100 Commits
Author SHA1 Message Date
Alvaro FuentesandChristophe Simonis c18b9f44be [IMP] *: optimize multi-company rule
When we use the `|` (or) version of this rule the ORM generates two
sub-queries when checking the company. This causes sub-optimal and in
some cases really bad planning for the queries and thus PG takes hours
to complete them.

Example (formatted):
```sql
    SELECT "mrp_routing_workcenter".id
      FROM "mrp_routing_workcenter"
 LEFT JOIN "mrp_bom" AS "mrp_routing_workcenter__bom_id"
        ON "mrp_routing_workcenter"."bom_id" = "mrp_routing_workcenter__bom_id"."id"
     WHERE "mrp_routing_workcenter"."workcenter_id" in (1)
       AND (  ("mrp_routing_workcenter"."bom_id" in (
                    SELECT "mrp_bom".id
                      FROM "mrp_bom"
                     WHERE ("mrp_bom"."company_id" in (1))
                   )
              )
           OR ("mrp_routing_workcenter"."bom_id" in (
                    SELECT "mrp_bom".id
                      FROM "mrp_bom"
                     WHERE "mrp_bom"."company_id" IS NULL
                   )
              )
           )
  ORDER BY "mrp_routing_workcenter__bom_id"."sequence",
           "mrp_routing_workcenter__bom_id"."id",
           "mrp_routing_workcenter"."sequence",
           "mrp_routing_workcenter"."id"
```

If we use the single term version the generated query has only one
sub-query:
```sql
    SELECT "mrp_routing_workcenter".id
      FROM "mrp_routing_workcenter"
 LEFT JOIN "mrp_bom" AS "mrp_routing_workcenter__bom_id"
        ON "mrp_routing_workcenter"."bom_id" = "mrp_routing_workcenter__bom_id"."id"
     WHERE "mrp_routing_workcenter"."workcenter_id" in (1)
       AND (  ("mrp_routing_workcenter"."bom_id" in (
                    SELECT "mrp_bom".id
                      FROM "mrp_bom"
                     WHERE (("mrp_bom"."company_id" in (1))
                        OR  ("mrp_bom"."company_id" IS NULL))
                   )
              )
           )
  ORDER BY "mrp_routing_workcenter__bom_id"."sequence",
           "mrp_routing_workcenter__bom_id"."id",
           "mrp_routing_workcenter"."sequence",
           "mrp_routing_workcenter"."id"
```
In this version PG is able to produce a better query plan resulting in
better execution times.

Also, the `company_id` field is required on some models, so the "= False" comparison is useless.

closes odoo/odoo#159123

X-original-commit: 1b5c41f36801fb886ec591f29dba42787d698526
Related: odoo/enterprise#59378
Signed-off-by: Christophe Simonis (chs) <chs@odoo.com>
Co-authored-by: Christophe Simonis <chs@odoo.com>
2024-03-25 17:50:06 +00:00
Pierre-Yves Dufays 7053e37df1 [IMP] hr(_contract/_fleet): convert hr.plan to mail.activity.plan
We convert the custom plan implementation to use the generic one. As the
generic one can define plans for multiple model. We use the check
dedicated_to_res_model == 'hr.employee' to activate the specific feature for
hr.employee. Indeed, that field contains the model name when the plan is
applicable only for one model.

We also remove the 'launch plan' button as we can now launch a plan directly
from the activities button in the chatter.

Technical notes:
For the activity schedule wizard, we add the support for active_ids and
active_model as default values for res_ids and res_model because it is used as
link in the chatter to launch the wizard and we want to avoid a big migration
by keeping the link identical (and there are probably no simple solution to
keep the same behavior).

HR CONTRACT

Before the first contract date of the first selected element was chosen to
determine the planned due date if all first contract date were different
otherwise the minimum was chosen. So if the selection included 2 different date
among 3, the minimum was chosen but the first if the 3 were different.
With this change, the minimum is always used to determine the default planned
due date.

Task-3390865

Part-of: odoo/odoo#137969
2023-10-12 16:12:09 +00:00
Yannick Tivisse 3c63396e07 [IMP] hr: Add multi company rule on contract types
Part-of: odoo/odoo#105119
2023-08-25 13:58:18 +02:00
Yannick Tivisse b634498fc0 [IMP] hr: Make contract type country specific
Part-of: odoo/odoo#124222
2023-08-17 10:32:49 +02:00
Yannick Tivisse 84e8aa90dd [IMP] hr: Prevent non HR people from accessing employees bank accounts
- Billing officers / HR officers have access to all bank accounts
- Internal users only have access to bank accounts that are not linked to an employee
- Portal/Public users have access to nothing.

