Commit Graph
84 Commits
Author SHA1 Message Date
mreficent 0632274451 [IMP] base: add hook to be able to hide more module categories
closes odoo/odoo#32662

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2019-05-10 10:21:44 +00:00
Raphael Collet f44571f550 [IMP] base: remove mapped() where not necessary 2019-04-30 07:54:49 +00:00
Christophe Simonis 44515bc7be [MERGE] forward port branch saas-12.2 up to c9f832d9f0
closes odoo/odoo#31790

Signed-off-by: Christophe Simonis <chs@odoo.com>
2019-03-13 14:24:51 +00:00
Christophe Simonis 71faa19af0 [MERGE] forward port branch saas-12.1 up to 2b3296bbf8 2019-03-11 14:42:34 +01:00
Christophe Simonis 2c5c9b8342 [MERGE] forward port branch 12.0 up to c023d0784f 2019-03-08 17:56:14 +01:00
jbm-odoo ec07e72845 [IMP] base,*: Reorganize access rights groups
Purpose
=======

Access group terminology is missleading. Yous have to be manager to administrate
an application. This task consists to rename groups to be understandable for everyone.

Groups should be reorganised on the users form to be more explicit.

Specification
=============

1/ Rename 'Manager' to 'Administrator' in users groups.
2/ Define a hierarchy on access groups by using the category_id in the manifests
   A category 'Operations/Project' will create a category Project with a parent
   category 'Operations', and something smart is already developed (in modules/db.py)
   to avoid duplicating categories.
3/ Add a group in expenses to be able to approve expenses reports for my team.
4/ Add a group in timesheets to be able to approve timesheets for my team.
5/ Remove partially the useless crap in ir_module_category_data.xml
6/ Sort access rights groups on users form according to its parent category

closes odoo/odoo#29362

Signed-off-by: "Yannick Tivisse (yti)" <yti@odoo.com>
2019-03-05 09:08:12 +00:00
Lucas Lefèvre d77ce4c2a9 [IMP] hr_*: introduce the employee profile
General Purpose
===============

We want an 'Employee profile' gathering every data about an employee.
The main form view is modified to become this employee profile.
A user can also see his own profile through the Preferences menu.
The new profile replaces the current Preferences view if the hr module is installed
and the current user is linked to an employee.

A user should be able to see and edit his own profile.

*Problem*:
Many fields on hr.employee are protected by groups="hr.group_hr_user".
Therefore, a regular user cannot see or edit those fields.

This protection must be bypassed to allow read/write access
to the regular user's own data.
A similar mechanism already exists for res.users (for Preferences)

The better (least worst) solution found is to reuse this mechanism by adding related fields on res.users.

Pros:
- Don't change security access on hr.employee
- Don't implement yet another custom security layer, risking to add new security breaches
- A lot of fields are added by other modules on hr.employee.
  It would have required to integrate them with the custom security layer.
- Fields added by other modules on the user's preferences view (normal view, not the profile)
  are automatically included in the employee's profile view.
- Allow the hr.employee form view to be different than the user profile accessible
  through the Preferences menu.
  E.g. add custom buttons only relevant to the logged in user such as "Request a leave".
Cons:
- Each field from hr.employee that you want to appear on its profile
  must be added as a related field on res.users
- Those related fields must be added to user's preferences view (duplicate views)
- They also must be added to SELF_[READABLE | WRITABLE]_FIELDS

Note:
When the front-end loads the views it gets the list of available fields
for the user (according to its access rights). Later, when the front-end wants to
populate the view with data, it only asks to read those available fields.
However, in this case, we want the user to be able to read/write its own data,
even if they are protected by groups (groups are kept on the related fields on res.users).
The front-end need to be made  aware of those fields by sending all field definitions.

hr_attendance
=============

This commit integrate attendance in the new employee profile.
It also adds a stat button to this employee profile showing
the number of hours worked last month.

Remove the boolean computed field 'manual_attendance'.
This field is just a shortcut to add/remove the employee's user
in the "Manual Attendance" group.
The checkbox is confusing on the employee's form and this should
be done through the normal group management screens.

hr_presence
===========

Display the presence status on the employee kanban template.
The status is a colored chip which can be green (present),
orange (to define) or red (absent).

Currently, the presence status is only computed when accessing
the report view. As this commits displays it on the employee kanban,
it should be updated more frequently.
The state should not be updated every time the kanban view is loaded
since the computation is a bit heavy. Instead: add a cron to update
status every 15 minutes.
-> The status is accurate on the report view (status is still updated
   when loading the view)
-> The status in accurate at 15 minutes on the kanban view

[ADD] hr_attendance_presence
============================

Bridge module between hr_attendance and hr_presence.

