Commit Graph
44 Commits
Author SHA1 Message Date
Kevin Baptiste 278f5a6995 [IMP] hr_expense: show confirmation on duplicate expenses
Display a confirmation dialog when a user creates duplicate expenses.

Two expenses (or more) are considered duplicates when they share the same
date, amount, product, employee, company and currency.

closes odoo/odoo#64190

Taskid: 2368636
Related: odoo/upgrade#2061
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2021-03-04 12:54:34 +00:00
Laurent Smet b25e53a0b9 [IMP] hr_expense(_check): Remove the custom register payment expense wizard
- Use the one defined in the account module allowing paying multiple journal entries
and group payments together.
- Remove the hr_expense_check module that contains only duplicated features regarding the
register payment wizard.

--task: 2273528
2020-08-12 12:30:43 +00:00
Florent de Labarre b6fc5ef468 [FIX] hr_expense: Team Approver have acces to all accounting
1. Apply same logic for sale and purchase user.
2. The group Expense Team Approuver can write/create/unlink,
it is opposite than https://github.com/odoo/odoo/blob/13.0/addons/hr_expense/security/ir.model.access.csv#L15
and https://github.com/odoo/odoo/blob/13.0/addons/hr_expense/security/ir.model.access.csv#L16

opw:2275116

closes odoo/odoo#53405

Signed-off-by: Simon Goffin (sig) <sig@openerp.com>
2020-06-22 11:23:34 +00:00
Aurélien (avd) 7e5ae026fd [FIX] hr_expense: Apply miscellaneous fixes
closes odoo/odoo#53834

Taskid: 2229597
X-original-commit: cc125a1fe850941a7bf1cec2cd0392fdf025a60a
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2020-06-29 18:51:25 +00:00
Victor Feyens 066214b36b [IMP] *: remove duplicate ACL targeting same group/model.
In the same xml file (meaning one of the two rule is useless, or wrong
if giving less rights than the other).

Removing rules that had no impact will ease the understanding of
security problems, by reducing the number of interconnecting rules.
2020-03-27 09:55:33 +01:00
Martin Trigaux 65530dfd6a [ADD] *: add ir.model.access on all transient models
Following changes needing ir.model.access on transient models too.
Remove groups declaration on the action to move it to ir.model.access
when possible.
Rules are strict by default with no unlink access by default and high
priviledge asked. Adaptations may be needed later.
Write access is given as a wizard may need to be modified in case the
action triggers an error and the user has to correct a value

account*: use account.group_account_user for all transient by default
	  remove account.print.journal relic
stock*: use stock.group_stock_user by default
survey: survey user can send invitations
mail: allow any employee to execute wizards
      additional verifications are made to ensure they are executed
      only on the documents the user has access to you
      give portal access to mail.compose.message as portal still does
      some actions like posting messages on the forum
      add ir.rule to avoid reading somebody else messages
      increase the query count because of undeterminist count
crm: saleman for lead2opp, manager for massmailing
     partner manager for actions linked to partners
     avoid a write in test_lead_lost
sms: any employee can send sms
mrp: mrp user can execute wizards
     give unlink access as making write during do_produce operation
base_import: employees can import files
delivery: stock user can deliver
event_sale: sale user can configure the wizards
	    event user inherit from  sale rights
gamification: employee can give badge
google_service: resolve FIXME
hr: add specific rights
    manager can set a plan according to group on button
    anyone who can write on an employee can register a departure
hr_expense: set rights based on buttons
hr_holidays: an approver can make a summary report
hr_recruitment: recruiter can refuse a candidate
hr_timesheet: can use the wizard if can create a timesheet
l10n_eu_service: managers can create fiscal positions
mass_mailing: same group as on mass.mailing.list
membership: accountant can create invoice from membership
payment: accountant can create a link
	 as the source is an account.move
	 keep the payment.acquirer.onboarding.wizard to system user
	 only as it is called during company configuration
point_of_sale: PoS manager only can use wizards
	       never create closing_balance_confirm_wizard records
product_expiry: stock user has rights on stock.picking
product_margin: access from accounting menus
repair: same rules as for above models
sale: set ir.rule for self wizard only
      add rule from model introduced in payment to add salesman group
sale_crm: saleman can create a quotation from a lead
sale_coupon: any saleman can generate coupon
	     add self ir.rule
sale_product_configurator: salesman can select product variants
snailmail: employee can send letters
website: designers can write on website
website_crm_partner_assign: same rule as group on action
website_sale: sale ACL as for payment.acquirer.onboarding.wizard
website_slides: anyone can send invitation

base: base.language.*: allow employee (cf lang_install)
      change.password.user: can not read change password wizard of
      other users
      test.*: no access is needed

