Commit Graph
104 Commits
Author SHA1 Message Date
Damien Bouvy 4eb3b4ba87 [IMP] base: mass_editable users list view
Rationale:
- allow mass changing languages (in case you want to remove one lang)
- allow quick company re-assign

Other fields are marked as readonly to avoid messes.

Task-3494874

closes odoo/odoo#134786

Signed-off-by: Bouvy Damien (dbo) <dbo@odoo.com>
2023-09-08 09:47:10 +00:00
Gorash 774a3fad0e [REF] base,all: Update modifier syntax: view migration
Apply of the migration script to update all view modifiers.

Part-of: odoo/odoo#104741
2023-08-18 09:49:13 +02:00
william-andre dc4dcead6e [IMP] base: add more support for sub companies
Add fields and tooling to support sub companies.
The new fields are
* `parent_ids`, which consists of all the ancestors of the current
  company
* `root_id`, the upmost parent, which is the company controlling the
  subsidiaries
* `parent_path` is added to avoid a hit on the performances when using
  the multibranch feature

Also add a mechanism to ensure some fields are shared with a root
company and all it's descendents.
All fields listed by `_get_company_root_delegated_field_names` will be
readonly and copied from the `root_id`.

task-3371677

Part-of: odoo/odoo#125642
2023-07-20 11:49:04 +02:00
Julien Carion (juca) 6c412be2ea [IMP] *: coherent hotkey uses
This commit makes hotkey uses more coherent throughout the entire
codebase by setting alt+q as main shortcurt for confirm and default
actions and alt+x for cancel actions.

task-3370463

closes odoo/odoo#127469

Related: odoo/enterprise#43694
Signed-off-by: Mathieu Duckerts-Antoine (dam) <dam@odoo.com>
2023-07-19 18:24:15 +02:00
Thomas (thbe) 82985296e1 [ADD] base: Revoke access to your account to all devices
Prior to this, there was no way to shut an active session you didn't have the
access to anymore or close every active session remotely.

Adding the RevokeAllDevices class, it is now possible to close every open
sessions, including the one you are performing the action on of the account
you are logged into via the Account Security page in the preferences.

This system is based on the principle that every open session uses the password
hash to maintain it. When the hash is computed, salt is added to it to make it
not reversible. Thanks to that salt, it is possible to change the user's
password's hash without changing the password. Therefore, the flow of this
addition is the following :
1. User clicks on the button and uses his passord to confirm identity.
2. User's input is used to check his identity (_check_credentials()).
3. User's input is used to refresh the password hash in the db (_change_password()).
4. User is logged out.

This adds a way to close all sessions remotely and improve user's control over
their account and therefore their security.

task-3191567

closes odoo/odoo#113899

Related: odoo/upgrade#4951
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-07-18 19:27:19 +02:00
niyasraphy db8a289384 [FIX] base: search groups with full name
before this commit, if user search with full group
name in the search view of res.groups, currently
it returns no results.

* open groups menu
* search for Sales / Administrator
* will return no result

after this commit, searching a user group with
full name with return the corresponding user
group.

closes odoo/odoo#123723

X-original-commit: 6ef080a4818dd0bb85aa4ef257900522d9e9fbd6
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
2023-06-06 11:45:11 +02:00
Elisabeth Dickinson b2ef35a431 [IMP] *: replace .bg-color by .text-bg-color on ribbons
Also remove unnecessary CSS on ribbons.

Part-of: odoo/odoo#116641
2023-05-12 22:59:16 +02:00
Patrick Hoste cde4a9c647 [IMP] base: improve user password wizard
This commit fix the users login disappearance when
hitting 'Change Password' button without setting a
password by adding force_save parameter. It also
removes the required parameter from the new_passwd
field so we don't get a vague missing field error
when one omits to enter a new password. Instead of
an error, we just leave the old password for the
missing lines.

