Commit Graph
37 Commits
Author SHA1 Message Date
Martin Trigaux ccc98e0169 [IMP] base: remove read access to ir.ui.view
Only system users should be able to access directly ir.ui.view records
Other users should use helper methods like fields_view_get or render
to interact with view records (or use sudo)

Give read access to views to publisher
He needs to call read_template on some views like
'web_editor.colorpicker' in edition mode

Restrict ACL on website.page
Apply the same ACL than on ir.ui.view as the model inherits from it.
Give access to designer to modify views
2020-05-14 13:59:10 +02:00
Mitali Patel c248594ee5 [IMP] base: allow restricting / removing exports right
Add a new group allowing administrators to remove the ability for
users to bulk-export data from the database. It's pretty minor as
technically the user can still access the underlying object through
the basic methods but it's still a bit of a roadblock.

Users can export by default.

Task 2170900

closes odoo/odoo#45400

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-04-01 13:07:50 +00:00
Romain Derie 96d3fa4e01 [IMP] base, website: add ir.ui.view action to compare arch (wizard)
This commit adds the possibility to compare a view arch to another one.
The result will be shown in a diff viewer (github like).

This is following what was done at #32009

task-2190072

closes odoo/odoo#44646

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-03-17 15:58:45 +00:00
Martin Trigaux 65530dfd6a [ADD] *: add ir.model.access on all transient models
Following changes needing ir.model.access on transient models too.
Remove groups declaration on the action to move it to ir.model.access
when possible.
Rules are strict by default with no unlink access by default and high
priviledge asked. Adaptations may be needed later.
Write access is given as a wizard may need to be modified in case the
action triggers an error and the user has to correct a value

account*: use account.group_account_user for all transient by default
	  remove account.print.journal relic
stock*: use stock.group_stock_user by default
survey: survey user can send invitations
mail: allow any employee to execute wizards
      additional verifications are made to ensure they are executed
      only on the documents the user has access to you
      give portal access to mail.compose.message as portal still does
      some actions like posting messages on the forum
      add ir.rule to avoid reading somebody else messages
      increase the query count because of undeterminist count
crm: saleman for lead2opp, manager for massmailing
     partner manager for actions linked to partners
     avoid a write in test_lead_lost
sms: any employee can send sms
mrp: mrp user can execute wizards
     give unlink access as making write during do_produce operation
base_import: employees can import files
delivery: stock user can deliver
event_sale: sale user can configure the wizards
	    event user inherit from  sale rights
gamification: employee can give badge
google_service: resolve FIXME
hr: add specific rights
    manager can set a plan according to group on button
    anyone who can write on an employee can register a departure
hr_expense: set rights based on buttons
hr_holidays: an approver can make a summary report
hr_recruitment: recruiter can refuse a candidate
hr_timesheet: can use the wizard if can create a timesheet
l10n_eu_service: managers can create fiscal positions
mass_mailing: same group as on mass.mailing.list
membership: accountant can create invoice from membership
payment: accountant can create a link
	 as the source is an account.move
	 keep the payment.acquirer.onboarding.wizard to system user
	 only as it is called during company configuration
point_of_sale: PoS manager only can use wizards
	       never create closing_balance_confirm_wizard records
product_expiry: stock user has rights on stock.picking
product_margin: access from accounting menus
repair: same rules as for above models
sale: set ir.rule for self wizard only
      add rule from model introduced in payment to add salesman group
sale_crm: saleman can create a quotation from a lead
sale_coupon: any saleman can generate coupon
	     add self ir.rule
sale_product_configurator: salesman can select product variants
snailmail: employee can send letters
website: designers can write on website
website_crm_partner_assign: same rule as group on action
website_sale: sale ACL as for payment.acquirer.onboarding.wizard
website_slides: anyone can send invitation

base: base.language.*: allow employee (cf lang_install)
      change.password.user: can not read change password wizard of
      other users
      test.*: no access is needed

Courtesy of Damien Bouvy, William Andre and Antoine Prieëls for review
of acl
2020-02-04 17:54:18 +01:00
Martin TrigauxandRaphaël Collet 7593b887df [REF] fields: use ir.model.fields.selection
The selection values of a selection field are now stored in database in the
model ir.model.fields.selection

This will allow to have a modular approche on selections and each selection
is now linked to the module that declared it.
Previously to this change, the selections were linked to the field, meaning
uninstalling a module had no impact on the selections stored on database.

