Commit Graph
29 Commits
Author SHA1 Message Date
Sébastien Mottet (oms) e8a5af2e28 [IMP] website: configurator for automatic website generation
On website app  installation and on new website creation a configurator is launched.
The purpose of this configurator is to generate a website that meet the user's needs.

The configurator is composed of 4 steps:

1) Business description: the user is asked to describe its need with its website purpose (dropdown), its industry (autocomplete search) and its objective (dropdown).

2) Logo and palette selection: the user must select a color palette for its website. He can also upload its logo. In this case color palettes recommendations are generated based on the logo's colors.

3) Features selection: the user select the pages and applications he needs.

4) Theme selection: three themes are recommended to the user based on its industry. This screen display a preview of these three themes.

task-id: 2451965
ENT PR: odoo/enterprise#16949
UPG PR: odoo/upgrade#2316

closes odoo/odoo#67537

Signed-off-by: Sébastien Mottet <smottet@users.noreply.github.com>
2021-04-02 13:04:03 +00:00
8cc066173d [IMP] *: Improve assets management
This commit changes the way assets are declared in Odoo modules.

Before: assets were declared in template files. Template bundles were
generated from primary templates, so technically any qweb template could
have been called as an asset bundle, with the 't-call-assets' directive.

Being standard qweb templates, they had access to standard HTML tags
(script, link, with or without raw scripts or style definition), qweb
directives (t-call, t-raw, etc.) and could be inherited by other
templates.

Now: assets are defined in the module's manifest and generated by the
't-call-assets' directive.

More information on the new system can be found on the updated user
documentation (see the "JavaScript Reference" section).

Task: 2352566

Co-authored-by: Bruno Boi <boi@odoo.com>
Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Lucas Perais <lpe@odoo.com>
Co-authored-by: Mathieu Duckerts-Antoine <dam@odoo.com>
Co-authored-by: Raphael Collet <rco@odoo.com>
Co-authored-by: Simon Genin <ges@odoo.com>
2021-03-31 13:57:17 +02:00
Krupal Oza f0dccae14a [FIX] website: prevent manual creation of website visitors
Currently, admin and system users have the ability to manually create new
visitors from UI, which was introduced since ACL revamp[1] on visitors.
However, even admin should not be able to create visitors manually. Indeed
having a create button makes no sense as everything is managed through
frontend. Those menus are mainly present for reporting and displaying
information.

This commit fixes the behaviour by preventing manual creation of visitors
for all users including admin.

[1] - 5e605f5

Task ID-2288363

closes odoo/odoo#56651

X-original-commit: 1db514f8d2a9f1ba6861c89ced9a2a9f5dcf48be
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2020-08-27 11:34:06 +00:00
Laurent Stukkens (LTU) 0e7640b5f2 [IMP] website, website_sale: add dynamic snippets
* Implement new snippets that allow the user to choose a filter
  and a template.
  Three snippets have been created:
  - Dynamic Snippet: Displays the data in a grid format
  - Dynamic Carousel: Displays the date in a carousel
  - Dynamic Products: Let the user pick a product category and
                      displays the products in a carousel

task-2276740
PR #53175

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-08-18 17:40:25 +00:00
Martin Trigaux ccc98e0169 [IMP] base: remove read access to ir.ui.view
Only system users should be able to access directly ir.ui.view records
Other users should use helper methods like fields_view_get or render
to interact with view records (or use sudo)

Give read access to views to publisher
He needs to call read_template on some views like
'web_editor.colorpicker' in edition mode

Restrict ACL on website.page
Apply the same ACL than on ir.ui.view as the model inherits from it.
Give access to designer to modify views
2020-05-14 13:59:10 +02:00
Victor Feyens 066214b36b [IMP] *: remove duplicate ACL targeting same group/model.
In the same xml file (meaning one of the two rule is useless, or wrong
if giving less rights than the other).

