Commit Graph
49 Commits
Author SHA1 Message Date
std-odoo e0c2a8a2cc [IMP] event_*: clean ACL and add a new group "Registration Desk"
Purpose
=======

Clean the ACLs related to the Event application.

Add a new group to manage the registration in the entrance of an event. This
group should not be able to modify or remove records in Event but should be
able to create and manage the registrations.

Specifications
==============

Now, there are 3 event groups

  * ``Registration Desk User``, who can manage the registrations and
    read all event-related information;
  * ``Event User`` who can create event, sponsor, ticket... His role is
    to globally handle events on a day-to-day basis;
  * ``Event Administrator`` who can create event type, sponsor type,
    ticket type... His role is to manage the way events are managed withint
    its company:

Each group implies all previous groups.

Compared to previous event users gain a lot of rules, allowing to update
records like tickets, registrations, ... Low-end event users should now
use the registration desk group.

Links
=====

Task ID-2204364
COM odoo/odoo#57022
ENT odoo/enterprise#13984
UPG odoo/upgrade#1897
2021-04-02 13:40:50 +00:00
std-odoo 3dfb3c1e74 [FIX] website_event(_*): improve user flow and experience from frontend
PURPOSE

Provide some fixes after internal test deployment of event online features.
Notably: user registration flow, various fixes in templates.

Also add some unit tests to avoid regressions while working on event features.

LINKS

Task ID-2169118
odoo/odoo#55967
odoo/enterprise#12438

X-original-commit: e66684b23eebaadc3df7b908427d3d7a83d4f0a0
2020-08-17 16:29:49 +00:00
Victor Feyens 532c083cbb [IMP] *: remove global field definition in ir rules xml
It is a computed field, there is no need to manually set its value.
2020-03-20 16:15:40 +01:00
Yannick Tivisse a5b6f31cf2 [IMP] base: Contextualize the multi company
Purpose
=======

Allow the user to select the allowed companies for which he wants to see records
on top of selecting his current company.

It is confusing for users to see the records from the company he is connected to
and the records of the children companies.

Instead of using the hierarchy of companies to access records across companies,
the user can now select (from his set of allowed companies) the companies for
which he wants to access records.

/!\ This means that the user will interact with records from company A when in
company B.
Example: a SO has been created and confirmed in A. When in B, I create the
invoice from it.

Specifications
==============

1/ Deprecate the parent/children hierarchy on the res.company model. The fields are
kept on the res.company model to ensure the retro-compatibility, but won't be used
accross the standard code anymore. The only functional usage for this mechanism
was to allow to see records from several companies by creating a virtual parent
company, which will be possible with the new mechanism.

2/ By default, a user will only see the records of the company he is connected
to (or records without a company). (It is still editable by the user if needed).
For that, put this information in the user context, to allow having different
configurations on different browser tabs. Instead of having domains like
['|',
('company_id', '=', False),
('company_id', 'child_of', user.company_id.id)]
you'll have something like
['|',
('company_id', '=', False),
('company_id', 'in', company_ids)]
Note that the 'company_ids' is a value that is passed in the evaluation
context on the record rule, as we already have user, or time.
company_ids is a list of the ids of all the enabled companies in the
user's context.

3/ Out of the generic improvements brought by this task, this will illustrate
issues that could exist since several versions. For example, it should not be
possible to create a scrap order for the company A with a package of the company
B, or it should not be possible to create an invoice on the company A with
payment terms from the company B. Before the version 12.0, it was easy to
encounter this kind of issues as the admin was the SUPERUSER_ID. A positive side
effect of the fact that the SUPERUSER_ID has become an inactive user was to
make it more difficult to introduce mismatch on the records, but haven't solved
the issue, as it was still possible to do it with parent companies
configuration. Some of these issues have been fixed in this commit, but all the
business flows should be re-tested to check if an ir.rule should be introduced
(eg: a multi company rule for stock.quand.package), if the company of a record
is correctly transfered to another record created from the first record (eg:
From a SO, create an invoice and a payment, the company of the sales order
should be transfered on the invoice and the payment, even if the company of the
sales order is A and I'm logged into the company B with the company A enabled.

4/ Currently, if I click on a button on a notification email (example 'View
Task'), I face a traceback if I'm not logged into the company of the record.
Now, if you click on a button and if you have access to the record, the correct
company will be automatically set.

5/ If I display a kanban view with several records from several companies (and
an image), all the images should be displayed.