Task-3184727

Part-of: odoo/odoo#112806
2023-05-04 19:09:55 +02:00
Patrick Hoste 3c5d9e8e1d [REV] base,auth_password_policy: add form view for changing password
This reverts commit 14d97ec2
We revert this to keep the same design when changing password for
one or multiple users.

Task-3184727

Part-of: odoo/odoo#112806
2023-05-04 19:09:55 +02:00
sofiagvaladze 7ca2d7dbd6 [IMP] base: UX improvement
Remove an option used by the phone widget in the res_user view.

task - 3246848

closes odoo/odoo#117805

X-original-commit: a998437ed465f1a2a0aaee3651472ff8c58ba067
Related: odoo/enterprise#39387
Signed-off-by: Kevin Baptiste <kba@odoo.com>
2023-04-05 17:31:49 +02:00
Victor Feyens 24ccf7d9b0 [CLN] *: useless type info for actions
The type fields of actions already defaults to
the model name in the base model definition.

Therefore, specifying `ir.actions.server`, `ir.actions.act_window`
& so on as type is useless (and adds noise since it's the same as
the action model).

closes odoo/odoo#114539

Related: odoo/enterprise#37855
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
2023-03-08 17:33:37 +01:00
dasz 5060163ef2 [FIX] hr,base: fix layout of simple user form, access rights on create_employee
company_id is not in the group with phone, which makes it unaligned and weird looking, you can
see that especially when HR is installed and adds a boolean with a longer label.

this commit closes odoo/odoo#111567.
task 3127608

Signed-off-by: Kevin Baptiste <kba@odoo.com>
2023-02-28 13:01:34 +01:00
sofiagvaladze 14d97ec28a [IMP] base,auth_password_policy: add form view for changing password
Purpose: The form view is more intuitive then list view in case
user wants to change the password only for one user.

task - 3105178

closes odoo/odoo#109869

Signed-off-by: Kevin Baptiste <kba@odoo.com>
2023-02-07 14:35:33 +01:00
amdi-odoo 2a015600b2 [FIX] web,auth_totp,base: fix 2FA views
Web:

Adding a css rule constraint to avoid the rule
from overwriting the o_field_highlight css class
applied on a field in a form view.

Base, auth_totp:

Adding the o_field_highlight class on the 2FA
form fields to display the input bottom border and
thereby more easily identify the fields.

Adding a placeholder to the 2FA password field.

Modifying the 2FA title and toggle font to keep
a consistency between the different page titles.

Task-3083540

closes odoo/odoo#108611

X-original-commit: c128a01490bbbcbf824781f5e8716aa30e65ba5b
Signed-off-by: Warnon Aurélien (awa) <awa@odoo.com>
2022-12-26 11:39:47 +01:00
Jordan D.(Joda) 5c219ec80e [FIX] base: enforce tree view on change.password.wizard
No view is available for the mobile form of change.password.wizard. The
default behavior of the framework is to generate one using the backend
model. This result on showing some hidden fields to the user, some of
them (like in this case `Wizard Id`) is impossible to fill in.

opw-3027797

closes odoo/odoo#107911

X-original-commit: 0860ba8538793c081358105238946ebc0d2015e5
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2022-12-14 14:20:01 +01:00
niyasraphy 72aab77331 [FIX] base, hr_recruitment_skills: fix typo
closes odoo/odoo#106839

X-original-commit: 4e85ee767f9cc0781823c0bfb4c79df8da1c6c2e
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-11-30 12:13:55 +01:00
Aurélien Warnon bb58fdacba [FIX] base: allow user to modify its own preferences
The res.users model functions a bit uniquely since it should allow a user to
modify their own parameters but turns off model edition priviledges by default.
See "SELF_WRITEABLE_FIELDS".

This implies that ir_ui_view#_postprocess_access_rights method will by default
turn off record edition, by automatically adding a 'edit="false"' attribute on
the form node when the frontend calls 'get_views'.

This will in turn prevent the user from modifying its preferences as it will
set the form view in readonly mode.
(It was apparently ignored pre-OWL, hence why we only have this issue now).

