Commit Graph
91 Commits
Author SHA1 Message Date
Thibault Libioulle b1f0e1a42a [REV] project: following a private project no longer required
This reverts commit odoo/odoo@7059b17.

This commit translates tests introduced in this reverted commit to be
aligned with the current workflow.

This commit reverts functionality or business logic linked to the
reverted commit :
- odoo/odoo#47248 : You no longer have to be an allowed user to see the
timesheets but only a message partner.
- odoo/odoo#49021 : We no longer deal with allowed_user_ids or
allowed_portal_user_ids
- odoo/odoo@f2a1a00 : We no longer deal with the allowed users lists.

This commit removes the button project_privacy_visibility for functional
reasons.

Closes: #65367
task-2439329

Related: odoo/upgrade#2128
Related: odoo/enterprise#16067
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2021-04-09 12:12:54 +00:00
Xavier BOL (xbo) 70d7f31d58 [IMP] project: add task dependencies feature in project settings
This commit brings a new feature for the Project App and project
configuration. This feature is called "Task Dependencies" and it allows
to the user to determine the order in which to perform tasks in a
project.

task-2387984

closes #66740
2021-03-12 14:15:36 +01:00
Kevin Baptiste 1b62bd9508 [IMP] project: add recurring tasks
Some interventions are done on a regular basis (e.g. maintenance of
fire alarms, safety inspections). Having tasks auto-generate would
facilitate the process and would ensure that the next intervention
isn't missed/forgotten.

closes odoo/odoo#55517

Taskid: 2172156
Related: odoo/enterprise#12246
Related: odoo/upgrade#1604
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2020-08-12 08:39:32 +00:00
Victor Feyens 532c083cbb [IMP] *: remove global field definition in ir rules xml
It is a computed field, there is no need to manually set its value.
2020-03-20 16:15:40 +01:00
Yannick Tivisse 4c291e3f70 [IMP] base: Display searchpanel on ir.module.module views
Purpose
=======

The current kanban view is messy. It is difficult to identify which
apps are installed or not. The user can completely miss a module
that might have interested him. A search panel would make things way
more readable.

closes odoo/odoo#44401

Taskid: 2181557
Related: odoo/enterprise#8144
Related: odoo/upgrade#879
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2020-03-05 14:03:45 +00:00
Lucas Lefèvre 7059b177ee [IMP] project: Following a private project no longer required
=======
Purpose
=======

Currently for a user to be allowed to see a private project they must follow the
project. This means that they will be added as a follower of all new tasks in the
project which causes them to receive 1000000 notifications, especially if there are a
lot of tasks in a project.

==============
Specifications
==============

1) Add an Employee m2m field on project next to 'Invited Employees'
    - only visible if the 'Invited Employees' option is selected
    - the project should only be visible to employees selected there (regardless if they
      are followers or not)
2) Add an Employee m2m field on tasks below the 'Email cc' one in debug mode
    - only visible if the 'Invited Employees' option is selected on the related project
    - should be pre-filled with what is set on the project
    - the task should be visible to employees selected there (regardless if they are
      followers or not)
3) Add a Portal users m2m field on project next to 'Portal users and all employees'
    - only visible if the 'Portal users and all employees' option is selected
    - the project should only be visible to portal users selected there (regardless if
      they are followers or not)
    - rename the option into 'Invited portal users and all employees'
4) Add a Portal users m2m field on tasks below the 'Email cc' one in debug mode
    - only visible if the 'Portal users and all employees' option is selected
    - should be pre-filled with what is set on the project
    - the task should be visible to portal users selected there (regardless if they are
      followers or not)
5) Following a project/task should not grant the user/employee the ability to see the
   project/task

Task 2031527

closes odoo/odoo#40505

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2020-01-14 16:26:32 +00:00
jem-odoo 938990f698 [IMP] project: company required on task
As task can be billed, it became a important business model. To avoid mistakes in a multi company
environment, we need to make the company_id field required. Indeed shared task can be problematic
with access rights when a employee will log timesheet from another company in a task that is not in
the same company as its project.

