Commit Graph
18 Commits
Author SHA1 Message Date
Martin Trigaux cd2f330bec [IMP] *: remove glocal ACL
Specify explicit route for each ,, line
This is part of task 3230280 where global ir.model.access will be
forbidden.
The goal is to make access to public/portal explicit. Too often,
global access was granted with only employees in mind.

Remove ,,0,0,0,0 lines

mail:
employee already had read access to mail.group
still needed to subtypes as in ir.rule domain

mail_group: employee already had read access
pos_mercury: only needed for employees

membership:
move public access for website_membership as needed in the controllers

website_customer: employee already had read access

website_event_booth: no need for category
website_event_exhibitor: retrieved in sudo
website_event_track: not needed for location

Part-of: odoo/odoo#125216
2023-07-11 22:33:47 +02:00
Martin Trigaux 65530dfd6a [ADD] *: add ir.model.access on all transient models
Following changes needing ir.model.access on transient models too.
Remove groups declaration on the action to move it to ir.model.access
when possible.
Rules are strict by default with no unlink access by default and high
priviledge asked. Adaptations may be needed later.
Write access is given as a wizard may need to be modified in case the
action triggers an error and the user has to correct a value

account*: use account.group_account_user for all transient by default
	  remove account.print.journal relic
stock*: use stock.group_stock_user by default
survey: survey user can send invitations
mail: allow any employee to execute wizards
      additional verifications are made to ensure they are executed
      only on the documents the user has access to you
      give portal access to mail.compose.message as portal still does
      some actions like posting messages on the forum
      add ir.rule to avoid reading somebody else messages
      increase the query count because of undeterminist count
crm: saleman for lead2opp, manager for massmailing
     partner manager for actions linked to partners
     avoid a write in test_lead_lost
sms: any employee can send sms
mrp: mrp user can execute wizards
     give unlink access as making write during do_produce operation
base_import: employees can import files
delivery: stock user can deliver
event_sale: sale user can configure the wizards
	    event user inherit from  sale rights
gamification: employee can give badge
google_service: resolve FIXME
hr: add specific rights
    manager can set a plan according to group on button
    anyone who can write on an employee can register a departure
hr_expense: set rights based on buttons
hr_holidays: an approver can make a summary report
hr_recruitment: recruiter can refuse a candidate
hr_timesheet: can use the wizard if can create a timesheet
l10n_eu_service: managers can create fiscal positions
mass_mailing: same group as on mass.mailing.list
membership: accountant can create invoice from membership
payment: accountant can create a link
	 as the source is an account.move
	 keep the payment.acquirer.onboarding.wizard to system user
	 only as it is called during company configuration
point_of_sale: PoS manager only can use wizards
	       never create closing_balance_confirm_wizard records
product_expiry: stock user has rights on stock.picking
product_margin: access from accounting menus
repair: same rules as for above models
sale: set ir.rule for self wizard only
      add rule from model introduced in payment to add salesman group
sale_crm: saleman can create a quotation from a lead
sale_coupon: any saleman can generate coupon
	     add self ir.rule
sale_product_configurator: salesman can select product variants
snailmail: employee can send letters
website: designers can write on website
website_crm_partner_assign: same rule as group on action
website_sale: sale ACL as for payment.acquirer.onboarding.wizard
website_slides: anyone can send invitation

base: base.language.*: allow employee (cf lang_install)
      change.password.user: can not read change password wizard of
      other users
      test.*: no access is needed

Courtesy of Damien Bouvy, William Andre and Antoine Prieëls for review
of acl
2020-02-04 17:54:18 +01:00
Patrick Hoste bfbc7c6a18 [IMP] gamification: track karma change on users
PURPOSE

Allow karma gain tracking enabling notably display of top users based on
weekly / monthly gain in website profile.

SPECIFCIATIONS

Each time a user gains karma a record is created in the gamification karma
tracking model. Scheduled activity runs to consolidate the records into
monthly gain records to avoid having crowdy table and unnecessary noise
in karma gain.

This model is made private and only accessible through some dedicated
compute methods / controllers used in website profile.

In website profile module buttons are added to see users ranking based
on their total karma (like before) but also by last week and last month
gains (using the newly introduced tracking model).