To fix the issue, we force the edition by manually setting 'edit="1"' on our
"view_users_form_simple_modif" form.
Allowing the end-user to modify their own settings again.

A tour was added to ensure this behavior.
Note that tour steps need to be adapted in the 'hr' module, as this module
changes the flow of modifying user preferences.

Task-3067001

closes odoo/odoo#106440

X-original-commit: 490d480458590c205962c3f9b95a63790a59f4d3
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Signed-off-by: Warnon Aurélien (awa) <awa@odoo.com>
2022-11-24 19:25:16 +01:00
Sébastien Theys c0f78e9d27 [IMP] base, web, mail: clean and move notification_alert
The code does not actually depend on mail features and it is intended to be used
in the base form view of user.

closes odoo/odoo#105415

Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
2022-11-14 18:17:49 +01:00
Joseph Caburnay 1a4750942a [IMP] base: truncate long email in res_users kanban
Instead of making the language badge a list item, we bundle together
the email and the language badge and put them in a flex container
that wraps when the email is too long. The .ms-auto in the language
badge element makes it "float" to the right (or end).

Furthermore, we removed the t-if conditions because:
- Email (login) field is required anyway so it will always be there.
- Language badge will not render an element if it's empty.

closes odoo/odoo#104262

Task-id: 2758990
Signed-off-by: Julien Castiaux <juc@odoo.com>
2022-10-31 13:39:51 +01:00
Damien Bouvy e647a2de09 [IMP] *: adapt to grid form views
The recent switch from tables to css grids for form views `group` nodes
has introduced several inconsistencies/issues with several views accross
modules - these will not be the last fixes.

closes odoo/odoo#102174

X-original-commit: 836568dfd59886a6d52f15e0e2109709903b6803
Related: odoo/enterprise#32295
Signed-off-by: Bouvy Damien (dbo) <dbo@odoo.com>
2022-10-11 13:15:12 +02:00
Nikunj Ladava 1f819b5f28 [IMP] base: communicate access group inheritance warning(s)
Due to group inheritance mechanism, if we try to "downgrade" the group
on a user's form view, after saving the record, sometimes the changes
may be reset automatically. Same kind of confusing behavior appears when
groups are automatically added due to cross-apps access rights dependencies.

This is very confusing because users can not easily understand what is
happening and why.

This commit improves the behavior by providing a proper warning string
to user on the fly when the groups are changed (which can potentially
be reset upon saving). For better understanding of possible scenarios
and the warning linked with them, see the test-cases that explain
everything with visual hierarchy.

taskID-2646704

closes odoo/odoo#91641

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-09-20 11:33:46 +02:00
Xavier Morel b3b85cae9b [IMP] *: owlify password meter and convert change password to real wizard
The changes in `auth_password_policy` are largely the owlification of
the password meter widget:

- modernize the password policy module and convert it to an
  odoo-module (note: now exports a pseudo-abstract class which is
  really a policy, for the sake of somewhat sensibly typing
  `recommendations`)
- replace the implementation of the Meter and PasswordField widgets by
  owl versions

The changes to web and base stem from taking a look at converting the
ChangePassword wizard, and finding that it would be a pain in the ass
but also... unnecessary? It seems to have been done as a wizard
completely in javascript despite being backend-only for legacy
reasons: apparently one of the very old web clients (v5 or v6
probably) implemented it as a "native action" which was directly part
of the client's UI, and so it had to be implemented entirely in the
client.

Over time it was moved back into the regular UI (and moved around
quite a bit), hooked as a client action to maintain access to the
existing UI / dialog.

But since it's been an action opened via a button for years it can
just... be a normal wizard, with password fields, which
auth_password_policy can then set the widget of.