To populate this field, we recommend to take the company of task's project, or to fallback on
the company of the user that created one.

Task-1999686
2019-07-04 15:28:24 +00:00
Yannick Tivisse a5b6f31cf2 [IMP] base: Contextualize the multi company
Purpose
=======

Allow the user to select the allowed companies for which he wants to see records
on top of selecting his current company.

It is confusing for users to see the records from the company he is connected to
and the records of the children companies.

Instead of using the hierarchy of companies to access records across companies,
the user can now select (from his set of allowed companies) the companies for
which he wants to access records.

/!\ This means that the user will interact with records from company A when in
company B.
Example: a SO has been created and confirmed in A. When in B, I create the
invoice from it.

Specifications
==============

1/ Deprecate the parent/children hierarchy on the res.company model. The fields are
kept on the res.company model to ensure the retro-compatibility, but won't be used
accross the standard code anymore. The only functional usage for this mechanism
was to allow to see records from several companies by creating a virtual parent
company, which will be possible with the new mechanism.

2/ By default, a user will only see the records of the company he is connected
to (or records without a company). (It is still editable by the user if needed).
For that, put this information in the user context, to allow having different
configurations on different browser tabs. Instead of having domains like
['|',
('company_id', '=', False),
('company_id', 'child_of', user.company_id.id)]
you'll have something like
['|',
('company_id', '=', False),
('company_id', 'in', company_ids)]
Note that the 'company_ids' is a value that is passed in the evaluation
context on the record rule, as we already have user, or time.
company_ids is a list of the ids of all the enabled companies in the
user's context.

3/ Out of the generic improvements brought by this task, this will illustrate
issues that could exist since several versions. For example, it should not be
possible to create a scrap order for the company A with a package of the company
B, or it should not be possible to create an invoice on the company A with
payment terms from the company B. Before the version 12.0, it was easy to
encounter this kind of issues as the admin was the SUPERUSER_ID. A positive side
effect of the fact that the SUPERUSER_ID has become an inactive user was to
make it more difficult to introduce mismatch on the records, but haven't solved
the issue, as it was still possible to do it with parent companies
configuration. Some of these issues have been fixed in this commit, but all the
business flows should be re-tested to check if an ir.rule should be introduced
(eg: a multi company rule for stock.quand.package), if the company of a record
is correctly transfered to another record created from the first record (eg:
From a SO, create an invoice and a payment, the company of the sales order
should be transfered on the invoice and the payment, even if the company of the
sales order is A and I'm logged into the company B with the company A enabled.

4/ Currently, if I click on a button on a notification email (example 'View
Task'), I face a traceback if I'm not logged into the company of the record.
Now, if you click on a button and if you have access to the record, the correct
company will be automatically set.

5/ If I display a kanban view with several records from several companies (and
an image), all the images should be displayed.

6/ Currently if you copy paste an url, this will crash if you're not in the
correct company. This won't be fixed because it's quite impossible to do it in
a clean way. This task brings a workaround. Copy/Paste -> Traceback -> Log into
the correct company, re-copy/paste -> Ok.

7/ 2 property methods have been added on the environment to retrieve the company
on which the user is logged in and the companies the user enabled, on a specific
tab.
That way, when creating a record, instead of doing
default=lambda self: self.env.user.company_id
do
default=lambda self: self.env.company_id
On the other hand, to retrieve the enabled companies, do
companies = self.env.company_ids

8/ Modify the Company Switcher widget to allow to log into another company
WITHOUT writing on the res.users (and thus bringing cache invalidation issues
and so on). Also allow to enable several companies and see records from several
companies, and independantly of the other browser's tabs.

9/ When focusing on a tab, save the current company configuration on the local
storage. That way, when doing 'CTRL+T' or a middle click, the context is
propagated to the new tab.

10/ Improve the error message in case of multi company access errors. Now, when
the user is in debug mode, display the related names of the records and the name
of the user who brings the issue.

