[IMP] base: improve consistency of ACL views
Further improves on previous commit:
- Remove some unnecessary cruft
- Make names/labels more consistent
- Make fields and their ordering more consistent in list views
- Change "active" field on rules into an "Archive" button
- Slightly improve inline doc on rules form view
- Add colors for "global" rules and "apply-for-all" access rights
('Global' is an info, but "Apply For All" is a warning, as it can
indicate an ACL problem)
This commit is contained in:
@@ -160,22 +160,25 @@
|
||||
</page>
|
||||
<page string="Access Rights">
|
||||
<field name="access_ids">
|
||||
<tree string="Access Rules" editable="bottom">
|
||||
<tree string="Access Rights" editable="top"
|
||||
decoration-warning="not group_id and
|
||||
(perm_read or perm_write or
|
||||
perm_create or perm_unlink)">
|
||||
<field name="name"/>
|
||||
<field name="group_id"/>
|
||||
<field name="perm_read"/>
|
||||
<field name="perm_write"/>
|
||||
<field name="perm_create"/>
|
||||
<field name="perm_unlink"/>
|
||||
<field name="name"/>
|
||||
</tree>
|
||||
</field>
|
||||
</page>
|
||||
<page string="Record Rules">
|
||||
<field name="rule_ids">
|
||||
<tree string="Record Rules" editable="top">
|
||||
<tree string="Record Rules" editable="top" decoration-info="global">
|
||||
<field name="name"/>
|
||||
<field name="groups" widget="many2many_tags" options="{'no_create':True}"/>
|
||||
<field name="global"/>
|
||||
<field name="global" invisible="1"/>
|
||||
<field name="domain_force"/>
|
||||
<field name="perm_read"/>
|
||||
<field name="perm_write"/>
|
||||
@@ -525,7 +528,10 @@
|
||||
<record id="ir_access_view_tree" model="ir.ui.view">
|
||||
<field name="model">ir.model.access</field>
|
||||
<field name="arch" type="xml">
|
||||
<tree string="Access Controls" editable="top">
|
||||
<tree string="Access Rights" editable="top"
|
||||
decoration-warning="not group_id and
|
||||
(perm_read or perm_write or
|
||||
perm_create or perm_unlink)">
|
||||
<field name="name"/>
|
||||
<field name="model_id"/>
|
||||
<field name="group_id"/>
|
||||
@@ -539,7 +545,7 @@
|
||||
<record id="ir_access_view_form" model="ir.ui.view">
|
||||
<field name="model">ir.model.access</field>
|
||||
<field name="arch" type="xml">
|
||||
<form string="Access Controls">
|
||||
<form string="Access Rights">
|
||||
<sheet>
|
||||
<group col="4">
|
||||
<field name="name"/>
|
||||
@@ -560,8 +566,8 @@
|
||||
<record id="ir_access_view_search" model="ir.ui.view">
|
||||
<field name="model">ir.model.access</field>
|
||||
<field name="arch" type="xml">
|
||||
<search string="Access Controls">
|
||||
<field name="name" string="Access Control"/>
|
||||
<search string="Access Rights">
|
||||
<field name="name" string="Access Rights"/>
|
||||
<filter string="Global" name="global" domain="[('group_id','=',False)]"/>
|
||||
<separator/>
|
||||
<filter string="Full Access" name="full_access" domain="[('perm_read','=',True),('perm_write','=',True),('perm_create','=',True),('perm_unlink','=',True)]"/>
|
||||
@@ -577,7 +583,7 @@
|
||||
</field>
|
||||
</record>
|
||||
<record id="ir_access_act" model="ir.actions.act_window">
|
||||
<field name="name">Access Controls List</field>
|
||||
<field name="name">Access Rights</field>
|
||||
<field name="res_model">ir.model.access</field>
|
||||
<field name="view_type">form</field>
|
||||
<field name="view_id" ref="ir_access_view_tree"/>
|
||||
|
||||
@@ -6,11 +6,15 @@
|
||||
<field name="arch" type="xml">
|
||||
<form string="Record rules">
|
||||
<sheet>
|
||||
<div class="oe_button_box" name="button_box">
|
||||
<button name="toggle_active" type="object" class="oe_stat_button" icon="fa-archive">
|
||||
<field name="active" widget="boolean_button"/>
|
||||
</button>
|
||||
</div>
|
||||
<group>
|
||||
<group string="General">
|
||||
<field name="name"/>
|
||||
<field name="model_id"/>
|
||||
<field name="active"/>
|
||||
</group>
|
||||
<group col="4" string="Access Rights">
|
||||
<field name="perm_read"/>
|
||||