So did that:

- removed the old unnecessary JS, and its dedicated endpoint (which is
  *not* used by portal, portal has its own endpoint)
- used check_identity for the "old password check"
- split out `change_password` with an internal bit so we can have a
  safer (and logged) "set user password" without needing to provide
  the old password, which is now used for the bulk password change
  wizard as well
- added a small wizard which just takes a new password (and
  confirmation), for safety a given change password wizard is only
  accessible to their creator (also the wizard is restricted to
  employees though technically it would probably be fine for portal
  users as well)

Rather than extensive messy rewrite / monkeypatching (the original
wizard was 57 LOC, though also 22 LOC of template, the auth_policy
hooking / patching was 33, plus 8 lines of CSS),
`auth_password_policy` just sets the widget of the `new_password`
field in the new wizard, much as it did the bulk wizard.

Also improve the "hide meter if field is empty" feature by leveraging
`:placeholder-shown`. This requires setting a placeholder, and while
empty works fine in firefox, it doesn't work in chrome. So the
placeholder needs to be a single space. Still, seems better than
updating a fake attribute or manipulating a class for the sake of
trivial styling.

Notes on unlink + transient vacuum

Although the wizard object is only created when actually calling
`change_password`, and is deleted on success, it is possible for the
user to get an error and fail to continue (it should be unlikely
without overrides since the passwords are checked while creating /
saving but...).

While in that case the `new_password` in the database is not the
user's own, it could be their *future* password, or give evidence as
to their password-creation scheme, or some other signal useful to
attack that front of the user's life and behavior. As such, quickly
removing leftovers from the database (by setting a very low transient
lifetime) seems like a good idea.

This is compounded by the `check_identity` having a grace period of 10
minutes. 0.1 is 6 minutes, but because the cron runs every 10 the user
effectively has 6~10 minutes between the moment they create an
incorrect / incomplete version of the wizard and the moment where it
is destroyed if they just leave it.

closes odoo/odoo#99458

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-09-08 18:31:18 +02:00
Florian Damhaut 8646ebb8f5 [IMP] base: On profile, open lang wizard instead of technical view
Step to  reproduce:
- Go to 'My Preference' or User profile as admin
- Click on the world icon to add a language

Old Behaviour:
- Open the technical view of languages

New Behaviour:
- Open a wizard to add a a language

taskid-2774319

closes odoo/odoo#92855

Signed-off-by: Arnaud Joset <arj@odoo.com>
2022-07-14 16:41:56 +02:00
Romeo Fragomeli 1fcd098af5 [REF] *: BS5: migration
Automated change made by a lot of RegEx to change all think that is
possible to automate.

https://getbootstrap.com/docs/5.1/migration

Task ID: 2766483

Part-of: odoo/odoo#95450
2022-07-07 13:30:24 +02:00
Antoine Vandevenne (anv) fd1e27c43d [FIX] base: fix link to non-existing documentation page
The documentation page for the external API was moved elsewhere with PR
odoo/documentation#2026.

closes odoo/odoo#94488

X-original-commit: 99eb55e14782bd32c4b2281681a62eb5f3d34407
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-06-24 11:32:51 +02:00
bve-odoo ad6827f5e5 [FIX] base: allow the codeview on users signature
Since v15 and the owl improvment, the signatures of other users
could not be modified in HTML (as v14 and previous) as the
codeview button was missing.

In order to modify the signature with this commit in v15:
1/ Access a user
2/ Edit
3/ Click on the codeview button (Odoo Green button with </> inside)
4/ Copy/paste your html code
5/ (/!\) Click again on the codeview button
> You should see your HTML signature
6/ Save

opw-2728194
follow-up of https://github.com/odoo/odoo/pull/80788

closes odoo/odoo#87506

X-original-commit: 573a33d10d0cc830ab6e23b4ec512f9394530c90
Signed-off-by: Simon Goffin <sig@odoo.com>
Signed-off-by: Vergote Baptiste (bve) <bve@odoo.com>
2022-03-30 11:13:30 +02:00
Fabio Barbero 47041f2d45 [IMP] base: allow user to activate multiple languages at once
Purpose
=======
Add "Activate" button when selecting multiple languages, select multiple
languages when clicking on "Add languages" in settings.

