Commit Graph
38 Commits
Author SHA1 Message Date
Martin Trigaux 8f57863707 [IMP] *: remove access to ir.property
Only administrators can access properties and configure them.
ir.property may contain sensitive information and should only be
accessed via code call to specific methods
2020-05-26 15:50:11 +02:00
Martin Trigaux 65530dfd6a [ADD] *: add ir.model.access on all transient models
Following changes needing ir.model.access on transient models too.
Remove groups declaration on the action to move it to ir.model.access
when possible.
Rules are strict by default with no unlink access by default and high
priviledge asked. Adaptations may be needed later.
Write access is given as a wizard may need to be modified in case the
action triggers an error and the user has to correct a value

account*: use account.group_account_user for all transient by default
	  remove account.print.journal relic
stock*: use stock.group_stock_user by default
survey: survey user can send invitations
mail: allow any employee to execute wizards
      additional verifications are made to ensure they are executed
      only on the documents the user has access to you
      give portal access to mail.compose.message as portal still does
      some actions like posting messages on the forum
      add ir.rule to avoid reading somebody else messages
      increase the query count because of undeterminist count
crm: saleman for lead2opp, manager for massmailing
     partner manager for actions linked to partners
     avoid a write in test_lead_lost
sms: any employee can send sms
mrp: mrp user can execute wizards
     give unlink access as making write during do_produce operation
base_import: employees can import files
delivery: stock user can deliver
event_sale: sale user can configure the wizards
	    event user inherit from  sale rights
gamification: employee can give badge
google_service: resolve FIXME
hr: add specific rights
    manager can set a plan according to group on button
    anyone who can write on an employee can register a departure
hr_expense: set rights based on buttons
hr_holidays: an approver can make a summary report
hr_recruitment: recruiter can refuse a candidate
hr_timesheet: can use the wizard if can create a timesheet
l10n_eu_service: managers can create fiscal positions
mass_mailing: same group as on mass.mailing.list
membership: accountant can create invoice from membership
payment: accountant can create a link
	 as the source is an account.move
	 keep the payment.acquirer.onboarding.wizard to system user
	 only as it is called during company configuration
point_of_sale: PoS manager only can use wizards
	       never create closing_balance_confirm_wizard records
product_expiry: stock user has rights on stock.picking
product_margin: access from accounting menus
repair: same rules as for above models
sale: set ir.rule for self wizard only
      add rule from model introduced in payment to add salesman group
sale_crm: saleman can create a quotation from a lead
sale_coupon: any saleman can generate coupon
	     add self ir.rule
sale_product_configurator: salesman can select product variants
snailmail: employee can send letters
website: designers can write on website
website_crm_partner_assign: same rule as group on action
website_sale: sale ACL as for payment.acquirer.onboarding.wizard
website_slides: anyone can send invitation

base: base.language.*: allow employee (cf lang_install)
      change.password.user: can not read change password wizard of
      other users
      test.*: no access is needed

Courtesy of Damien Bouvy, William Andre and Antoine Prieëls for review
of acl
2020-02-04 17:54:18 +01:00
RomainLibert c9ca376146 [IMP] hr: Introduce the public employee profile
Purpose
=======

1/ Robustness & security: right now it is not easy to understand and do something
   clean in term of security (hr people vs employees, private info vs public). A
   HR officer doesn't know if he can write something on the chatter. Currently, a
   note will be visible for all the employees who have access to the employee form
   view for example.
2/ In term of business, it makes sense to let a hr manages payroll stuff (contract,
   employees private information, ... and other employee see public information
   (résumé and work information)

Specification
=============

Introduce 2 new models:

- hr.employee.base (AbstractModel): This represents the basic skeleton
  model on which the shared fields and methods between the public and
  the private employees models.
- hr.employee.public (_auto=False): This is a sql view based on the
  employee values, readable for an internal user (i.e. an employee).

The model hr.employee is not readable anymore for an employee.

There are now 3 ways to access the employee data:
1/ From the hr.employee views. HR officer access rights are required
2/ From the public profile. The public data for an employee are accessible
   but can't be modified.
3/ From the 'My Profile' menu. A classic employee can access its own
   data from there, and can modify them.
2019-05-31 10:21:20 +02:00
RomainLibert d5fd84b89a [IMP] hr: add onboarding/offboarding activity plannings
Purpose
=======

Give the possibility to elaborate plans through Odoo. For instance, in HR,
you could create an onboarding plan when a employee is created. Someone manages
laptop and other equipment, someone check hr stuff, ... This feature is generic
but in a first time we will apply it only on the hr module.

Ease HR process in a company by creating plans: a plan is an assembly of Next
Activities that will be launched together whenever you need it.

