Rationale:
- allow mass changing languages (in case you want to remove one lang)
- allow quick company re-assign
Other fields are marked as readonly to avoid messes.
Task-3494874
closesodoo/odoo#134786
Signed-off-by: Bouvy Damien (dbo) <dbo@odoo.com>
Add fields and tooling to support sub companies.
The new fields are
* `parent_ids`, which consists of all the ancestors of the current
company
* `root_id`, the upmost parent, which is the company controlling the
subsidiaries
* `parent_path` is added to avoid a hit on the performances when using
the multibranch feature
Also add a mechanism to ensure some fields are shared with a root
company and all it's descendents.
All fields listed by `_get_company_root_delegated_field_names` will be
readonly and copied from the `root_id`.
task-3371677
Part-of: odoo/odoo#125642
This commit makes hotkey uses more coherent throughout the entire
codebase by setting alt+q as main shortcurt for confirm and default
actions and alt+x for cancel actions.
task-3370463
closesodoo/odoo#127469
Related: odoo/enterprise#43694
Signed-off-by: Mathieu Duckerts-Antoine (dam) <dam@odoo.com>
Prior to this, there was no way to shut an active session you didn't have the
access to anymore or close every active session remotely.
Adding the RevokeAllDevices class, it is now possible to close every open
sessions, including the one you are performing the action on of the account
you are logged into via the Account Security page in the preferences.
This system is based on the principle that every open session uses the password
hash to maintain it. When the hash is computed, salt is added to it to make it
not reversible. Thanks to that salt, it is possible to change the user's
password's hash without changing the password. Therefore, the flow of this
addition is the following :
1. User clicks on the button and uses his passord to confirm identity.
2. User's input is used to check his identity (_check_credentials()).
3. User's input is used to refresh the password hash in the db (_change_password()).
4. User is logged out.
This adds a way to close all sessions remotely and improve user's control over
their account and therefore their security.
task-3191567
closesodoo/odoo#113899
Related: odoo/upgrade#4951
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
before this commit, if user search with full group
name in the search view of res.groups, currently
it returns no results.
* open groups menu
* search for Sales / Administrator
* will return no result
after this commit, searching a user group with
full name with return the corresponding user
group.
closesodoo/odoo#123723
X-original-commit: 6ef080a4818dd0bb85aa4ef257900522d9e9fbd6
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
This commit fix the users login disappearance when
hitting 'Change Password' button without setting a
password by adding force_save parameter. It also
removes the required parameter from the new_passwd
field so we don't get a vague missing field error
when one omits to enter a new password. Instead of
an error, we just leave the old password for the
missing lines.
Task-3184727
Part-of: odoo/odoo#112806
This reverts commit 14d97ec2
We revert this to keep the same design when changing password for
one or multiple users.
Task-3184727
Part-of: odoo/odoo#112806
Remove an option used by the phone widget in the res_user view.
task - 3246848
closesodoo/odoo#117805
X-original-commit: a998437ed465f1a2a0aaee3651472ff8c58ba067
Related: odoo/enterprise#39387
Signed-off-by: Kevin Baptiste <kba@odoo.com>
The type fields of actions already defaults to
the model name in the base model definition.
Therefore, specifying `ir.actions.server`, `ir.actions.act_window`
& so on as type is useless (and adds noise since it's the same as
the action model).
closesodoo/odoo#114539
Related: odoo/enterprise#37855
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
company_id is not in the group with phone, which makes it unaligned and weird looking, you can
see that especially when HR is installed and adds a boolean with a longer label.
this commit closesodoo/odoo#111567.
task 3127608
Signed-off-by: Kevin Baptiste <kba@odoo.com>
Purpose: The form view is more intuitive then list view in case
user wants to change the password only for one user.
task - 3105178
closesodoo/odoo#109869
Signed-off-by: Kevin Baptiste <kba@odoo.com>
Web:
Adding a css rule constraint to avoid the rule
from overwriting the o_field_highlight css class
applied on a field in a form view.
