Commit Graph
25 Commits
Author SHA1 Message Date
Victor Feyens a3ded9043d [IMP] *: declare ir.rule in noupdate
ir.rule are default values but can be customized based on the
company's policy and needs.
This is typically a record that is in noupdate as should be
customization-friendly.
2020-03-20 16:21:25 +01:00
Victor Feyens 532c083cbb [IMP] *: remove global field definition in ir rules xml
It is a computed field, there is no need to manually set its value.
2020-03-20 16:15:40 +01:00
Yannick Tivisse a5b6f31cf2 [IMP] base: Contextualize the multi company
Purpose
=======

Allow the user to select the allowed companies for which he wants to see records
on top of selecting his current company.

It is confusing for users to see the records from the company he is connected to
and the records of the children companies.

Instead of using the hierarchy of companies to access records across companies,
the user can now select (from his set of allowed companies) the companies for
which he wants to access records.

/!\ This means that the user will interact with records from company A when in
company B.
Example: a SO has been created and confirmed in A. When in B, I create the
invoice from it.

Specifications
==============

1/ Deprecate the parent/children hierarchy on the res.company model. The fields are
kept on the res.company model to ensure the retro-compatibility, but won't be used
accross the standard code anymore. The only functional usage for this mechanism
was to allow to see records from several companies by creating a virtual parent
company, which will be possible with the new mechanism.

2/ By default, a user will only see the records of the company he is connected
to (or records without a company). (It is still editable by the user if needed).
For that, put this information in the user context, to allow having different
configurations on different browser tabs. Instead of having domains like
['|',
('company_id', '=', False),
('company_id', 'child_of', user.company_id.id)]
you'll have something like
['|',
('company_id', '=', False),
('company_id', 'in', company_ids)]
Note that the 'company_ids' is a value that is passed in the evaluation
context on the record rule, as we already have user, or time.
company_ids is a list of the ids of all the enabled companies in the
user's context.

3/ Out of the generic improvements brought by this task, this will illustrate
issues that could exist since several versions. For example, it should not be
possible to create a scrap order for the company A with a package of the company
B, or it should not be possible to create an invoice on the company A with
payment terms from the company B. Before the version 12.0, it was easy to
encounter this kind of issues as the admin was the SUPERUSER_ID. A positive side
effect of the fact that the SUPERUSER_ID has become an inactive user was to
make it more difficult to introduce mismatch on the records, but haven't solved
the issue, as it was still possible to do it with parent companies
configuration. Some of these issues have been fixed in this commit, but all the
business flows should be re-tested to check if an ir.rule should be introduced
(eg: a multi company rule for stock.quand.package), if the company of a record
is correctly transfered to another record created from the first record (eg:
From a SO, create an invoice and a payment, the company of the sales order
should be transfered on the invoice and the payment, even if the company of the
sales order is A and I'm logged into the company B with the company A enabled.

4/ Currently, if I click on a button on a notification email (example 'View
Task'), I face a traceback if I'm not logged into the company of the record.
Now, if you click on a button and if you have access to the record, the correct
company will be automatically set.

5/ If I display a kanban view with several records from several companies (and
an image), all the images should be displayed.

6/ Currently if you copy paste an url, this will crash if you're not in the
correct company. This won't be fixed because it's quite impossible to do it in
a clean way. This task brings a workaround. Copy/Paste -> Traceback -> Log into
the correct company, re-copy/paste -> Ok.

7/ 2 property methods have been added on the environment to retrieve the company
on which the user is logged in and the companies the user enabled, on a specific
tab.
That way, when creating a record, instead of doing
default=lambda self: self.env.user.company_id
do
default=lambda self: self.env.company_id
On the other hand, to retrieve the enabled companies, do
companies = self.env.company_ids

8/ Modify the Company Switcher widget to allow to log into another company
WITHOUT writing on the res.users (and thus bringing cache invalidation issues
and so on). Also allow to enable several companies and see records from several
companies, and independantly of the other browser's tabs.

9/ When focusing on a tab, save the current company configuration on the local
storage. That way, when doing 'CTRL+T' or a middle click, the context is
propagated to the new tab.

10/ Improve the error message in case of multi company access errors. Now, when
the user is in debug mode, display the related names of the records and the name
of the user who brings the issue.

11/ Remove the context erasing when writing on a res.users
This is probably coming from the migration to new API of the base module.
The context was not propagated at this moment, which was a common mistake at
that time. When migrating the module, probably by using the 'black box' method,
as the context was not propagated, it was erased on the new version. This is
now an issue because the context (i.e. the enabled companies) was erased when
writing on a res.users, leading to tracebacks.
See: https://github.com/odoo/odoo/commit/7eab8e26d3d46c53f4be924d6a34e80a66e74960#diff-4c2e738ee8f64f11806c889ea097b5e7R624

12/ Fix the crash manager on redirect warnings. The issue is the following
- Create an invoice on a company without a configured CoA.
- Set a partner
- On the onchange_partner_id, a redirect warning is raised to propose you
to configure a CoA
- Click on 'Go to the configuration panel'
- A generic warning says something like 'Do you want to discard your changes?'
- Click on yes, the page refreshes, but not on the redirect action.
Now, set correctly the action on the hash, and reload instead. The breadcrumb is
lost for example, but you reach the correct action at least.

13/ Introduce a res.group to enable/disable the multi company per tab
feature.

14/ To help the users to know which tab is in which company, add the
possibility to have a favicon per company. When creating a company,
the classical 'O' icon is colored by default in a random color.