Removing rules that had no impact will ease the understanding of
security problems, by reducing the number of interconnecting rules.
2020-03-27 09:55:33 +01:00
Martin Trigaux 65530dfd6a [ADD] *: add ir.model.access on all transient models
Following changes needing ir.model.access on transient models too.
Remove groups declaration on the action to move it to ir.model.access
when possible.
Rules are strict by default with no unlink access by default and high
priviledge asked. Adaptations may be needed later.
Write access is given as a wizard may need to be modified in case the
action triggers an error and the user has to correct a value

account*: use account.group_account_user for all transient by default
	  remove account.print.journal relic
stock*: use stock.group_stock_user by default
survey: survey user can send invitations
mail: allow any employee to execute wizards
      additional verifications are made to ensure they are executed
      only on the documents the user has access to you
      give portal access to mail.compose.message as portal still does
      some actions like posting messages on the forum
      add ir.rule to avoid reading somebody else messages
      increase the query count because of undeterminist count
crm: saleman for lead2opp, manager for massmailing
     partner manager for actions linked to partners
     avoid a write in test_lead_lost
sms: any employee can send sms
mrp: mrp user can execute wizards
     give unlink access as making write during do_produce operation
base_import: employees can import files
delivery: stock user can deliver
event_sale: sale user can configure the wizards
	    event user inherit from  sale rights
gamification: employee can give badge
google_service: resolve FIXME
hr: add specific rights
    manager can set a plan according to group on button
    anyone who can write on an employee can register a departure
hr_expense: set rights based on buttons
hr_holidays: an approver can make a summary report
hr_recruitment: recruiter can refuse a candidate
hr_timesheet: can use the wizard if can create a timesheet
l10n_eu_service: managers can create fiscal positions
mass_mailing: same group as on mass.mailing.list
membership: accountant can create invoice from membership
payment: accountant can create a link
	 as the source is an account.move
	 keep the payment.acquirer.onboarding.wizard to system user
	 only as it is called during company configuration
point_of_sale: PoS manager only can use wizards
	       never create closing_balance_confirm_wizard records
product_expiry: stock user has rights on stock.picking
product_margin: access from accounting menus
repair: same rules as for above models
sale: set ir.rule for self wizard only
      add rule from model introduced in payment to add salesman group
sale_crm: saleman can create a quotation from a lead
sale_coupon: any saleman can generate coupon
	     add self ir.rule
sale_product_configurator: salesman can select product variants
snailmail: employee can send letters
website: designers can write on website
website_crm_partner_assign: same rule as group on action
website_sale: sale ACL as for payment.acquirer.onboarding.wizard
website_slides: anyone can send invitation

base: base.language.*: allow employee (cf lang_install)
      change.password.user: can not read change password wizard of
      other users
      test.*: no access is needed

Courtesy of Damien Bouvy, William Andre and Antoine Prieëls for review
of acl
2020-02-04 17:54:18 +01:00
David Beguin 5e605f589d [FIX-IMP] website, website_livechat : disable create visitor and review ACLS
This commit applies the following ACLs rules:

C : nobody can create visitor (except system)
R : everyone that should access to this model
U : website_designer can update (even if only few fields are editable),
    mainly useful for language (+ system obviously)
    + livechat users as they are the guys who directly speaks with the visitors
D : system + website_designer can delete, mainly useful to clean if necessary

Remove the no_create from all visitor views as handled by ACLs.

This fixes the 'can create' that should not be done by any users
except system + admin

Task ID: 2092502
PR #40439

closes odoo/odoo#40865

X-original-commit: 23f3324830adf31edb0a12c7009fcb65b0f54614
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2019-11-28 14:31:29 +00:00
qsm-odoo 88e910e187 [REF] website, *: merge website_theme_install into website
* theme_bootswatch, theme_default, website_theme_install
2019-11-12 15:53:13 +00:00
fja-odoo fe1dddb1ec [FIX] website: allow visitor sort by last visit time
A visitor needs to be sorted by last visit datetime, to do so we need to
remove the temp table and ignore concurrent updates.

task-2072877
2019-10-01 19:49:46 +00:00
Jeremy Kersten be8fc2296b [IMP] base, http_routing, website: allow custom routing rule
After this commit, you will be able (in technical mode) to update the url for
the python controllers.