6/ Currently if you copy paste an url, this will crash if you're not in the
correct company. This won't be fixed because it's quite impossible to do it in
a clean way. This task brings a workaround. Copy/Paste -> Traceback -> Log into
the correct company, re-copy/paste -> Ok.

7/ 2 property methods have been added on the environment to retrieve the company
on which the user is logged in and the companies the user enabled, on a specific
tab.
That way, when creating a record, instead of doing
default=lambda self: self.env.user.company_id
do
default=lambda self: self.env.company_id
On the other hand, to retrieve the enabled companies, do
companies = self.env.company_ids

8/ Modify the Company Switcher widget to allow to log into another company
WITHOUT writing on the res.users (and thus bringing cache invalidation issues
and so on). Also allow to enable several companies and see records from several
companies, and independantly of the other browser's tabs.

9/ When focusing on a tab, save the current company configuration on the local
storage. That way, when doing 'CTRL+T' or a middle click, the context is
propagated to the new tab.

10/ Improve the error message in case of multi company access errors. Now, when
the user is in debug mode, display the related names of the records and the name
of the user who brings the issue.

11/ Remove the context erasing when writing on a res.users
This is probably coming from the migration to new API of the base module.
The context was not propagated at this moment, which was a common mistake at
that time. When migrating the module, probably by using the 'black box' method,
as the context was not propagated, it was erased on the new version. This is
now an issue because the context (i.e. the enabled companies) was erased when
writing on a res.users, leading to tracebacks.
See: https://github.com/odoo/odoo/commit/7eab8e26d3d46c53f4be924d6a34e80a66e74960#diff-4c2e738ee8f64f11806c889ea097b5e7R624

12/ Fix the crash manager on redirect warnings. The issue is the following
- Create an invoice on a company without a configured CoA.
- Set a partner
- On the onchange_partner_id, a redirect warning is raised to propose you
to configure a CoA
- Click on 'Go to the configuration panel'
- A generic warning says something like 'Do you want to discard your changes?'
- Click on yes, the page refreshes, but not on the redirect action.
Now, set correctly the action on the hash, and reload instead. The breadcrumb is
lost for example, but you reach the correct action at least.

13/ Introduce a res.group to enable/disable the multi company per tab
feature.

14/ To help the users to know which tab is in which company, add the
possibility to have a favicon per company. When creating a company,
the classical 'O' icon is colored by default in a random color.

15/ Remove the company switcher on the frontend. This was mainly there
to allow a user to swicth to the company linked to the website.
This behavior is now transparent to the user. If the website A is
activated, then the company set on the context is the company of the
website.

16/ Deprecated the _company_default_get method on the res.company
model. Remove the method _get_company on the res.users model.

17/ Add 'allowed_company_ids' and 'current_company_id' on the pyeval
context. You can now use those variables on domains in the views to
access directly to the activated company.ies on the current tab.

TaskID: 1960971

closes odoo/odoo#32341

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-05-13 08:57:49 +00:00
jbm-odoo ec07e72845 [IMP] base,*: Reorganize access rights groups
Purpose
=======

Access group terminology is missleading. Yous have to be manager to administrate
an application. This task consists to rename groups to be understandable for everyone.

Groups should be reorganised on the users form to be more explicit.

Specification
=============

1/ Rename 'Manager' to 'Administrator' in users groups.
2/ Define a hierarchy on access groups by using the category_id in the manifests
   A category 'Operations/Project' will create a category Project with a parent
   category 'Operations', and something smart is already developed (in modules/db.py)
   to avoid duplicating categories.
3/ Add a group in expenses to be able to approve expenses reports for my team.
4/ Add a group in timesheets to be able to approve timesheets for my team.
5/ Remove partially the useless crap in ir_module_category_data.xml
6/ Sort access rights groups on users form according to its parent category

closes odoo/odoo#29362

Signed-off-by: "Yannick Tivisse (yti)" <yti@odoo.com>
2019-03-05 09:08:12 +00:00
Raphael Collet 2f7c03d9ca [IMP] base: add regular user admin as uid 2
User 1 simply becomes a technical user (inactive, no password).
2018-08-23 21:38:57 +02:00
Lucas Perais (lpe) cda2ac9b71 [FIX] event, event_sale, website_event: allow portal access to own registrations
OPW 1859364
2018-06-26 15:07:42 +02:00
Mitali Patel ddd4479d10 [IMP] event: apply various usability improvements
* reporting: remove report.event.registration as it can be replaced by
   pivot and graph views on event.registration model directly. The
   custom SQL view does not add any valuable information;
 * event: correctly take limitations from event category and check
   minimum seats is lesser or equal to maximum seats;
 * event: reorganize a bit the form view

