Commit Graph
7188 Commits
Author SHA1 Message Date
Alexandre Kühn 2f1688868a [FIX] mail: correctly compute direct_partner_id for dm_chat
Revision on https://github.com/odoo/odoo/commit/975164473ccd51c00eee5917dddbd8be71b5aefc

The commit above improves the channel_info, so that there
are less DB queries.

However, the computation was wrong for partners on dm chat,
which resulted in omitting the name and email of the partner.

closes odoo/odoo#31033
2019-02-12 15:55:01 +00:00
Robot Odoo 1f2766a955 [IMP] Add employee profile
[IMP] hr_*: introduce the employee profile
================================

## General Purpose

We want an 'Employee profile' gathering every data about an employee.
The main form view is modified to become this employee profile.
A user can also see his own profile through the Preferences menu.
The new profile replaces the current Preferences view if the `hr` module is installed and the current user is linked to an employee. The Profile will show the employee of the current company.

A user should be able to see and edit his own profile.

*Problem*:
Many fields on hr.employee are protected by `groups="hr.group_hr_user"`.
Therefore, a regular user cannot see or edit those fields.

This protection must be bypassed to allow read/write access to the regular user's own data.
A similar mechanism already exists for `res.users` (for Preferences)

The better (least worst) solution found is to reuse this mechanism by adding related fields on `res.users`.

Pros:
- Don't change security access on hr.employee
- Don't implement yet another custom security layer, risking to add new security breaches
- A lot of fields are added by other modules on hr.employee.
  It would have required to integrate them with the custom security layer.
- Fields added by other modules on the user's preferences view (normal view, not the profile)
  are automatically included in the employee's profile view.
- Allow the hr.employee form view to be different than the user profile accessible
  through the Preferences menu.
  E.g. add custom buttons only relevant to the logged in user such as "Request a leave".
Cons:
- Each field from hr.employee that you want to appear on its profile
  must be added as a related field on res.users
- Those related fields must be added to user's preferences view (duplicate views)
- They also must be added to `SELF_[READABLE | WRITABLE]_FIELDS`

Note:
When the front-end loads the views it gets the list of available fields for the user (according to its access rights). Later, when the front-end wants to populate the view with data, it only asks to read those available fields. However, in this case, we want the user to be able to read/write its own data, even if they are protected by groups (groups are kept on the related fields on res.users). The front-end need to be made  aware of those fields by sending all field definitions.

## Changed modules

### hr_attendance

Adds a stat button to this employee profile showing the number of hours worked last month.

Remove the Boolean computed field `manual_attendance`.
This field is just a shortcut to add/remove the employee's user in the "Manual Attendance" group.
The checkbox is confusing on the employee's form and this should be done through the normal group management screens.

### hr_presence

Display the presence status on the employee kanban template.
The status is a colored chip which can be green (present), orange (to define) or red (absent).

Currently, the presence status is only computed when accessing the report view. As this commits displays it on the employee kanban, it should be updated more frequently.
The state should not be updated every time the kanban view is loaded since the computation is a bit heavy. Instead: add a cron to update status every hour.
-> The status is accurate on the report view (status is still updated
   when loading the view)
-> The status in accurate at 1 hour on the kanban view

### [ADD] hr_attendance_presence

Bridge module between `hr_attendance` and `hr_presence`.

This PR integrates `hr_presence` module in the employee profile and adds the presence status on the employee kanban view. But `hr_attendance` adds at the same place a similar status icon for checkin/checkout.
This bridge module makes the status from `hr_presence` invisible as `hr_attendance` should be the main presence control mechanism.

Also, this commit adds the ability (through a new setting option) for `hr_presence` to take into account checkin/checkout to determine the presence status.

### l10n_be_hr_payroll
integration with employee profile

[ADD] hr_skills: Introduce a new module for employee resumé and skills
=======================================================

Purpose
-----------

Consultancy companies need resumé and skills of their consultants.
For big projects, they often need to send them to their customers.
These information are also useful to statistics.