Eg.
You can now rename /shop in /garden and /shop/product/ in /garden/vegetable/

Most of urls will be replaced at fly in the renderd qweb, with the function
url_for but all old urls will keep available. So if you access url /shop you
will be automatically redirected to /garden (308 Permanent Redirect).

As for cdn and other post-process of att, the automatically replacement in the
rendered qweb is only done when you will be not website editor. But the new
dispatch of URL will be applied in all cases.

For developper, since it is Permanent Redirect, don't forget to clear cache or
open chrome debug tool (with option 'Disable cache while DevTools is Open) to
see your lasts changes.

closes odoo/odoo#36555

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-09-30 13:58:14 +00:00
fja-odoo e33172e832 [IMP] website_sale, *: keep track of products viewed
*= website, website_livechat, website_rating

///// Tracking Product /////

Now when a user browse products in eCommerce, we keep track of the
products he looked at. We use the website_visitor
to store the products viewed. A cookie is added with a TTl of 30 min it
will prevent the RPC for that time. We track the page only if the
product view is tracked.

The recently viewed products are displayed as a snippet but also
with the customize option in product pages of website_sale.

Products that are in cart will not be returned as recently viewed.

It is possible to add a recently viewed product to the cart directly
from the carousel, it will not redirect to the cart. If we are on the
cart page, the product is displayed in the cart.

The Visitor page in website now references products viewed

///// Tracking Page /////

Feature to track a view was remove in: https://github.com/odoo/enterprise/pull/4834

That feature is now reintroduced and will use website_track instead of
leads to be stored.

The track field is now on the view instead of the page.

url field is added to website.track, it will store the url for pages and
views

The Visitor page in website now references urls viewed

Add some tests

task-1984575

closes odoo/odoo#35810

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-09-16 09:38:53 +00:00
David Beguin 6bec0e4d29 [IMP] website : add website visitors activity tracking
This commit adds the website_visitor model that will be used
to track website visitor activity (page viewed, number of visits and
more general info about the visitor (country, lang, etc..)

This model will, in later commit, be used to send chat requests
and push notification from the operators (or backend users)
directly to the visitor.

- A website_visitor is created once the visitor is requesting
a website.page that is tracked.
- A website_visitor is considered as connected if his last tracked
website_page request is within the last 5 minutes.
- The number of visits for a website_visitor is incremented
if his last tracked website_page request was at least 8 hours ago.
- A website_visitor is only handled by the system. Users cannot
create, edit or delete a website_visitor.
- A unique website_visitor is created per website.
That means that the same real person can triggers multiple visitor
creation if visits multiple websites.
This is because, for livechat purpose on later commit, for example,
the chat request can be created on the correct livecaht channel
(linked to the correct website)
- The visitor is recognized via his cookie (visitor_id). So if the visitor
flush his cookies, a new visitor will be created the next time he will
request a tracked website_page.
- Link user's res.partner to website.visitor.
    If a website_visitor log in
    (a visitor that has visitor_id in his cookie),
    the website_visitor is linked to the res.partner.
    The website visitor name is than adapted to match the name of
    the first res.partner linked to the visitor.
    A visitor can have multiple partners as the same session
    can be used by multiple person (one PC for a team for example).

To keep a detailed history of the visitor page views,
we add a website.visitor.page model that makes the link
between visitor and website.page but that keeps the visit date.
So that we can see if a visitor went mulitple times
on the same page and when. It's usefull to see his last page views.

Task ID : 2028059
PR #34624
2019-08-19 06:33:37 +00:00
Moises Lopez 85a3e1e385 [REF] *: deal with duplicated xml_ids in views and security rules
Was part of PR #19820. Courtesy of Vauxoo
2017-11-24 15:37:28 +01:00
rde 4ecbacaf59 [ADD] website: add new page management
website.page = old ir.ui.view with page=True
website.redirect is a new mechanism to replace in the futur the ir.attachment
mechanism of redirect.

From now, we don't have a specific /page controller to serve 'page'.

