[ADD] convenience res_users._is_admin

Checks that the provided user (or user in the provided dataset):

* is the superadmin
* or is a member of group_erp_manager

There are a number of hand-rolled "is_admin" checks in the codebase some
of which are fairly gnarly. The shortcut provides a single point of
contact, avoids forgetting about cases (e.g. SUPERUSER_ID) and is
relatively convenient when checking a user which is not the "current"
user.

closes #8146
This commit is contained in:
Xavier Morel
2015-08-20 09:42:06 +02:00
parent 992220eb4c
commit e80f1152c7
8 changed files with 13 additions and 10 deletions
+1 -1
View File
@@ -702,7 +702,7 @@ class WizardMultiChartsAccounts(models.TransientModel):
all the provided information to create the accounts, the banks, the journals, the taxes, the
accounting properties... accordingly for the chosen company.
'''
if self._uid != self.sudo()._uid and not self.env.user.has_group('base.group_erp_manager'):
if not self.env.user._is_admin():
raise AccessError(_("Only administrators can change the settings"))
ir_values_obj = self.env['ir.values']
company = self.company_id
@@ -17,7 +17,7 @@ class ImportModule(Controller):
def check_user(self, uid=None):
if uid is None:
uid = request.uid
is_admin = request.registry['res.users'].has_group(request.cr, uid, 'base.group_erp_manager')
is_admin = request.registry['res.users']._is_admin(request.cr, uid, [uid])
if not is_admin:
raise openerp.exceptions.AccessError("Only administrators can upload a module")
+1 -1
View File
@@ -921,7 +921,7 @@ class google_calendar(osv.AbstractModel):
return url
def can_authorize_google(self, cr, uid, context=None):
return self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager')
return self.pool['res.users']._is_admin(cr, uid, [uid])
def set_all_tokens(self, cr, uid, authorization_code, context=None):
gs_pool = self.pool['google.service']
+1 -2
View File
@@ -46,9 +46,8 @@ class config(osv.Model):
def get_access_token(self, cr, uid, scope=None, context=None):
ir_config = self.pool['ir.config_parameter']
google_drive_refresh_token = ir_config.get_param(cr, SUPERUSER_ID, 'google_drive_refresh_token')
user_is_admin = self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager')
if not google_drive_refresh_token:
if user_is_admin:
if self.pool['res.users']._is_admin(cr, uid, [uid]):
model, action_id = self.pool['ir.model.data'].get_object_reference(cr, uid, 'base_setup', 'action_general_configuration')
msg = _("You haven't configured 'Authorization Code' generated from google, Please generate and configure it .")
raise openerp.exceptions.RedirectWarning(msg, action_id, _('Go to the configuration panel'))
+1 -1
View File
@@ -47,7 +47,7 @@ class sale_configuration(osv.osv_memory):
}
def set_sale_defaults(self, cr, uid, ids, context=None):
if uid != SUPERUSER_ID and not self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager'):
if not self.pool['res.users']._is_admin(cr, uid, [uid]):
raise openerp.exceptions.AccessError(_("Only administrators can change the settings"))
ir_values = self.pool.get('ir.values')
wizard = self.browse(cr, uid, ids)[0]
+1 -1
View File
@@ -104,7 +104,7 @@ class ir_attachment(osv.osv):
def force_storage(self, cr, uid, context=None):
"""Force all attachments to be stored in the currently configured storage"""
if not self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager'):
if not self.pool['res.users']._is_admin(cr, uid, [uid]):
raise AccessError(_('Only administrators can execute this action.'))
location = self._storage(cr, uid, context)
+2 -2
View File
@@ -547,7 +547,7 @@ class res_config_settings(osv.osv_memory, res_config_module_installation_mixin):
context = {}
context = dict(context, active_test=False)
if uid != SUPERUSER_ID and not self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager'):
if not self.pool['res.users']._is_admin(cr, uid, [uid]):
raise openerp.exceptions.AccessError(_("Only administrators can change the settings"))
ir_values = self.pool['ir.values']
@@ -713,4 +713,4 @@ class res_config_settings(osv.osv_memory, res_config_module_installation_mixin):
# 3/ substitute and return the result
if (action_id):
return exceptions.RedirectWarning(msg % values, action_id, _('Go to the configuration panel'))
return exceptions.UserError(msg % values)
return exceptions.UserError(msg % values)
+5 -1
View File
@@ -568,6 +568,10 @@ class res_users(osv.osv):
(uid, module, ext_id))
return bool(cr.fetchone())
@api.multi
def _is_admin(self):
return self.id == openerp.SUPERUSER_ID or self.sudo(self).has_group('base.group_erp_manager')
def get_company_currency_id(self, cr, uid, context=None):
return self.browse(cr, uid, uid, context=context).company_id.currency_id.id
@@ -933,7 +937,7 @@ class users_view(osv.osv):
def fields_get(self, cr, uid, allfields=None, context=None, write_access=True, attributes=None):
res = super(users_view, self).fields_get(cr, uid, allfields, context, write_access, attributes)
# add reified groups fields
if uid != SUPERUSER_ID and not self.pool['res.users'].has_group(cr, uid, 'base.group_erp_manager'):
if not self.pool['res.users']._is_admin(cr, uid, [uid]):
return res
for app, kind, gs in self.pool['res.groups'].get_groups_by_application(cr, uid, context):
if kind == 'selection':