Commit Graph
32 Commits
Author SHA1 Message Date
william-andre 0479b2b594 [IMP] account,*: manage subsidiary companies
Allow sharing records between company
* accounts
* taxes
* fiscal positions
* products
* ...and some related models

These records can be read and used in children companies.

This can be used to
* have different branding for different businesses
* allow more complex security rules
* consolidate branches differently
* manage different tax reports with different tax ids in the same
  country

task-3371677

closes odoo/odoo#125642

Related: odoo/enterprise#43215
Signed-off-by: Quentin De Paoli <qdp@odoo.com>
2023-07-20 11:49:06 +02:00
Martin Trigaux cd2f330bec [IMP] *: remove glocal ACL
Specify explicit route for each ,, line
This is part of task 3230280 where global ir.model.access will be
forbidden.
The goal is to make access to public/portal explicit. Too often,
global access was granted with only employees in mind.

Remove ,,0,0,0,0 lines

mail:
employee already had read access to mail.group
still needed to subtypes as in ir.rule domain

mail_group: employee already had read access
pos_mercury: only needed for employees

membership:
move public access for website_membership as needed in the controllers

website_customer: employee already had read access

website_event_booth: no need for category
website_event_exhibitor: retrieved in sudo
website_event_track: not needed for location

Part-of: odoo/odoo#125216
2023-07-11 22:33:47 +02:00
Horacio Tellez 2b1e2abda3 [IMP] payment,*: restrict access to payment.transaction records
Since 15.0, it is no longer possible to have partnerless transactions.
Nonetheless, migrated databases could contain transactions without a
`partner_id` set.
This commit cleans existing rules to make those transactions are not
accessible to unwanted users.

We take the opportunity to clean the security of payment.transaction
records globally.
Now only admin and accounting users have access to payment.transaction
records. The code of different applications has been adapted accordingly.

Task - 3102824

closes odoo/odoo#113515

Related: odoo/upgrade#4564
Related: odoo/enterprise#40939
Signed-off-by: Masereel Pierre <pim@odoo.com>
2023-05-15 15:07:13 +02:00
Demesmaeker 7f2ae9ed5b [IMP] payment(_adyen): allow partial capture
Before this commit, it was not possible to partially capture a
transaction from Odoo, and doing so in the provider backend would often
result in a full capture in Odoo when capture was supported.

With this commit, partial captures are made available in Odoo directly
from the sales order or invoice, for providers that support them.
Provider can either only support full capture or also support partial
ones. It also optionally managed the automatic void of the remaining
amount at the user request when multiple captures are supported by the
provider.

As of now, the only acquirer allowing partial capture is Adyen.

task-2728768

closes odoo/odoo#87251

Related: odoo/enterprise#35205
Related: odoo/documentation#2063
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2023-03-09 10:51:29 +01:00
Horacio Tellez 0f2de18849 [IMP] payment: only give access to tokens when required by the flow
Until this point the access to tokens was somehow arbitrary and
illogical.
After this commit we will uniformize the tokens access rule where by
default an user can only access its own tokens by default and in
function of the use case then relax the rules.

Task - 2832561

closes odoo/odoo#104808

Related: odoo/enterprise#33541
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2023-02-17 13:06:53 +01:00
Anita (anko) 5cc86c3bb1 [IMP] payment: Rename Payment Icon to Payment Method.
Payment Icon sounds confusig comparing to what it really is,
payment method name makes it clearer for user to understand
what it is.

task-2882564

closes odoo/odoo#105678

Related: odoo/enterprise#33908
Related: odoo/upgrade#4029
Related: odoo/documentation#2955
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2023-01-20 18:54:44 +01:00
Valentin Vallaeys (vava) 034218a5dc [IMP] payment: prevent creating payment tokens
Payment tokens should not be created manually, as it is useless,
confusing and potentially harmful. They should only be created alongside
payment details of a customer payment method.

task-2848379

closes odoo/odoo#99915

Related: odoo/enterprise#31199
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-10-20 18:12:44 +02:00
Horacio Tellez f7b8f07501 [IMP] payment: rename of acquirer to provider
Changing the name of model payment.acquirer to payment.provider
and everything that it touches. It is technically incorrect to
use the term "acquirer" for systems that only provide a service
of payment.
After this commit the model payment.acquirer and all related to
it will be renamed to payment.provider.

