[FIX] web: session_info: introduce is_superuser key

This is done in order to enable the tour service only for the
superuser. Commit 6ef1644a7b changed the meaning of `is_admin`
to achieve this but broke the fact that some features of the debug
manager are available to admin and not only to the superuser. Anyway
a `is_admin` key should mean that the user is in the admin group.

We could have checked client side that the uid is equal to 1 but
adding a `is_superuser` key is more elegant and easier to grep.
Also fix the only occurence of a uid check in the weblcient.

This reverts commit 6ef1644a7b.
This commit is contained in:
Simon Lejeune
2016-07-20 14:16:01 +02:00
parent 6ef1644a7b
commit d1cd293ece
6 changed files with 14 additions and 8 deletions
+2 -1
View File
@@ -21,7 +21,8 @@ class Http(models.AbstractModel):
return { return {
"session_id": request.session_id, "session_id": request.session_id,
"uid": request.session.uid, "uid": request.session.uid,
"is_admin": request.env.uid == openerp.SUPERUSER_ID, "is_admin": request.env.user.has_group('base.group_system'),
"is_superuser": request.env.user._is_superuser(),
"user_context": request.session.get_context() if request.session.uid else {}, "user_context": request.session.get_context() if request.session.uid else {},
"db": request.session.db, "db": request.session.db,
"server_version": version_info.get('server_version'), "server_version": version_info.get('server_version'),
+1 -1
View File
@@ -62,7 +62,7 @@ return AbstractWebClient.extend({
var company = session.company_id; var company = session.company_id;
var img = session.url('/web/binary/company_logo' + '?db=' + session.db + (company ? '&company=' + company : '')); var img = session.url('/web/binary/company_logo' + '?db=' + session.db + (company ? '&company=' + company : ''));
this.$('.oe_logo img').attr('src', '').attr('src', img); this.$('.oe_logo img').attr('src', '').attr('src', img);
this.$('.oe_logo_edit').toggleClass('oe_logo_edit_admin', session.uid === 1); this.$('.oe_logo_edit').toggleClass('oe_logo_edit_admin', session.is_superuser);
}, },
logo_edit: function(ev) { logo_edit: function(ev) {
var self = this; var self = this;
+1 -1
View File
@@ -6,6 +6,6 @@ class Http(models.AbstractModel):
def session_info(self): def session_info(self):
result = super(Http, self).session_info() result = super(Http, self).session_info()
if result['is_admin']: if result['is_superuser']:
result['web_tours'] = request.env['web_tour.tour'].get_consumed_tours() result['web_tours'] = request.env['web_tour.tour'].get_consumed_tours()
return result return result
@@ -24,7 +24,7 @@ return session.is_bound.then(function () {
// Load the list of consumed tours and the tip template only if we are admin, in the frontend, // Load the list of consumed tours and the tip template only if we are admin, in the frontend,
// tours being only available for the admin. For the backend, the list of consumed is directly // tours being only available for the admin. For the backend, the list of consumed is directly
// in the page source. // in the page source.
if (session.is_frontend && session.is_admin) { if (session.is_frontend && session.is_superuser) {
defs.push(new Model('web_tour.tour').call('get_consumed_tours')); defs.push(new Model('web_tour.tour').call('get_consumed_tours'));
defs.push(ajax.loadXML('/web_tour/static/src/xml/tip.xml', QWeb)); defs.push(ajax.loadXML('/web_tour/static/src/xml/tip.xml', QWeb));
} }
@@ -61,11 +61,11 @@ return session.is_bound.then(function () {
}; };
// Enable the MutationObserver for the admin or if a tour is running, when the DOM is ready // Enable the MutationObserver for the admin or if a tour is running, when the DOM is ready
if (session.is_admin || tour.running_tour) { if (session.is_superuser || tour.running_tour) {
observe(); observe();
} }
// Override the TourManager so that it enables/disables the observer when necessary // Override the TourManager so that it enables/disables the observer when necessary
if (!session.is_admin) { if (!session.is_superuser) {
var run = tour.run; var run = tour.run;
tour.run = function () { tour.run = function () {
run.apply(this, arguments); run.apply(this, arguments);
+1 -1
View File
@@ -127,7 +127,7 @@
var odoo = { var odoo = {
csrf_token: "<t t-esc="request.csrf_token(None)"/>", csrf_token: "<t t-esc="request.csrf_token(None)"/>",
session_info: { session_info: {
is_admin: <t t-esc="json.dumps(request.env.user.has_group('base.group_system'))"/>, is_superuser: <t t-esc="json.dumps(request.env.user._is_superuser())"/>,
is_frontend: true, is_frontend: true,
}, },
}; };
+6 -1
View File
@@ -569,7 +569,12 @@ class Users(models.Model):
@api.multi @api.multi
def _is_admin(self): def _is_admin(self):
self.ensure_one() self.ensure_one()
return self.id == SUPERUSER_ID or self.has_group('base.group_erp_manager') return self._is_superuser() or self.has_group('base.group_erp_manager')
@api.multi
def _is_superuser(self):
self.ensure_one()
return self.id == SUPERUSER_ID
@api.model @api.model
def get_company_currency_id(self): def get_company_currency_id(self):