Specification
-----------------

### New models

####  `hr.resume.line.type`
Types of resumé lines. e.g. *Experience*, *Education*, *Hobbies*

#### `hr.resume.line`
It is a line in the resumé of an employee.

#### `hr.skill`
Name of a skill. e.g *French*, *Python*, *Piano*

#### `hr.skill.type`
Skills can belongs to a particular type. A skill type has skill levels associated.
e.g. *Languages*, *Dev*, *Music*

#### `hr.skill.level`
Levels available for a particular skill type. Each level has a label
and a progress (between 0 and 100) associated.
e.g. *Intermediary (20%)*, *Advanced (85%)*, *Expert (100%)*

#### `hr.employee.skill`
These are skills which employees have. It links an employee with a particular skill
and level.
e.g. Mitchell has an *Intermediary* level in *Python*

### Access Rights

Only a `hr_user` can create/edit `hr.resume.line.type`, `hr.skill`, `hr.skill.level`, `hr.skill.type`.
If employees are allowed to edit their infos (setting), they can also create/edit `hr.resume.line`,
`hr.employee.skill` for themselves.

### UI

Resumé lines are displayed, grouped by type, in a new 'Resumé' tab in the employee
form. Resumé lines can be reordered (handle widget)

Emloyee skills are displayed in the Resumé tab, grouped by skill type.

[IMP] hr, hr_holidays, hr_expense: Change onchange parent_id behaviour
=========================================================

Purpose
-----------

When the manager (parent_id) of an employee changes, it doesn't always mean that other responsibles (Leave responsible, expense responsible, coach) should also change.

Specification
-----------------

When changing the employee's manager, the leave responsible, the expense responsible and the coach should be changed only if the field was not set or if the responsible is the previous manager. In that case, they should be set to the new manager. Otherwise, it means the field was most probably set manually and it should be left unchanged.

Task 1913089

--
I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr

closes odoo/odoo#30502
2019-02-14 19:09:34 +01:00
Lucas Lefèvre c7aa8c5f66 [IMP] mail: allow tracking on groups protected fields
Purpose
=======

Currently fields with a `groups` attribute can't be tracked.
Otherwise changes would be visible by all in the chatter, including
users which normally don't have the access rights because they are
not members of `groups`.

Specification
=============

Filter tracking field values according to the `groups` attributes.
Users without the access rights should not see them.

If a message is only composed of tracking values and the user doesn't
have the rights to see them, an empty message should not be displayed.
2019-02-13 11:03:33 +01:00
Martin Geubelle 7abeaf56b3 [REF] im_livechat, *: remove JSONP in favor of CORS
When embedding the livechat on an external website, we used to make JSONP calls.
As the support of JSONP calls has been dropped, we now use the CORS mechanism
instead.
2019-02-13 09:38:30 +00:00
Martin Geubelle 31664422c1 [IMP] web, *: remove explicit references to session_id
Since rev. odoo/odoo@f4d541e the `session_id` cookie uses the `httponly` flag so
it cannot be accessed through client side script. But before this rev. the
`session_id` was still provided by the server to the webclient (in session_info,
mostly) and was stored and accessible. This made XSS injection more
dangerous than they should be as it was very easy to steal the `session_id`.

As the browser automatically set the `session_id` on every request to the server,
the webclient shouldn't need any explicit reference.
2019-02-13 09:38:30 +00:00
Christophe Simonis 8c29df10e0 [MERGE] forward port branch saas-12.1 up to 93d736e905 2019-02-11 17:00:35 +01:00
Christophe Simonis 93d736e905 [MERGE] forward port branch 12.0 up to 6e8dff1952 2019-02-11 16:17:02 +01:00
XavierDo 975164473c [IMP] mail, hr_holidays: improve channel_info
`channel_info` can be called on multiple channels especially during
the init_messaging. The current implementation will perform read and
other queries in the loop. This commits aims to refactor `channel_info`
in order to read all informations in database out of the loop.

Computation of members informations is now the same as for `direct_partner`
As a side effect direct partner will have an email adress and members will have
im_status and out_of_office message if the partner is in a
channel of type chat. It would be easier to compute im_status in all case but
this could create performances issues when calling channel info on channel with
hundreds of users.

channel_fetch_preview will make a query in database in any case but seems to work ok
in api multi. We can put it out of the loop.

