Commit Graph
27 Commits
Author SHA1 Message Date
fja-odoo e33172e832 [IMP] website_sale, *: keep track of products viewed
*= website, website_livechat, website_rating

///// Tracking Product /////

Now when a user browse products in eCommerce, we keep track of the
products he looked at. We use the website_visitor
to store the products viewed. A cookie is added with a TTl of 30 min it
will prevent the RPC for that time. We track the page only if the
product view is tracked.

The recently viewed products are displayed as a snippet but also
with the customize option in product pages of website_sale.

Products that are in cart will not be returned as recently viewed.

It is possible to add a recently viewed product to the cart directly
from the carousel, it will not redirect to the cart. If we are on the
cart page, the product is displayed in the cart.

The Visitor page in website now references products viewed

///// Tracking Page /////

Feature to track a view was remove in: https://github.com/odoo/enterprise/pull/4834

That feature is now reintroduced and will use website_track instead of
leads to be stored.

The track field is now on the view instead of the page.

url field is added to website.track, it will store the url for pages and
views

The Visitor page in website now references urls viewed

Add some tests

task-1984575

closes odoo/odoo#35810

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-09-16 09:38:53 +00:00
David Beguin 6bec0e4d29 [IMP] website : add website visitors activity tracking
This commit adds the website_visitor model that will be used
to track website visitor activity (page viewed, number of visits and
more general info about the visitor (country, lang, etc..)

This model will, in later commit, be used to send chat requests
and push notification from the operators (or backend users)
directly to the visitor.

- A website_visitor is created once the visitor is requesting
a website.page that is tracked.
- A website_visitor is considered as connected if his last tracked
website_page request is within the last 5 minutes.
- The number of visits for a website_visitor is incremented
if his last tracked website_page request was at least 8 hours ago.
- A website_visitor is only handled by the system. Users cannot
create, edit or delete a website_visitor.
- A unique website_visitor is created per website.
That means that the same real person can triggers multiple visitor
creation if visits multiple websites.
This is because, for livechat purpose on later commit, for example,
the chat request can be created on the correct livecaht channel
(linked to the correct website)
- The visitor is recognized via his cookie (visitor_id). So if the visitor
flush his cookies, a new visitor will be created the next time he will
request a tracked website_page.
- Link user's res.partner to website.visitor.
    If a website_visitor log in
    (a visitor that has visitor_id in his cookie),
    the website_visitor is linked to the res.partner.
    The website visitor name is than adapted to match the name of
    the first res.partner linked to the visitor.
    A visitor can have multiple partners as the same session
    can be used by multiple person (one PC for a team for example).

To keep a detailed history of the visitor page views,
we add a website.visitor.page model that makes the link
between visitor and website.page but that keeps the visit date.
So that we can see if a visitor went mulitple times
on the same page and when. It's usefull to see his last page views.

Task ID : 2028059
PR #34624
2019-08-19 06:33:37 +00:00
Jeremy Kersten b5091c7017 [ADD] website: ability to restrict groups on website menu
Courtesy of @Yenthe666

This commit closes odoo#32580

closes odoo/odoo#34039

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-06-11 15:41:25 +00:00
jbm-odoo ec07e72845 [IMP] base,*: Reorganize access rights groups
Purpose
=======

Access group terminology is missleading. Yous have to be manager to administrate
an application. This task consists to rename groups to be understandable for everyone.

Groups should be reorganised on the users form to be more explicit.

Specification
=============

1/ Rename 'Manager' to 'Administrator' in users groups.
2/ Define a hierarchy on access groups by using the category_id in the manifests
   A category 'Operations/Project' will create a category Project with a parent
   category 'Operations', and something smart is already developed (in modules/db.py)
   to avoid duplicating categories.
3/ Add a group in expenses to be able to approve expenses reports for my team.
4/ Add a group in timesheets to be able to approve timesheets for my team.
5/ Remove partially the useless crap in ir_module_category_data.xml
6/ Sort access rights groups on users form according to its parent category

closes odoo/odoo#29362

Signed-off-by: "Yannick Tivisse (yti)" <yti@odoo.com>
2019-03-05 09:08:12 +00:00
Raphael Collet 2f7c03d9ca [IMP] base: add regular user admin as uid 2
User 1 simply becomes a technical user (inactive, no password).
2018-08-23 21:38:57 +02:00
Christophe Simonis 228ecdbe28 [MERGE] forward port branch 11.0 up to ff0abd214c 2018-01-10 11:41:35 +01:00
Nicolas Martinelli 81d1296323 [FIX] account, stock, website: access rights
1. Create a new user with all the permissions as manager (or at least
   Accounting) except Inventory
2. Login and then go to Invoicing --> Settings
3. Do a minor change, save

An access error occurs.

Since the settings of all modules are smartly loaded in v11, it now
implies that a user must have extra manager access rights to be allowed
to save them. We could have kept separate actions for each setting page,
but we would have missed the fun of access errors.

Anyway, security-wise this is not an issue to force the manager groups
since a user with 'Settings' access rights can change his own rights.
It's just very annoying. Or fun.

Complement of aa65a46fc5

Fixes #21766
opw-801210
2018-01-09 13:19:33 +01:00
Moises Lopez 85a3e1e385 [REF] *: deal with duplicated xml_ids in views and security rules
Was part of PR #19820. Courtesy of Vauxoo
2017-11-24 15:37:28 +01:00
rde 4ecbacaf59 [ADD] website: add new page management
website.page = old ir.ui.view with page=True
website.redirect is a new mechanism to replace in the futur the ir.attachment
mechanism of redirect.

From now, we don't have a specific /page controller to serve 'page'.

We use a new model website.page which is rendered if none route matches the url
 and that the field 'url' on website.page matches the request.httprequest.path.