We use a new model website.page which is rendered if none route matches the url
 and that the field 'url' on website.page matches the request.httprequest.path.

The order to serve a path is:
    - Routes defines in controllers (/shop, /blog, ...)
    - ir.attachment with name matching the path
    - website.page with url matching the path
    - website.redirect with url_from matching the path
    - 404

To improve:
    - allow regexp in website.redirect model
    - allow to edit the view_arch from the page.management via redirect backend
      (needed when traceback in the page, or when modifying a js/css/less/...)
2017-09-15 15:29:37 +02:00
Martin Trigaux 11812b0b9e [FIX] all: remove external ids fakely from base
Several modules defines records with the external ID `base.foo_bar` while it is
created inside this module (typically menus and groups).
While there is no technical reasons to do so but this may introduce issues:

- these records will not be deleted during uninstall
- if a language is loaded before the installation of the module, it won't be
  translated

The uninstallation will only remove the records with an external id linked to
this module (these would only be removed when removing base).

Installing a language before the module will drop the translations not linked
to an existing external id (as it can not be resolved).

This commit correct all the external ids tagged as from base or other incorrect
modules.
2016-09-02 16:14:26 +02:00
Christophe Matthieu 8c559044a5 [IMP] web_editor: split website into web_editor (to use editor in backend for html field) and website 2015-07-10 17:00:11 +02:00
Denis Ledoux deb091ea64 [FIX] website: missing acl for manage website menu
bzr revid: dle@openerp.com-20140502134135-zp05ecbpcj8inftc
2014-05-02 15:41:35 +02:00
Olivier Dony 81c251836d [FIX] website: grant edit rights to website manager
bzr revid: odo@openerp.com-20140429123517-wtjcw6xl8qgtnkeg
2014-04-29 14:35:17 +02:00
Xavier Morel 3848855462 [FIX] remove outdated & unnecessary security rules
bzr revid: xmo@openerp.com-20140128151009-8hie0sex8ev2pads
2014-01-28 16:10:09 +01:00
Christophe Matthieu cf79ae7635 [FIX] website: access for portal user
bzr revid: chm@openerp.com-20140117154648-sxfisxqcv8o3fvzt
2014-01-17 16:46:48 +01:00
ddm ee2d4327a8 [FIX] access rights
bzr revid: ddm@openerp.com-20131203163131-g7o86fc08gv4if9v
2013-12-03 17:31:31 +01:00
Christophe Matthieu 176a78e161 [IMP] website: add website_designer group and access rules to edit qweb view
bzr revid: chm@openerp.com-20131119135717-6sv54lpm5smybsib
2013-11-19 14:57:17 +01:00
Fabien Meghazi eb7b1362cd [WIP] Menu working from database (not yet multi-website)
bzr revid: fme@openerp.com-20131025152446-si9gsjujzcn40hip
2013-10-25 17:24:46 +02:00
Xavier Morel 9da0ead28d [ADD] support for formatted date and datetime t-field in website
bzr revid: xmo@openerp.com-20131021152651-ner2zggjfofb5rc4
2013-10-21 17:26:51 +02:00
Xavier Morel 0a74b6ef77 [ADD] security rules for qweb.field.integer model
bzr revid: xmo@openerp.com-20131021091542-m2e213pa6kq0bmqz
2013-10-21 11:15:42 +02:00
Xavier Morel a3f7cfd669 [FIX] renaming of currency widget to monetary to match view
bzr revid: xmo@openerp.com-20131008122039-tzw7nq8cx0y0zh5p
2013-10-08 14:20:39 +02:00
Xavier Morel 510a4f51d2 [ADD] customizable qweb rendering, add translate flag on fields through this
bzr revid: xmo@openerp.com-20131008092233-9su66923zthl9jyg
2013-10-08 11:22:33 +02:00
Christophe Matthieu f9b3003517 [FIX] website: ir.model.access.csv
bzr revid: chm@openerp.com-20130917082342-kgg8f52tw8tgmygu
2013-09-17 10:23:42 +02:00