Task - 2842088

closes odoo/odoo#90899

Related: odoo/upgrade#3542
Related: odoo/documentation#1981
Related: odoo/enterprise#27131
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2022-09-09 13:38:08 +02:00
Victor Feyens 61b8c0c1a2 [REF] (account_)payment: extract accounting logic from payment 2022-09-06 13:31:00 +02:00
Demesmaeker e0233a1010 [IMP] payment(_adyen): allow to refund confirmed transactions
Before this commit, it was not possible to refund a payment from Odoo.
Users had to go through the payment acquirer's backend and update the
payment accordingly in Odoo.

With this commit, refunds are made available in Odoo directly from the
payment form, for acquirers that support them. Acquirer can either only
support full refunds or also support partial refunds.

As of now, the only acquirer allowing refunds is Adyen, with partial
refund support.

task-2527891

closes odoo/odoo#70881

Related: odoo/upgrade#2689
Related: odoo/enterprise#19829
Signed-off-by: Antoine Vandevenne (anv) <AntoineVDV@users.noreply.github.com>
2021-08-23 10:54:17 +00:00
Antoine Vandevenne (anv)andVictor Feyens 573ed74c12 [REF] payment, *: refactor online payments API
This commit replaces the old online payments API of the `payment`
module with the new one and adapts to it all the implementing modules.

See the merge commit for more details.

task-2085989
task-2119838
task-2165982
task-2289255

Co-authored-by: Victor Feyens <vfe@odoo.com>
2021-03-30 09:25:51 +02:00
Thibault Francois 458c26ae18 [FIX] website_sale, payment: perf issue when displaying tokens
Problem:
the controller rely on record rules to select the payment.token
to be displayed on the payment page.
This works fine with portal user, but internal user
will face client side performance issue
as they can see all the token of the database

Solution:
Don't rely on record.rule in the controller. Use the domain
from the portal user rule in the search.

To make the search of token working for partners with more than
2 levels of hierachy, use child_of operator

closes odoo/odoo#56326

X-original-commit: 3999e249ea9902e009f0366949886e14e3d7fdf4
Related: odoo/enterprise#12579
Signed-off-by: Damien Bouvy (dbo) <dbo@odoo.com>
2020-08-21 15:33:06 +00:00
Damien Bouvy ba93b4a243 [IMP] payment: ir rules in payment module for invoicing users
Security rules are added in the sale module for transactions and tokens,
but it is entirely possible to have the payment module without those,
and preventing invcoicing users from accessing transactions is
functionnaly stupid - they are often required to check payment statuses,
references, etc.

closes odoo/odoo#52139

Signed-off-by: Damien Bouvy (dbo) <dbo@odoo.com>
2020-05-28 14:32:58 +00:00
Victor Feyens a3ded9043d [IMP] *: declare ir.rule in noupdate
ir.rule are default values but can be customized based on the
company's policy and needs.
This is typically a record that is in noupdate as should be
customization-friendly.
2020-03-20 16:21:25 +01:00
Martin Trigaux 65530dfd6a [ADD] *: add ir.model.access on all transient models
Following changes needing ir.model.access on transient models too.
Remove groups declaration on the action to move it to ir.model.access
when possible.
Rules are strict by default with no unlink access by default and high
priviledge asked. Adaptations may be needed later.
Write access is given as a wizard may need to be modified in case the
action triggers an error and the user has to correct a value