11/ Remove the context erasing when writing on a res.users
This is probably coming from the migration to new API of the base module.
The context was not propagated at this moment, which was a common mistake at
that time. When migrating the module, probably by using the 'black box' method,
as the context was not propagated, it was erased on the new version. This is
now an issue because the context (i.e. the enabled companies) was erased when
writing on a res.users, leading to tracebacks.
See: https://github.com/odoo/odoo/commit/7eab8e26d3d46c53f4be924d6a34e80a66e74960#diff-4c2e738ee8f64f11806c889ea097b5e7R624

12/ Fix the crash manager on redirect warnings. The issue is the following
- Create an invoice on a company without a configured CoA.
- Set a partner
- On the onchange_partner_id, a redirect warning is raised to propose you
to configure a CoA
- Click on 'Go to the configuration panel'
- A generic warning says something like 'Do you want to discard your changes?'
- Click on yes, the page refreshes, but not on the redirect action.
Now, set correctly the action on the hash, and reload instead. The breadcrumb is
lost for example, but you reach the correct action at least.

13/ Introduce a res.group to enable/disable the multi company per tab
feature.

14/ To help the users to know which tab is in which company, add the
possibility to have a favicon per company. When creating a company,
the classical 'O' icon is colored by default in a random color.

15/ Remove the company switcher on the frontend. This was mainly there
to allow a user to swicth to the company linked to the website.
This behavior is now transparent to the user. If the website A is
activated, then the company set on the context is the company of the
website.

16/ Deprecated the _company_default_get method on the res.company
model. Remove the method _get_company on the res.users model.

17/ Add 'allowed_company_ids' and 'current_company_id' on the pyeval
context. You can now use those variables on domains in the views to
access directly to the activated company.ies on the current tab.

TaskID: 1960971

closes odoo/odoo#32341

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-05-13 08:57:49 +00:00
Goffin Simon 2afd482c1a [FIX] project: adding channels members to a private project
Steps to reproduce:
- Create a channels C with user A linked to an employee E
- Create project P with privacy_visibility='followers' meaning only visible for employees that follow P
- Add the channel C as a follower of P
- Log as user A go to Project app

Bug:
The project P is not readable for A

opw:1958386

closes odoo/odoo#32324

Signed-off-by: Simon Goffin (sig) <sig@openerp.com>
2019-04-02 07:10:43 +00:00
jbm-odoo ec07e72845 [IMP] base,*: Reorganize access rights groups
Purpose
=======

Access group terminology is missleading. Yous have to be manager to administrate
an application. This task consists to rename groups to be understandable for everyone.

Groups should be reorganised on the users form to be more explicit.

Specification
=============

1/ Rename 'Manager' to 'Administrator' in users groups.
2/ Define a hierarchy on access groups by using the category_id in the manifests
   A category 'Operations/Project' will create a category Project with a parent
   category 'Operations', and something smart is already developed (in modules/db.py)
   to avoid duplicating categories.
3/ Add a group in expenses to be able to approve expenses reports for my team.
4/ Add a group in timesheets to be able to approve timesheets for my team.
5/ Remove partially the useless crap in ir_module_category_data.xml
6/ Sort access rights groups on users form according to its parent category

closes odoo/odoo#29362

Signed-off-by: "Yannick Tivisse (yti)" <yti@odoo.com>
2019-03-05 09:08:12 +00:00
Christophe Simonis 86ff929ad6 [MERGE] forward port branch saas-11.4 up to 1199451606 2018-09-10 17:06:18 +02:00
Yannick Tivisse 4587816198 Revert "[IMP] base: Remove unused module categories"
This reverts commit 382fbd3520.
2018-09-10 14:23:43 +02:00
Raphael Collet 2f7c03d9ca [IMP] base: add regular user admin as uid 2
User 1 simply becomes a technical user (inactive, no password).
2018-08-23 21:38:57 +02:00
Yannick Tivisse 382fbd3520 [IMP] base: Remove unused module categories
The categories other extra rigths and hidden are not used now.
2018-04-26 15:13:38 +02:00
jem-odoo d50a1e2622 [IMP] project,hr_timesheet: no 'remaining hours' field in project
'remaining_hours' is defined in project as a simple
float field, manually updateable, only displayed
when the group "Time Estimation on Task" is activated.
But for now, there is no setting to active this group.