TaskID: 3101400
2023-07-05 14:21:28 +02:00
Yannick Tivisse b1f7e56f79 [IMP] base: Remove private res.partner type
- Improve performances, as the ir.rule restricting private partners
  visibility is also applied on res.users by inheritance, on each
  prefetch.
- Solve the issue of partners set as followers on records (eg: application
  form) and then made private, making them impossible to contact via the
  chatter.
- Solve the multiple access issues when trying to access the bank
  account, or the private address for non HR people like the accountants
  forcing the usage of sudo in the business code.

TaskID: 3101400
2023-07-05 14:21:28 +02:00
Louis Wicket (wil) 9afe7c74c9 [IMP] *: remove "French spacing" 👺
According to Wiktionary, French spacing is "the archaic practice (though
still current in French) of inserting a space around colons, semicolons,
question marks, and exclamation marks". This is not standard practice in
English and most languages of the world.

The purpose of this commit is to start purging the code from this typo,
as it may reflect poorly on the software for some people.

closes odoo/odoo#114533

Related: odoo/enterprise#37853
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-03-14 15:52:10 +01:00
Kevin Baptiste 901e3814fc [IMP] hr: allow users to manage plan activities
When starting an onboarding/offboarding plan on an employee, activities
were only created for the users that were part of the HR Officer group.

Regular users can't access the `hr.employee` model and it's not possible
to have activities on `hr.employee.public`.

A new model has been created to manage those activities and is only
accessible to the user and their manager.

task-3151758

closes odoo/odoo#111505

Signed-off-by: Kevin Baptiste <kba@odoo.com>
2023-02-14 15:52:03 +01:00
Dossogne Bertrand 3f3d4370e8 [FIX] hr: allow onboarding plan access for officers
taskID 2969653

closes odoo/odoo#99407

Signed-off-by: Kevin Baptiste <kba@odoo.com>
2022-09-15 19:20:49 +02:00
Dossogne Bertrand 0a8c3e7451 [IMP] hr_*: improve web application submission
hr_*:
hr
hr_contract
hr_recruitment
website_hr_recruitment

Increase UX and possibilities to postulate to a job on recruitement.
Also moves the model hr.contract.type from hr_contract to hr so that it
can also be used from hr_recruitment without having two models in parallel.

taskID 2898063

closes odoo/odoo#96551

Related: odoo/enterprise#29777
Related: odoo/upgrade#3861
Signed-off-by: Kevin Baptiste <kba@odoo.com>
2022-09-07 23:10:25 +02:00
William Braeckman b4f77a5362 [FIX] hr: fix access error on language change
Backport of odoo/odoo#81474
Before odoo/odoo#86889 a regular user with employees in multiple
companies was not able to change his own language due to a chain of
event calling onchange on all the employee_ids and employee_ids on
res.users being read as sudo.
The fix does work but was wrong because it gave access to the user's
public employee regardless of the active company_id
A domain was added to employee_ids to make force the security rules even
in sudo.

closes odoo/odoo#94618

X-original-commit: 90cec4073e065c142043fcea1d68a10c7cb72e73
Signed-off-by: Kevin Baptiste <kba@odoo.com>
Signed-off-by: William Braeckman (wbr) <wbr@odoo.com>
2022-06-25 10:50:48 +02:00
Victor Feyens 131c19f2d8 [FIX] hr: settings user doesn't have access to hr.employee
The field pos_employee_ids (pos_hr) links hr employees records to 
settings records
but this model isn't readable for Pos Administrators by default.

This commit gives read rights on hr.employee model to settings users,
reusing a confusing existing ACL whose name targeted system users,
whereas the group effectively targeted was the internal users.

Since this rule didn't give any rights, we might as well correctly 
replace
it so that the name can match its purpose.