44ac7903cc fix shouldn't be broken by this refactoring since we are no longer using the many2many to find direct_partners.
2019-02-11 09:22:24 +00:00
Martin Trigaux b6d62f8ce3 [FIX] mail: translate activity name
This commit fixes two untranslated terms in the activity view.
From the cohort view, when clicking on a cell to see details, the title was not
translated (missing _t call).

The content was not translated either as the language was not present in the
context.
36d45175b0 was a first step to fix it but while self.record contained data,
self.record.getContext() returns an empty dictionnary (no context is set in the
cohort view).

When computing the context, check that it is not empty, otherwise, fallback on
the session context.

opw-1936855

closes odoo/odoo#30942
2019-02-08 05:34:44 +00:00
Odoo Translation Bot 1bec017c15 [I18N] Update translation terms from Transifex 2019-02-10 01:32:20 +01:00
XavierDo 5c3aaacd2e [IMP] mail: correctly patch mail status manager timers
We want to avoid that a `setTimeout` started in one test has an impact on other
tests. This is especially true with the status update loop. Since mail_service
is used in multiple tests, the safest solution is to patch timeouts everytime
we make a call to getMailServices.
There is no need for an unpatch, the patch become the default behaviour until
the page is refresh at the end of tests.

It is possible to manually add the patch after calling `getMailServices`
```
this.services = mailTestUtils.getMailServices(this);
this.timeoutMock = mailTestUtils.patchMailTimeouts();
```
This can be usefull if we want to get the timeoutMock to simulate time changes.

Task: 1856205
2019-02-07 12:53:14 +00:00
XavierDo 2d45df1081 [IMP] mail, web: Add indication abouts it's own status in user_menu.
Task: 1856205
2019-02-07 12:53:10 +00:00
XavierDo 062f748efb [IMP] mail: add a Read More on out of office message
Task: 1856205
2019-02-07 12:53:07 +00:00
XavierDo 086405344e [IMP] mail, hr_holidays: use leaves to compute im_status
When on leave, the im_status can be either leave_online or leave_offline.
This will allow to display a specific icon and a default message when the user
is not at the office.
The leave can have an out of office message. This message will be displayed
in the chat window instead of the user ooo message, and the end date of the leave will be displayed too.

Technical details.
Right now the im_status access leaves directly to know if a user is on leave or not.
An index has been added to optimise this request (thanks to rco).
A solution to optimise this would be to compute part of the information in a cron.

Task: 1856205
2019-02-07 12:53:03 +00:00
Christophe Simonis 87924cb5ad [MERGE] forward port branch 12.0 up to a46138cb01 2019-02-07 13:14:02 +01:00
XavierDo c21d200285 [IMP] mail: add ooo status in chats windows.
In a chat window with a single usert (dm_chat) the ooo status of the
other user is displayed on the top when set.

Task: 1856205
2019-02-07 08:54:33 +00:00
XavierDo b60224c41c [IMP] mail, base: add out of office status to user.
This status can be edited by user in preferences, indicates if user
is available or not.
2019-02-07 08:54:33 +00:00
XavierDo 07a261db71 [IMP] bus, mail, mail_bot: add im_status service
This commit is a refactoring of im_status management.
This commit also add im_status in two places, near the author in a mail thread and on each suggestion when using mentions.

A service to manage im_status will have multiple benefits here:
-centralise information, avoid to call the server multiple time for the same im_status
-update all im_status at once and keep consistency in display.

With this commit, the im_status updates are now done by rpc call.
Updates where previously made with the bus but this has some drawback,
since the bus will only give the information 50 seconds after the beginning of
the request, in the worst case, we van wait 2*50 seconds to get an update.

More than that, the im_status where only updates for pinned dm_chat. Dm chat
are synchronized cross tabs, making the use of the bus possible for this purpose.
Since we will need to display im_status not linked to dm_chat, the list to update
will be different from tab to tab making the use of bus difficult for this purpose.