Courtesy of Damien Bouvy, William Andre and Antoine Prieëls for review
of acl
2020-02-04 17:54:18 +01:00
Laurent Smet bc131c0cfb [MERGE] manual forward port of accounting-pocalypse (beaa30a3d1)
This commit merges the following models
 * account.invoice and account.move
 * account.invoice.line and account.move.line
 * account.voucher and account.move
 * account.voucher.line and account.move.line

It was the opportunity for a big cleanup of the code, so it also restructures the whole account module, its different models/fields, the tests etc. for a better world and a better code readability.

==== Rationale ====
The rationale of this huge change is that we want journal entries / invoices to be easily edited, and changes reflected in the other model. It's a HUGE feature and very strategic for the fiduciary companies. For example, changing the account of a journal entry needs to be automatically reflected on the related invoice.

The same reasoning applies to sale/purchase vouchers.

==== Changes made in features =====
When creating an invoice, you are now creating a journal entry directly.
--> The object account.invoice no longer exists.
In the same fashion when creating an invoice line, you're now adding journal items directly in the journal entry representing the invoice. If this invoice line has some tax, it may create additional journal items as well.
--> The models account.invoice.line & account.invoice.tax no longer exist

Identically, when creating a sale/purchase receipt with its lines, you are now creating a journal entry directly and there's no more usability difference between encoding a receipt or an invoice.
--> The object account.voucher no longer exists.
--> The object account.voucher.line no longer exists.
--> The whole account_voucher module no longer exists.

Positive side-effects coming from these changes are
* draft invoices/bills/sale or purchase receipts now create a draft accounting entry. Validate these objects now simply post its journal entry. That means that draft invoices/bills/sale or purchase receipt can straightforwardly be included in reporting or budgets.
* opening a journal entry in form view will now always open the correct view: if it's a sale/purchase journal entry we will have a customer invoice/vendor bill view or a sale/purchase receipt view, whatever the menu we're coming from.
* code & business logic simplification. It is also condensed in a single place instead of being partially duplicated on invoices, vouchers and journal entries.

There should be no feature loss, except the one allowing to group multiple journal items together based on the same product during the invoice validation.

==== Changes made in models =====
* account.invoice: model removed. Instead, now use account.move with following mapping

field (account.invoice) 		field (account.move)
-----------------------			--------------------
name 					invoice_payment_ref
number 					name
reference 				ref
comment 				narration
user_id 				invoice_user_id
amount_					total_company_signed amount_total_signed
residual 				amount_residual
state 					state + invoice_payment_state 		/!\ selection changed
date_invoice 				invoice_date
date_due 				invoice_date_due
sent 					invoice_sent
origin 					invoice_origin
payment_term_id 			invoice_payment_term_id
partner_bank_id 			invoice_partner_bank_id
incoterm_id 				invoice_incoterm_id
vendor_bill_id 				invoice_vendor_bill_id
source_email 				invoice_source_email
vendor_display_name 			invoice_vendor_display_name
invoice_icon 				invoice_vendor_icon
cash_rounding_id 			invoice_cash_rounding_id
sequence_number_next 			invoice_sequence_number_next
sequence_number_next_prefix 		invoice_sequence_number_next_prefix

'invoices' subset of account.move can be accessed by using the selection field 'type' or one of the many helpers like is_invoice()

* account.move: now has a valid state 'cancel' that has to be excluded from all business logic
* account.move: field 'amount' renamed into 'amount_total'
* account.move: field 'reverse_entry_id' renamed into 'reversed_entry_id'
* account.move.line: now has a field 'display_type' that has to be excluded from all business logic, in order to support invoice layouting
* account.invoice.line: model removed. Instead, now use account.move.line with following mapping

field (account.invoice.line) 		field (account.move.line)
----------------------------		-------------------------
invoice_id 				move_id
uom_id 					product_uom_id
invoice_line_tax_ids 			tax_ids
account_analytic_id 			analytic_account_id

'invoice lines' subset of all account.move.line from a journal entry can be accessed by using the boolean field 'exclude_from_invoice_tab'

* account.invoice.tax: model removed. Instead, now use account.move.line with following mapping

field (account.invoice.tax) 		field (account.move.line)
---------------------------		-------------------------
invoice_id 				move_id
account_analytic_id 			analytic_account_id
amount 					price_unit
base 					tax_base_amount

'tax lines' subset of all account.move.line from a journal entry can be accessed by using the relational field 'tax_line_id'