Part-of: odoo/odoo#91909
2022-06-23 23:48:31 +02:00
Dossogne Bertrand 605a3c1e44 [IMP] hr_*: uniformize group category
*:
approvals
hr_apprasaisal
hr_payroll
hr_referral
fleet
hr
hr_attendance
hr_holidays
hr_recruitment
lunch

Change various access rights names to improve understandability for users.
Addition of an officer role in fleet with intermediate accesses

TaskID 2742855

closes odoo/odoo#87545

Related: odoo/enterprise#25741
Signed-off-by: Kevin Baptiste <kba@odoo.com>
2022-05-03 14:38:19 +02:00
Abdelouahab (abla) d44af30816 [FIX] hr : fixing access rule to be able to update its own res users record
To reproduce
============

- Connect with Mitchell Admin

- Go to Employee -> Settings and uncheck "Skills Management"

- Go to Settings -> Users, create a user "Test" and give him access to 2 companies (e.g. My Company [San Fransisco] and My Company [Chicago])

- Set current company to My Company [San Fransisco], go to Employees, create an employee record and associate it with your test user (in HR Settings tab)

- Set current company to My Company [Chicago] and create another employee and associate it with your test user too

- Connect as "test" user and go to my profile

- Try to change your langage (From English US to French) ==> Access rights error

Purpose
=======

When the `OnChange` is triggred we try to read the two employees linked to this user, but one of this employees is in unslected company
which leads to Access rights error.

Specification
=============

To solve the issue the domain in the security rule **Employee multi company rule** has been updated, where we added the condition
`('user_id', '=', user.id)` which gives the user the ability to read the needed data.

opw-2793123

closes odoo/odoo#87244

X-original-commit: 5916e15f6fa29fd89e12472b316475e757001945
Signed-off-by: Kevin Baptiste <kba@odoo.com>
2022-03-25 10:23:20 +01:00
William Braeckman 60ee56c0ed [REV] hr: revert commit 0e12620
Reverts commit 0e126201bf801e20412ae2b4cdf07e4a600adbd1
from PR #79472

TaskId-2715341

X-original-commit: bf1b27f9a77b42cd969a5129f67b9ffb0feed656
Part-of: odoo/odoo#81612
2021-12-17 16:58:09 +00:00
Philippe Wauthy 1db8dc26c7 [FIX] hr: update accesss right for hr_employee
In a multi-company environment, it is not possible to update information (language, email,...) from My Profile.
The security rule only allows to change information if the right company is selected or if the user has no company.
Since a user assigned to several companies will have several records in hr_employee referring the same user_id, the security rule is now updated to allow updating information from the My Profile page if the hr_employee.user_id refers to the current user_id.

task-2678411

closes odoo/odoo#80637

X-original-commit: 3e9393c71ccf1b00c051155afd68b3a0cfff05cd
Signed-off-by: Kevin Baptiste <kba@odoo.com>
2021-11-30 17:40:04 +00:00
Kevin Baptiste 3cad69a838 [IMP] hr: make Plan company dependent
It was possible to assign a user that was not part of the same company
as the employee's for an activity which is misleading.

Make hr.plan and hr.plan.activity.type company dependent.

closes odoo/odoo#77524

Related: odoo/upgrade#2879
Taskid: 2658773
Signed-off-by: Kevin Baptiste <kba@odoo.com>
2021-10-15 07:24:38 +00:00
sofiagvaladze b320c789a0 [IMP] hr:revert plan automation on triggers
task - 2628793

closes odoo/odoo#75528

Related: odoo/enterprise#20430
Related: odoo/upgrade#2776
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2021-08-27 17:43:23 +00:00
William Braeckman 864595901e [IMP] hr,hr_payroll: plan automation on triggers
Automate activites linked to plan on certain triggers.
To automate onboarding and offboarding processes, we can now define
plans that will activate upon triggers, such as employee creation,
departure (archive), contract start or contract end.
Manual plans are still possible.

Upon activation of a plan, a message will be added to the employee's
chatter with the name of the plan.

More options have been added related to when to schedule the plan's
activities.

The blocking mechanism has been removed (the plan would not launch if an
activity could not be started, due to lack of information), failed
activities will now be logged into the employee's chatter.

The list and kanban employee views have also been updated to include
info such as first contract date and activity information.

Task ID: 2489095

closes odoo/odoo#68451

Related: odoo/enterprise#17343
Related: odoo/upgrade#2314
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2021-06-03 12:09:32 +00:00
Kevin Baptiste 5f98b6acdb [IMP] hr: add a model for departure reasons
The "Departure Reasons" where hardcoded and couldn't reflect all the
valid departure reasons (like "End Of Fixed-Term Contract").

This commit introduces a new model `hr.departure.reason`.

closes odoo/odoo#66905

Taskid: 2447056
Related: odoo/enterprise#16709
Related: odoo/upgrade#2211
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2021-03-10 08:32:36 +00:00
Kevin Baptiste 3d5e912da7 [IMP] hr: add a model for work locations
The work location of an employee was previously a fields.Char. That was
changed to a Many2one field to a the new model called work.location.
That had some consequences in other modules that had to be slightly
adjusted.  The modules impacted were hr, hr_appraisal, hr_payroll.