Specifications
=============
`lang` variable in `base.language.install` changed from Selection to
Many2many to allow multiple languages being activated at once.
Hide globe icon for language fields from view mode (only visible when
editing). Remove state in base.language.install since it's no longer
need to keep track of the installation step.

Task-2662548

closes odoo/odoo#78287

Related: odoo/upgrade#2921
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-03-14 08:42:58 +00:00
Antoine Vandevenne (anv) adf70bf9dc [FIX] *: retarget documentation links to master
closes odoo/odoo#84990

X-original-commit: 39bdf46
Related: odoo/enterprise#24582
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-02-21 17:01:02 +00:00
std-odoo e1535583db [FIX] base: the filter "no share" is not applied in the users list view
Bug
===
Since cd8e0e9f46 the filter "no_share"
has been renamed to "filter_no_share", but the context key
"search_default_no_share" has not been updated in the other views.

closes odoo/odoo#83048

X-original-commit: 131b366e8d841fe7b8d2325941ea8518bcf998a7
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-01-20 08:22:02 +00:00
Nicolas Bayet f02b1727dd [FIX] base: allow the codeview for the user signature
Task-2674070

closes odoo/odoo#80897

X-original-commit: 17d9a044ff0cab09a40695da00769dd55135577f
Signed-off-by: David Monjoie (dmo) <dmo@odoo.com>
2021-12-06 12:55:11 +00:00
std-odooandnounoubensebia cd8e0e9f46 [IMP] base, *: hide non-relevant fields for portal users
Purpose
=======
Hide non-relevant fields for a portal user. E.G. we want to hide the
notification type,  the menu customization... Because those fields
make no sense for a portal user.

Force the non-internal user to receive notifications by emails since
they can not open Discuss.

Task-2508521

Part-of: odoo/odoo#77766
Co-authored-by: nounoubensebia <neb@odoo.com>
2021-11-09 14:45:49 +00:00
Victor Feyens ab022ec12d [FIX] *: target v15.0 documentation with doc links
X-original-commit: acc95ec204baa1dddbe292c379a1768fe1deccbf
Part-of: odoo/odoo#77923
2021-10-07 17:59:52 +00:00
Xavier Morel 499b1621ba [FIX] *: non-accessible buttons
closes odoo/odoo#76581

Related: odoo/enterprise#20897
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2021-09-15 15:22:58 +00:00
David Beguin 29db699e9b [IMP] auth_top, *: revamp Two-factor authentication flow
Purpose
=======

Review the UX of the 2-factor authentication flow in order to make it more clear
and easy to use.

Specifications
==============

This commit applies multiple rewording of instructions, button, etc. Tests have
been adapted accordingly.

It also adds an 'invite to use two-factor authentication' flow that will
send an email to the selected used to redirect them their account security
settings.
- If portal is not installed yet, the user is redirected to his account security
settings in backend.
- If portal is installed, the user is redirected to /my/profile if them are
portal user. Otherwise, the redirection is still done at backend side.

As the backend view of auth_totp wizard is used at frontend side, copyclipboard
widget has to be rebuilt at frontend side (click event, style etc..).

As API key section is now displayed only on debug mode, test urls have been
adapted accordingly.

Task-2487630

Part-of: odoo/odoo#71142
2021-08-30 21:05:12 +00:00
Kevin Baptiste 86aa7b78aa [IMP] *: introduce data-hotkey on form and modal views
Define `data-hotkey` on most used action buttons.

For the modals, the following keys are dedicated for "special"
actions:
 - Alt+G: add
 - Alt+V: save
 - Alt+Z: cancel

closes odoo/odoo#73275

Taskid: 2588233
Related: odoo/enterprise#19464
Signed-off-by: Kevin Baptiste <kba@odoo.com>
2021-07-15 08:39:49 +00:00
Leonardo Pavan Rocha c53724ebc3 [IMP] *: adds generic user avatar
Description of the issue/feature this PR addresses:
It is currently quite difficult to differentiate users. Most of the time, people
don't take the time to upload an actual avatar so everybody looks the same. This
PR generates a custom avatar with the users initials and random color to
differentiate them. For res.users, res.partner and hr.employee, image fields now
hold the binary image and avatar are used to show the image or svg.

