449,7 @@ res.users -
+