Task id: 2335646

closes odoo/odoo#63192

Related: odoo/enterprise#15235
Related: odoo/upgrade#2020
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2021-02-05 13:00:09 +00:00
Martin Trigaux 8f57863707 [IMP] *: remove access to ir.property
Only administrators can access properties and configure them.
ir.property may contain sensitive information and should only be
accessed via code call to specific methods
2020-05-26 15:50:11 +02:00
Victor Feyens 532c083cbb [IMP] *: remove global field definition in ir rules xml
It is a computed field, there is no need to manually set its value.
2020-03-20 16:15:40 +01:00
Martin Trigaux 65530dfd6a [ADD] *: add ir.model.access on all transient models
Following changes needing ir.model.access on transient models too.
Remove groups declaration on the action to move it to ir.model.access
when possible.
Rules are strict by default with no unlink access by default and high
priviledge asked. Adaptations may be needed later.
Write access is given as a wizard may need to be modified in case the
action triggers an error and the user has to correct a value

account*: use account.group_account_user for all transient by default
	  remove account.print.journal relic
stock*: use stock.group_stock_user by default
survey: survey user can send invitations
mail: allow any employee to execute wizards
      additional verifications are made to ensure they are executed
      only on the documents the user has access to you
      give portal access to mail.compose.message as portal still does
      some actions like posting messages on the forum
      add ir.rule to avoid reading somebody else messages
      increase the query count because of undeterminist count
crm: saleman for lead2opp, manager for massmailing
     partner manager for actions linked to partners
     avoid a write in test_lead_lost
sms: any employee can send sms
mrp: mrp user can execute wizards
     give unlink access as making write during do_produce operation
base_import: employees can import files
delivery: stock user can deliver
event_sale: sale user can configure the wizards
	    event user inherit from  sale rights
gamification: employee can give badge
google_service: resolve FIXME
hr: add specific rights
    manager can set a plan according to group on button
    anyone who can write on an employee can register a departure
hr_expense: set rights based on buttons
hr_holidays: an approver can make a summary report
hr_recruitment: recruiter can refuse a candidate
hr_timesheet: can use the wizard if can create a timesheet
l10n_eu_service: managers can create fiscal positions
mass_mailing: same group as on mass.mailing.list
membership: accountant can create invoice from membership
payment: accountant can create a link
	 as the source is an account.move
	 keep the payment.acquirer.onboarding.wizard to system user
	 only as it is called during company configuration
point_of_sale: PoS manager only can use wizards
	       never create closing_balance_confirm_wizard records
product_expiry: stock user has rights on stock.picking
product_margin: access from accounting menus
repair: same rules as for above models
sale: set ir.rule for self wizard only
      add rule from model introduced in payment to add salesman group
sale_crm: saleman can create a quotation from a lead
sale_coupon: any saleman can generate coupon
	     add self ir.rule
sale_product_configurator: salesman can select product variants
snailmail: employee can send letters
website: designers can write on website
website_crm_partner_assign: same rule as group on action
website_sale: sale ACL as for payment.acquirer.onboarding.wizard
website_slides: anyone can send invitation

base: base.language.*: allow employee (cf lang_install)
      change.password.user: can not read change password wizard of
      other users
      test.*: no access is needed

Courtesy of Damien Bouvy, William Andre and Antoine Prieëls for review
of acl
2020-02-04 17:54:18 +01:00
RomainLibert c9ca376146 [IMP] hr: Introduce the public employee profile
Purpose
=======

1/ Robustness & security: right now it is not easy to understand and do something
   clean in term of security (hr people vs employees, private info vs public). A
   HR officer doesn't know if he can write something on the chatter. Currently, a
   note will be visible for all the employees who have access to the employee form
   view for example.
2/ In term of business, it makes sense to let a hr manages payroll stuff (contract,
   employees private information, ... and other employee see public information
   (résumé and work information)

Specification
=============

Introduce 2 new models:

- hr.employee.base (AbstractModel): This represents the basic skeleton
  model on which the shared fields and methods between the public and
  the private employees models.
- hr.employee.public (_auto=False): This is a sql view based on the
  employee values, readable for an internal user (i.e. an employee).

The model hr.employee is not readable anymore for an employee.