Base, auth_totp:
Adding the o_field_highlight class on the 2FA
form fields to display the input bottom border and
thereby more easily identify the fields.
Adding a placeholder to the 2FA password field.
Modifying the 2FA title and toggle font to keep
a consistency between the different page titles.
Task-3083540
closesodoo/odoo#108611
X-original-commit: c128a01490bbbcbf824781f5e8716aa30e65ba5b
Signed-off-by: Warnon Aurélien (awa) <awa@odoo.com>
No view is available for the mobile form of change.password.wizard. The
default behavior of the framework is to generate one using the backend
model. This result on showing some hidden fields to the user, some of
them (like in this case `Wizard Id`) is impossible to fill in.
opw-3027797
closesodoo/odoo#107911
X-original-commit: 0860ba8538793c081358105238946ebc0d2015e5
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
The res.users model functions a bit uniquely since it should allow a user to
modify their own parameters but turns off model edition priviledges by default.
See "SELF_WRITEABLE_FIELDS".
This implies that ir_ui_view#_postprocess_access_rights method will by default
turn off record edition, by automatically adding a 'edit="false"' attribute on
the form node when the frontend calls 'get_views'.
This will in turn prevent the user from modifying its preferences as it will
set the form view in readonly mode.
(It was apparently ignored pre-OWL, hence why we only have this issue now).
To fix the issue, we force the edition by manually setting 'edit="1"' on our
"view_users_form_simple_modif" form.
Allowing the end-user to modify their own settings again.
A tour was added to ensure this behavior.
Note that tour steps need to be adapted in the 'hr' module, as this module
changes the flow of modifying user preferences.
Task-3067001
closesodoo/odoo#106440
X-original-commit: 490d480458590c205962c3f9b95a63790a59f4d3
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Signed-off-by: Warnon Aurélien (awa) <awa@odoo.com>
The code does not actually depend on mail features and it is intended to be used
in the base form view of user.
closesodoo/odoo#105415
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Instead of making the language badge a list item, we bundle together
the email and the language badge and put them in a flex container
that wraps when the email is too long. The .ms-auto in the language
badge element makes it "float" to the right (or end).
Furthermore, we removed the t-if conditions because:
- Email (login) field is required anyway so it will always be there.
- Language badge will not render an element if it's empty.
closesodoo/odoo#104262
Task-id: 2758990
Signed-off-by: Julien Castiaux <juc@odoo.com>
The recent switch from tables to css grids for form views `group` nodes
has introduced several inconsistencies/issues with several views accross
modules - these will not be the last fixes.
closesodoo/odoo#102174
X-original-commit: 836568dfd59886a6d52f15e0e2109709903b6803
Related: odoo/enterprise#32295
Signed-off-by: Bouvy Damien (dbo) <dbo@odoo.com>
Due to group inheritance mechanism, if we try to "downgrade" the group
on a user's form view, after saving the record, sometimes the changes
may be reset automatically. Same kind of confusing behavior appears when
groups are automatically added due to cross-apps access rights dependencies.
This is very confusing because users can not easily understand what is
happening and why.
This commit improves the behavior by providing a proper warning string
to user on the fly when the groups are changed (which can potentially
be reset upon saving). For better understanding of possible scenarios
and the warning linked with them, see the test-cases that explain
everything with visual hierarchy.
taskID-2646704
closesodoo/odoo#91641
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
The changes in `auth_password_policy` are largely the owlification of
the password meter widget:
- modernize the password policy module and convert it to an
odoo-module (note: now exports a pseudo-abstract class which is
really a policy, for the sake of somewhat sensibly typing
`recommendations`)
- replace the implementation of the Meter and PasswordField widgets by
owl versions
The changes to web and base stem from taking a look at converting the
ChangePassword wizard, and finding that it would be a pain in the ass
but also... unnecessary? It seems to have been done as a wizard
completely in javascript despite being backend-only for legacy
reasons: apparently one of the very old web clients (v5 or v6
probably) implemented it as a "native action" which was directly part
of the client's UI, and so it had to be implemented entirely in the
client.
