Commit Graph
12 Commits
Author SHA1 Message Date
Martin Trigaux 604a47ead8 [IMP] *: remove global ACL
THese are rarely intended for all users but often intended only for
employees.

account:
account.incoterms: only used within internal business models
account.journal.group: same as account.journal, add sudo in computed field

account_edi: need access to accounting objects

base_address_extended:
res.city: only employees should access address data

board: only employees uses this (old) module

crm:
crm.stage: internal users business object

hr_recruitment: employees can read

im_livechat: apply same as for the steps

l10n_ar: used on partner, not only invoices
l10n_ec: accessed only through account.move
l10n_latam: accessed on res.partner

mail:
publisher.warrenty.contract: no data, only static models
mail.channel: group_user has already his own rule
mail.group: group_user has already his own rule
mail.message.subtype: group_user has already his own rule
mail.message.all: remove, already has a portal and employee rule

partner_autocomplete: no interaction with public

project:
project.tags: only needed for project sharing

sale_management:
sale.order.option: same as sale.order

utm: employee already has write access

web_editor: test models that have nothing to do here
web_tour: only employees uses tours

website_sale:
product.ribbon: add sudo for access

base:
ir.default: only employees uses set (could probably be converted to group_system)
ir.ui.view.custom: same as ir.ui.view, add sudo when needed
report.*: portal users don't configure reports
res.users.log: create in sudo, no access needed (adapt test to use another model)
res.lang: still needed for public

closes odoo/odoo#118701

Related: odoo/enterprise#41285
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-06-12 22:39:26 +02:00
Adrien Widart (awt) 28075c915b [FIX] core: translate SQL constraints
To reproduce the issue:
1. Install `mrp`
2. Send a RPC to create a new BoM:
   - `{"product_tmpl_id": 1, "product_qty": -1}`

Error: It will generate a traceback

Because of the negative product qty, the RPC triggers a SQL constraint
that we try to return. However, the context does not have any `lang`,
hence the traceback

sentry-4088426130

closes odoo/odoo#120614

X-original-commit: badc554b9dd7a299aac8ebca24bec6b90bef779a
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
Signed-off-by: Rémy Voet <ryv@odoo.com>
2023-05-09 11:57:14 +02:00
Victor Feyens 42bad1a6d2 [IMP] *: remove useless keys from manifests
Remove most values uselessly specified because giving the same value as 
the default one (see _DEFAULT_MANIFEST in odoo/modules/module.py)

* auto_install is Falsy by default
* author is Odoo SA by default
* summary & description are empty strings by default
* application is False by default
* test, demo, depends and data are empty lists by default

This will reduce noise/inconsistencies between manifests specifications, 
simplify analysis of manifests content, ...

closes odoo/odoo#90209

Related: odoo/enterprise#26807
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2022-05-03 13:31:16 +02:00
Julien Castiaux c0647b5c52 [REF] core: HTTPocalypse (14) changes all addons
This commit is the 14th commit of a comprehensive refactor of our HTTP
framework. See odoo/odoo#78857 for complete historic, discussions and
rationnals.

* `request.uid = x` => `request.update_env(user=x)`.
* `request.context = x` => `request.update_env(context=x)`.
* `request.context = dict(request.context, x=y)`
   => `request.update_context(x=y)`.
* `request.cr = None` => `request.cr.close()`.
* `http.mono_db()` => `request.db`.
* `http.dispatch_rpc()` => `service.dispatch_rpc()`.
* `@service.model.check` => `service.model.retrying()`.
* `request.endpoint`
   => `env['ir.http']._match(request.httprequest.path)[0].endpoint`.
* `request.routing_iteration `=> `removed`.
* `request.jsonrequest` => `request.dispatcher.jsonrequest`.

Note that `request.params` is now set much later in the process. If you
are in a situation where you values from the query string or the
http body you can use `request.get_http_params()`.

Note that using the new `request.future_response`, it is possible to
add headers and cookies on the response object before the response
object is initialized. Please note that headers/cookies saved on
the future response will NOT be injected in case of error.

