[ADD] convenience res_users._is_admin
Checks that the provided user (or user in the provided dataset): * is the superadmin * or is a member of group_erp_manager There are a number of hand-rolled "is_admin" checks in the codebase some of which are fairly gnarly. The shortcut provides a single point of contact, avoids forgetting about cases (e.g. SUPERUSER_ID) and is relatively convenient when checking a user which is not the "current" user. closes #8146
This commit is contained in:
@@ -702,7 +702,7 @@ class WizardMultiChartsAccounts(models.TransientModel):
|
||||
all the provided information to create the accounts, the banks, the journals, the taxes, the
|
||||
accounting properties... accordingly for the chosen company.
|
||||
'''
|
||||
if self._uid != self.sudo()._uid and not self.env.user.has_group('base.group_erp_manager'):
|
||||
if not self.env.user._is_admin():
|
||||
raise AccessError(_("Only administrators can change the settings"))
|
||||
ir_values_obj = self.env['ir.values']
|
||||
company = self.company_id
|
||||
|
||||
@@ -17,7 +17,7 @@ class ImportModule(Controller):
|
||||
def check_user(self, uid=None):
|
||||
if uid is None:
|
||||
uid = request.uid
|
||||
is_admin = request.registry['res.users'].has_group(request.cr, uid, 'base.group_erp_manager')
|
||||
is_admin = request.registry['res.users']._is_admin(request.cr, uid, [uid])
|
||||
if not is_admin:
|
||||
raise openerp.exceptions.AccessError("Only administrators can upload a module")
|
||||
|
||||
|
||||
@@ -921,7 +921,7 @@ class google_calendar(osv.AbstractModel):
|
||||
return url
|
||||
|
||||
def can_authorize_google(self, cr, uid, context=None):
|
||||
return self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager')
|
||||
return self.pool['res.users']._is_admin(cr, uid, [uid])
|
||||
|
||||
def set_all_tokens(self, cr, uid, authorization_code, context=None):
|
||||
gs_pool = self.pool['google.service']
|
||||
|
||||
@@ -46,9 +46,8 @@ class config(osv.Model):
|
||||
def get_access_token(self, cr, uid, scope=None, context=None):
|
||||
ir_config = self.pool['ir.config_parameter']
|
||||
google_drive_refresh_token = ir_config.get_param(cr, SUPERUSER_ID, 'google_drive_refresh_token')
|
||||
user_is_admin = self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager')
|
||||
if not google_drive_refresh_token:
|
||||
if user_is_admin:
|
||||
if self.pool['res.users']._is_admin(cr, uid, [uid]):
|
||||
model, action_id = self.pool['ir.model.data'].get_object_reference(cr, uid, 'base_setup', 'action_general_configuration')
|
||||
msg = _("You haven't configured 'Authorization Code' generated from google, Please generate and configure it .")
|
||||
raise openerp.exceptions.RedirectWarning(msg, action_id, _('Go to the configuration panel'))
|
||||
|
||||
@@ -47,7 +47,7 @@ class sale_configuration(osv.osv_memory):
|
||||
}
|
||||
|
||||
def set_sale_defaults(self, cr, uid, ids, context=None):
|
||||
if uid != SUPERUSER_ID and not self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager'):
|
||||
if not self.pool['res.users']._is_admin(cr, uid, [uid]):
|
||||
raise openerp.exceptions.AccessError(_("Only administrators can change the settings"))
|
||||
ir_values = self.pool.get('ir.values')
|
||||
wizard = self.browse(cr, uid, ids)[0]
|
||||
|
||||
@@ -104,7 +104,7 @@ class ir_attachment(osv.osv):
|
||||
|
||||
def force_storage(self, cr, uid, context=None):
|
||||
"""Force all attachments to be stored in the currently configured storage"""
|
||||
if not self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager'):
|
||||
if not self.pool['res.users']._is_admin(cr, uid, [uid]):
|
||||
raise AccessError(_('Only administrators can execute this action.'))
|
||||
|
||||
location = self._storage(cr, uid, context)
|
||||
|
||||
@@ -547,7 +547,7 @@ class res_config_settings(osv.osv_memory, res_config_module_installation_mixin):
|
||||
context = {}
|
||||
|
||||
context = dict(context, active_test=False)
|
||||
if uid != SUPERUSER_ID and not self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager'):
|
||||
if not self.pool['res.users']._is_admin(cr, uid, [uid]):
|
||||
raise openerp.exceptions.AccessError(_("Only administrators can change the settings"))
|
||||
|
||||
ir_values = self.pool['ir.values']
|
||||
@@ -713,4 +713,4 @@ class res_config_settings(osv.osv_memory, res_config_module_installation_mixin):
|
||||
# 3/ substitute and return the result
|
||||
if (action_id):
|
||||
return exceptions.RedirectWarning(msg % values, action_id, _('Go to the configuration panel'))
|
||||
return exceptions.UserError(msg % values)
|
||||
return exceptions.UserError(msg % values)
|
||||
|
||||
@@ -568,6 +568,10 @@ class res_users(osv.osv):
|
||||
(uid, module, ext_id))
|
||||
return bool(cr.fetchone())
|
||||
|
||||
@api.multi
|
||||
def _is_admin(self):
|
||||
return self.id == openerp.SUPERUSER_ID or self.sudo(self).has_group('base.group_erp_manager')
|
||||
|
||||
def get_company_currency_id(self, cr, uid, context=None):
|
||||
return self.browse(cr, uid, uid, context=context).company_id.currency_id.id
|
||||
|
||||
@@ -933,7 +937,7 @@ class users_view(osv.osv):
|
||||
def fields_get(self, cr, uid, allfields=None, context=None, write_access=True, attributes=None):
|
||||
res = super(users_view, self).fields_get(cr, uid, allfields, context, write_access, attributes)
|
||||
# add reified groups fields
|
||||
if uid != SUPERUSER_ID and not self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager'):
|
||||
if not self.pool['res.users']._is_admin(cr, uid, [uid]):
|
||||
return res
|
||||
for app, kind, gs in self.pool['res.groups'].get_groups_by_application(cr, uid, context):
|
||||
if kind == 'selection':
|
||||
|
||||
Reference in New Issue
Block a user