account*: use account.group_account_user for all transient by default
	  remove account.print.journal relic
stock*: use stock.group_stock_user by default
survey: survey user can send invitations
mail: allow any employee to execute wizards
      additional verifications are made to ensure they are executed
      only on the documents the user has access to you
      give portal access to mail.compose.message as portal still does
      some actions like posting messages on the forum
      add ir.rule to avoid reading somebody else messages
      increase the query count because of undeterminist count
crm: saleman for lead2opp, manager for massmailing
     partner manager for actions linked to partners
     avoid a write in test_lead_lost
sms: any employee can send sms
mrp: mrp user can execute wizards
     give unlink access as making write during do_produce operation
base_import: employees can import files
delivery: stock user can deliver
event_sale: sale user can configure the wizards
	    event user inherit from  sale rights
gamification: employee can give badge
google_service: resolve FIXME
hr: add specific rights
    manager can set a plan according to group on button
    anyone who can write on an employee can register a departure
hr_expense: set rights based on buttons
hr_holidays: an approver can make a summary report
hr_recruitment: recruiter can refuse a candidate
hr_timesheet: can use the wizard if can create a timesheet
l10n_eu_service: managers can create fiscal positions
mass_mailing: same group as on mass.mailing.list
membership: accountant can create invoice from membership
payment: accountant can create a link
	 as the source is an account.move
	 keep the payment.acquirer.onboarding.wizard to system user
	 only as it is called during company configuration
point_of_sale: PoS manager only can use wizards
	       never create closing_balance_confirm_wizard records
product_expiry: stock user has rights on stock.picking
product_margin: access from accounting menus
repair: same rules as for above models
sale: set ir.rule for self wizard only
      add rule from model introduced in payment to add salesman group
sale_crm: saleman can create a quotation from a lead
sale_coupon: any saleman can generate coupon
	     add self ir.rule
sale_product_configurator: salesman can select product variants
snailmail: employee can send letters
website: designers can write on website
website_crm_partner_assign: same rule as group on action
website_sale: sale ACL as for payment.acquirer.onboarding.wizard
website_slides: anyone can send invitation

base: base.language.*: allow employee (cf lang_install)
      change.password.user: can not read change password wizard of
      other users
      test.*: no access is needed

Courtesy of Damien Bouvy, William Andre and Antoine Prieëls for review
of acl
2020-02-04 17:54:18 +01:00
Olivier Dony 71ccea35ba [FIX] payment: employees should not edit acquirers 2018-03-02 18:27:18 +01:00
tbe-odoo ad095e492f [IMP] payment,website_payment: Change payment.option model name to payment.icon 2017-08-29 17:16:42 +02:00
tbe-odoo 3c062d9345 [IMP] website_sale: Added S2S payment with new payment form
- Added the support of form payment.
- Fixed payment form's errors not being displayed.
- Fixed a crash when paying on e-commerce with a saved token.
(dev commit, need to clean the code)
2017-08-29 17:11:23 +02:00
Goffin Simon 4c8c996f4d [FIX] payment: Deleting payment tokens from website
When deleting payment tokens from website, in My account, by clicking
on button "Manage your payment methods", the public user, the user and
the portal user got a 403 error. But when creating a subscription
for a customer with admin user and setting a payment token for
the company of this customer. This payment token could not be deleted
or modified by its users. In a few cases, it's needed to delete or
modify a payment token, for example, when the expiration date of
the payment token is expired.

opw:740169
2017-04-25 09:53:18 +02:00
Thibault Delavallée a969931f9c [MIG] payment: new API
No functional change.
2016-07-06 15:10:45 +02:00
Joren Van Onder e3730cf1f2 [IMP] payment*,website: rename payment.method -> payment.token
payment.method was not a good name because it was too easy to confuse
with account.payment.method.
2016-06-17 13:09:18 +02:00
Yannick Tivisse 9e57185449 [IMP] base,sales_team: Move res_groups and menuitems to sales_team
Purpose:
Having the res_group defined in base and sales_team auto installed
with mail doens't make sense.