PR: odoo#78857
Task: 2571224
2022-02-24 13:30:51 +00:00
Xavier-Do 288595f558 [FIX] *: add explicit license to all manifest
The license is missing in most enterprise manifest so
the decision was taken to make it explicit in all cases.
When not defined, a warning will be triggered starting from
14.0 when falling back on the default LGPL-3.

closes odoo/odoo#74245

Related: odoo/design-themes#48
Related: odoo/enterprise#19862
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2021-07-26 13:09:57 +00:00
Yannick Tivisse 4c291e3f70 [IMP] base: Display searchpanel on ir.module.module views
Purpose
=======

The current kanban view is messy. It is difficult to identify which
apps are installed or not. The user can completely miss a module
that might have interested him. A search panel would make things way
more readable.

closes odoo/odoo#44401

Taskid: 2181557
Related: odoo/enterprise#8144
Related: odoo/upgrade#879
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2020-03-05 14:03:45 +00:00
Christophe Monniez 8d5da6e4be [IMP] tests: log a warning when HttpCase test in at_install
When loading a page on an existing starting database, registry is not
fully loaded causing potential error when trying to access model
existing in database (views, menitem, ...) since model added in last
loaded module does not exist in registry.

Thus, executing browser js test may lead to errors when executed during
an update on a database with other modules installed.

HTTPCase should be executed post_install to ensure that registry is
fully loaded to avoid this problem.

Since HTTPCase are slower than other test, it is also a good idea to
execute them at the end, in order to prioritize fast fail.

With this commit, a warning is isued if such a test class is tagged to
run at install time.

While at it, remove deprecated at_install and post_install helpers and
remove the deprecated phantom_js alias.

closes odoo/odoo#39462

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2019-10-30 12:35:23 +00:00
Christophe Simonis f3b6ff0c19 [FIX] test_rpc: adapt test to new version
Oversight of previous forward-port
2019-07-05 11:32:31 +02:00
Christophe Simonis ee28b1bf78 [FIX] test_rpc: adapt test to version 12
In version 12, user 1 is deactivated. Use `base.user_admin` instead.
2019-07-04 20:10:03 +02:00
Christophe Simonis a3dcde21d5 [FIX] test_rpc: use relative import (P3 compat)
Oversight of previous forward-port.
2019-07-04 11:54:23 +02:00
Christophe Simonis 24b677a359 [FIX] test_rpc: more robust tests
- mute logger to avoid logging bad queries
 - enforce fields strings

These changes will forbid tests to fail in following versions.
2019-07-03 19:20:31 +02:00
6b647139b4 [IMP] base: make the integrity constraint violation error messages clearer
When an `IntegrityError` is raised, the user receives a cryptic error
message which doesn't provide much valuable information in order to
solve the problem.

However, such an error is raised in 3 cases:
1. A mandatory field is not provided at creation/update.
2. The deletion of a record makes a mandatory Many2one field NULL on a
referenced table (`ON DELETE SET NULL` on a not nullable field).
3. The deletion of a record raises a `ON DELETE RESTRICT` foreign-key
constaints.

In the first and second cases, we provide the table and field on which
the `NOT NULL` constaint is raised. We also suggest to archive the
record in case of a deletion.

In the third case, we provide the table and the constraint raised. We
also suggest to archive the record.

Notes:
- The IDs of the records causing the issue is not provided since the
information is not provided by PostgreSQL.
- Although cases 2 and 3 have a different root cause, the error
message raised is very similar. Indeed, from an end-user perspective
the solution is identical: archive the record. Another solution would
also be to manually edit the records raising the error, but most of
the time this is not an option: these records are locked and cannot be
edited anymore.

task-1970853
Closes #32949

closes odoo/odoo#33922

Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>


Co-authored-by: Sapan Zaveri <sza@odoo.com>
Co-authored-by: Pragya Ladda <pla@odoo.com>
2019-06-28 07:57:26 +00:00