With this change, the selections will now be translated in the correct module
(having an external id) and the records having a used selection will now be
reset to null.

closes odoo/odoo#30228

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>


Co-authored-by: Raphaël Collet <rco@odoo.com>
2019-08-19 11:44:34 +00:00
Julien MougenotandLucas Perais ed18095127 [IMP] base: Configure document layout
The onboarding modal for setting up the few base fields of a company
has now been moved to a wizard
It is accessible from the general settings, but also in the onboarding
section of sale and account modules.

The following company settings are editable with that wizard:

- Set report **layout**:
The user can chose the overall look of the report. The current choices
are : *Standard* (default), *Background*, *Boxed* and *Clean*.

- Set company **logo**:
Changes the company logo.

- Set report **colors**:
The user can set the primary and secondary colors of the report through
a newly added widget allowing to pick a custom color.
When changing the **logo**, colors are automatically set to its most dominant
colors.
> A "Reset colors" button also triggers the color calculation.

- Set report **font**:
Changes the overall font of the report. Only Google Fonts are used
for enhanced compatibility.

- Company **tagline**, also called "header"
- **Footer**
- **Paper format**
- Report **preview**:
A mockup of a final report
Automatically updates when changing **layout**, **logo**, **colors** or **font**

Co-authored by: Julien Mougenot <jum@odoo.com>

closes odoo/odoo#33863

Signed-off-by: VincentSchippefilt <VincentSchippefilt@users.noreply.github.com>


Co-authored-by: Lucas Perais <lpe@odoo.com>
2019-07-29 08:29:26 +00:00
Martin Trigaux dd2fae2ead [IMP] base: remove decimal.precision.test model
It should not be a standard model but a test model
2019-07-03 11:16:24 +00:00
Martin Trigaux a1eb000c93 [IMP] base: remove read access to decimal.precision
There is no reason to interact directly with it.
The method precision_get is done in SQL and ormcached, it is better to use it
2019-07-03 11:16:24 +00:00
Mitali Patel 0c5121a979 [IMP] decimal_precision: integrate into base
The decimal precision feature makes sense to be an ORM feature, no need to be
in a specific module

Previous syntax was
    from odoo.addons import decimal_precision as dp
    fields.Float(digits=dp.get_precision('Foo'))

and now is:
    fields.Float(digits='Foo')

Remove the possibility to have a callable method on the digits attribute (it
was only used for precision anyway) and directly retrieve the digits on the
decimal.precision model

Rename the method digits to get_digits to avoid confusion between the field
attribute when declaring a field and the method to retrieve the precision

Task id: 48198
2019-07-03 11:15:48 +00:00
Yannick Tivisse 62c9dedafd [IMP] base: Remove useless ACL rules
Now that portal users don't have access to the backend, it doesn't make
sense to give the read access on attachments, as this is the role of
the specific controllers to provide this access according to the business
logic.

For the record, these rules have been introduced at:
https://github.com/odoo/odoo/commit/61065b6d04248aa496765e1035c4c90cbdc38de7
https://github.com/odoo/odoo/commit/f3fa266d115ac9d4723164af10f8dee40821b290

closes odoo/odoo#32134

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-03-29 12:00:25 +00:00
Martin Trigaux c8a3e20f7b [IMP] base: make the name reflect what the rule does
Was called "group user" while was applying to manager

Fixes odoo/odoo#31300

closes odoo/odoo#31537
2019-03-01 14:18:23 +00:00
Christophe Simonis 1ade6675c3 [MERGE] forward port branch 11.0 up to 717f458394 2018-10-11 16:29:46 +02:00
Stijn Houben 26d67991c2 [FIX] base: allow admin to modify paperformats
If a user creates a paperformat, he should be able to modify it too.
Employees have no reason to modify the paperformat though (nor create).
Having a malicious employee modifying an existing report may be dangerous.