@@ -25,31 +29,36 @@
|
||||
<field name="global"/>
|
||||
<field name="groups" nolabel="1" colspan="4"/>
|
||||
</group>
|
||||
<group string="Interaction between rules">
|
||||
<label colspan="2"
|
||||
string="Global rules (non group-specific) are restrictions, and cannot be bypassed. Group-local rules grant additional permissions, but are constrained within the bounds of global ones. The first group rules restrict further than global rules, but any additional group rule will add more permissions"/>
|
||||
<label colspan="2"
|
||||
string="Detailed algorithm:"/>
|
||||
<label colspan="2"
|
||||
string="1. Global rules are combined together with a logical AND operator, and with the result of the following steps"/>
|
||||
<label colspan="2"
|
||||
string="2. Group-specific rules are combined together with a logical OR operator"/>
|
||||
<label colspan="2"
|
||||
string="3. If user belongs to several groups, the results from step 2 are combined with logical OR operator"/>
|
||||
<label colspan="2"
|
||||
string="Example: GLOBAL_RULE_1 AND GLOBAL_RULE_2 AND ( (GROUP_A_RULE_1 OR GROUP_A_RULE_2) OR (GROUP_B_RULE_1 OR GROUP_B_RULE_2) )"/>
|
||||
</group>
|
||||
</sheet>
|
||||
<i class="fa fa-info fa-3x text-info pull-left"/>
|
||||
<h3>Interaction between rules</h3>
|
||||
<div>
|
||||
<p>
|
||||
Global rules (non group-specific) are restrictions, and cannot be bypassed.
|
||||
Group-specific rules grant additional permissions, but are constrained within the bounds of global ones.
|
||||
The first group rules restrict further the global rules, but can be relaxed by additional group rules.
|
||||
</p>
|
||||
<p>
|
||||
Detailed algorithm:
|
||||
<ol>
|
||||
<li>Global rules are combined together with a logical AND operator, and with the result of the following steps</li>
|
||||
<li>Group-specific rules are combined together with a logical OR operator</li>
|
||||
<li>If user belongs to several groups, the results from step 2 are combined with logical OR operator</li>
|
||||
</ol>
|
||||
</p>
|
||||
<p>Example: GLOBAL_RULE_1 AND GLOBAL_RULE_2 AND ( (GROUP_A_RULE_1 OR GROUP_A_RULE_2) OR (GROUP_B_RULE_1 OR GROUP_B_RULE_2) )</p>
|
||||
</div>
|
||||
</sheet>
|
||||
</form>
|
||||
</field>
|
||||
</record>
|
||||
<record id="view_rule_tree" model="ir.ui.view">
|
||||
<field name="model">ir.rule</field>
|
||||
<field name="arch" type="xml">
|
||||
<tree string="Record rules">
|
||||
<field name="model_id"/>
|
||||
<tree string="Record Rules" decoration-info="global">
|
||||
<field name="name"/>
|
||||
<field name="global"/>
|
||||
<field name="model_id"/>
|
||||
<field name="global" invisible="1"/>
|
||||
<field name="groups" widget="many2many_tags" options="{'no_create':True}"/>
|
||||
<field name="domain_force"/>
|
||||
<field name="perm_read"/>
|
||||
<field name="perm_write"/>
|
||||
|
||||
@@ -78,26 +78,14 @@
|
||||
</page>
|
||||
<page string="Access Rights">
|
||||
<field name="model_access">
|
||||
<tree string="Access Rules" editable="top">
|
||||
<tree string="Access Rights" editable="top">
|
||||
<field name="name"/>
|
||||
<field name="model_id"/>
|
||||
<field name="perm_read"/>
|
||||
<field name="perm_write"/>
|
||||
<field name="perm_create"/>
|
||||
<field name="perm_unlink"/>
|
||||
<field name="name"/>
|
||||
</tree>
|
||||
<form string="Access Controls">
|
||||
<group col="4">
|
||||
<field name="name"/>
|
||||
<field name="active"/>
|
||||
<field name="model_id"/>
|
||||
<newline/>
|
||||
<field name="perm_read"/>
|
||||
<field name="perm_write"/>
|
||||
<field name="perm_create"/>
|
||||
<field name="perm_unlink"/>
|
||||
</group>
|
||||
</form>
|
||||
</field>
|
||||
</page>
|
||||
<page string="Record Rules">
|
||||
@@ -105,7 +93,6 @@
|
||||
<tree string="Record Rules" editable="top">
|
||||
<field name="name"/>
|
||||
<field name="model_id"/>
|
||||
<field name="global"/>
|
||||
<field name="domain_force"/>
|
||||
<field name="perm_read"/>
|
||||
<field name="perm_write"/>
|
||||
|
||||
Reference in New Issue
Block a user