The order to serve a path is:
    - Routes defines in controllers (/shop, /blog, ...)
    - ir.attachment with name matching the path
    - website.page with url matching the path
    - website.redirect with url_from matching the path
    - 404

To improve:
    - allow regexp in website.redirect model
    - allow to edit the view_arch from the page.management via redirect backend
      (needed when traceback in the page, or when modifying a js/css/less/...)
2017-09-15 15:29:37 +02:00
qsm-odoo d04a42022b [REF] website, *: review website access rights
* event, website_event, website_forum,
* website_hr_recruitment, website_sale

Website access rights were buggy. The editor assets and website editor
assets have to be loaded together to work so the previous behavior
which only loaded one with the restricted access right was not right.
Also, people which had the "Manager" access right for model like event
or job only got access to creation and edition of those objects if they
had the full access to website access rights.

Now the website module creates the two same groups :
* group_website_publisher: load all editor assets, give access to
page creation for model the user has access (event, job, ...) and
edition of those pages
* group_website_designer: implies the first one and give access in
creation and edition of all pages + access of all website menus

The manager access rights for event, product, jobs, etc now implies
the group_website_publisher group for the user (so that the manager
have the editor assets and editor ui).
Note: some python codes use the group_website_publisher for no right
reason, this has to be adapted.
2016-09-28 15:56:04 +02:00
Martin Trigaux 11812b0b9e [FIX] all: remove external ids fakely from base
Several modules defines records with the external ID `base.foo_bar` while it is
created inside this module (typically menus and groups).
While there is no technical reasons to do so but this may introduce issues:

- these records will not be deleted during uninstall
- if a language is loaded before the installation of the module, it won't be
  translated

The uninstallation will only remove the records with an external id linked to
this module (these would only be removed when removing base).

Installing a language before the module will drop the translations not linked
to an existing external id (as it can not be resolved).

This commit correct all the external ids tagged as from base or other incorrect
modules.
2016-09-02 16:14:26 +02:00
Ravi Gadhia fd09ddb6f3 [MIG] website: migration to new api
Migration of website module to new API.
The tricky phase is ir_http.py : we need to use `request.env`
only when the authenfication phase is done. Normally by
calling `super` of `_dispatch` method, but website module
required it to be done before. This is important since
`env`is a lazy property of `request` object.

Some hack were kept since this commit is a migration ('RequestUID'
in ir.http, ...)

Some docstrings were added.
2016-08-04 12:02:14 +02:00
Jérome Maes 2becc4a59a [MOV] website: module directory organization 2016-08-04 12:02:13 +02:00
Christophe Matthieu 8c559044a5 [IMP] web_editor: split website into web_editor (to use editor in backend for html field) and website 2015-07-10 17:00:11 +02:00
Denis Ledoux bf8877e485 [FIX] website: allow create/write/unlink for any views for group_system
A user (other than the admin) part of the group 'Manage QWeb views'
and the group 'Administration Settings' couldn't edit
any other view than QWeb views.

opw-640376
2015-05-22 10:15:01 +02:00
Denis Ledoux deb091ea64 [FIX] website: missing acl for manage website menu
bzr revid: dle@openerp.com-20140502134135-zp05ecbpcj8inftc
2014-05-02 15:41:35 +02:00
Olivier Dony 81c251836d [FIX] website: grant edit rights to website manager
bzr revid: odo@openerp.com-20140429123517-wtjcw6xl8qgtnkeg
2014-04-29 14:35:17 +02:00
Xavier Morel 3848855462 [FIX] remove outdated & unnecessary security rules
bzr revid: xmo@openerp.com-20140128151009-8hie0sex8ev2pads
2014-01-28 16:10:09 +01:00
Christophe Matthieu cf79ae7635 [FIX] website: access for portal user
bzr revid: chm@openerp.com-20140117154648-sxfisxqcv8o3fvzt
2014-01-17 16:46:48 +01:00
ddm ee2d4327a8 [FIX] access rights
bzr revid: ddm@openerp.com-20131203163131-g7o86fc08gv4if9v
2013-12-03 17:31:31 +01:00
Christophe Matthieu 176a78e161 [IMP] website: add website_designer group and access rules to edit qweb view
bzr revid: chm@openerp.com-20131119135717-6sv54lpm5smybsib
2013-11-19 14:57:17 +01:00
Fabien Meghazi eb7b1362cd [WIP] Menu working from database (not yet multi-website)
bzr revid: fme@openerp.com-20131025152446-si9gsjujzcn40hip
2013-10-25 17:24:46 +02:00
Xavier Morel 9da0ead28d [ADD] support for formatted date and datetime t-field in website
bzr revid: xmo@openerp.com-20131021152651-ner2zggjfofb5rc4
2013-10-21 17:26:51 +02:00
Xavier Morel 0a74b6ef77 [ADD] security rules for qweb.field.integer model
bzr revid: xmo@openerp.com-20131021091542-m2e213pa6kq0bmqz
2013-10-21 11:15:42 +02:00
Xavier Morel a3f7cfd669 [FIX] renaming of currency widget to monetary to match view
bzr revid: xmo@openerp.com-20131008122039-tzw7nq8cx0y0zh5p
2013-10-08 14:20:39 +02:00
Xavier Morel 510a4f51d2 [ADD] customizable qweb rendering, add translate flag on fields through this
bzr revid: xmo@openerp.com-20131008092233-9su66923zthl9jyg
2013-10-08 11:22:33 +02:00
Christophe Matthieu f9b3003517 [FIX] website: ir.model.access.csv
bzr revid: chm@openerp.com-20130917082342-kgg8f52tw8tgmygu
2013-09-17 10:23:42 +02:00