  * avoid some kind of random ordering of buttons;
  * move seats availability directly in the form view;
  * ticket page is now used only for ticketing purpose, not a mismatch
    with seats;

 * registration: attendees can be set as done only for confirmed events
   to avoid confusion when working with draft events;

Misc usability

 * event.type: rename event type to event category to have a unified
   term across various event addons;
 * event: stop tracking active field as it does not add interesting
   information; it should not toggle everyday;
 * event: track location as it does add valuable information;
 * event: rename some labels to ease user experience;
 * event.mail: add missing description and rec name;
2017-03-03 13:04:36 +01:00
qsm-odoo d04a42022b [REF] website, *: review website access rights
* event, website_event, website_forum,
* website_hr_recruitment, website_sale

Website access rights were buggy. The editor assets and website editor
assets have to be loaded together to work so the previous behavior
which only loaded one with the restricted access right was not right.
Also, people which had the "Manager" access right for model like event
or job only got access to creation and edition of those objects if they
had the full access to website access rights.

Now the website module creates the two same groups :
* group_website_publisher: load all editor assets, give access to
page creation for model the user has access (event, job, ...) and
edition of those pages
* group_website_designer: implies the first one and give access in
creation and edition of all pages + access of all website menus

The manager access rights for event, product, jobs, etc now implies
the group_website_publisher group for the user (so that the manager
have the editor assets and editor ui).
Note: some python codes use the group_website_publisher for no right
reason, this has to be adapted.
2016-09-28 15:56:04 +02:00
Yannick Tivisse ff63f5d0a3 [IMP] base_setup: Allow the admin to modify the default user acess rights
Add a link in the general settings to access easily the default_user form view in order to modify the default access rights

The default_user manager rights declarations in all the applications have been move in a noupdate="1" definition to avoid the manual configuration overwrittings
2016-08-23 11:14:37 +02:00
Thibault Delavallée 274e94d715 [REF] event: remove group_mail_scheduling as email scheduling is part of event management
In the interface using the email scheduler of events is limited to a group
that is not activated by default. However by default emails are sent and
therefore cannot be configured by the event maanger.

As managers should always be able to configure sent emails we decided to
remove the group and always give access to the email scheduling tab of the
event form view.
2016-08-19 15:49:37 +02:00
Thibault Delavallée efd55ab8a5 [REF] various: rename openerp node to odoo in xml files 2016-08-10 15:48:10 +02:00
dut-odoo c83702a36a [IMP] event: change term 'Subscription' to 'Registration'
Changed term 'subscription' to 'registration' in event, event_sale,
website_event, website_event_sale modules
2016-05-13 11:28:28 +02:00
Yannick Tivisse 1ecba213f4 [IMP] Newly created users get all manager access right
Coming from a bug in web_settings_dashboard. Invited user didn't have any rights
when created from the dashboard, which was leading to an error.

This bug leaded to a new discussion. Better to have basic employee having user
rights for all main applications. For bigger entreprises there is an admin that
will carefully remove extra rights, if necessary. The target is small businesses,
it makes sense that every way to create a user gives the same result.

In conclusion, each new user has a full access to the applications by default

How is it implemented ?
We added an inactive default user which original access right to the groups
'base.group_user' and 'base.group_partner_manager' in base. Each
application will extend the default user's access right by adding the maximal
access right for this application.

On user creation, we will use by default the 'group_id' field from the default
user. We will in the same time remove the ugly 'default_groups_ref' key which
was passed sometimes in the context for some fields in some views, and sometimes
nothing.