Over time it was moved back into the regular UI (and moved around
quite a bit), hooked as a client action to maintain access to the
existing UI / dialog.
But since it's been an action opened via a button for years it can
just... be a normal wizard, with password fields, which
auth_password_policy can then set the widget of.
So did that:
- removed the old unnecessary JS, and its dedicated endpoint (which is
*not* used by portal, portal has its own endpoint)
- used check_identity for the "old password check"
- split out `change_password` with an internal bit so we can have a
safer (and logged) "set user password" without needing to provide
the old password, which is now used for the bulk password change
wizard as well
- added a small wizard which just takes a new password (and
confirmation), for safety a given change password wizard is only
accessible to their creator (also the wizard is restricted to
employees though technically it would probably be fine for portal
users as well)
Rather than extensive messy rewrite / monkeypatching (the original
wizard was 57 LOC, though also 22 LOC of template, the auth_policy
hooking / patching was 33, plus 8 lines of CSS),
`auth_password_policy` just sets the widget of the `new_password`
field in the new wizard, much as it did the bulk wizard.
Also improve the "hide meter if field is empty" feature by leveraging
`:placeholder-shown`. This requires setting a placeholder, and while
empty works fine in firefox, it doesn't work in chrome. So the
placeholder needs to be a single space. Still, seems better than
updating a fake attribute or manipulating a class for the sake of
trivial styling.
Notes on unlink + transient vacuum
Although the wizard object is only created when actually calling
`change_password`, and is deleted on success, it is possible for the
user to get an error and fail to continue (it should be unlikely
without overrides since the passwords are checked while creating /
saving but...).
While in that case the `new_password` in the database is not the
user's own, it could be their *future* password, or give evidence as
to their password-creation scheme, or some other signal useful to
attack that front of the user's life and behavior. As such, quickly
removing leftovers from the database (by setting a very low transient
lifetime) seems like a good idea.
This is compounded by the `check_identity` having a grace period of 10
minutes. 0.1 is 6 minutes, but because the cron runs every 10 the user
effectively has 6~10 minutes between the moment they create an
incorrect / incomplete version of the wizard and the moment where it
is destroyed if they just leave it.
closesodoo/odoo#99458
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Step to reproduce:
- Go to 'My Preference' or User profile as admin
- Click on the world icon to add a language
Old Behaviour:
- Open the technical view of languages
New Behaviour:
- Open a wizard to add a a language
taskid-2774319
closesodoo/odoo#92855
Signed-off-by: Arnaud Joset <arj@odoo.com>
The documentation page for the external API was moved elsewhere with PR
odoo/documentation#2026.
closesodoo/odoo#94488
X-original-commit: 99eb55e14782bd32c4b2281681a62eb5f3d34407
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Since v15 and the owl improvment, the signatures of other users
could not be modified in HTML (as v14 and previous) as the
codeview button was missing.
In order to modify the signature with this commit in v15:
1/ Access a user
2/ Edit
3/ Click on the codeview button (Odoo Green button with </> inside)
4/ Copy/paste your html code
5/ (/!\) Click again on the codeview button
> You should see your HTML signature
6/ Save
opw-2728194
follow-up of https://github.com/odoo/odoo/pull/80788closesodoo/odoo#87506
X-original-commit: 573a33d10d0cc830ab6e23b4ec512f9394530c90
Signed-off-by: Simon Goffin <sig@odoo.com>
Signed-off-by: Vergote Baptiste (bve) <bve@odoo.com>
Purpose
=======
Add "Activate" button when selecting multiple languages, select multiple
languages when clicking on "Add languages" in settings.