There are now 3 ways to access the employee data:
1/ From the hr.employee views. HR officer access rights are required
2/ From the public profile. The public data for an employee are accessible
   but can't be modified.
3/ From the 'My Profile' menu. A classic employee can access its own
   data from there, and can modify them.
2019-05-31 10:21:20 +02:00
Yannick Tivisse a5b6f31cf2 [IMP] base: Contextualize the multi company
Purpose
=======

Allow the user to select the allowed companies for which he wants to see records
on top of selecting his current company.

It is confusing for users to see the records from the company he is connected to
and the records of the children companies.

Instead of using the hierarchy of companies to access records across companies,
the user can now select (from his set of allowed companies) the companies for
which he wants to access records.

/!\ This means that the user will interact with records from company A when in
company B.
Example: a SO has been created and confirmed in A. When in B, I create the
invoice from it.

Specifications
==============

1/ Deprecate the parent/children hierarchy on the res.company model. The fields are
kept on the res.company model to ensure the retro-compatibility, but won't be used
accross the standard code anymore. The only functional usage for this mechanism
was to allow to see records from several companies by creating a virtual parent
company, which will be possible with the new mechanism.

2/ By default, a user will only see the records of the company he is connected
to (or records without a company). (It is still editable by the user if needed).
For that, put this information in the user context, to allow having different
configurations on different browser tabs. Instead of having domains like
['|',
('company_id', '=', False),
('company_id', 'child_of', user.company_id.id)]
you'll have something like
['|',
('company_id', '=', False),
('company_id', 'in', company_ids)]
Note that the 'company_ids' is a value that is passed in the evaluation
context on the record rule, as we already have user, or time.
company_ids is a list of the ids of all the enabled companies in the
user's context.

3/ Out of the generic improvements brought by this task, this will illustrate
issues that could exist since several versions. For example, it should not be
possible to create a scrap order for the company A with a package of the company
B, or it should not be possible to create an invoice on the company A with
payment terms from the company B. Before the version 12.0, it was easy to
encounter this kind of issues as the admin was the SUPERUSER_ID. A positive side
effect of the fact that the SUPERUSER_ID has become an inactive user was to
make it more difficult to introduce mismatch on the records, but haven't solved
the issue, as it was still possible to do it with parent companies
configuration. Some of these issues have been fixed in this commit, but all the
business flows should be re-tested to check if an ir.rule should be introduced
(eg: a multi company rule for stock.quand.package), if the company of a record
is correctly transfered to another record created from the first record (eg:
From a SO, create an invoice and a payment, the company of the sales order
should be transfered on the invoice and the payment, even if the company of the
sales order is A and I'm logged into the company B with the company A enabled.

4/ Currently, if I click on a button on a notification email (example 'View
Task'), I face a traceback if I'm not logged into the company of the record.
Now, if you click on a button and if you have access to the record, the correct
company will be automatically set.

5/ If I display a kanban view with several records from several companies (and
an image), all the images should be displayed.

6/ Currently if you copy paste an url, this will crash if you're not in the
correct company. This won't be fixed because it's quite impossible to do it in
a clean way. This task brings a workaround. Copy/Paste -> Traceback -> Log into
the correct company, re-copy/paste -> Ok.

7/ 2 property methods have been added on the environment to retrieve the company
on which the user is logged in and the companies the user enabled, on a specific
tab.
That way, when creating a record, instead of doing
default=lambda self: self.env.user.company_id
do
default=lambda self: self.env.company_id
On the other hand, to retrieve the enabled companies, do
companies = self.env.company_ids

8/ Modify the Company Switcher widget to allow to log into another company
WITHOUT writing on the res.users (and thus bringing cache invalidation issues
and so on). Also allow to enable several companies and see records from several
companies, and independantly of the other browser's tabs.

9/ When focusing on a tab, save the current company configuration on the local
storage. That way, when doing 'CTRL+T' or a middle click, the context is
propagated to the new tab.

10/ Improve the error message in case of multi company access errors. Now, when
the user is in debug mode, display the related names of the records and the name
of the user who brings the issue.