So, the user can modify the access rights for the default user, but he should be
aware that removing project user access rights for a default user will prevent
a *created on the fly in a task* user will not be able to access the task.
2015-11-20 16:27:32 +01:00
Gaurav Panchal 4898d3a598 [IMP] event: groups and config update
Move the module category declaration in base to fit the other categories
declaration. Use event groups instead of marketing groups.
2015-08-12 11:41:58 +02:00
Richard Mathot 5ab531f6d0 [FIX] event: unused group added at 581c2f1aa1 2015-04-28 11:23:12 +02:00
Yannick Tivisse 581c2f1aa1 [IMP] event: usability improvements
- New filter "not cancelled" for attendees management
- No more readonly nor invisibility on "minimum number of seats"
- Event questions and mail scheduling have been put under an optional
  tab
2015-04-22 09:25:26 +02:00
sgo@tinyerp.com 2e272a7687 [MERGE]sync with trunk
bzr revid: sgo@tinyerp.com-20130626111029-e6szwugpewn3cd2g
2013-06-26 16:40:29 +05:30
Thibault Delavallée 7c026132ff [REF] event: visibility moved from portal_event to event. Customized rules, removed now unnecessary files.
bzr revid: tde@openerp.com-20130410125117-m9ir36qhkp9fqax1
2013-04-10 14:51:17 +02:00
Foram Katharotiya (OpenERP) edc4077c54 [IMP] remove access rights in mail,crm,event
bzr revid: fka@tinyerp.com-20130222072757-0fain23pzyb8dzk9
2013-02-22 12:57:57 +05:30
Olivier Dony 3fe6987ce7 [MERGE] Harmonization of noupdate flag on security XML data, courtesy of Alexis de Lattre (Akretion)
ir.rule records are in noupdate data blocks to let the admin
alter them without fear of them being reset at next update.
Other records such as groups are in normal mode, so they
can be updated whenever necessary

bzr revid: odo@openerp.com-20121218232001-t425t4hi7qbmsip2
2012-12-19 00:20:01 +01:00
Hardik a41714da56 [IMP]User : Access rights in changed menu name
bzr revid: hsa@tinyerp.com-20120919085103-mmen7f0vzqvmp9bx
2012-09-19 14:21:03 +05:30
Antonin Bourguignon 74aa5cfa8e [IMP] identation, also remove useless 'noupdate=0' attribute
bzr revid: abo@openerp.com-20120725144039-o3kjxo065qhode33
2012-07-25 16:40:39 +02:00
Alexis de Lattre 5101771cd9 Harmonize the noupdate flag on security XML files :
- ir.rule objects are noupdate="1"
- all other objects are noupdate="0"