Example of plan for an employee onboarding:

Activity: Prepare materials
Responsible: Alain
Deadline: At the contract signature

Activity: Manage Cars
Responsible: Cécile
Deadline: at the contract signature (both signature)

Activity: Plan Training
Responsible: Caroline
Deadline: After signature

Activity: Training
Responsible: Employee
Deadline: 1 week after the employement date

Specifications
==============

On HR Configuration: Add a menu "Activity Plans"

Activity plan object:
 - Name
 - Model (debug mode) (hr by default)
 - Activity Template o2m
    - Activity Type (only the one related to hr)
    - Deadline (come from Activity Type)
    - Responsible \/
        0  Coach
        0  Manager
        0  Other
        [Responsible_name] \/  (coach, manager or manually set if other)

Add datas, 2 plans:

Onboarding
    - Name: Onboarding
    - Plan lines:
        Activity: Setup IT Materials
        Responsible: [a user] (manager)
        Deadline: At the contract signature

        Activity: Plan Training
        Responsible: [manager]
        Deadline: After signature

        Activity: Training
        Responsible: [Employee]
        Deadline: 1 week after the employement date

Offboarding
    - Name: Onboarding
    - Plan lines:
        Activity: Compute Out Delais
        Responsible: [a user] (manager)
        Deadline: today

        Activity: Take Back HR Materials
        Responsible: [manager]
        Deadline: today

        Activity: Manage Car
        Responsible: [manager]
        Deadline: today

When to trigger it ?

HR specific use case:

1/ On employee, from the employee chatter:
when you create an employee, Odoobot will log a note with the following message:
"Congratulations ! May i recommand you to setup an onboarding plan?", with a link
create a plan from it.

2/ Add a button 'launch plan' to open a wizard to select the plan

3/ When archive an employee
Open a wizard with:
    - Reason (selection)
    - Action plan (m2o not required)

Error if employee not linked to a user.

Task : 1912681

closes odoo/odoo#29151
2018-12-18 11:20:54 +00:00
Martin Trigaux 11812b0b9e [FIX] all: remove external ids fakely from base
Several modules defines records with the external ID `base.foo_bar` while it is
created inside this module (typically menus and groups).
While there is no technical reasons to do so but this may introduce issues:

- these records will not be deleted during uninstall
- if a language is loaded before the installation of the module, it won't be
  translated

The uninstallation will only remove the records with an external id linked to
this module (these would only be removed when removing base).

Installing a language before the module will drop the translations not linked
to an existing external id (as it can not be resolved).