11/ Remove the context erasing when writing on a res.users
This is probably coming from the migration to new API of the base module.
The context was not propagated at this moment, which was a common mistake at
that time. When migrating the module, probably by using the 'black box' method,
as the context was not propagated, it was erased on the new version. This is
now an issue because the context (i.e. the enabled companies) was erased when
writing on a res.users, leading to tracebacks.
See: https://github.com/odoo/odoo/commit/7eab8e26d3d46c53f4be924d6a34e80a66e74960#diff-4c2e738ee8f64f11806c889ea097b5e7R624

12/ Fix the crash manager on redirect warnings. The issue is the following
- Create an invoice on a company without a configured CoA.
- Set a partner
- On the onchange_partner_id, a redirect warning is raised to propose you
to configure a CoA
- Click on 'Go to the configuration panel'
- A generic warning says something like 'Do you want to discard your changes?'
- Click on yes, the page refreshes, but not on the redirect action.
Now, set correctly the action on the hash, and reload instead. The breadcrumb is
lost for example, but you reach the correct action at least.

13/ Introduce a res.group to enable/disable the multi company per tab
feature.

14/ To help the users to know which tab is in which company, add the
possibility to have a favicon per company. When creating a company,
the classical 'O' icon is colored by default in a random color.

15/ Remove the company switcher on the frontend. This was mainly there
to allow a user to swicth to the company linked to the website.
This behavior is now transparent to the user. If the website A is
activated, then the company set on the context is the company of the
website.

16/ Deprecated the _company_default_get method on the res.company
model. Remove the method _get_company on the res.users model.

17/ Add 'allowed_company_ids' and 'current_company_id' on the pyeval
context. You can now use those variables on domains in the views to
access directly to the activated company.ies on the current tab.

TaskID: 1960971

closes odoo/odoo#32341

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-05-13 08:57:49 +00:00
jbm-odoo ec07e72845 [IMP] base,*: Reorganize access rights groups
Purpose
=======

Access group terminology is missleading. Yous have to be manager to administrate
an application. This task consists to rename groups to be understandable for everyone.

Groups should be reorganised on the users form to be more explicit.

Specification
=============

1/ Rename 'Manager' to 'Administrator' in users groups.
2/ Define a hierarchy on access groups by using the category_id in the manifests
   A category 'Operations/Project' will create a category Project with a parent
   category 'Operations', and something smart is already developed (in modules/db.py)
   to avoid duplicating categories.
3/ Add a group in expenses to be able to approve expenses reports for my team.
4/ Add a group in timesheets to be able to approve timesheets for my team.
5/ Remove partially the useless crap in ir_module_category_data.xml
6/ Sort access rights groups on users form according to its parent category

closes odoo/odoo#29362

Signed-off-by: "Yannick Tivisse (yti)" <yti@odoo.com>
2019-03-05 09:08:12 +00:00
Christophe Simonis 0e7675847f [MERGE] forward port branch saas-12.1 up to 0f4abc5c22 2019-02-22 16:25:02 +01:00
Yannick Tivisse 8fa8ffdf27 [FIX] hr: Add a multi company ir.rule on hr.employee model 2019-02-18 15:28:15 +00:00
RomainLibert d5fd84b89a [IMP] hr: add onboarding/offboarding activity plannings
Purpose
=======

Give the possibility to elaborate plans through Odoo. For instance, in HR,
you could create an onboarding plan when a employee is created. Someone manages
laptop and other equipment, someone check hr stuff, ... This feature is generic
but in a first time we will apply it only on the hr module.

Ease HR process in a company by creating plans: a plan is an assembly of Next
Activities that will be launched together whenever you need it.

Example of plan for an employee onboarding:

Activity: Prepare materials
Responsible: Alain
Deadline: At the contract signature

Activity: Manage Cars
Responsible: Cécile
Deadline: at the contract signature (both signature)

Activity: Plan Training
Responsible: Caroline
Deadline: After signature

Activity: Training
Responsible: Employee
Deadline: 1 week after the employement date

Specifications
==============

On HR Configuration: Add a menu "Activity Plans"

Activity plan object:
 - Name
 - Model (debug mode) (hr by default)
 - Activity Template o2m
    - Activity Type (only the one related to hr)
    - Deadline (come from Activity Type)
    - Responsible \/
        0  Coach
        0  Manager
        0  Other
        [Responsible_name] \/  (coach, manager or manually set if other)

Add datas, 2 plans:

Onboarding
    - Name: Onboarding
    - Plan lines:
        Activity: Setup IT Materials
        Responsible: [a user] (manager)
        Deadline: At the contract signature

        Activity: Plan Training
        Responsible: [manager]
        Deadline: After signature

        Activity: Training
        Responsible: [Employee]
        Deadline: 1 week after the employement date

Offboarding
    - Name: Onboarding
    - Plan lines:
        Activity: Compute Out Delais
        Responsible: [a user] (manager)
        Deadline: today

        Activity: Take Back HR Materials
        Responsible: [manager]
        Deadline: today

        Activity: Manage Car
        Responsible: [manager]
        Deadline: today

When to trigger it ?