Specifications
=============
`lang` variable in `base.language.install` changed from Selection to
Many2many to allow multiple languages being activated at once.
Hide globe icon for language fields from view mode (only visible when
editing). Remove state in base.language.install since it's no longer
need to keep track of the installation step.
Task-2662548
closesodoo/odoo#78287
Related: odoo/upgrade#2921
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Bug
===
Since cd8e0e9f46 the filter "no_share"
has been renamed to "filter_no_share", but the context key
"search_default_no_share" has not been updated in the other views.
closesodoo/odoo#83048
X-original-commit: 131b366e8d841fe7b8d2325941ea8518bcf998a7
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Purpose
=======
Hide non-relevant fields for a portal user. E.G. we want to hide the
notification type, the menu customization... Because those fields
make no sense for a portal user.
Force the non-internal user to receive notifications by emails since
they can not open Discuss.
Task-2508521
Part-of: odoo/odoo#77766
Co-authored-by: nounoubensebia <neb@odoo.com>
Purpose
=======
Review the UX of the 2-factor authentication flow in order to make it more clear
and easy to use.
Specifications
==============
This commit applies multiple rewording of instructions, button, etc. Tests have
been adapted accordingly.
It also adds an 'invite to use two-factor authentication' flow that will
send an email to the selected used to redirect them their account security
settings.
- If portal is not installed yet, the user is redirected to his account security
settings in backend.
- If portal is installed, the user is redirected to /my/profile if them are
portal user. Otherwise, the redirection is still done at backend side.
As the backend view of auth_totp wizard is used at frontend side, copyclipboard
widget has to be rebuilt at frontend side (click event, style etc..).
As API key section is now displayed only on debug mode, test urls have been
adapted accordingly.
Task-2487630
Part-of: odoo/odoo#71142
Define `data-hotkey` on most used action buttons.
For the modals, the following keys are dedicated for "special"
actions:
- Alt+G: add
- Alt+V: save
- Alt+Z: cancel
closesodoo/odoo#73275
Taskid: 2588233
Related: odoo/enterprise#19464
Signed-off-by: Kevin Baptiste <kba@odoo.com>
Description of the issue/feature this PR addresses:
It is currently quite difficult to differentiate users. Most of the time, people
don't take the time to upload an actual avatar so everybody looks the same. This
PR generates a custom avatar with the users initials and random color to
differentiate them. For res.users, res.partner and hr.employee, image fields now
hold the binary image and avatar are used to show the image or svg.
Current behavior before PR:
Avatar had only random colors and was being saved in database, being inefficient
Desired behavior after PR is merged:
A new mixin defines image fields and in case no image is set, it generates an
SVG image with the user's initials and random color.
closesodoo/odoo#69819
Task: 2404630
Related: odoo/enterprise#18199
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
Following the recent reorganisation of the documentation in 12.0+,
the majority of the documents have been moved and their old links are no longer valid.
Some redirection rules will soon be deployed, but those rules might be dropped in some years
and we want the links to still work, which is why we still replace the links to the new ones.
FW-Port of odoo/odoo#70675 (13.0)
closesodoo/odoo#70920
X-original-commit: bc9c1eef538ba6095e74c19d5d9ed9e01625ec7c
Related: odoo/enterprise#18361
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
1. Create a new user with only "Administration / Access Right"
2. Login as the user
3. Turn on debug mode (via plugin or by editing url)
4. Go to "Settings -> Users and Companies -> Groups"
5. Open any group form / Press "Create" button.
Bug:
Error "You are not allowed to access 'View' (ir.ui.view) records."
A user who is managing "Access Right" must be able to create/edit groups
opw:2492803
closesodoo/odoo#69332
X-original-commit: e179011b3118fe355ea33be194585f674d40df3f
Signed-off-by: Simon Goffin (sig) <sig@openerp.com>
Co-authored-by: mart-e <mat@odoo.com>
The mail signature of an user did not inline the CSS like the body of a
message, so for example icons seemed to work but would not be seen
(unless the mail reader had the same font-awesome system).