Those are legacy useless stuff, so we can remove it.
The purpose is to make 'time estimation' feature only
available when timesheet is installed.

Thie commit also split the compute methods of
'remaining_hours' and 'progress' fields to make
'remaining_hours' updateable, though inverse method.
Without splitting the compute method, the calculation
of the progress was done correctly during onchange
but not when saving.
2018-04-06 14:30:47 +02:00
Jérome Maes 95698bd408 [REM] rating_project: kill the module and move feature in project
Impacted modules: project, rating_project,
sale_service_rating and website_rating_project.

Removed modules: rating_project and sale_service_rating.

Move code to empty 'rating_project' module, in order
to kill it.
Code is not modified, simply copy/paste at the right
place in 'project' module code.

However, 'enable rating on task' options is convert
into a res.groups that can be activated from the
project settings.
2017-12-12 14:06:29 +01:00
Fabien Pinckaers b7cb6fe536 [IMP] project: misc typos 2017-11-03 21:13:13 +01:00
Jérome Maes 424c16f115 [MOV] website_project,project: move all features
Making project depending on portal, makes website_project
useless. So move all feature from one module to the other.
2017-08-16 14:56:41 +02:00
Hiral Bhavsar 332b83ef9e [IMP] project, *_timesheet: move subtasks to project
-> Move Subtasks mechanism from hr_timesheet to project.

-> Various functional improvements:
 - Add new 'Sub-tasks' setting and 'Sub-task Project' field based on
     this setting.
 - Relabel 'Team Collaboration' section to 'Task Management'.
 - Remove 'Customer Satisfaction' section and move setting
     'Rating on Tasks' into 'Task Management' section.
 - Add customer name on the project's kanban view.
 - Set default value of 'Sub-task Project' field is the same project.
 - Add 'Parent Task' stat button on task form view.
 - Make 'Sub-Tasks' stat button visible when no parent task
2017-05-24 11:39:54 +02:00
Yannick Tivisse ff63f5d0a3 [IMP] base_setup: Allow the admin to modify the default user acess rights
Add a link in the general settings to access easily the default_user form view in order to modify the default access rights

The default_user manager rights declarations in all the applications have been move in a noupdate="1" definition to avoid the manual configuration overwrittings
2016-08-23 11:14:37 +02:00
Antony Lesuisse ccf606e026 [ADD] website_project: Portal access to Projects
Split project to move portal features to a new module named website_project.

Portal users may now access their projects and tasks throught the
website_portal My account page. The Backend portal menuitem is removed.

Simplify the privacy settings of project, to be visible to portal users the
project must be in 'portal' mode.

Original authors: Vipul Bhatt, Florian Wintjens
2016-07-06 01:17:43 +02:00
Gaurav Panchal 40fa74e3f5 [MIG] project: migration to new api except project.py 2016-06-30 14:41:21 +02:00
Tanguy Charlier 16bf40f7c4 [IMP] hr_timesheet: Timesheet entries are now related to projects
- Hide account_id field and add a required project_id field on timesheet entries
- Remove is_timesheet field: as project_id is only required for timesheet entries and not for other analytic lines, it can be used to determine wether a line is a timeheet entry or not.
- Remove project_timesheet module as all its functionalities are moved to hr_timesheet
- Replace timesheets on contract option on products by timesheets on project
- Small fixes and improvements in timesheets and projects views and groups
2016-02-18 01:25:55 +01:00
Yannick Tivisse 1ecba213f4 [IMP] Newly created users get all manager access right
Coming from a bug in web_settings_dashboard. Invited user didn't have any rights
when created from the dashboard, which was leading to an error.

This bug leaded to a new discussion. Better to have basic employee having user
rights for all main applications. For bigger entreprises there is an admin that
will carefully remove extra rights, if necessary. The target is small businesses,
it makes sense that every way to create a user gives the same result.

In conclusion, each new user has a full access to the applications by default

How is it implemented ?
We added an inactive default user which original access right to the groups
'base.group_user' and 'base.group_partner_manager' in base. Each
application will extend the default user's access right by adding the maximal
access right for this application.