HR specific use case:

1/ On employee, from the employee chatter:
when you create an employee, Odoobot will log a note with the following message:
"Congratulations ! May i recommand you to setup an onboarding plan?", with a link
create a plan from it.

2/ Add a button 'launch plan' to open a wizard to select the plan

3/ When archive an employee
Open a wizard with:
    - Reason (selection)
    - Action plan (m2o not required)

Error if employee not linked to a user.

Task : 1912681

closes odoo/odoo#29151
2018-12-18 11:20:54 +00:00
Christophe Simonis a7a30791de [MERGE] forward port branch saas-11.4 up to a5187cef10 2018-08-27 11:16:44 +02:00
Raphael Collet 2f7c03d9ca [IMP] base: add regular user admin as uid 2
User 1 simply becomes a technical user (inactive, no password).
2018-08-23 21:38:57 +02:00
Martin Trigaux 44d92b560a [IMP] hr: rephrase help message
Courtesy of Yenthe Van Ginneken
2018-08-23 09:51:11 +02:00
Jeremy Kersten d5b0f99943 [FIX] hr: security - an officier is an employee/internal user
Tests from hr_recruitments work luckily until now.
Because module maintenance imply base.group_user for group_equipment_manager

    <record id="group_equipment_manager" model="res.groups">
        ...
        <field name="implied_ids" eval="[(4, ref('base.group_user'))]"/>
    </record>

and module hr_maintenante imply group_equipment_manager for hr_user

    <record id="hr.group_hr_user" model="res.groups">
        <field name="implied_ids" eval="[(4, ref('maintenance.group_equipment_manager'))]"/>
    </record>

After this commit launch test on hr_recruitment module without any other module will works.

Design-theme repo show this error because repo tests hr_recruitment without installing maintenance
(Repo install website_* modules -> website_hr_recruitment -> hr_recruitment -> hr)
2018-08-15 16:23:23 +02:00
Yannick Tivisse 2f15a5fa64 [IMP] base: Add support for private addresses
Purpose
=======

Add the possibility to create private addresses, only accessible for a subset
of users.

Specification
=============

- Add a new 'Private' partner type
- Add a res.groups in base 'Access to Private Addresses'
- Add ir.rules for the following behavior:
    - Every employees/internal users can read non-private addresses
    - Only users in group_private_addresses can access private addresses
- Add in base a simplified form view for private addresses
- A HR Officer is automatically granted in group_private_addresses
- Use the simplified form view to open the address_home_id form on employees
2018-05-04 13:17:25 +02:00
Yannick Tivisse 99f497b390 [IMP] *: Define groups on res.users models
The reified view on the res users will be dropped in the following commit.

The previous commit adds support to define each group as a computed field on the res users.

This commit defines:
- A boolean field for each 'isolated' res.group, i.e. a group in the hidden category.
- A selection field for each 'Application' res.group, i.e. a group in a application category.

Example:
- The group to manage pricelist in sales becomes a boolean field
- The groups project user/manager become a selection field
2018-04-26 15:13:38 +02:00
Viral Thakar f53f6f865b [IMP] hr,mail: adapt tooltip message to new field values and fix a typo 2017-12-13 11:16:05 +01:00
Martin Trigaux 998a1aee3b [IMP] hr: remove useless group description
The group is in base, this is where the group should be described.
Manage your "own stuff" is probably not very informative anyway.
2017-10-02 13:58:01 +02:00
Denis Vermylen 1c2e3d3838 [FIX] hr_attendance, hr_*: move group_hr_attendance to hr_attendance
move group_hr_attendance from hr -> hr_attendance where it belongs.
2017-01-26 19:19:19 +01:00
Martin Trigaux 11812b0b9e [FIX] all: remove external ids fakely from base
Several modules defines records with the external ID `base.foo_bar` while it is
created inside this module (typically menus and groups).
While there is no technical reasons to do so but this may introduce issues:

- these records will not be deleted during uninstall
- if a language is loaded before the installation of the module, it won't be
  translated

The uninstallation will only remove the records with an external id linked to
this module (these would only be removed when removing base).

Installing a language before the module will drop the translations not linked
to an existing external id (as it can not be resolved).