This commit integrates hr_presence module in the employee
profile and adds the presence status on the employee kanban view.
But hr_attendance adds at the same place a similar status icon for
checkin/checkout.
This bridge module makes the status from hr_presence invisible as
hr_attendance should be the main presence control mechanism.

Also, this commit adds the ability (through a new setting option)
for hr_presence to take into account checkin/checkout to determine
the presence status.

l10n_be_hr_payroll
==================
integration with employee profile
2019-02-14 16:28:54 +01:00
Christophe Simonis 87924cb5ad [MERGE] forward port branch 12.0 up to a46138cb01 2019-02-07 13:14:02 +01:00
RomainLibert 5fcf891e07 [IMP] various: optimize _name_search
In the overrides of _name_search we should avoid creating domains with
huge lists of ids as it is inefficient.
We can also make sure that we optimize the empty search as in this case
the custom domain doesn't make sense, we can simply search on an empty
domain and, thanks to the limit argument, still keep a fast query.

Linked to task 1918906

Thanks to @odony and @nseinlet

closes odoo/odoo#30155

closes odoo/odoo#30887
2019-02-06 13:26:33 +00:00
Christophe Simonis f927c68ddb [MERGE] forward port branch 12.0 up to cb8fefa899 2019-01-31 16:59:58 +01:00
RomainLibert 6dbdfb9bf7 [IMP] various: optimize _name_search
In the overrides of _name_search we should avoid creating domains with
huge lists of ids as it is inefficient.
We can also make sure that we optimize the empty search as in this case
the custom domain doesn't make sense, we can simply search on an empty
domain and, thanks to the limit argument, still keep a fast query.

Linked to task 1918906

Thanks to @odony and @nseinlet

closes odoo/odoo#30155
2019-02-05 11:44:21 +00:00
Lucas Perais (lpe) 897834f406 [FIX] base: res_users form message partner active correct condition
Before this commit, the condition and the field on which it applied were wrong
That is, when both the user and the partner were inactive, the message saying that
the partner was still active displayed anyway

After this commit, we show the message only when the user is inactive but its
directly related partner is still active

OPW 1928247

closes odoo/odoo#30337
2019-01-18 10:07:26 +00:00
Christophe Simonis 6a0675d36d [MERGE] forward port branch saas-11.3 up to e033114879 2019-01-11 18:56:24 +01:00
Christophe Simonis d11dc31e7a [MERGE] forward port branch 11.0 up to 617652bbfe 2019-01-10 17:59:26 +01:00
Christophe Simonis 3cbc9dd6c0 [MERGE] forward port branch 12.0 up to 6a0675d36d 2019-01-14 10:34:50 +01:00
Christophe Simonis efe7ca16b7 [MERGE] forward port branch 11.0 up to bb6f6c57f9 2018-11-28 17:44:46 +01:00
Adrian Torres 52f5528cfb [REF] *: replace deprecated pycompat helpers for builtins
This commit replaces calls to pycompat helpers that were intended for
python 2 <-> python 3 interoperability for python 3 builtins, as python
2 is no longer officially supported by Odoo.

This includes:
    * calls to imap/izip/ifilter replaced by map/zip/filter
    * uses of text_type replaced by str
    * uses of unichr replaced by chr
    * calls to implements_to_string, implements_iterator removed
    * string_types and integer_types replaced by str, int respectively
    * calls to to_native replaced by calls to to_text

This is done in preparation to the removal of these deprecated helpers
in the following commit.
2018-11-29 09:28:17 +00:00
Jorge Pinna Puissant f206714af0 [FIX] base: creation of portal user
When creating a portal user from the User & Companies menu in the
Settings.

Before this commit, the created user had both groups' portal user and
internal user, which generated an error in the display of the user
accesses and rights. This also occurred if we manually add a portal
user to the internal user group.

Now, when creating a portal user, the user only has this group. Also,
if we manually add a portal user to the internal user group, an error
is raised to inform that only one user type is allowed.

OPW-1929367

closes odoo/odoo#30958

Signed-off-by: "Lucas Perais (lpe)" <lpe@odoo.com>
2019-02-26 09:07:45 +00:00
Christophe Simonis b106b7ce0b [MERGE] forward port branch 12.0 up to dd70c68426 2018-11-06 16:40:07 +01:00
David BeguinandFMDL 0b1a3da01f [IMP] base : adds direct access to groups, record rules and access rights from user form
Adds 3 smart buttons with count to see :
- Groups
- Access Controls
- Record Rules
Buttons available in debug mode only
Every user that have access to user form has at least admin / Settings or Admin / Access rights.
Admin / Settings includes Admin / Access Rights

Create and delete are not allowed for those views.
Indeed users may think they are modifying current user's access
whereas they are modifying the whole group access.
To avoid confusion, the user's access rights list is now not editable.
Clicking on a row redirects to form view that can be edited.
A warning has been added on access rights form to be sure the user
is aware of what he is doing.

