[FIX] web: session_info: introduce is_superuser key
This is done in order to enable the tour service only for the superuser. Commit6ef1644a7bchanged the meaning of `is_admin` to achieve this but broke the fact that some features of the debug manager are available to admin and not only to the superuser. Anyway a `is_admin` key should mean that the user is in the admin group. We could have checked client side that the uid is equal to 1 but adding a `is_superuser` key is more elegant and easier to grep. Also fix the only occurence of a uid check in the weblcient. This reverts commit6ef1644a7b.
This commit is contained in:
@@ -21,7 +21,8 @@ class Http(models.AbstractModel):
|
|||||||
return {
|
return {
|
||||||
"session_id": request.session_id,
|
"session_id": request.session_id,
|
||||||
"uid": request.session.uid,
|
"uid": request.session.uid,
|
||||||
"is_admin": request.env.uid == openerp.SUPERUSER_ID,
|
"is_admin": request.env.user.has_group('base.group_system'),
|
||||||
|
"is_superuser": request.env.user._is_superuser(),
|
||||||
"user_context": request.session.get_context() if request.session.uid else {},
|
"user_context": request.session.get_context() if request.session.uid else {},
|
||||||
"db": request.session.db,
|
"db": request.session.db,
|
||||||
"server_version": version_info.get('server_version'),
|
"server_version": version_info.get('server_version'),
|
||||||
|
|||||||
@@ -62,7 +62,7 @@ return AbstractWebClient.extend({
|
|||||||
var company = session.company_id;
|
var company = session.company_id;
|
||||||
var img = session.url('/web/binary/company_logo' + '?db=' + session.db + (company ? '&company=' + company : ''));
|
var img = session.url('/web/binary/company_logo' + '?db=' + session.db + (company ? '&company=' + company : ''));
|
||||||
this.$('.oe_logo img').attr('src', '').attr('src', img);
|
this.$('.oe_logo img').attr('src', '').attr('src', img);
|
||||||
this.$('.oe_logo_edit').toggleClass('oe_logo_edit_admin', session.uid === 1);
|
this.$('.oe_logo_edit').toggleClass('oe_logo_edit_admin', session.is_superuser);
|
||||||
},
|
},
|
||||||
logo_edit: function(ev) {
|
logo_edit: function(ev) {
|
||||||
var self = this;
|
var self = this;
|
||||||
|
|||||||
@@ -6,6 +6,6 @@ class Http(models.AbstractModel):
|
|||||||
|
|
||||||
def session_info(self):
|
def session_info(self):
|
||||||
result = super(Http, self).session_info()
|
result = super(Http, self).session_info()
|
||||||
if result['is_admin']:
|
if result['is_superuser']:
|
||||||
result['web_tours'] = request.env['web_tour.tour'].get_consumed_tours()
|
result['web_tours'] = request.env['web_tour.tour'].get_consumed_tours()
|
||||||
return result
|
return result
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ return session.is_bound.then(function () {
|
|||||||
// Load the list of consumed tours and the tip template only if we are admin, in the frontend,
|
// Load the list of consumed tours and the tip template only if we are admin, in the frontend,
|
||||||
// tours being only available for the admin. For the backend, the list of consumed is directly
|
// tours being only available for the admin. For the backend, the list of consumed is directly
|
||||||
// in the page source.
|
// in the page source.
|
||||||
if (session.is_frontend && session.is_admin) {
|
if (session.is_frontend && session.is_superuser) {
|
||||||
defs.push(new Model('web_tour.tour').call('get_consumed_tours'));
|
defs.push(new Model('web_tour.tour').call('get_consumed_tours'));
|
||||||
defs.push(ajax.loadXML('/web_tour/static/src/xml/tip.xml', QWeb));
|
defs.push(ajax.loadXML('/web_tour/static/src/xml/tip.xml', QWeb));
|
||||||
}
|
}
|
||||||
@@ -61,11 +61,11 @@ return session.is_bound.then(function () {
|
|||||||
};
|
};
|
||||||
|
|
||||||
// Enable the MutationObserver for the admin or if a tour is running, when the DOM is ready
|
// Enable the MutationObserver for the admin or if a tour is running, when the DOM is ready
|
||||||
if (session.is_admin || tour.running_tour) {
|
if (session.is_superuser || tour.running_tour) {
|
||||||
observe();
|
observe();
|
||||||
}
|
}
|
||||||
// Override the TourManager so that it enables/disables the observer when necessary
|
// Override the TourManager so that it enables/disables the observer when necessary
|
||||||
if (!session.is_admin) {
|
if (!session.is_superuser) {
|
||||||
var run = tour.run;
|
var run = tour.run;
|
||||||
tour.run = function () {
|
tour.run = function () {
|
||||||
run.apply(this, arguments);
|
run.apply(this, arguments);
|
||||||
|
|||||||
@@ -127,7 +127,7 @@
|
|||||||
var odoo = {
|
var odoo = {
|
||||||
csrf_token: "<t t-esc="request.csrf_token(None)"/>",
|
csrf_token: "<t t-esc="request.csrf_token(None)"/>",
|
||||||
session_info: {
|
session_info: {
|
||||||
is_admin: <t t-esc="json.dumps(request.env.user.has_group('base.group_system'))"/>,
|
is_superuser: <t t-esc="json.dumps(request.env.user._is_superuser())"/>,
|
||||||
is_frontend: true,
|
is_frontend: true,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -569,7 +569,12 @@ class Users(models.Model):
|
|||||||
@api.multi
|
@api.multi
|
||||||
def _is_admin(self):
|
def _is_admin(self):
|
||||||
self.ensure_one()
|
self.ensure_one()
|
||||||
return self.id == SUPERUSER_ID or self.has_group('base.group_erp_manager')
|
return self._is_superuser() or self.has_group('base.group_erp_manager')
|
||||||
|
|
||||||
|
@api.multi
|
||||||
|
def _is_superuser(self):
|
||||||
|
self.ensure_one()
|
||||||
|
return self.id == SUPERUSER_ID
|
||||||
|
|
||||||
@api.model
|
@api.model
|
||||||
def get_company_currency_id(self):
|
def get_company_currency_id(self):
|
||||||
|
|||||||
Reference in New Issue
Block a user