[CLA] signature for stijnh92

Fixes #26292

closes odoo/odoo#27444
2018-10-10 13:13:19 +00:00
Thibault Delavallée 4fd6945535 [REM] base, various: remove res.request.link
Not used since a while, remaining of old res.request. Requests have been
removed at 881a76dbcf . Links have been kept because still
used in some reference fields. It seems the last use was in OpenERP v9.0
in crm_claim module. As links are not used since a while let us get rid of
it.
2017-10-19 14:53:39 +02:00
Raphael Collet 10cb1beead [REM] base: remove model ir.values 2017-08-28 09:53:23 +02:00
Raphael Collet 60d9f6fef9 [ADD] base: model ir.default to store user-defined defaults 2017-08-28 09:53:23 +02:00
Olivier Dony 5d2869cbc8 [MERGE] Forward-port saas-16 up to ba15df47cb 2017-06-01 01:46:13 +02:00
Yannick Tivisse 9a572f8eec [IMP] base: Add a new model 'Sector of Activity' used on partners
purpose
=======

We need to store and produce reports about customer activity sectors to improve references mechanism.

Specification
=============

- add a new model res.partner.industry "Sector of Activity"
    - fields:
        - name (translatable)
        - full_name (translatable)
        - active
    - add minimalist form and list views (à la Contact Tags)
    - menu: Sales/Settings/Contacts/Contact Industries  (Technical Settings only)
    - ACL: R for group_user, CRUD for group_system
- add a default XML data file to preload res.partner.industry with the ISIC 2008 aka NACE rev.2 level 1: https://docs.google.com/a/odoo.com/spreadsheets/d/1IrGbHIaaDDkBAS2uGABeNRPndtYbyVBVoYYpQNXnhnY/edit?usp=sharing
    - Note: we leave it as an option for end-users to import their own industries, because there are many competing standards: ISIC, NACE, NAICS, OKVED, etc.
    - Each standard also has different hierarchical levels, and we only use the top level one by default.
- add a m2o industry_id ("Sector of Activity") on res.partner towards res.partner.industry
    - add industry_id in partner form view, in Sales & Purchase > Misc, only visible when contact type is Company
    - No quick create for this field
2017-05-22 11:30:11 +02:00
Laurent Smet e80238042c [REF] report: remove the report module
The content of the report module is now dispatched in
the 'base' and the 'web' modules.
2017-05-08 09:23:12 +02:00
Laurent Smet 3425752eac [REM] odoo/report: remove deprecated stuff
- RML Reports
- Webkit Reports (most part already removed by 13b9982c62)
- LocalService in netsvc.py
- rename attributes like rml_% to report_%
- rename ir.actions.report.xml to ir.actions.report
- allow rendering directly on an ir.actions.report by calling render method
- remove 'controller' report_type
- remove unused res.font stuff
- remove print_report method in models.py (not used)
- restore removed call to pdftotext process in test_reports
2017-05-08 09:22:56 +02:00
Raphael Collet 6498f35145 [IMP] base: add individual module exclusions 2017-04-06 11:17:58 +02:00
Jérome Maes 48f5c81755 [IMP] base,website_portal: webclient forbidden for portal user
About a `sudo` on ir.ui.menu, this commit (3649b7f359) removed it,
this commit (3d0cc2d6d2) re-added it.
Since portal user can not go on /web anymore, I think portal does not need to read ir.ui.menu.