* account.invoice.confirm: model removed. Instead, now use the 'post()' function of account.move
* account.invoice.refund: model removed. Instead, now use account.move.reversal to reverse the entries with the same options as we had for invoices
* account.voucher: model removed. Instead, now use account.move of type in ['out_receipt', 'in_receipt]
* account.voucher.line: model removed. Instead, now use account.move.line

==== Changes made in functions ====
* on account.move, method _run_post_draft_to_post() renamed into _autopost_draft_entries()
* on account.move, method action_account_invoice_payment() renamed into action_invoice_register_payment()
* on account.move, method action_invoice_reconcile_to_check() renamed into action_open_matching_suspense_moves()
* on account.move, method _get_domain_edition_mode_available() renamed into _get_domain_matching_supsense_moves()
* on account.move, method _get_intrastat_country_id() renamed into _get_invoice_intrastat_country_id()
* on account.move.line, method _get_domain_for_edition_mode() renamed into _get_suspense_moves_domain()
* in account.bank.statement, contextual key 'edition_mode' renamed into 'suspense_moves_mode'

Was task 1917430
2019-07-01 13:45:57 +02:00
jbm-odoo ec07e72845 [IMP] base,*: Reorganize access rights groups
Purpose
=======

Access group terminology is missleading. Yous have to be manager to administrate
an application. This task consists to rename groups to be understandable for everyone.

Groups should be reorganised on the users form to be more explicit.

Specification
=============

1/ Rename 'Manager' to 'Administrator' in users groups.
2/ Define a hierarchy on access groups by using the category_id in the manifests
   A category 'Operations/Project' will create a category Project with a parent
   category 'Operations', and something smart is already developed (in modules/db.py)
   to avoid duplicating categories.
3/ Add a group in expenses to be able to approve expenses reports for my team.
4/ Add a group in timesheets to be able to approve timesheets for my team.
5/ Remove partially the useless crap in ir_module_category_data.xml
6/ Sort access rights groups on users form according to its parent category

closes odoo/odoo#29362

Signed-off-by: "Yannick Tivisse (yti)" <yti@odoo.com>
2019-03-05 09:08:12 +00:00
RomainLibert 631891dc5d [IMP] hr_expense: add draft state to expense lines
We need to be able to change an expense report before submitting it, for
this we add a new step in the expense process (a draft state for the
expense sheets).

Task #41700
Closes #24806
2018-06-07 13:55:06 +02:00
RomainLibert 5c24368e33 [IMP] hr_expense : improve access rights of manager/officer
Currently the distinction between expense officers and expense managers
doesn't make sense because they both have the same rights.

This commit aims at making a clear difference between an officer and a
manager.

After this commit the rights will look like this :

  * Expense Manager :
  	- See and approve any expense

  * Expense Officer :
  	- Can see and approve the expenses of employees in his department
	  or employees for which he is the manager (field parent_id on
	  hr_employee)

	- Cannot approve his own expenses

  * Simple user :
  	- Can only see his own expenses

	- Can only send his expenses to a manager (either the manager of
	  his department, his direct manager [parent_id field] or an
	  expense manager)

Related to task #51520
Closes #23033
2018-05-25 11:52:17 +02:00
Thibault Delavallée bdb0d128b7 [FIX] hr_expense: limit activity type creation to expense managers
Expense users should not be able to create activity types. This is limited to
managers like in other applications allowing to create activity types.
2018-04-20 17:56:32 +02:00
Thibault Delavallée 133fd0a21e [IMP] hr_expense: improve activity management on expense sheet model
This commit improves expense flow management through a better integration
of activities and addition of automated activities. Several things are done
in this commit :

 * expense sheet (report) model do not inherit from mail.activity.mixin.
   This commit adds the inherit so that expense users and managers can now
   schedule and manage activities on expense reports. This will help them
   in their daily job;
 * automatic activities generation is added for expense reports. Activities
   are generated for approval. They are also automatically set as done when
   validating or unlinked when refusing or resetting to avoid bloating users
   with unnecessary activities;
 * a menu to configure activity types is added. Indeed HR managers should be
   able to see and configure activity types related to their job;
 * filters are added to be able to use the systray and to filter the kanban
   view based on activities

Having automated activities allow to replace some messages and tracking
that were implemented to warn people of expense reports to approve.
This commit therefore

 * simplifies the tracking as tracking to confirm reports is not necessary
   anymore;
 * removes to approve subtype on report model as well as its parent subtype
   on the department. This allows to simplify chatter in hr_expense app;
2018-03-27 15:19:34 +02:00
XavierDo 2966d4faed [IMP] product: rename product.uom into uom.uom
Also rename product.uom.categ into uom.category to
 give it a decent name.
2018-02-26 14:27:26 +01:00
XavierDo 6a378e3839 [IMP] product: move uom in a new addon
Moves UoM models, test and data to a new addon in
order to be able to use uom without product.
A simple example is be to be able to use UoM for
timesheets.