This commit correct all the external ids tagged as from base or other incorrect
modules.
2016-09-02 16:14:26 +02:00
Bhumika (OpenERP) 0cf6e236e8 [FIX] hr: remove referecne of res.partner.address
bzr revid: sbh@tinyerp.com-20120307052100-ylqekp6w7xe72ucd
2012-03-07 10:51:00 +05:30
Fabien Pinckaers f27318c8af [IMP] Security Rule: removed duplicates due to inheritancies of groups
bzr revid: fp@tinyerp.com-20111212181113-mhnnbps3ip8ls6pp
2011-12-12 19:11:13 +01:00
Quentin (OpenERP) f7323eb1af [IMP] hr: replaced marital.status object by a fields.selection to ease to use in payroll module
bzr revid: qdp-launchpad@openerp.com-20110408163116-3qmhc4phurtpuzmf
2011-04-08 18:31:16 +02:00
qdp-launchpad@tinyerp.com 9fb4e60e68 [FIX] hr, access rights: a simple employee should be able to see the list of departments
bzr revid: qdp-launchpad@tinyerp.com-20110128092939-u6lpij6zexv6qztl
2011-01-28 10:29:39 +01:00
François Degrave 469b5a8c6e [IMP] removed contract tab in employee form view + fixed holidays shortcut
bzr revid: fde@openerp.com-20101229161029-o5cko7yu1sf3li45
2010-12-29 17:10:29 +01:00
François Degrave 63e49cf25d [IMP] HR access rights
bzr revid: fde@openerp.com-20101229074726-3iucy5o1886n9y9e
2010-12-29 08:47:26 +01:00
François Degrave 6fd9d3bb9c [IMP+FIX] HR access rights, menus
bzr revid: fde@openerp.com-20101229073956-oze90c0gwlkk4s9t
2010-12-29 08:39:56 +01:00
Fabien Pinckaers 6e3a64a534 fix
bzr revid: fp@tinyerp.com-20101228171706-yxthy7o0u5vs21q8
2010-12-28 18:17:06 +01:00
François Degrave 644e615762 [FIX] crm/security/ir.model.access.csv: ValueError: No references to base.group_hr_user
bzr revid: fde@openerp.com-20101228145612-f0akf0k22yjb8wlv
2010-12-28 15:56:12 +01:00
Vir (Open ERP) eecda53df5 [MOD] improvements in access rights
bzr revid: vir@tinyerp.com-20101008101042-ak2z1vuzbmak7yt3
2010-10-08 15:40:42 +05:30
DBR (OpenERP) 389a623545 [MOD/IMP] hr_* : Usability Improvement in Accessrights
bzr revid: dbr@tinyerp.com-20101007071157-z52414z1sz9h85qh
2010-10-07 12:41:57 +05:30
Vir (Open ERP) 99c74952a7 [MOD] hr,hr_attendance : Improvements in access rights
bzr revid: vir@tinyerp.com-20101006111517-91jab3steqyimmev
2010-10-06 16:45:17 +05:30
DBR (OpenERP) ef28e951f5 [MOD/IMP] hr : Usability Improvenment in Accessrights
bzr revid: dbr@tinyerp.com-20101006093147-xaqdyfd23izwtfmm
2010-10-06 15:01:47 +05:30
AMP (OpenERP) 3362c2ea82 [MOD]hr_*: usability improvement in access rights
bzr revid: amp@tinyerp.com-20100911131911-7k4g0r1b4kta30cc
2010-09-11 18:49:11 +05:30
AMP (OpenERP) 0a8c9772b6 [MOD]hr_* : usability improvement in employee access rights
bzr revid: amp@tinyerp.com-20100906063006-gcuxdswiunwokvn4
2010-09-06 12:00:06 +05:30
AMP (OpenERP) 1d15f71146 [MOD] project_timesheet,hr_* : usability improvement in access rights
bzr revid: amp@tinyerp.com-20100901132905-hslnywxf4zxogxdo
2010-09-01 18:59:05 +05:30
AMP(Open ERP) aff16ab9a5 [MOD/IMP] hr_* : Improvement in access rights
bzr revid: vir@tinyerp.com-20100813133645-w8nex9k1he2zjq9h
2010-08-13 19:06:45 +05:30
DBR (OpenERP) 5f4d7ff09b [MOD/IMP]hr_* modules access right changes in configuration
bzr revid: dbr@tinyerp.com-20100804133252-vh4vbkhmvsev0pnw
2010-08-04 19:02:52 +05:30
DBR (OpenERP) 3e9a0b3ca5 [MOD/IMP]hr_* modules access right changes
bzr revid: dbr@tinyerp.com-20100804112853-issapx9dk7ztcscm
2010-08-04 16:58:53 +05:30
DBR (OpenERP) 9261375e2e [MOD/IMP]hr_* modules access right changes
bzr revid: dbr@tinyerp.com-20100804085628-58nplf4yw8zp80dj
2010-08-04 14:26:28 +05:30
DBR (OpenERP) a446dfb18e [MOD] hr_* :Improvement in hr_* modules groups and accessright
bzr revid: dbr@tinyerp.com-20100803131117-jkvf2a7pe955en2u
2010-08-03 18:41:17 +05:30
AMP (OpenERP) 6eb86abda3 [MOD] usability improvement in access rights
bzr revid: amp@tinyerp.com-20100723072243-kpex4cdgckhga46d
2010-07-23 12:52:43 +05:30
UCO (OpenERP) 3217cf7e4c [REM]: Removed access rules for OSV memory objects
bzr revid: rpa@tinyerp.com-20100628134938-23kiccr4355jfhmg
2010-06-28 19:19:38 +05:30
Fabien Pinckaers 65b70827c4 fix_and_better_access_rights
bzr revid: fp@tinyerp.com-20100612220005-4a33xqgs8bvvoa7x
2010-06-13 00:00:05 +02:00
Fabien Pinckaers 8baf16f25e [IMP] access rights. Remove bad stuff on point of sale
bzr revid: fp@tinyerp.com-20100612162154-f9dgju8wsmn79gq0
2010-06-12 18:21:54 +02:00
uco (OpenERP) 48e7f8370a [ADD]: Added access rules for remaining objects in account, hr, mail_gateway, mrp, stock, project, base_calendar and resource modules.
bzr revid: uco@tinyerp.co.in-20100305100813-2wsyownr15sk335s
2010-03-05 15:38:13 +05:30
Mantavya Gajjar c72753bfa1 [FIX]:fix a bug related to the twise Marital status
complete move to hr module instead of hr_contract

lp bug: https://launchpad.net/bugs/520992 fixed

bzr revid: mga@tinyerp.com-20100216070246-jq8d9zf6aogz1lt8
2010-02-16 12:32:46 +05:30
HDA (OpenERP) 92ae38eb0a Project management improvements
bzr revid: hda@tinyerp.com-20100119073547-dqn2c0i9ycx6kp3a
2010-01-19 13:05:47 +05:30
Rvo (Open ERP) de52c987b1 Project Improvement
bzr revid: rvo@tinyerp.co.in-20100112053248-fkxz9h06ljzgt65q
2010-01-12 11:02:48 +05:30
Christophe Simonis 1a138e1454 fix and complete access rules
bzr revid: christophe@tinyerp.com-20081017162038-kzsgroivk73t0vyx
2008-10-17 18:20:38 +02:00
Christophe Simonis c66e4e63bb fix hr security
bzr revid: christophe@tinyerp.com-20080930142350-o225bunnk5f80s65
2008-09-30 16:23:50 +02:00
Fabien Pinckaers 51f8c2b263 Better Security Rules
bzr revid: fp@tinyerp.com-20080903224650-u1oadqv9x75atmyl
2008-09-04 00:46:50 +02:00
Fabien Pinckaers b4d6690794 Improved Security
bzr revid: fp@tinyerp.com-20080903180400-df7l6wxg1zpirmmi
2008-09-03 20:04:00 +02:00