bzr revid: alexis@via.ecp.fr-20120713170838-pjsysliyt6twazrc
2012-07-13 19:08:38 +02:00
Sanjay Gohel (Open ERP) 1702b2335d [IMP]remove tabs and add spaces instead of them
bzr revid: sgo@tinyerp.com-20120628064005-zuerrpazumf5lf1q
2012-06-28 12:10:05 +05:30
Raphael Collet ba1454149c [IMP] groups: remove auto-inclusion of admin in groups, and make the inclusion explicit in groups
bzr revid: rco@openerp.com-20120404090830-nteimn2kvz8nkk7h
2012-04-04 11:08:30 +02:00
Quentin (OpenERP) 236ed739b9 [FIX] event: fixed the access rights in order to have that being in the manager group implies being in the user group too
bzr revid: qdp-launchpad@openerp.com-20120329085703-419271p8s81cl6zo
2012-03-29 10:57:03 +02:00
Sanjay Gohel (Open ERP) 4f69e02d1c [IMP]add share access to registration and changes in security view
bzr revid: sgo@tinyerp.com-20120326124825-xewmd0qc82k9hk11
2012-03-26 18:18:25 +05:30
Quentin (OpenERP) 6aa5b2e701 [REF] event: removed useless TODO statement
bzr revid: qdp-launchpad@openerp.com-20120301114523-8rrplgaojxhwdn51
2012-03-01 12:45:23 +01:00
Quentin (OpenERP) c530c27c2c [ADD] event: added security file
bzr revid: qdp-launchpad@openerp.com-20120224133302-w3fr4nxju54zs4nh
2012-02-24 14:33:02 +01:00
Raphael Collet 70bb0dd810 [IMP] base_contact, event, knowledge, product, project, sale_mrp: avoid redefinition of sale groups
bzr revid: rco@openerp.com-20111212145128-zx64v0uwf8n0lwyu
2011-12-12 15:51:28 +01:00
Raphael Collet 857e45e84c [IMP] base_contact, crm, document, event: add group categories
bzr revid: rco@openerp.com-20111212134354-49p2gyf93qozplll
2011-12-12 14:43:54 +01:00
Raphael Collet ba6342174e add group implications
bzr revid: rco@openerp.com-20110802130811-pkdmw43ufifz0tpj
2011-08-02 15:08:11 +02:00
rpa (Open ERP) 6caca89f87 [IMP]: Moved reference of demo user from *_security.xml to demo file
bzr revid: rpa@tinyerp.com-20101119102525-8gyj1gmm1w29rwxu
2010-11-19 15:55:25 +05:30
Harry (OpenERP) 764b9f251e [FIX] correct regression on intalling module without demo data
bzr revid: hmo@tinyerp.com-20101114134821-7djwpr6nmmxu584q
2010-11-14 19:18:21 +05:30
vth 448fc93683 [IMP] account,hr,sale,point_of_sale,event: give user role to the demo user
bzr revid: vth@tinyerp.com-20101101124606-ia3nqngu19u8b7oa
2010-11-01 18:16:06 +05:30
Fabien Pinckaers fe9500c14e [IMP] access rights cleaning
bzr revid: fp@tinyerp.com-20101016164709-8w551aaosqx0dufu
2010-10-16 18:47:09 +02:00
psi (Open ERP) a186491d91 [IMP] event: Improve search view and small change in Make invoice wizard
bzr revid: psi@tinyerp.co.in-20101008105948-1qflslhcp1qla6qo
2010-10-08 16:29:48 +05:30
Vir (Open ERP) 4ac33ec1f9 [MOD] Group name changed , Sales / Salesman to Sales / User
bzr revid: vir@tinyerp.com-20100809060226-jx6plkn6mafiplyz
2010-08-09 11:32:26 +05:30
AMP (OpenERP) 5d42b703b5 [MOD] event: usability improvement in access rights
bzr revid: amp@tinyerp.com-20100806135358-yapv8rqd34ac6oms
2010-08-06 19:23:58 +05:30
AMP (OpenERP) 39d1c31b49 [MOD] usability improvement and changes in access rights
bzr revid: amp@tinyerp.com-20100730130247-1hvssj5z0f9gvd3a
2010-07-30 18:32:47 +05:30
AMP (OpenERP) 7e0180c254 [MOD] usability improvement in access rights
bzr revid: amp@tinyerp.com-20100729133057-gdhqqohzpkdnq8vl
2010-07-29 19:00:57 +05:30
Harry (OpenERP) 4079548800 [IMP] event: demo data
bzr revid: hmo@tinyerp.com-20100716081957-0gnd1eilovf01sbf
2010-07-16 13:49:57 +05:30
Harry (OpenERP) b651a55c71 [IMP] Event: clean
bzr revid: hmo@tinyerp.com-20100716064714-ivuu3ux3sayo28fh
2010-07-16 12:17:14 +05:30
Mod2 Team (OpenERP) b93efbe7c4 [REF+IMP] event, membership:
Event :
 * Change button icon for all searchview.
 * Develop 'group by partner' functionality in make invoice wizard of registration form.
 * change yaml as per changes in make invoice wizard.
 * remove 'List of register event' wizard and put link on in event form.
 * ADD 'Send a new mail' button for mail
 * Improve history functionality.
 * add group : event/manager and event/subscriber.

Membership .
 * merge two sql query in one repor_membership file.
 * develop search view of that report.
 * change icon for search view.

bzr revid: hmo@tinyerp.com-20100626101340-bt77wjb8ug3a3flj
2010-06-26 15:43:40 +05:30
atp (Open ERP) 6be896b14b [ADD]: event: add new group event/manager, event/subscriber.
bzr revid: atp@tinyerp.co.in-20100622110023-5w6fnbtiwqyq7f6u
2010-06-22 16:30:23 +05:30
atp (Open ERP) 704d545952 [IMP]: event: use inherit in place of inherits.Improve report using report guidlines.
bzr revid: atp@tinyerp.co.in-20100607064312-3cl1vc0gfal7wvhe
2010-06-07 12:13:12 +05:30
rpa (Open ERP) c3c3e539f8 [IMP, FIX]: event: Improvement in event modules for:
* Removed dependency on crm.case as it is removed
 * Fixes in event/registration computation as per ner changes
 * Improvement in wizard

bzr revid: rpa@tinyerp.com-20100517133114-jjp82khn32m5zvjr
2010-05-17 19:01:14 +05:30
Christophe Simonis 6ecdbc0e9d fix access rights
bzr revid: christophe@tinyerp.com-20081024070849-cjjlrvz52t67ll0m
2008-10-24 09:08:49 +02:00