Commit Graph
40 Commits
Author SHA1 Message Date
Nicolas Martinelli aa65a46fc5 [FIX] auth_signup, crm, project_timesheet_holidays, sales_team, website_sale: settings access error
The new settings model loads by default all settings. In the case of
non-admin user having the 'Settings' access rights this can lead to
access errors.

This commit deals with the multi-company issues on a standard
installation. If the admin is in Company A and the other user in Company
B, accessing the settings is pretty much impossible because of records
rules.

This fixes the master or demo data to avoid setting a company by
default. Note that it only fixes a standard installation: if the
settings are later customized, there is no guarantee that it will still
work.

Problematic fields:
`auth_signup_template_user_id`
`crm_default_team_id`
`leave_timesheet_task_id`

opw-801210
2018-01-03 08:49:32 +01:00
Deep Patel 98748a93c0 [FIX] res_config: Fix several layout issues on config views
- subscription settings are broken and show up at the bottom of any setting page: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrra01leUZ1Wnczbms/view?usp=drivesdk
- don't put setting item of the app you are configuring at the top of the list: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrdXEwUmFWTTlLd1E/view?usp=drivesdk
- hide empty sections when searching not in debug mode: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrVGFOa0FKVmtNTWs/view?usp=drivesdk
- when installing Invoicing, setting item should be Invoicing and not "Accounting": https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrWGQwY1ktaXlNSUk/view?usp=drivesdk
- app labels: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrreXlNTXZnbU13aFk/view?usp=drivesdk
- coupon programs links: duplicate in sales + no link at all in website: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrraTV1YTNPdWU2VUE/view?usp=drivesdk
- delivery methods: links are duplicated in sales settings https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrczR5X1FOUllUZHM/view?usp=drivesdk
- add subtitles to all the carriers in sales settings: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrS1NXXzhwRTFQV2c/view?usp=drivesdk
- inner options should never be in bold:
	customer account: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrMnpualBta2x6dU0/view?usp=drivesdk
	phone validation: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrraHJrYngtaGJ6T2s/view?usp=drivesdk
	signature & payment: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrWTJ3dVBuTzNONlU/view?usp=drivesdk
	bill control: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrRy16UkdTWWdrdDQ/view?usp=drivesdk
- make similar settings look the same through all the apps:
	taxcloud: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrraGlVWmNXRjJ5WEk/view?usp=drivesdk
	pricelist: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrQ2pwVmtEZXM1SWM/view?usp=drivesdk
	multi-currencies: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrTFNWTTJpcS1XbnM/view?usp=drivesdk
	shipping costs: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrM2hKdk5XRy1WTjg/view?usp=drivesdk
2017-09-29 14:12:03 +02:00
Sanjay Jamod 67d1173bf3 [IMP] auth_signup: Disable 'Sign Up' button to prevent user from continuous clicking 2017-09-26 11:02:26 +02:00
Christophe Simonis c5f680200c [MERGE] forward port branch saas-17 up to d08b4407be 2017-09-12 12:09:11 +02:00
Thibault Delavallée 060e98e0a5 [FIX] auth_signup: allow to (re)set signup template user in settings
If it is unsetted there is currently no way to set it back unless putting
directly the ID in the ir.config_parameter table. Let us therefore allow
people to reset their template user for signup.
2017-09-08 18:59:53 +02:00
Yannick Tivisse 781a03b2bc [IMP] res_config: Update file names, xmlids, class names according to guidelines
Now that we only have one model (res.config.settings). Uniformize everything according to the guidelines.
2017-09-01 13:03:18 +02:00
Deep Patel 898224f110 [IMP] web,account,...: Regroup settings, add a nav and search bar
Purpose
=======

Settings are often way too long and hard to scan and sometimes you don't know where to find the settings you're looking for.
By adding a left navigation, you can already have an overview of the settings, and switch easily between them.