Current behavior before PR:
Avatar had only random colors and was being saved in database, being inefficient

Desired behavior after PR is merged:
A new mixin defines image fields and in case no image is set, it generates an
SVG image with the user's initials and random color.

closes odoo/odoo#69819

Task: 2404630
Related: odoo/enterprise#18199
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2021-06-01 14:36:23 +00:00
Victor Feyens 0348b95aee [FIX] *: update documentation links
Following the recent reorganisation of the documentation in 12.0+,
the majority of the documents have been moved and their old links are no longer valid.
Some redirection rules will soon be deployed, but those rules might be dropped in some years
and we want the links to still work, which is why we still replace the links to the new ones.

FW-Port of odoo/odoo#70675 (13.0)

closes odoo/odoo#70920

X-original-commit: bc9c1eef538ba6095e74c19d5d9ed9e01625ec7c
Related: odoo/enterprise#18361
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2021-05-17 19:26:27 +00:00
Goffin Simonandmart-e 89d9ae940b [FIX] base: User with "Administration /Access Right" can't View "Groups"
1. Create a new user with only "Administration / Access Right"
2. Login as the user
3. Turn on debug mode (via plugin or by editing url)
4. Go to "Settings -> Users and Companies -> Groups"
5. Open any group form / Press "Create" button.

Bug:

Error "You are not allowed to access 'View' (ir.ui.view) records."

A user who is managing "Access Right" must be able to create/edit groups

opw:2492803

closes odoo/odoo#69332

X-original-commit: e179011b3118fe355ea33be194585f674d40df3f
Signed-off-by: Simon Goffin (sig) <sig@openerp.com>
Co-authored-by: mart-e <mat@odoo.com>
2021-04-15 15:07:44 +00:00
Nicolas Lempereur 115965fdc5 [FIX] base: mail signature CSS inlined for icons etc
The mail signature of an user did not inline the CSS like the body of a
message, so for example icons seemed to work but would not be seen
(unless the mail reader had the same font-awesome system).

With this change we inline the signature too.

On edition there was also an issue since the original icon was saved as
data-class which was stripped: so eg. when editing a mail.message with
working icon, the icons would disappear.

opw-2453912

closes odoo/odoo#66372

X-original-commit: 5e093b7a37984c8cc5aa73d1c0f7aa9c9345e6b1
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2021-02-17 14:13:29 +00:00
Michael Mattiello (mcm) 785b304876 [IMP] *: reduce shift in form views (xml)
* account, analytic, calendar, coupon, crm, crm_iap_lead_website,
  delivery, digest, event, event_crm, fleet, gamification, hr,
  hr_expense, hr_skills, im_livechat, lunch, mail, maintenance,
  mass_mailing, membership, mrp, point_of_sale, pos_mercury, product,
  purchase, purchase_requisition, sale_management, sales_team, sms,
  stock, stock_landed_costs, survey, website_crm_partner_assign,
  website_event_exhibitor, website_event_track, website_forum,
  website_slides, base

This commit removes oe_edit_only labels and adds placeholder
on fields in form views from a lot of apps to minimize the
shift when switching mode.

task 2330101
2021-02-02 12:40:22 +00:00
Julien Castiaux 90b52d144a [REF] base: Use Command helper for x2many
Task: 2366606
2020-11-30 10:16:09 +00:00
Moens Alexandre fef82f3c97 [FIX] base: API documentation link
opw-2374318

closes odoo/odoo#61326

X-original-commit: c1f43707c6e9efc7321b71120df45f2e2cf7ee82
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
2020-11-04 12:59:47 +00:00
Olivier Dony 3f3c7b507a [IMP] base, totp: simplify form layout and improve responsiveness
Some of the TOTP-related forms contained an attempt at making a centered
modal pop-up, using a bootstrap `card` that would also serve to
emphasize that the interaction was sensitive and security-related.
Some of the "footer buttons" were moved inside the form to make it
more obvious that they were part of the interaction flow.