- Move the empty res_config class and the related view from
  base_setup to sales_team (base_setup only contains the 'General Settings'
  model and views
- Move the 'sale' related content from product to sale module (Access rights,
  menuitems,...)
- Set sales_team at autoinstall False. The module is installed when needed by
  crm or sale for example
- Set sales_team as a dependency of voip. (Access rights defined for configuration
  purpose)
- Set sales_team ad a dependency of subscription (Access rights issue too)

[FIX] account: move some ir.model.access to sale module
[FIX] payment: Move some ir.rule to website_sale
[FIX] stock: move some ir.model.access rule to sale_stock
[FIX] project: Move some ir.model.access rules to crm_project_issue
[FIX] mrp: Move some ir.model.access rules to sale_mrp
[FIX] calendar: move some ir.model.access rules to crm

Rename xmlids accordingly. Example: 'base.group_sale_manager' becomes
sales_team.group_sale_manager.

[ADD] sales_team: See own documents => See only his sales team
Moved the "User: Own Leads Only", "User: All Leads" and "Manager" groups from sale and crm
into sales_team module. Add the record rules so that user can see only his Own Sales Team
if "See Own Leads" is sales right and can see all sales teams if he is having sales rights
of "See All Leads" or manager.
2016-06-09 16:05:25 +02:00
Yannick Tivisse ccdb5cbfc0 Revert "[IMP] base,sales_team: Move res_groups and menuitems to sales_team"
This branch need more testing instead of doing 10 fixes. A lot of issues are occuring
when installing modules in different orders.

This reverts commit fa6e415cdb.
2016-06-06 17:26:30 +02:00
Yannick Tivisse caf1e4dd70 Revert "[FIX] payment: Move some ir.rule to website_sale"
This reverts commit 930bea9758.
2016-06-06 17:26:12 +02:00
Yannick Tivisse 930bea9758 [FIX] payment: Move some ir.rule to website_sale
The group group_sale_salesman has been moved from base to
sales_team.
2016-06-06 16:47:18 +02:00
Yannick Tivisse fa6e415cdb [IMP] base,sales_team: Move res_groups and menuitems to sales_team
Purpose:
Having the res_group defined in base and sales_team auto installed
with mail doens't make sense.

- Move the empty res_config class and the related view from
  base_setup to sales_team (base_setup only contains the 'General Settings'
  model and views
- Move the 'sale' related content from product to sale module (Access rights,
  menuitems,...)
- Set sales_team at autoinstall False. The module is installed when needed by
  crm or sale for example
- Set sales_team as a dependency of voip. (Access rights defined for configuration
  purpose)
- Set sales_team ad a dependency of subscription (Access rights issue too)

Rename xmlids accordingly. Example: 'base.group_sale_manager' becomes
sales_team.group_sale_manager.
2016-06-06 15:46:52 +02:00
Damien Bouvy a0bc204bb1 [FIX] payment: missing right for users on payment method
Let's be consistent, shall we?

If portal users can delete their own card, employees should have
the same rights.
2016-02-26 13:48:19 +01:00
Damien Bouvy c9a1d4d01c [FIX] payment: missing delete right for portal user
Portal users should be able to delete their credit card/payment method.
This ACL in combination with the ir.rule allows them to do so.
2016-02-26 13:43:05 +01:00
Damien Bouvy dbd3efef1f [IMP] payment: add support for server2server payments
This commit adds a new model, Payment Method, which stores
a reference to the payment acquirer's database and a reference to
a partner. Each payment module must have its own implementation.

The implementation is completely abstract but may not suit every
provider's way of implementing recurring payments.
2015-06-15 14:57:14 +02:00
Martin Trigaux 28a27a9f91 [IMP] payment: simplify rev d99835e
The group public is defined in base so no need to add security rule in website_payment module (same as for portal)
2014-09-17 11:05:32 +02:00
Martin Trigaux d99835ee9c [FIX] payment: access rights limitation
Do not allow everybody to access account.transactions.
Restrict by default to readonly and even restrict the access with a record rule, give access to salesman.
2014-09-16 16:44:42 +02:00
Thibault Delavallée 0b69bad996 [RENAME] payment_acquirer_* -> payment_ *
bzr revid: tde@openerp.com-20140122175702-1h1e51z4njt4s70w
2014-01-22 18:57:02 +01:00