The ERP managers (users with 'Access Rights' rights) cannot even click on
the Settings app menuitem. Because of 2 things:
- The Dashboard settings is accessing the model ir_module_module. So
we set a groups 'group_settings' on it.
- The Users view is accessing the model ir_module_category to groups
the aggregate and display the settings. So we change the security rules
by giving the access to the group_erp_manager instead of group_settings
- The global rules opn companies was applied to the erp managers. We
splitted this ir.rules into three new ones on portal,public and employee
users to allow the erp managers to access the companies
- Writing on the res_groups was calling the method _update_user_groups_view
in all the cases. This method should be called only when the view was
needed to be modified, i.e. when the category_id is modified for this
group.
Searching on `log_ids` field is slow when there is a lot of users.
Count the number of active/pending users directly in sql.
Only show the last 10 pending users. Add a link to the full list view.
Writing frequently to master data, and particularly to res.users
records is dangerous because it can temporarily delay/abort
concurrent transactions due to FK locking/serializability
heuristics. (Even with PostgreSQL 9.3+)
The `login_date` field updated when a user is authentiocated
is still useful but better handled in a separate table that
exclusively receives independent INSERTs (no UPDATE/DELETE).
This minimizes the chances of transactional conflicts.
This commit moves the login_date info into a separate
`res.users.log` table for this purpose, replacing it
with a related field. The user and login date info are
automatically handled by the magical fields (create_uid,
create_date) in `res.users.log`.
The related field must not be stored because that would
create the same problems as the original field.
In order to cleanup redundant entries in res.users.log
the 'auto-vacuum' cron job used for TransientModels was
extended to be a generic "internal data vacuum cleaner",
and now takes care of this as well.
The code for updating last login and vacuuming was split
up into smaller methods to make extensions easier.
Fixes#8585Fixes#8590
Now that most refactoring has been merged
It is better to have red a great work of another culture in translation than never to have read it at all.
― Henry Gratton Doyle