Technical notes:
-im_search has been moved from bus to mail addons since it concerns mail.channel
-Update of an im_status should be reflected everywhere in the page.
Since im_status is a rendered template used in multiple widget, we should add
the correct logic to all concerened widget. The current solution is simple:
use a jquery selector to find every place where im_status is rendered.
-we add a new im_status: im_partner. This will indicate that that
the partner has no user linked to him, making it possible to avoid to ask
for status updates for this partner.
-The update will only be done when the tab is focused. (and will be done
asap once the tab get focus back)
2019-02-07 08:54:33 +00:00
Lucas Perais (lpe) a46138cb01 [FIX] mail: create partner from template in right company
Before this commit, when creating a partner automatically when creating
a message with a template, the company on the partner was wrongly set

After this commit, we try to retrieve the company from the model on the template

OPW 1934392

closes odoo/odoo#30893
2019-02-06 16:48:23 +00:00
Christophe Simonis 530f364547 [MERGE] forward port branch saas-11.3 up to 0c42a607ec 2019-02-06 11:59:44 +01:00
Christophe Simonis 9c6acbaaa0 [MERGE] forward port branch 11.0 up to e0b14bf9a7 2019-02-05 17:53:35 +01:00
Lucas Perais (lpe) 703263ad45 [FIX] mail: activity model js: pass context to get activity data
Go on the crm activity view
Have your user operate in another language than en_US

Bafore this commit, the activity types were not translated
This was because the context was not passed to the function

After this commit, the terms are translated

OPW 1924232

closes odoo/odoo#30837
2019-02-05 13:37:08 +00:00
Nicolas Lempereur d730f66964 [FIX] mail: mention special char=>link partner
This is a regression from: 10f0766b3. In it the visual side was solved,
but unexpectedly the functional side still worked on unescaped content.

Thus visually a @partnèr could be seen as a link, but it was no anymore
added as follower.

Without change, modified test fails with:

 mentioned partners are sent to server (expected: [1], result: [])

note: change is partial backport of 12.2 e2f20ffa9

opw-1931247
closes #30846
2019-02-05 17:24:19 +00:00
Géry Debongnie 1f5807f1c8 [FIX] web: allow user to move cursor in search bar
With the control panel refactoring, the auto_complete widget was set on
a different target, which caused issues with the search bar: the event
handlers for the search bar were triggered before the handlers for the
auto_complete widget.

With this commit, we make sure they are handled in the proper order.

Also, a small piece of code that was supposed to check the position of
the cursor was lost.

closes odoo/odoo#30795
2019-02-04 08:22:34 +00:00
Julien (juc) Castiaux 262e001086 [FIX] mail: delete messages on module uninstallation
When uninstalling a module, the messages linked to the records
of that module are not deleted leading to ghost messages when
reinstalling the module.

This is due to the lack of foreign keys in the definition of the
chatter making it impossible to cascade delete.

opw-1928208

closes odoo/odoo#30798
2019-02-04 14:16:47 +00:00
Fabrice Henrion ae7f82f621 [IMP] mail: change string label
closes odoo/odoo#30858
2019-02-06 13:55:51 +00:00
Alexandre Kühn e8f7770a13 [FIX] mail: do not open chat window twice
Revision on https://github.com/odoo/odoo/commit/0d87b1ccea07b952d9079008cfa3cddaf1ccdbee

The commit above prevents opening a chat window when we do not have
access to messages of the conversation. This may happen when
receiving a notification from a document we do not have access
rights.

However, the changes in the code above has an unintended side-effect
of opening a chat window twice when clicking on a channel preview
from the systray messaging menu.

This happens because when clicking on a preview, it detaches the
thread and opens the chat window. Meanwhile, there is a RPC to
notify that the chat window is detached, and the new window state of
the channel is received on the longpolling. Two concurrent attempts
to open a chat window occur at the same.
It was working fine before the commit above, because the registering
of a newly open chat window was synchronous.
This is however no longer the case, because it fetches messages
beforehand: it has become a requirement to open a chat window. Since
the registering of a newly open chat window is now asynchronous,
it was fetching messages and opening the chat window twice.

