Commit Graph
9 Commits
Author SHA1 Message Date
Martin Trigaux 604a47ead8 [IMP] *: remove global ACL
THese are rarely intended for all users but often intended only for
employees.

account:
account.incoterms: only used within internal business models
account.journal.group: same as account.journal, add sudo in computed field

account_edi: need access to accounting objects

base_address_extended:
res.city: only employees should access address data

board: only employees uses this (old) module

crm:
crm.stage: internal users business object

hr_recruitment: employees can read

im_livechat: apply same as for the steps

l10n_ar: used on partner, not only invoices
l10n_ec: accessed only through account.move
l10n_latam: accessed on res.partner

mail:
publisher.warrenty.contract: no data, only static models
mail.channel: group_user has already his own rule
mail.group: group_user has already his own rule
mail.message.subtype: group_user has already his own rule
mail.message.all: remove, already has a portal and employee rule

partner_autocomplete: no interaction with public

project:
project.tags: only needed for project sharing

sale_management:
sale.order.option: same as sale.order

utm: employee already has write access

web_editor: test models that have nothing to do here
web_tour: only employees uses tours

website_sale:
product.ribbon: add sudo for access

base:
ir.default: only employees uses set (could probably be converted to group_system)
ir.ui.view.custom: same as ir.ui.view, add sudo when needed
report.*: portal users don't configure reports
res.users.log: create in sudo, no access needed (adapt test to use another model)
res.lang: still needed for public

closes odoo/odoo#118701

Related: odoo/enterprise#41285
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-06-12 22:39:26 +02:00
Thibault Delavallée 7bd5b64f67 [MOV] utm: split data and demo in different files
Purpose
=======

This commit cleans the UTM module and uses a different file for each model
data and demo in order to clarify organization and ease reading. Each model
owns its own demo and data file. Security file is reorganized per model.

Task-2245823

Part-of: odoo/odoo#83070
2022-01-20 10:06:47 +00:00
Aurélien Warnon 1e25946a76 [IMP] utm: globally improve UTM records management across all apps
PURPOSE

This commit consolidates UTM usage across all applications.

Global purpose is to avoid having undesired side-effects, such as unlinking an
utm.source/utm.medium/utm.campaign and at the same time cascading the deletion
to various records without noticing.

SPECS

ALLOW MORE PEOPLE TO CLEAN UTM RECORDS

Currently, not even the system administrator can delete utm.mediums and
utm.sources (he can only delete campaigns).

These were considered as "technical records", but allowing some cleanup is
a good idea since these records are often automatically generated and can
create a lot of unnecessary noise in the database.

That's why we now allow the following groups to delete all UTM records
(sources, mediums and campaigns):
- group_system
- group_mass_mailing_user
- group_social_manager (enterprise)

PREVENT DELETION

For some use cases, removing an utm.source/utm.medium/utm.campaign would
cascade delete the related record, which was unintended / hidden side effect.

These combinations were secured by preventing to unlink:
- mailing.mailing source_id field
  Trying to delete the utm.source will throw an error message
- mailing.mailing medium_id field
  Trying to delete the utm.medium will throw an error message
- hr.recruitment.source source_id field
  Trying to delete the utm.source will throw an error message

ADDING CLEAN ERROR MESSAGES

When trying to delete an UTM record that is linked with ondelete="restrict", we
improved the error message to give a clear explication to the user, e.g:

"You can't delete these UTM sources as they are linked to the following
mailings in the Mass Mailing APP, and deleting the source would break the
statistics: Newsletter"

SPECIFY 'ondelete' strategy

For a lot of uses of sources/mediums/campaigns, the 'ondelete' strategy was not
specified, leading to the confusion of "is this really how we want to handle
this?".

A lot of ondelete="set null" have been added in various field definitions to
ensure that this is the desired and logical strategy we want for that
specific model.

PREVENT REMOVING HARDCODED UTM RECORDS

In some functional flows, UTM records are hardcoded using their direct
record reference.
This is notably the case for the recruitment process and its creation of
aliases, and for the Email / SMS Marketing flows.

As deleting them would break these flows, we prevent their deletion in a
"api.ondelete" method.

ENFORCE NEW RULES WITH TESTS

A lot of python tests have been added to make sure we enforce the decisions
taken here above.

LINKS

ENT PR odoo/enterprise#19048
Task-2459480

closes odoo/odoo#72239

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-11-23 11:12:04 +00:00
qmo-odoo a661b00015 [REF] utm,mass_mailing: replace mass mailing campaign by utm campaign
PURPOSE

This commit removes the mass_mailing.campaign model. Instead of having a fully
fledged model, we will simply inherit utm.campaign. We will also add relevant
statistics on utm campaign model in order to use it in various applications.

SPECIFICATIONS

This commit removes the mass_mailing.campaign model. Instead of having a fully
fledged model, we will simply inherit utm.campaign. This change implies that
mass_mailing.tag and mass_mailing.stage have to move to the utm model along
their associated views/data.

These changes were made so that campaigns could be used in the future
by social, mass_mailing and mass_sms and available in the same view

This commit also removes the source_id and the medium_id
fields on the campaign.

This commit also moves the unique_ab_testing field from the mass_mailing_campaign
to the mass_mailing model

Task ID: 2002029
PR: #34015
2019-08-02 12:32:35 +00:00
Fabien Pinckaers ff7a40c1c9 [FIX] utm: employees should be able to edit UTM (e.g. HR Job recruitment tracker creation 2016-06-23 11:21:35 -07:00
Yannick Tivisse fdb3ad7082 [REM] Remove the group 'base.group_configuration'
This additional administration group was formerly used to hide
the configuration menuitems for the common users.

Being manager should be enough to access these items
2016-03-07 15:53:29 +01:00
Gaurav Panchal e473cd5614 [IMP] utm, link_tracker: groups and config update
Remove link to marketing groups on access rights and main menu. UTM being a
technical module it is now linked to the configuration group. Link tracking has
also been updated to use the configuration group.

Access rights and main menu display have been udpated.
2015-08-12 11:41:58 +02:00
Julien De Coster 32389f0073 [FIX] UTM security 2015-04-14 15:30:06 +02:00
Julien De Coster ddac26cdbb [ADD] Add the website_links module.
This module tracks clicks in mass mailing mails and allow the generation of trackable links in a website interface.

Modules modifications
---------------------
Refractoring of the crm_tracking_* classes in a new module.

* Extract the crm_tracking_* from the crm module into a new module "utm"
* Remove the crm_mass_mailing bridge module
* New dependencies of mass_mailing and website_links to utm.
2014-12-17 17:14:33 +01:00