15/ Remove the company switcher on the frontend. This was mainly there
to allow a user to swicth to the company linked to the website.
This behavior is now transparent to the user. If the website A is
activated, then the company set on the context is the company of the
website.

16/ Deprecated the _company_default_get method on the res.company
model. Remove the method _get_company on the res.users model.

17/ Add 'allowed_company_ids' and 'current_company_id' on the pyeval
context. You can now use those variables on domains in the views to
access directly to the activated company.ies on the current tab.

TaskID: 1960971

closes odoo/odoo#32341

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-05-13 08:57:49 +00:00
Jérome Maes b91b66c686 [REM] portal_gamification: kill the module
The goal is to prepare the removal of
'portal' module.

Since this module only provides access rules and
rights, those ones are moved directly into its
parent module (aka gamification).
Since no module depends on it, we can remove it
without problem.
2017-03-23 09:59:58 +01:00
Martin Trigaux e5f05074f8 [FIX] gamification: remove duplicated manager groups
hr_gamification should be adding hr groups to the security of gamification.
Creating the group base.group_hr_manager in gamification in case hr is not
installed is confusing and redundant with existing manager groups.
2016-09-02 16:13:29 +02:00
Xavier Morel 0c649644db [MIG] gamification: Migrate to new API
Includes compatibility-change to website_forum: a selection(callable)
converted to a Selection(list) since that can easily be extended in the
new API.
2016-08-05 10:18:02 +02:00
Gaurav Panchal ede13fd43b [IMP] gamification: groups and config udpate
Clean access, groups and categories in gamification. Remove custom
goal_category aka Gamification category. As gamification is mostly
integrated in HR, use HR categories. Remove custom group_goal_manager
group, replaced by HR manager. Gamification groups and configuration is
therefore linked to HR now.

Updated access rights accordingly.
2015-08-12 11:41:58 +02:00
Martin Trigaux 55ac64258f [FIX] gamification: correct name of ir.rule fixing bad copy-paste
bzr revid: mat@openerp.com-20140512085041-b0euexzgxgvb30oe
2014-05-12 10:50:41 +02:00
Martin Trigaux f6a75093b9 [FIX] gamification: add security rule for multicompany (avoid getting error messages on home page when displaying top 3 goals)
bzr revid: mat@openerp.com-20140416130924-8pyuejefcu7hnzmf
2014-04-16 15:09:24 +02:00
Martin Trigaux 4bc29b9ffa [REF] gamification
bzr revid: mat@openerp.com-20131217170232-e0zruxzl1wlycaji
2013-12-17 18:02:32 +01:00
Martin Trigaux 122c15c48d [REF] gamification: pretty much changing half of the code to make tde happy...
bzr revid: mat@openerp.com-20131217161541-oxsgy7gmko2x6qui
2013-12-17 17:15:41 +01:00
Martin Trigaux c301558bf9 [FIX] gamification: no, actually make record rule for every user, will handle portal later
bzr revid: mat@openerp.com-20131212115524-u25hz4xjj9l8gatb
2013-12-12 12:55:24 +01:00
Martin Trigaux c797a9071b [FIX] gamification: make record rule global and not for employees only
bzr revid: mat@openerp.com-20131212113639-lg2w2pm1mldbqe7a
2013-12-12 12:36:39 +01:00
Martin Trigaux 01784af22c [IMP] better security rules
bzr revid: mat@openerp.com-20130424081216-cjyq0edrht6r0j1v
2013-04-24 10:12:16 +02:00
Martin Trigaux f70b0017f6 [IMP] fixing and UI
bzr revid: mat@openerp.com-20130410101454-nkt8mbt8qb13zrge
2013-04-10 12:14:54 +02:00
Martin Trigaux 1a5ae7f32e [IMP] better UI
bzr revid: mat@openerp.com-20130408141132-or43mhdl8d5ds7xb
2013-04-08 16:11:32 +02:00
Martin Trigaux 8c07975c91 [IMP] security rules
bzr revid: mat@openerp.com-20130408101940-syg67y7nx3hw12gg
2013-04-08 12:19:40 +02:00
Martin Trigaux 750a3ae2b6 [IMP] better security rules
bzr revid: mat@openerp.com-20130405073205-gfcolcdv3oomlo0z
2013-04-05 09:32:05 +02:00
Martin Trigaux 57c1ad67fe [REF] cleaning code
bzr revid: mat@openerp.com-20130404152359-3x3gt9xhkrkr0au4
2013-04-04 17:23:59 +02:00
Martin Trigaux a3c5009a7a [ADD] autostart discover plan
bzr revid: mat@openerp.com-20130329163137-l6e45b0qj89yfm5c
2013-03-29 17:31:37 +01:00
Martin Trigaux 8731c49b69 [FIX] every employee is a goal_user
bzr revid: mat@openerp.com-20130319100035-le3qkcbi35lf95r5
2013-03-19 11:00:35 +01:00
Martin Trigaux c39be93667 [IMP] small changes
bzr revid: mat@openerp.com-20130314142439-04espxwt7049xzz5
2013-03-14 15:24:39 +01:00
Martin Trigaux 9f05370cfc [IMP] remove useless rule auth and better domain
bzr revid: mat@openerp.com-20130314120157-ac8nygcm2p11xu48
2013-03-14 13:01:57 +01:00
Martin Trigaux df917d317f [ADD] add security rule for badges
bzr revid: mat@openerp.com-20130314110529-pl65an41ds08sazb
2013-03-14 12:05:29 +01:00
Martin Trigaux 95c244d35a [ADD] gamification: security rules
bzr revid: mat@openerp.com-20130313095154-b5wi1ohu0wo6hz5w
2013-03-13 10:51:54 +01:00