This commit fixes the issue by aborting attempt to open a chat
window if it's currently opening a chat window, as this process may
take some time due to the `message_fetch` RPC.

closes odoo/odoo#30741
2019-02-01 14:21:47 +00:00
Odoo Translation Bot 69dbbea09a [I18N] Update translation terms from Transifex 2019-02-03 01:38:30 +01:00
Obay Abdelgadir ed3792fdeb [FIX] doc: specify correct field name in mail
closes odoo/odoo#30718
2019-02-04 07:51:25 +00:00
Christophe Simonis f927c68ddb [MERGE] forward port branch 12.0 up to cb8fefa899 2019-01-31 16:59:58 +01:00
Alexandre Kühn 24ba5ae276 [FIX] mail: open 'My Activities' from systray activity menu
Before this commit, when clicking on the activity view icon
from an item in the systray activity menu, the activity view
had no search filter by default.

This commit now auto-select 'My Activities' in the activity
view when redirected from the systray activity menu.

closes odoo/odoo#30702
2019-01-30 17:18:48 +00:00
Alexandre Kühn 8897cb1feb [FIX] mail: keep activity notification counter on today's meetings
Before this commit, when a user had some meetings planned today
and open the systray activity menu, the counter would disappear.

This was caused by a weak computation of the counter that relies
on activity having always a total counter. This was not the case
for activity that are today's meetings: Counter would be computed
as `NaN`, and since `NaN` is falsy, it won't display the counter.

Today's meetings have no reason to have a counter, so this commit
fixes the issue by letting those activities not change the
computation of the counter.

closes odoo/odoo#30695
2019-01-30 13:18:18 +00:00
Alexandre Kühn 1a774f9e0e [FIX] mail: click on item from composer's emoji menu
Before this commit, clicking on an item from the
emoji menu of a composer was not putting the emoji
in the input.

Steps to reproduce:
- Open discuss app
- Select a conversation with a composer
- click on emoji menu in the right-side of the composer
- click on an emoji in the emoji menu
> the emoji has not been put in the input of the composer

This problem was caused by a race condition with the event
`focusout` on the emoji button and the `click` on an emoji
item. `focusout` always happens before `click`, and `click`
event following a `focusout` event can only happen when the
element is visible. This was not the case, because the emoji
container is removed from the `focusout`, so no `click` is
triggered on the emoji item.

This commit fixes the issue by listening on `mousedown` on
the emoji item instead of `click`, which is triggered before
`focusout`.

closes odoo/odoo#30694
2019-01-30 12:23:28 +00:00
Mohit Ghodasara 0db0e66e96 [IMP] mail: improve usability of activities
Purpose of the task is to improve the usability of activity types and
activity scheduling.

Another purpose is alto to protect some master data activity types by flagging
them and preventing their deletion.

Containing
 * make the activity type as master data so deletion will be prevented;
 * improve the usability of the activity type;
 * prevent the deletion of activity type which are used for automated activity;
 * change the usability of activity scheduling modal;

This commit is linked to task ID 1907970 and PR #29257.
2019-02-05 11:32:14 +00:00
Christophe Simonis 4400cce820 [MERGE] forward port branch saas-12.1 up to 4524ad06a8 2019-02-04 13:27:22 +01:00
Julien (juc) Castiaux e65446fe42 [FIX] mail: Force the writing of the attachment when the user can post
To reproduce:
1) Enable multi-company
2) Create two companies: c1, c2
3) Create two users: bob in c1 and alice in c2
4) Install subscription
5) Remove the ir.rule that forbid users from accessing subscriptions
   made in other companies: "Subscription multi-company"
6) Using u1, create a new subscription in c1
7) Using u2, follow the chatter of the newly created subscription
   allowing the user to post messages/log notes.
8) Using u2, send a message with an attachment. Access Error.

The problem raises only for the **first** attachment. That
attchement is written on the record as the main attachment thus
raises an error if the user doesn't have write access.

