diff --git a/odoo/addons/base/ir/ir_model_view.xml b/odoo/addons/base/ir/ir_model_view.xml index 5090ca70d96..39d7db4bc85 100644 --- a/odoo/addons/base/ir/ir_model_view.xml +++ b/odoo/addons/base/ir/ir_model_view.xml @@ -160,22 +160,25 @@ - + + - - + - + @@ -525,7 +528,10 @@ ir.model.access - + @@ -539,7 +545,7 @@ ir.model.access -
+ @@ -560,8 +566,8 @@ ir.model.access - - + + @@ -577,7 +583,7 @@ - Access Controls List + Access Rights ir.model.access form diff --git a/odoo/addons/base/ir/ir_rule_view.xml b/odoo/addons/base/ir/ir_rule_view.xml index 2d551832b36..c4f0ca99967 100644 --- a/odoo/addons/base/ir/ir_rule_view.xml +++ b/odoo/addons/base/ir/ir_rule_view.xml @@ -6,11 +6,15 @@ +
+ +
- @@ -25,31 +29,36 @@ - - -
+ +

Interaction between rules

+
+

+ Global rules (non group-specific) are restrictions, and cannot be bypassed. + Group-specific rules grant additional permissions, but are constrained within the bounds of global ones. + The first group rules restrict further the global rules, but can be relaxed by additional group rules. +

+

+ Detailed algorithm: +

    +
  1. Global rules are combined together with a logical AND operator, and with the result of the following steps
  2. +
  3. Group-specific rules are combined together with a logical OR operator
  4. +
  5. If user belongs to several groups, the results from step 2 are combined with logical OR operator
  6. +
+

+

Example: GLOBAL_RULE_1 AND GLOBAL_RULE_2 AND ( (GROUP_A_RULE_1 OR GROUP_A_RULE_2) OR (GROUP_B_RULE_1 OR GROUP_B_RULE_2) )

+
+
ir.rule - - + - + + + diff --git a/odoo/addons/base/res/res_users_view.xml b/odoo/addons/base/res/res_users_view.xml index 99156eb4144..ef6d8f76026 100644 --- a/odoo/addons/base/res/res_users_view.xml +++ b/odoo/addons/base/res/res_users_view.xml @@ -78,26 +78,14 @@
- + + - -
- - - - - - - - - - -
@@ -105,7 +93,6 @@ -