From d1cd293ecefde56bf649aa69b5da808755f6a4b8 Mon Sep 17 00:00:00 2001 From: Simon Lejeune Date: Wed, 20 Jul 2016 12:23:58 +0200 Subject: [PATCH] [FIX] web: session_info: introduce `is_superuser` key This is done in order to enable the tour service only for the superuser. Commit 6ef1644a7b3812 changed the meaning of `is_admin` to achieve this but broke the fact that some features of the debug manager are available to admin and not only to the superuser. Anyway a `is_admin` key should mean that the user is in the admin group. We could have checked client side that the uid is equal to 1 but adding a `is_superuser` key is more elegant and easier to grep. Also fix the only occurence of a uid check in the weblcient. This reverts commit 6ef1644a7b3812f4cc0d066ea74970791a4b4d54. --- addons/web/models/ir_http.py | 3 ++- addons/web/static/src/js/web_client.js | 2 +- addons/web_tour/models/ir_http.py | 2 +- addons/web_tour/static/src/js/tour_service.js | 6 +++--- addons/website/views/website_templates.xml | 2 +- openerp/addons/base/res/res_users.py | 7 ++++++- 6 files changed, 14 insertions(+), 8 deletions(-) diff --git a/addons/web/models/ir_http.py b/addons/web/models/ir_http.py index 2b4b7509b52..0c3aacc09c9 100644 --- a/addons/web/models/ir_http.py +++ b/addons/web/models/ir_http.py @@ -21,7 +21,8 @@ class Http(models.AbstractModel): return { "session_id": request.session_id, "uid": request.session.uid, - "is_admin": request.env.uid == openerp.SUPERUSER_ID, + "is_admin": request.env.user.has_group('base.group_system'), + "is_superuser": request.env.user._is_superuser(), "user_context": request.session.get_context() if request.session.uid else {}, "db": request.session.db, "server_version": version_info.get('server_version'), diff --git a/addons/web/static/src/js/web_client.js b/addons/web/static/src/js/web_client.js index 99237dccc6c..5fc1f3f2796 100644 --- a/addons/web/static/src/js/web_client.js +++ b/addons/web/static/src/js/web_client.js @@ -62,7 +62,7 @@ return AbstractWebClient.extend({ var company = session.company_id; var img = session.url('/web/binary/company_logo' + '?db=' + session.db + (company ? '&company=' + company : '')); this.$('.oe_logo img').attr('src', '').attr('src', img); - this.$('.oe_logo_edit').toggleClass('oe_logo_edit_admin', session.uid === 1); + this.$('.oe_logo_edit').toggleClass('oe_logo_edit_admin', session.is_superuser); }, logo_edit: function(ev) { var self = this; diff --git a/addons/web_tour/models/ir_http.py b/addons/web_tour/models/ir_http.py index c337d75f14e..38c2c876d46 100644 --- a/addons/web_tour/models/ir_http.py +++ b/addons/web_tour/models/ir_http.py @@ -6,6 +6,6 @@ class Http(models.AbstractModel): def session_info(self): result = super(Http, self).session_info() - if result['is_admin']: + if result['is_superuser']: result['web_tours'] = request.env['web_tour.tour'].get_consumed_tours() return result diff --git a/addons/web_tour/static/src/js/tour_service.js b/addons/web_tour/static/src/js/tour_service.js index c5fe6c786ef..8fd07845201 100644 --- a/addons/web_tour/static/src/js/tour_service.js +++ b/addons/web_tour/static/src/js/tour_service.js @@ -24,7 +24,7 @@ return session.is_bound.then(function () { // Load the list of consumed tours and the tip template only if we are admin, in the frontend, // tours being only available for the admin. For the backend, the list of consumed is directly // in the page source. - if (session.is_frontend && session.is_admin) { + if (session.is_frontend && session.is_superuser) { defs.push(new Model('web_tour.tour').call('get_consumed_tours')); defs.push(ajax.loadXML('/web_tour/static/src/xml/tip.xml', QWeb)); } @@ -61,11 +61,11 @@ return session.is_bound.then(function () { }; // Enable the MutationObserver for the admin or if a tour is running, when the DOM is ready - if (session.is_admin || tour.running_tour) { + if (session.is_superuser || tour.running_tour) { observe(); } // Override the TourManager so that it enables/disables the observer when necessary - if (!session.is_admin) { + if (!session.is_superuser) { var run = tour.run; tour.run = function () { run.apply(this, arguments); diff --git a/addons/website/views/website_templates.xml b/addons/website/views/website_templates.xml index fbcbe77aa67..514f1f75963 100644 --- a/addons/website/views/website_templates.xml +++ b/addons/website/views/website_templates.xml @@ -127,7 +127,7 @@ var odoo = { csrf_token: "", session_info: { - is_admin: , + is_superuser: , is_frontend: true, }, }; diff --git a/openerp/addons/base/res/res_users.py b/openerp/addons/base/res/res_users.py index 15bb150c35e..c4849cc1fd0 100644 --- a/openerp/addons/base/res/res_users.py +++ b/openerp/addons/base/res/res_users.py @@ -569,7 +569,12 @@ class Users(models.Model): @api.multi def _is_admin(self): self.ensure_one() - return self.id == SUPERUSER_ID or self.has_group('base.group_erp_manager') + return self._is_superuser() or self.has_group('base.group_erp_manager') + + @api.multi + def _is_superuser(self): + self.ensure_one() + return self.id == SUPERUSER_ID @api.model def get_company_currency_id(self):