On user creation, we will use by default the 'group_id' field from the default
user. We will in the same time remove the ugly 'default_groups_ref' key which
was passed sometimes in the context for some fields in some views, and sometimes
nothing.

So, the user can modify the access rights for the default user, but he should be
aware that removing project user access rights for a default user will prevent
a *created on the fly in a task* user will not be able to access the task.
2015-11-20 16:27:32 +01:00
Christophe Simonis d750206c49 [MERGE] forward port of branch saas-6 up to e9f1ee4 2015-10-01 15:16:59 +02:00
Denis Ledoux fa17b86a9f [FIX] project: multi-company security rules in Tasks Analysis
This change avoid to display the tasks
that a user is not permitted to see
in the reporting view 'Task analysis'

Closes #4399

Courtesy of jkei
https://github.com/jkei
2015-09-28 15:58:15 +02:00
Thibault Delavallée e6f038a821 [REF] mail: mail_thread: followers update
Followers can now be partners or channels. Partners following a document
will receive needaction, as previously. However people can follow documents
through channels. Members of a channel are able to listen to a stream
of messages using the channel. Those messages do not create needaction
messages. It is therefore possible to follow documents without receiving
too much notifications. For interesting documents subscribing with its
partner will create notification.

message_follower_ids fields is udpated. It is now a many2many to
mail.followers, not to res.partner anymore. A subscription can be either
a partner (partner_id) or a channel (channel_id).

Some access rules have been updated accordingly.
2015-08-21 12:11:56 +02:00
Damien Bouvy 8bd6074f03 [IMP] project,project_issue,project_timesheet,project_issue_sheet: project visibility and access rights modifications
[REM] portal_project: move ALL the things
- move portal access rights from portal_project  and website_project_issue to project and project_issue
- move portal menuitems back to their respective module
- remove public visibility of projects
- adapt demo data to have a 'Demo Portal' project
- add correct access rights for account.analytic.line for portal users
- small view tweak (do not display 'timesheet' tab if one can't see antyhing in it anyway)
2015-08-14 13:19:03 +02:00
Yannick Tivisse e485b6c5ee [IMP] Project : remove task delegation
Conflicts:
	addons/project/wizard/project_task_delegate.py
2015-07-08 15:39:02 +02:00
Yannick Tivisse d2dd78889d [FIX] Menu configuration in root menu 2015-07-06 14:02:00 +02:00
Martin Trigaux 0b2ee16885 [FIX] project: access rights and followers
For privacy_visibility 'followers' or 'portal', the user should be follower of the project (not the task).
Remove public access to portal task
Fixes #2372

If no project on the task (or other rule), an employee (not a portal) can access if is follower of the task.
Follower rule is not enough as a user creating a rule will subscribe to the rule but to subscribe to record, the user should have access to it in the first place.
To make sure the snake does not bit its tail, fallback to give access on task where the user is reponsible (user_id = user.id).
Fixes #139