Here some news scenario:
- if website is not installed, portal can log in, but will be redirected to login page
with an error message 'only employee can access'. Indeed, there is no page to display for
such user.
- if website is installed, but not website_portal, portal user can log in and will be
redirected to homepage. If he tries to manually access to /web, he will be redirect to
login page with access error (even if he will still be logged).
- if website_portal is installed, the portal user can fully enjoy its features.
2017-03-23 10:16:28 +01:00
Jérome Maes 1f3da58cfe [MOV] base,portal: make portal module empty
The goal is to prepare the removal of
'portal' module.

- demo portal user is moved into base
- 'is_portal' field on res.group too
- remaining security rule are moved to base too
- mail template is moved to website_portal
2017-03-23 09:59:58 +01:00
Raphael Collet 4a18d5744e [FIX] base: restrict read access to ir.model and ir.model.fields to employees 2017-01-20 10:05:10 +01:00
Raphael Collet 3649b7f359 [FIX] base: access rights of ir.model and ir.model.fields
This partially reverts commits 5d746d0ac6 and
73de86c768.

The tightening of access rights was too strong: regular users need to be able
to read models and fields (to create an email templace, for instance.)

[FIX] ir_values: in `get_actions`, exclude field `code`
2017-01-17 16:15:26 +01:00
Raphael Collet 172a767e5f [IMP] base: tighten ir.rule access rights
The computed field `domain` was formerly read as the current user to evaluate
the rule's domain for the current user.  As we restrict the access of `ir.rule`
to advanced users only, the computed field has no purpose anymore.
2017-01-03 16:52:50 +01:00
Raphael Collet 6453e4eb23 [IMP] base: tighten ir.model.data access rights 2017-01-03 16:52:50 +01:00
Raphael Collet 34c661111b [IMP] base, *: tighten ir.model.access access rights
In `website_crm_partner_assign`, remove duplicate ACLs and reorganize files.
2017-01-03 16:52:50 +01:00
Raphael Collet 4f230b2180 [IMP] base: tighten ir.model.relation access rights 2017-01-03 16:52:50 +01:00
Raphael Collet 73de86c768 [IMP] base: tighten ir.model.fields access rights 2017-01-03 16:52:49 +01:00
Raphael Collet 18f4711dce [IMP] base: tighten ir.model.constraint access rights 2017-01-03 16:52:49 +01:00
Raphael Collet 5d746d0ac6 [IMP] base, *: tighten ir.model access rights
Remove unrestricted "read" access.  To make code internally using `ir.model`
work, add a private method `_get` on `ir.model` to retrieve the record
corresponding to a model name, without access rights issue.

Change signature of method `get_authorized_fields` to make it use a model name
instead of a model id.  This removes the necessity of a search on `ir.model`.
2017-01-03 16:52:49 +01:00
Raphael Collet 1abd543f14 [IMP] base: tighten ir.filters access rights
Remove "full access" for all users, and add it to specific groups.
2017-01-03 16:52:49 +01:00
Raphael Collet d0ca2d115e [REF] ir_config_parameter: remove group_ids and simplify
Add `sudo()` to call `get_param` where necessary, and make the web client use a
controller instead of directly accessing parameters.
2017-01-03 16:52:49 +01:00
Jérome Maes 13f84b9aca [REM] *: remove ir.needaction mixin
ir.needaction_mixin is not used anymore by the webclient.
From 9.0, the concept has changed: this feature is now
available in mail module, with the mail.thread mixin,
and message_neeadction field.

Remove all code handeling needaction bullet and
counter on ir.ui.menu, knowing that since 9.0
webclient does not display the counter anymore.

This code was, thus, useless and some RPC calls
were done for nothing, and adapt accounting
reconcialiation widget.
2016-12-05 11:30:03 +01:00
Yannick Tivisse 98cb4719db [REM] workflow: Remove workflow engine, documentation and tests 2016-11-23 11:52:39 +01:00
Raphael Collet 9e64f9f951 [REF] openerp: move openerp to odoo 2016-09-02 17:28:12 +02:00