Specification
=============

- Add a search bar on all the apps that have settings which can search results from all the installed apps.
  (If i'm on sales settings,and I search anything then it shows results from sales settings and also shows
  all the other matching results from all the other apps such as, Inventory...etc) with app name.
- Able to activate feature from the current page results (no matter if the searched result is from another apps).
- Highlight searched word in results
- Delete the sheet, have a full white background
- Add left navigation bar on setting
- Left navigation bar fixed
- List displayed based on installed apps
- On right panel, by default display current app setting and change accordingly
- [Mobile] Left navigation bar displayed on top
- Add Breadcrumb on top of the page: have the name "Settings" + Save / discard CTA + Search
- Add General Settings on the nav bar
- remove "save this page..." notif in all settings
- Delete all recommanded apps section + all checkbox that install app should disappear:
	payroll: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrSkMzWVpuZ0ZoaFE/view?usp=drivesdk
	Events: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrYXlHMHd2NTM2blE/view?usp=drivesdk
	Manufacturing: Delete Repair - Quality Control - Maintenance - Product Lifecycle Management [LAP][ok]
	Timesheets: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrdFg5XzNydkd2TlU/view?usp=drivesdk
	project: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrraWo3NE04TktwcTQ/view?usp=drivesdk
	inventory: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrQkRaVUR5ekFQYTQ/view?usp=drivesdk
	recruitment: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrbDdqLWQweF80UkE/view?usp=drivesdk
	purchase: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrRlAyUDBnb0trQWs/view?usp=drivesdk
	email marketing: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrOUZONjhvX2k3Y2s/view?usp=drivesdk
	expenses: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrR0JpN1ZpQmtxU3M/view?usp=drivesdk
	attendances: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrralpjZ1VJclNpMWs/view?usp=drivesdk
- About duplicate settings:
	Docsaway: Delete from Sales + delete Default Print Provider
	Attributs & Variants: Delete from Purchases - Manufacturing
	Multi-currencies: delete from Sales
	Unit Of Measures: Delete from Purchase & Expenses
- Add a scroll bar on the left bar when there's too many apps
- Keep the navbar visible even when you search
- Move General Settings to the bottom of the list
- Update on Settings:
    - Accounting:
        - rename automatic rates
        - Anglo Saxon Account: Should be in technical feature
        - Place Accounting Reports section before Taxes section
    - CRM:
        - Phone Validation: Enforce international format becomes
        - Local Numbers: (2 radio buttons proposals) Add international prefix / No prefix
    - Fleet: typo " ... a new car if ..." + text is too long <br>
    - project: fix tooltip for colab pads
2017-09-01 13:02:54 +02:00
Denis Vermylen 054c68689b [IMP] auth_signup: various usability improvements in signup process
* allow new signup on invalid token
 * relabel signup buttons
 * send a welcome email upon signup with a signup token.

This way, should the token somehow be usurped by someone else,
the original partner's email address will be notified.
(before the usurper can change the email)
2017-07-06 12:53:39 +02:00
Denis Vermylen 689d6d6829 [IMP] website: add signup option in website settings
This commit duplicates the General settings' User Signup options in
the Website configuration, with a clear description of the options.

We also remove the unnecessary usage of safe_eval in auth_signup's
res_config.py. As stored values are repr values of a boolean field
just comparing the string values is sufficient. There is no need to
use safe_eval as it should be used only when necessary.
2017-07-06 12:53:39 +02:00
Yannick Tivisse a38a3e93c2 [MOV] *: Reorganize configuration files according to guidelines 2017-06-19 17:37:38 +02:00
Akash Bhavsar 79fd51b2a5 [IMP] base_setup: Improve the General Settings form view 2017-01-03 17:07:02 +01:00
Christophe Simonis 3ed483caa1 [MERGE] forward port of branch 9.0 up to fa4a371 2016-06-07 19:21:18 +02:00
Christophe Simonis 7889d7e0ff [FIX] web,auth_signup: prevent login autocapitalization
Mobile virtual keyboards will often capitalize the first letter of
an input text field, which is annoying as odoo logins are case-sensitive.
This will no longer happen thanks to this new attribute.

X-port of commit odoo/enterprise@b8632f8bb6
2016-06-07 16:15:47 +02:00
Kinjal Mehta 416903d1b9 [MIG] auth_signup: Migrated into new api. 2015-12-16 13:39:41 +01:00
Kinjal Mehta 327de507a7 [MOVE] auth_signup: Moved files in related models and views directory. 2015-12-16 12:20:41 +01:00
Martin Geubelle 65d0faca4d [IMP] auth_signup: reset password form
* Hide 'back to login' when there is a token
* Hide the form when the token is invalid
2015-11-17 13:01:08 +01:00
Christophe Simonis 7636b510a2 [ADD] *: CSRF protection in forms and routes
* make CSRF protection the default on all non-SAFE methods
  note: there currently is no way to call a CSRF-protected endpoint
  without a form-encoded entity-body as that's the only place we get the
  CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
  generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
  the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
  the purpose of a CSRF token in the database manager screens.
  There is no request database to obtain the
  secret and generate a CSRF token.
2015-10-01 01:36:50 +02:00
Nicolas Martinelli 516b1e1cce [IMP] auth_signup: rename "Reset password" to "Confirm" 2015-09-09 11:28:10 +02:00
Christophe Simonis edeceba7df [MERGE] forward port of branch saas-6 up to 7a768a4
Due to `sale` rewrite (94716a3f14),
the commit 503820acb6 has been partially
ignored (in sale.order.line) and will be rewritten later using new-api.
2015-08-28 15:07:16 +02:00
Christophe Simonis 6d85a9a4b9 [MERGE] forward port of branch 8.0 up to d744923 2015-08-27 18:30:46 +02:00
Denis Ledoux 0f03699956 [FIX] auth_signup: login & name readonly if signup with token
In the case of a signup with token, the user login
already exists, and changing of login (email) is
therefore not allowed.