Adapted the tests to the new behaviour (removed not relevant and added some on creation)
2014-11-18 18:52:46 +01:00
Martin Trigaux c22ed1390b [FIX] project: access task without project
Allow access to task without a project defined if the user is follower.
Fixes #3450
2014-11-06 18:05:28 +01:00
Christophe Simonis d562249278 [FIX] project: force menu name
bzr revid: chs@openerp.com-20140425170357-iqcqqfe71mm2z0qg
2014-04-25 19:03:57 +02:00
sgo@tinyerp.com 6a3cdf718c [MERGE]sync with trunk
bzr revid: sgo@tinyerp.com-20130605071905-o2ldzc6vxqnoe099
2013-06-05 12:49:05 +05:30
Thibault Delavallée 8c31d9772a [FIX] project, task, issue, portal: fixed access rules for employees/portal users + added an help on privacy_visibility.
bzr revid: tde@openerp.com-20130426130259-35j0v7lg7unxhzzp
2013-04-26 15:02:59 +02:00
sgo@tinyerp.com d5451cf7f2 [MERGE]sync with trunk
bzr revid: sgo@tinyerp.com-20130417060441-6vnz2tiym5fawr2n
2013-04-17 11:34:41 +05:30
Thibault Delavallée b6223ecb7f [FIX] [ADD] project, project_issue, portal_project, portal_project_issue: improved privacy_visibility selection of project.project; improved access rules; added tests to enforce them.
bzr revid: tde@openerp.com-20130412143719-ztjo06r900l024dm
2013-04-12 16:37:19 +02:00
sgo@tinyerp.com 15f6bea1e9 [IMP]improve yml for project and add access rights as needed
bzr revid: sgo@tinyerp.com-20130312112700-zamjzcjp5d9nv5n0
2013-03-12 16:57:00 +05:30
Olivier Dony 3fe6987ce7 [MERGE] Harmonization of noupdate flag on security XML data, courtesy of Alexis de Lattre (Akretion)
ir.rule records are in noupdate data blocks to let the admin
alter them without fear of them being reset at next update.
Other records such as groups are in normal mode, so they
can be updated whenever necessary

bzr revid: odo@openerp.com-20121218232001-t425t4hi7qbmsip2
2012-12-19 00:20:01 +01:00
Ajay Chauhan (OpenERP) b5f940c04f [IMP] project: made little change in ir rule
bzr revid: cha@tinyerp.com-20121010083548-lt8oncuanvcfpqk2
2012-10-10 14:05:48 +05:30
Ajay Chauhan (OpenERP) 2d1cb5d05d [IMP] project: solved the issue of 'Followers Only' visibility for project
bzr revid: cha@tinyerp.com-20121008131720-v1573v9zitef1whp
2012-10-08 18:47:20 +05:30
Thibault Delavallée 41198901cd [FIX] Project: fixed a security rule based on follower_ids, that is now message_follower_ids.
bzr revid: tde@openerp.com-20120910075850-0b5sg1vljcc8gba9
2012-09-10 09:58:50 +02:00
Thibault Delavallée 6c109e7d7e [REM] project: removed custom 'followers' fields; security rule updated to use follower_ids.
bzr revid: tde@openerp.com-20120822074924-bbb5lc1w48dtebeb
2012-08-22 09:49:24 +02:00
Alexis de Lattre 5101771cd9 Harmonize the noupdate flag on security XML files :
- ir.rule objects are noupdate="1"
- all other objects are noupdate="0"

bzr revid: alexis@via.ecp.fr-20120713170838-pjsysliyt6twazrc
2012-07-13 19:08:38 +02:00
Quentin (OpenERP) 46f2c2c9ca [IMP] improvements during code review
bzr revid: qdp-launchpad@openerp.com-20120628121820-r8bxfzq38fy8pcgt
2012-06-28 14:18:20 +02:00
Sanjay Gohel (Open ERP) 1702b2335d [IMP]remove tabs and add spaces instead of them
bzr revid: sgo@tinyerp.com-20120628064005-zuerrpazumf5lf1q
2012-06-28 12:10:05 +05:30
Quentin (OpenERP) dc1edf44be [IMP] project: implemented the privacy/visibility record rule in a cleaner way + some cleanup and bug fixing related to contract management
bzr revid: qdp-launchpad@openerp.com-20120614100922-5g29ui88nhqojon2
2012-06-14 12:09:22 +02:00
Amit Patel (OpenERP) 618aacc5a7 [IMP]:passed base menus ref instead of project.
bzr revid: apa@tinyerp.com-20120613131507-1yezuu5k7dc1h9s3
2012-06-13 18:45:07 +05:30
Quentin (OpenERP) c44790c56d [MERGE] merged with main trunk
bzr revid: qdp-launchpad@openerp.com-20120613090855-9tpft9kutxzgwyze
2012-06-13 11:08:55 +02:00
Raphael Collet fcca76b487 [MERGE] trunk-first_10_clicks-psi (add group to enable task delegation)
bzr revid: rco@openerp.com-20120612095835-iisiv73hqbhe9l9w
2012-06-12 11:58:35 +02:00