With this change we inline the signature too.
On edition there was also an issue since the original icon was saved as
data-class which was stripped: so eg. when editing a mail.message with
working icon, the icons would disappear.
opw-2453912
closesodoo/odoo#66372
X-original-commit: 5e093b7a37984c8cc5aa73d1c0f7aa9c9345e6b1
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
* account, analytic, calendar, coupon, crm, crm_iap_lead_website,
delivery, digest, event, event_crm, fleet, gamification, hr,
hr_expense, hr_skills, im_livechat, lunch, mail, maintenance,
mass_mailing, membership, mrp, point_of_sale, pos_mercury, product,
purchase, purchase_requisition, sale_management, sales_team, sms,
stock, stock_landed_costs, survey, website_crm_partner_assign,
website_event_exhibitor, website_event_track, website_forum,
website_slides, base
This commit removes oe_edit_only labels and adds placeholder
on fields in form views from a lot of apps to minimize the
shift when switching mode.
task 2330101
Some of the TOTP-related forms contained an attempt at making a centered
modal pop-up, using a bootstrap `card` that would also serve to
emphasize that the interaction was sensitive and security-related.
Some of the "footer buttons" were moved inside the form to make it
more obvious that they were part of the interaction flow.
However some of this caused breakages of responsiveness and did not yield
a really satisfactory result anyway.
This commit switches back to using regular non-centered forms. It looks
quite ugly because the content is better suited for a narrow modal, but
it means less surprises in terms of layout and less responsiveness
issues.
closesodoo/odoo#58541closesodoo/odoo#58544
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
due to breaking changes in https://github.com/odoo/odoo/pull/55995/commits/bf32b22ce247c19fda94ded74e37f7c6120ce2c4
and especially the part:
"NOTE 1. If the default_get within the onchange returns a value for
a field that is not in the view, we ignore it, and it won't be saved.
Before, that value was kept and sent upon save. This change in behavior
may prove problematic, although the overall risk is small. Decision has
been made to keep heavy comments and code snippets if we were to revert
back somehow to the previous situation."
the wizard to update user password was broken as the field user_id
which is required was not present in the view and was thus ignored by
to web client when calling 'create'.
closesodoo/odoo#57937
X-original-commit: 641ae07dbce1d0515fb0710a3363db47b27548e7
Signed-off-by: Laurent Smet <smetl@users.noreply.github.com>
Signed-off-by: Cedric Snauwaert (csn) <csn@openerp.com>
* allows portal users to update their password
* and manage their API keys
* any anything technical / security related we may need to add in the
future
Also bridge module for the password meter (auth password policy).
* ability for a user to request / create keys associated to their user
* overrides can block RPC solely through API keys, by overriding
`_rpc_api_keys_only()` (to require API auth even in
situations where the user has not requested it themselves)
* hash keys just in case as we can do so and might as well, add a
cleartext index (first 4 bytes of 20) to avoid blowing up the DB if
a user decides to create millions of keys for some daft reason
* users can delete their own keys, admins can delete (invalidate)
anyone's keys
* `scope` on API keys can be used to restrict usage to certain
kind of applications, so API keys can be used for other things
than global authentication. New keys manually created by users
have no scope by default so they are valid everywhere (global
keys). RPC auth (stateless XML-RPC/JSON-RPC) requires global keys
Co-authored-by: Florimond Husquinet <fhu@odoo.com>
Co-authored-by: Olivier Dony <odo@odoo.com>
Similar to github's sudo mode, my understanding of the intent is to
avoid third parties being able to perform sensitive / serious
operations when leaving a logged-in machine unattended.
This v1 only handles protecting "action methods" (methods called
through buttons and intended to return action descriptors), although
they can be used to "lock out" any methods they won't be able to
prompt and the caller will likely be surprised.