There is no problem to add attachment to any following record or
when the user has write access on the model. If the user doesn't
have access to the chatter, he is blocked before accessing the
write thus it is safe to sudo it.

opw-1915606

closes odoo/odoo#30659
2019-01-30 10:46:01 +00:00
Christophe Simonis cd5c8a02f9 [MERGE] forward port branch 11.0 up to 36d96e0150 2019-01-29 13:17:12 +01:00
Nicolas Martinelli a5edf7ec09 [FIX] mail: user signature
- Install Invoicing
- Multi company Set up with no common contact book
- Create & validate an invoice with user A in company 1
- Change to company 2 with user A
- Connect with user B in company 1
- Send & Print the invoice

An error is raised on the template rendering because user B cannot read
info from user A.

opw-1928676

closes odoo/odoo#30649
2019-01-29 12:22:29 +00:00
Nans Lefebvre 9e276477ce [FIX] mail: keep record changes on attachment upload
Steps to reproduce:
 - Edit a record.
 - Log a note or send a message with an attachment.
 - Save the record.
Bug: changes made to the record are discarded.

Because uploading an attachment triggers a reload without 'keepChanges',
the record values are read from database.
However displayed values are not updated, so there is no feedback that changes
have been discarded.
On save, the page is reloaded so the user sees that changes have been lost.

Introduced by 7f97c9fc05.

opw 1923824

closes odoo/odoo#30642
2019-01-30 07:58:19 +00:00
Christophe Simonis bdfef60d60 [MERGE] forward port branch saas-11.3 up to cd5c8a02f9 2019-01-29 18:35:14 +01:00
Lucas Lefèvre 95ef460961 [FIX] mail: don't trigger if mail bus is undefined
Steps to reproduce the bug:
1. open an app such that there is a breadcrumb (e.g. an employee form view)
2. create a chat window with a user
3. click on the expand button to open the chat in Discuss
4. unsubscribe from the thread
5. click on the breadcrumb to go back

=> Traceback

When expanding the chat window to open Discuss, it registers a callback which
triggers an event on the mail bus. This callback is called when clicking
on the breadcrumb.
Because the channel was left, any related chat window is destroyed.
Since the widget is destroyed, it has no parent, so any service call
returns `undefined`, hence `getMailBus` returns `undefined`.

Fix: check if mailbus exists before triggering.

closes odoo/odoo#30640
2019-01-29 14:25:42 +00:00
Christophe Simonis fab415acab [MERGE] forward port branch 11.0 up to 984a99611e 2019-01-23 18:15:18 +01:00
Nicolas Martinelli 10d558ef2b [FIX] mail: failure notification
- Debug mode,
- Add multi-company to admin (user id 2),
- Create new company (company 2)
- Activate res.partner multi-company record rule
- Create invoice
  - with first company (the default one)
  - with a customer having an email address that doesn't exist
  - Send a message in the thread, making sure the customer is in the
    follower
- Wait for the message to bounce (red mail icon in the thread on the
  given message).
- Change user to company 2 (in the dropdown menu next to the user
  dropdown menu in the upper right corner)
- Refresh, access error, even in the app switcher.

This is because Odoo tries to display in the notifications the email
that failed, and crashes because the user doesn't have access to the
partner of the email.

We filter out the notifications related to objects that the user doesn't
have access to.

opw-1924359

closes odoo/odoo#30348
2019-01-18 11:41:43 +00:00
Thanh Dodeur 3c9cf1e753 [IMP] mail: adds delete and upload to chatter
backport of 73d9b9588f

This commit adds the ability to upload and delete
attachments from the chatter.

closes odoo/odoo#30636
2019-01-28 11:24:48 +00:00
Christophe Simonis 4aa153e65c [MERGE] forward port branch 11.0 up to 19558129f0 2019-01-17 20:49:36 +01:00
Christophe Simonis 19558129f0 [MERGE] forward port branch saas-15 up to c0471dd857 2019-01-17 19:07:34 +01:00
Christophe Simonis c0471dd857 [MERGE] forward port branch saas-14 up to 17adccd95c 2019-01-17 18:07:26 +01:00
Odoo Translation Bot fe36bff420 [I18N] Update translation terms from Transifex 2019-01-27 01:37:55 +01:00
Christophe Simonis c8ace043e5 [MERGE] forward port branch saas-11.3 up to 387d5cff90
closes odoo/odoo#30566
2019-01-25 17:29:34 +00:00
Christophe Simonis 17adccd95c [MERGE] forward port branch 10.0 up to 50bae1c0c5 2019-01-17 17:08:39 +01:00