[FIX] web: session_info: introduce is_superuser key
This is done in order to enable the tour service only for the superuser. Commit6ef1644a7bchanged the meaning of `is_admin` to achieve this but broke the fact that some features of the debug manager are available to admin and not only to the superuser. Anyway a `is_admin` key should mean that the user is in the admin group. We could have checked client side that the uid is equal to 1 but adding a `is_superuser` key is more elegant and easier to grep. Also fix the only occurence of a uid check in the weblcient. This reverts commit6ef1644a7b.
This commit is contained in:
@@ -21,7 +21,8 @@ class Http(models.AbstractModel):
|
||||
return {
|
||||
"session_id": request.session_id,
|
||||
"uid": request.session.uid,
|
||||
"is_admin": request.env.uid == openerp.SUPERUSER_ID,
|
||||
"is_admin": request.env.user.has_group('base.group_system'),
|
||||
"is_superuser": request.env.user._is_superuser(),
|
||||
"user_context": request.session.get_context() if request.session.uid else {},
|
||||
"db": request.session.db,
|
||||
"server_version": version_info.get('server_version'),
|
||||
|
||||
@@ -62,7 +62,7 @@ return AbstractWebClient.extend({
|
||||
var company = session.company_id;
|
||||
var img = session.url('/web/binary/company_logo' + '?db=' + session.db + (company ? '&company=' + company : ''));
|
||||
this.$('.oe_logo img').attr('src', '').attr('src', img);
|
||||
this.$('.oe_logo_edit').toggleClass('oe_logo_edit_admin', session.uid === 1);
|
||||
this.$('.oe_logo_edit').toggleClass('oe_logo_edit_admin', session.is_superuser);
|
||||
},
|
||||
logo_edit: function(ev) {
|
||||
var self = this;
|
||||
|
||||
@@ -6,6 +6,6 @@ class Http(models.AbstractModel):
|
||||
|
||||
def session_info(self):
|
||||
result = super(Http, self).session_info()
|
||||
if result['is_admin']:
|
||||
if result['is_superuser']:
|
||||
result['web_tours'] = request.env['web_tour.tour'].get_consumed_tours()
|
||||
return result
|
||||
|
||||
@@ -24,7 +24,7 @@ return session.is_bound.then(function () {
|
||||
// Load the list of consumed tours and the tip template only if we are admin, in the frontend,
|
||||
// tours being only available for the admin. For the backend, the list of consumed is directly
|
||||
// in the page source.
|
||||
if (session.is_frontend && session.is_admin) {
|
||||
if (session.is_frontend && session.is_superuser) {
|
||||
defs.push(new Model('web_tour.tour').call('get_consumed_tours'));
|
||||
defs.push(ajax.loadXML('/web_tour/static/src/xml/tip.xml', QWeb));
|
||||
}
|
||||
@@ -61,11 +61,11 @@ return session.is_bound.then(function () {
|
||||
};
|
||||
|
||||
// Enable the MutationObserver for the admin or if a tour is running, when the DOM is ready
|
||||
if (session.is_admin || tour.running_tour) {
|
||||
if (session.is_superuser || tour.running_tour) {
|
||||
observe();
|
||||
}
|
||||
// Override the TourManager so that it enables/disables the observer when necessary
|
||||
if (!session.is_admin) {
|
||||
if (!session.is_superuser) {
|
||||
var run = tour.run;
|
||||
tour.run = function () {
|
||||
run.apply(this, arguments);
|
||||
|
||||
@@ -127,7 +127,7 @@
|
||||
var odoo = {
|
||||
csrf_token: "<t t-esc="request.csrf_token(None)"/>",
|
||||
session_info: {
|
||||
is_admin: <t t-esc="json.dumps(request.env.user.has_group('base.group_system'))"/>,
|
||||
is_superuser: <t t-esc="json.dumps(request.env.user._is_superuser())"/>,
|
||||
is_frontend: true,
|
||||
},
|
||||
};
|
||||
|
||||
@@ -569,7 +569,12 @@ class Users(models.Model):
|
||||
@api.multi
|
||||
def _is_admin(self):
|
||||
self.ensure_one()
|
||||
return self.id == SUPERUSER_ID or self.has_group('base.group_erp_manager')
|
||||
return self._is_superuser() or self.has_group('base.group_erp_manager')
|
||||
|
||||
@api.multi
|
||||
def _is_superuser(self):
|
||||
self.ensure_one()
|
||||
return self.id == SUPERUSER_ID
|
||||
|
||||
@api.model
|
||||
def get_company_currency_id(self):
|
||||
|
||||
Reference in New Issue
Block a user