Task ID : 1830142
Closes PR #25587

Co-authored-by: David Beguin <dbe@odoo.com>
Co-authored-by: FMDL <florent.mirieu@gmail.com>
2018-10-24 07:31:06 +00:00
Stefan Rijnhart 4d8b0b723b [FIX] base: don't hardcode the new admin user id
There is no longer a priviledged user and the user named "Administrator" may
not have the id 2.

Instead of hardcoding an id, uses a group-based check

Remove the global variable ADMINUSER_ID to ensure nobody is using it (as it can
be a source of bugs when base.user_admin is not ID 2)

closes odoo/odoo#27432
2018-10-23 14:40:02 +00:00
Christophe Simonis 9dbb7d199c [MERGE] forward port branch 12.0 up to b81c2bce84 2018-10-22 17:57:08 +02:00
Fabrice Henrion 9d7ad0fe54 [FIX] terminology
The last time when a user connected to Odoo is a different concept than the last time when a user authenticated to Odoo. I can authenticate once and connect many times afterwards (cookie/session).

closes odoo/odoo#27963
2018-10-19 08:02:17 +00:00
Christophe Simonis 835b77ba94 [MERGE] forward port branch 12.0 up to ebe43bad9e 2018-10-09 11:37:30 +02:00
mreficent dddd4072de [FIX] v12 urls
Was still pointing to old links

closes odoo/odoo#27443
2018-10-09 13:44:38 +00:00
Pedro M. Baeza 1be50fdeaf [ADD] *: support SVG images
Introduce official support for SVG files in the framework, including the
following parts:

1. When client-side SVG images are uploaded, the content is displayed until
you save using data URI scheme according RFC 2397 [1]. This scheme requires
to specify content format. Using hardcoded "image/png" works for all images
types except SVG.
Type-sniffing is done using "magic byte" detection via the first base64
encode byte, so that the proper data URI scheme can be used.
This should not cause SVG-related security problems as the file is
displayed through `<img>` tag, which does not allow SVG scripting [2].

2. Make /web/image controller compatible with SVG

3. Add support for SVG files for company logo, which uses a dedicated
controller.

4. Resizing of SVG files is a no-op, as it makes little sense for a
vector-based format. We also want to avoid micro-alterations to the SVG
document (in "natural" viewport parameters) as we would store multiple
copies of the files in the filestore.

5. Because SVG files are inherently dangerous, upload of SVG files is
restricted to administrators, either by blocking it directly before
saving it in the database (binary fields with attachment=False), or by
neutering them to text/plain mimetype (for binary fields with
attachment=True)

6. Add tests for the SVG upload cases and for the non-admin uploads.

[1] https://tools.ietf.org/html/rfc2397
[2] https://www.w3.org/wiki/SVG_Security

Closes #26635
2018-10-03 17:48:01 +02:00
Christophe Simonis 43b63a0465 [MERGE] forward port branch saas-11.4 up to 57e387b645 2018-10-01 16:01:54 +02:00
Adrian Torres 3f4f77fd9d [REF] *: adapt code to new related default behaviour
This commit adapts the business code to changes introduced by
the parent commit in order to keep the same behaviour as before.

All readonly=False fields will have to be checked afterwards to confirm
that the business case requires write access to the source field.
2018-09-27 12:10:23 +02:00
Raphael Collet 3a30391e9d [FIX] base: superuser cannot become active 2018-09-27 09:54:28 +02:00
Nimesh Jethva 7eea263f36 [IMP]base_*: Improvement in model description
Purpose of this commit is to give description more "business oriented"
because those descriptions appears in Odoo Studio which is supposed to be used by end users, not only by developers.

Related Task ID : 37311
2018-09-21 11:45:15 +02:00
Yannick Tivisse b3fef6a72a [IMP] base: Order user's type groups by id
Purpose
=======

Traceback when following these steps:
- Install MRP
- Load French translations
- Set language to French
- Activate 'work orders' on MRP configuration

Error: The field 'sel_groups_9_10_1' doesn't exist.

This is because the only selection groups field on the res_users view
that doesn't have a transitive closure (the user's type Internal/Portal/Public)
is ordered by name.

1: Internal User
9: Portal
10: Public

becomes

9: Portail
10: Public
1: Utilisateur Interne

which lead to the traceback.