However some of this caused breakages of responsiveness and did not yield
a really satisfactory result anyway.

This commit switches back to using regular non-centered forms. It looks
quite ugly because the content is better suited for a narrow modal, but
it means less surprises in terms of layout and less responsiveness
issues.

closes odoo/odoo#58541

closes odoo/odoo#58544

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2020-09-26 09:45:17 +00:00
Cedric Snauwaert ab17ad3e5c [FIX] base: fix update password wizard
due to breaking changes in https://github.com/odoo/odoo/pull/55995/commits/bf32b22ce247c19fda94ded74e37f7c6120ce2c4
and especially the part:

"NOTE 1.  If the default_get within the onchange returns a value for
a field that is not in the view, we ignore it, and it won't be saved.
Before, that value was kept and sent upon save.  This change in behavior
may prove problematic, although the overall risk is small.  Decision has
been made to keep heavy comments and code snippets if we were to revert
back somehow to the previous situation."

the wizard to update user password was broken as the field user_id
which is required was not present in the view and was thus ignored by
to web client when calling 'create'.

closes odoo/odoo#57937

X-original-commit: 641ae07dbce1d0515fb0710a3363db47b27548e7
Signed-off-by: Laurent Smet <smetl@users.noreply.github.com>
Signed-off-by: Cedric Snauwaert (csn) <csn@openerp.com>
2020-09-17 10:52:46 +00:00
Xavier Morel 3e7d096f32 [WIP] base, auth_totp: add doc links for 2FA & API keys 2020-09-10 12:49:00 +00:00
Olivier Dony 63e38dad8d [FIX] base,hr*: adapt profile view to security fields 2020-08-14 23:06:24 +00:00
Xavier Morel ee1b67d607 [IMP] portal: /my/security page
* allows portal users to update their password
* and manage their API keys
* any anything technical / security related we may need to add in the
  future

Also bridge module for the password meter (auth password policy).
2020-08-14 23:06:11 +00:00
d0dbbe23f4 [ADD] base: API keys support
* ability for a user to request / create keys associated to their user
* overrides can block RPC solely through API keys, by overriding
  `_rpc_api_keys_only()` (to require API auth even in
  situations where the user has not requested it themselves)
* hash keys just in case as we can do so and might as well, add a
  cleartext index (first 4 bytes of 20) to avoid blowing up the DB if
  a user decides to create millions of keys for some daft reason
* users can delete their own keys, admins can delete (invalidate)
  anyone's keys
* `scope` on API keys can be used to restrict usage to certain
  kind of applications, so API keys can be used for other things
  than global authentication. New keys manually created by users
  have no scope by default so they are valid everywhere (global
  keys). RPC auth (stateless XML-RPC/JSON-RPC) requires global keys

Co-authored-by: Florimond Husquinet <fhu@odoo.com>
Co-authored-by: Olivier Dony <odo@odoo.com>
2020-08-14 23:03:27 +00:00
Xavier Morel 6e69465773 [ADD] base: enhanced security mode for users
Similar to github's sudo mode, my understanding of the intent is to
avoid third parties being able to perform sensitive / serious
operations when leaving a logged-in machine unattended.

This v1 only handles protecting "action methods" (methods called
through buttons and intended to return action descriptors), although
they can be used to "lock out" any methods they won't be able to
prompt and the caller will likely be surprised.
2020-08-14 21:20:47 +00:00
Xavier Morel 6835aeb0de [REM] core, *: deprecate <act_window> and <report>
Convert deprecated tags through the codebase.
2020-07-28 13:03:13 +00:00