LINKS

Task ID 2003505
PR #34594
2019-11-05 15:08:34 +00:00
David Beguin 9e082662af [IMP] gamification : add ranks based on karma
To encourage forum and slides users to be more active ranks are now added.
They are directly linked to karma. The more the user has karma the more his
rank will be high.

The default rank is Newbie, with 1 point of karma. Users with 0 karma are
considered as inactive on forum or slides. When a user reach a new rank
a mail is sent to him to congratulate him with his new rank.

To add a button in the mail template to allow users to go directly on
a website section (like forum or slides) simply override
get_gamification_redirection_data to add the target url.

Partial commit linked to eLearning project. Main specifications related
to gamification and user profile can be found on task 1922159 (PR #30514).
Main specifications related to eLearning can be found on task 1902304
(PR #29876).
2019-02-07 12:13:28 +00:00
Jérome Maes b91b66c686 [REM] portal_gamification: kill the module
The goal is to prepare the removal of
'portal' module.

Since this module only provides access rules and
rights, those ones are moved directly into its
parent module (aka gamification).
Since no module depends on it, we can remove it
without problem.
2017-03-23 09:59:58 +01:00
Martin Trigaux e5f05074f8 [FIX] gamification: remove duplicated manager groups
hr_gamification should be adding hr groups to the security of gamification.
Creating the group base.group_hr_manager in gamification in case hr is not
installed is confusing and redundant with existing manager groups.
2016-09-02 16:13:29 +02:00
Gaurav Panchal ede13fd43b [IMP] gamification: groups and config udpate
Clean access, groups and categories in gamification. Remove custom
goal_category aka Gamification category. As gamification is mostly
integrated in HR, use HR categories. Remove custom group_goal_manager
group, replaced by HR manager. Gamification groups and configuration is
therefore linked to HR now.

Updated access rights accordingly.
2015-08-12 11:41:58 +02:00
Martin Trigaux 122c15c48d [REF] gamification: pretty much changing half of the code to make tde happy...
bzr revid: mat@openerp.com-20131217161541-oxsgy7gmko2x6qui
2013-12-17 17:15:41 +01:00
Martin Trigaux 354190b44e [IMP] gamification: add portal_gamification module to add security rules
bzr revid: mat@openerp.com-20131216150726-su27319fvvxevam6
2013-12-16 16:07:26 +01:00
Martin Trigaux 01784af22c [IMP] better security rules
bzr revid: mat@openerp.com-20130424081216-cjyq0edrht6r0j1v
2013-04-24 10:12:16 +02:00
Martin Trigaux b4d1d803fd [FIX] avoid warning for anonymous
bzr revid: mat@openerp.com-20130415144455-w2jl8lxh0pdd6fo1
2013-04-15 16:44:55 +02:00
Martin Trigaux c7edf72350 [IMP] gamification officer rules
bzr revid: mat@openerp.com-20130412092603-aotk0y53snjz9c9i
2013-04-12 11:26:03 +02:00
Martin Trigaux 750a3ae2b6 [IMP] better security rules
bzr revid: mat@openerp.com-20130405073205-gfcolcdv3oomlo0z
2013-04-05 09:32:05 +02:00
Martin Trigaux 57c1ad67fe [REF] cleaning code
bzr revid: mat@openerp.com-20130404152359-3x3gt9xhkrkr0au4
2013-04-04 17:23:59 +02:00
Martin Trigaux 559d5f7042 [FIX] users shouldn't be able to write to badges
bzr revid: mat@openerp.com-20130329095932-gc58i4q2j32vpcxy
2013-03-29 10:59:32 +01:00
Martin Trigaux ef4197c8d2 [FIX] no warning message for anonymous
bzr revid: mat@openerp.com-20130329082627-cp3iolafolqxsosu
2013-03-29 09:26:27 +01:00
Martin Trigaux 00d4fa790b [ADD] badge menu and related security rules
bzr revid: mat@openerp.com-20130313110225-bjxs9rn3shux9rqh
2013-03-13 12:02:25 +01:00
Martin Trigaux 95c244d35a [ADD] gamification: security rules
bzr revid: mat@openerp.com-20130313095154-b5wi1ohu0wo6hz5w
2013-03-13 10:51:54 +01:00