We should retrieve these groups ordered by 'id' to avoid the issue.
2018-09-20 16:19:24 +02:00
Raphael Collet 19e9909557 [FIX] base: avoid prefetching all the fields when getting context
When getting the context of res_users, all the fields are read but if
the schema is being modified and the modifications are not yet commited
in the database, this leads to a bad query.

With this commit, a read is used to fetch only the needed fields.

Thanks to @RCO for finding this issue that only occurs in specific
planetary alignment.
2018-09-19 15:58:10 +02:00
Christophe Simonis 3117afbb7e [MERGE] forward port branch saas-11.5 up to 4e85ca8a76 2018-09-17 12:07:26 +02:00
Christophe Simonis 9c77066f34 [MERGE] forward port branch saas-11.4 up to 6c103589c1 2018-09-14 16:00:17 +02:00
Christophe Simonis d76cd50f0e [FIX] base: avoid generating invalid user group view
When no `base.module_category_user_type` Application is found, the group
view was generated with the domain `[('', '!=', <int>)]`, which is will
fail view validation.

This situation happen during database migration or if the module category
is deleted.
2018-09-12 19:05:29 +02:00
Christophe Simonis 86ff929ad6 [MERGE] forward port branch saas-11.4 up to 1199451606 2018-09-10 17:06:18 +02:00
Yannick TivisseandWolfgang Pichler b7e6f28100 [FIX] base: user fields_get no add group if asked
The override of fields_get adds "virtual" fields corresponding to
groups.

If for example we make "res.users" have inherit "mail.thread", we get
these "virtual" field as if they had "track_visibility", since we do a
"fields_get" with fields having track_visibility expecting to only get
back "track_visibility" ones.

So the system would then fail trying to track visibility on fields like
"in_group_5" and for example a res.users could not be created anymore.

With this fix, we fix the fields_get so it respect the fields we ask of
it.

fixes #22332
opw-1878654
closes #22338
closes #26705

Co-authored-by: Wolfgang Pichler <wpichler@callino.at>
2018-09-10 14:23:43 +02:00
Yannick Tivisse c3717f3018 [IMP] base: Erase user's groups if converted to public/portal 2018-09-10 14:23:43 +02:00
Yannick Tivisseandjem-odoo bb3f20710a [IMP] base: Display Internal Users/Portal/Public as a selection
Co-authored-by: jem-odoo <jem@openerp.com>
2018-09-10 14:23:43 +02:00
Yannick Tivisse 43dd9ecd82 Revert "[IMP] base: Remove the reified view on 'groups_id' in res_users' form"
This reverts commit bd49f9fd17.
2018-09-10 14:23:43 +02:00
Yannick Tivisse 7978d4ba0f Revert "[IMP] *: Define groups on res.users models"
This reverts commit 99f497b390.
2018-09-10 14:23:42 +02:00
Yannick Tivisse dae8ca3f87 Revert "[IMP] base: Add compute/inverse methods to manage user groups"
This reverts commit ab179bb2d7.
2018-09-10 14:23:42 +02:00
Christophe Simonis f19e6ce561 [MERGE] forward port branch 11.0 up to 213759b03e 2018-09-05 18:52:27 +02:00
Martin Trigaux e398e1674a [IMP] base: log the name of the group that is failing
Closes #26173
2018-08-28 14:47:13 +02:00
Christophe Simonis a7a30791de [MERGE] forward port branch saas-11.4 up to a5187cef10 2018-08-27 11:16:44 +02:00
Sébastien Theys 1addade28b [FIX] base: correctly detect when admin logs in
Since 2f7c03d9ca it's not possible to log in as user 1.

However, we reset the base url when the admin logs in, which is now user 2.

This fixes wkhtml2pdf was not able to load css file, and probably some other side effects.

PR: none
Task: 1879620
2018-08-24 15:55:46 +02:00
Christophe Simonis 3a95d2fdf8 [FIX] base: force comparison between strings
When using another login method than stored password (ldpa,i oauth...),
user's password is NULL in database. Passlib < 1.7 expect the encrypted
password to be a string, leading to an uncaught traceback, forbidding
login.
2018-08-24 10:58:18 +02:00
Jeremy Kersten 0cdfc84be8 [FIX] base: fix authentication, wrong login/password raise an error 500
During rebase of 4f6ec1c, we remove accidently a part of aac21e4.
Side effect is that uid was False but success_login True.

Courtesy of @xmo-odoo for help
2018-08-24 09:21:46 +02:00
Yannick Tivisse 9aaa32b6f6 [IMP] base: Better implementation of 8166eae 2018-08-16 14:40:46 +02:00
Yannick Tivisse 8166eae0bf [IMP] base: Don't set customer=True on new users
Purpose
=======

Create a user, then the partner is shown in Customers.

Most of the time, user is not a customer.
2018-08-16 14:19:37 +02:00