It's the same behavior than in the reset password
view (`auth_signup.reset_password`)

opw-648125
2015-08-27 12:22:21 +02:00
Antony Lesuisse cd5444a16d [IMP] web: login page cleanups
- fix html and css layout using only pure bootstrap
- replace db selection by a link to the database selector
- reorder templates
- remove unused templates
2015-08-01 18:06:45 +02:00
Richard Mathot 7b763176ba [REM] modelines: Gotta catch 'em all 2015-01-08 11:38:58 +01:00
Olivier Dony 95abee7579 [IMP] auth_signup: better autofocus handling
bzr revid: odo@openerp.com-20140424174842-5zzos30cq0jdu9w6
2014-04-24 19:48:42 +02:00
Olivier Dony be6bef3c59 [FIX] auth_signup: avoid losing direct query string params during when switching between signup/signin/reset
bzr revid: odo@openerp.com-20140424162401-qtnopdtfdkfa1zxa
2014-04-24 18:24:01 +02:00
Christophe Simonis d504764eff [MERGE] forward port of branch saas-3 up to revid 9298 chm@openerp.com-20140311130852-3ft0v1mc9ht1any6
bzr revid: chs@openerp.com-20140311145205-s56fj113fsrnisc3
2014-03-11 15:52:05 +01:00
Olivier Dony 2cf5d26b1a [FIX] auth_signup: autofocus second field in signup form if login is already filled in
bzr revid: odo@openerp.com-20140306210835-82auwdf2aal3a25x
2014-03-06 22:08:35 +01:00
Denis Ledoux ee67a1ae39 [IMP] auth_signup: email first in the signup form, as is regarded as the most important variable
bzr revid: dle@openerp.com-20140227161638-5rp3bunjx77fbavu
2014-02-27 17:16:38 +01:00
Fabien Meghazi 075640848e [FIX] signup and rest password links
bzr revid: fme@openerp.com-20140227121032-2nj47kqc5bwwpo23
2014-02-27 13:10:32 +01:00
Christophe Simonis 3954a2f9af [FIX] auth_signup: force login to be an email when signup
bzr revid: chs@openerp.com-20140211132839-a4lzg0t7m7kl5ihr
2014-02-11 14:28:39 +01:00
Fabien Meghazi de7c5f76bd [MERGE] upstream
bzr revid: fme@openerp.com-20140210134735-59csf1137d6v10ev
2014-02-10 14:47:35 +01:00
Christophe Simonis 4b22c30888 [FIX] auth_signup: keep query when generating links
bzr revid: chs@openerp.com-20140206164020-2yuf5xdciabt4zsp
2014-02-06 17:40:20 +01:00
Fabien Meghazi bce084bac2 [IMP] Seperate signup and reset into two controllers and templates
bzr revid: fme@openerp.com-20140205183232-fmlin6kiycu6bu0j
2014-02-05 19:32:32 +01:00
Fabien Meghazi 9ffb9d5632 [REM] Removed LoginForm javascript related
bzr revid: fme@openerp.com-20140205092354-oa6qxm0fsuojhuc2
2014-02-05 10:23:54 +01:00
Fabien Meghazi 2bf139a9a1 [ADD] database selector to auth_signup
bzr revid: fme@openerp.com-20140124151910-riy18qm3ix93nbdg
2014-01-24 16:19:10 +01:00
Fabien Pinckaers ef5a50fa98 [IMP] wording
bzr revid: fp@tinyerp.com-20140122193818-vxn20qaibfvgn1u3
2014-01-22 20:38:18 +01:00
Fabien Pinckaers df3a1486f4 [IMP] remove under construction
bzr revid: fp@tinyerp.com-20140122193523-ni1uzv38plutq41m
2014-01-22 20:35:23 +01:00
Fabien Pinckaers 986471dcba [IMP] design of sign in/up
bzr revid: fp@tinyerp.com-20140122192322-nvtcood5ll0outn9
2014-01-22 20:23:22 +01:00
Fabien Meghazi fff55213b5 [IMP] auth_signup converted to server side module
bzr revid: fme@openerp.com-20140121152027-7wch4r7dt2ew0did
2014-01-21 16:20:27 +01:00
Fabien Meghazi c3f7ab7ddd [WIP] auth_signup
bzr revid: fme@openerp.com-20140117141806-r6f1dejdcg7ii1e0
2014-01-17 15:18:06 +01:00