This commit correct all the external ids tagged as from base or other incorrect
modules.
2016-09-02 16:14:26 +02:00
Yannick Tivisse ff63f5d0a3 [IMP] base_setup: Allow the admin to modify the default user acess rights
Add a link in the general settings to access easily the default_user form view in order to modify the default access rights

The default_user manager rights declarations in all the applications have been move in a noupdate="1" definition to avoid the manual configuration overwrittings
2016-08-23 11:14:37 +02:00
Ravi Gohil 44c62e1b7f [MIGR] hr : migrate to new api
- Rewrite the code to new api without changes
business behavior
- Remove old v7 backward compatibility method
- Regroup view definitions in the same xml file
- Use read_group for computed fields
2016-04-13 12:28:34 +02:00
Yannick Tivisse 1ecba213f4 [IMP] Newly created users get all manager access right
Coming from a bug in web_settings_dashboard. Invited user didn't have any rights
when created from the dashboard, which was leading to an error.

This bug leaded to a new discussion. Better to have basic employee having user
rights for all main applications. For bigger entreprises there is an admin that
will carefully remove extra rights, if necessary. The target is small businesses,
it makes sense that every way to create a user gives the same result.

In conclusion, each new user has a full access to the applications by default

How is it implemented ?
We added an inactive default user which original access right to the groups
'base.group_user' and 'base.group_partner_manager' in base. Each
application will extend the default user's access right by adding the maximal
access right for this application.

On user creation, we will use by default the 'group_id' field from the default
user. We will in the same time remove the ugly 'default_groups_ref' key which
was passed sometimes in the context for some fields in some views, and sometimes
nothing.

So, the user can modify the access rights for the default user, but he should be
aware that removing project user access rights for a default user will prevent
a *created on the fly in a task* user will not be able to access the task.
2015-11-20 16:27:32 +01:00
Yannick Tivisse 024546919e [IMP] employees form view : Usability improvements
- remove otherid field from the model, and the reports
    - reorganize several fields on the form
    - removed group_multi_department group, departments are always activated,
      as 3 departments are now in the datas
    - departments menuitem is accessible to the hr officers and managers only
    - removed all the configurations in the employee root menu
    - moved payroll country module selection to payroll configuration
    - removed useless fields from the form : attendance state, goals_ids,
      remaining leaves, as they are accessible via stat buttons, kanban views, etc.

Conflicts:
	addons/hr/hr_view.xml
	addons/hr_holidays/hr_holidays_view.xml
2015-06-23 16:08:19 +02:00
Thibault Delavallée b865005fca Revert "[IMP] HR Usability cleaning"
This reverts commit 79c338dcb352be3d40118f998a76e1b7576a35da.
This commit has been done hastily without review. Moreover it
mixes changes related to different stuff.

The commit is then reverted to allow a propre review and cleaning
of the branch.
2015-06-09 12:52:03 +02:00
Yannick Tivisse 4997c18a8e [IMP] HR Usability cleaning 2015-06-09 12:52:03 +02:00
Gaurav Panchal 6e14dd0ef9 [IMP] config: various improvements
- sales_team: demo data enable sales team features to users
- hr_attendance: admin can enable attendance features from hr settings
- multi_company: if admin enable these features, she gets the
  multi-company usability settings
- account: enabling multi-currency functionalities enable pricelist
  functionalities
2015-03-31 17:31:11 +02:00
dka-odoo d27910a8f2 [IMP] hr_department: new kanban view for HR Departments.
hr add a simple kanban view that is updated by the various hr modules.
Each module adds statistics and links in the kanban vignette, either
in a to do or to approve column.

The department kanban view can be seen as a small dashboard to have
the main data about the department displayed. Links allow the HR
manager to be redirected towards the various things to do or to
approve in its department.
2015-02-25 11:25:40 +01:00
Xavier Morel 7a2d912964 [REM] bunch of nonsensical @model + @ref
bzr revid: xmo@openerp.com-20130429124333-p1h11fpy04y3sljy
2013-04-29 14:43:33 +02:00
Olivier Dony 3fe6987ce7 [MERGE] Harmonization of noupdate flag on security XML data, courtesy of Alexis de Lattre (Akretion)
ir.rule records are in noupdate data blocks to let the admin
alter them without fear of them being reset at next update.
Other records such as groups are in normal mode, so they
can be updated whenever necessary

bzr revid: odo@openerp.com-20121218232001-t425t4hi7qbmsip2
2012-12-19 00:20:01 +01:00