This commit only move code, and adapt xml ids
without chaging any feature or functionnal
behavior.
Note: 'product' module now depends on new
'uom' module.
2018-02-26 14:27:26 +01:00
Yannick Tivisse 7fa2691175 [IMP] hr_*: Split the HR access rights by application
PURPOSE
=======

For each and every Hr application there should be one user category (One app = one category).

SPECIFICATION
=============

HR remains as it is : Employee, Officer, Manager

Each Application should have 2 access rights: User and Manager. Example for Recruitment:
- The user has access to the recruitment process
- The manager has access to the job position configuration

Each Application should grant the employee user access right (Namely the 'HR Officer')
2016-09-06 14:35:09 +02:00
Martin Trigaux 11812b0b9e [FIX] all: remove external ids fakely from base
Several modules defines records with the external ID `base.foo_bar` while it is
created inside this module (typically menus and groups).
While there is no technical reasons to do so but this may introduce issues:

- these records will not be deleted during uninstall
- if a language is loaded before the installation of the module, it won't be
  translated

The uninstallation will only remove the records with an external id linked to
this module (these would only be removed when removing base).

Installing a language before the module will drop the translations not linked
to an existing external id (as it can not be resolved).

This commit correct all the external ids tagged as from base or other incorrect
modules.
2016-09-02 16:14:26 +02:00
Yannick Tivisse 717f9217bb [IMP] hr_expense: bring back the sheets + other new features
NB:
- The option no_delete is not working, a fix will come from chm
- The many2many widget on a sheet creation is not working correctly as
  the called command is a (1, id, values) without a (4, id, _) before.
  A fix will also come from chm, but a disgusting hack has been
  provided for this particular case (to remove after chm fix)
2016-06-17 12:14:57 +02:00
Fabien Pinckaers c665c1efa6 [FIX] removed old security rule 2015-09-05 16:35:14 +02:00
Foram Katharotiya 52d72e61de [MERGE] hr_expense: module rewritten for more easiness and a better usability. Concept of expense sheet removed. Was PR #7387. 2015-09-04 17:23:19 +02:00
qdp-odoo e4dc50bf58 [IMP] pricelists improvements. Was PR #8228 2015-08-31 16:57:32 +02:00
Nicolas Martinelli e021a08b30 [IMP] hr*: adaptation due to the new Sale module
Major changes:
- No use of UoS anymore
- No journal since invoicing is managed in Sale
- No invoicing from timesheet

Reason: complete rewrite of the Sale module.

Responsible: fp, dbo, nim
2015-08-27 18:10:18 +02:00
qdp-odoo c04065abd8 [IMP] accounting v9. Yeeeeaah 2015-05-05 17:28:04 +02:00
cod-odoo a301b4c7fc [MOVE] account: moved account/project files to analytic or account, depending on which module the moved code belongs to. This allows to remove references to project in account module. Also added some improvements in project when deleting a project (delete account if void) or when deleting an account (delete project if void). 2014-08-04 13:23:46 +02:00
Denis Ledoux dle@openerp.com 7e1ffaf613 [REM]Remove all account.journal.view and account.journal.column references
bzr revid: dle@openerp.com-20121122104504-ezgj2666zkhgybpj
2012-11-22 11:45:04 +01:00
Fabien Pinckaers 5c4348f7fe [FIX] HR useability improvements
bzr revid: fp@openerp.com-20121010192927-6ud5e3zvhp5gabip
2012-10-10 21:29:27 +02:00
Ajay Chauhan (OpenERP) 77d4347f4a [IMP] hr_expense: made access_rule to create expense as a employee
bzr revid: cha@tinyerp.com-20120926125325-xshc34cau22qnc40
2012-09-26 18:23:25 +05:30
Fabien Pinckaers f27318c8af [IMP] Security Rule: removed duplicates due to inheritancies of groups
bzr revid: fp@tinyerp.com-20111212181113-mhnnbps3ip8ls6pp
2011-12-12 19:11:13 +01:00
François Degrave a8a2183a77 [IMP] HR access rights
bzr revid: fde@openerp.com-20101230122428-wqsf7qcck7rasbfp
2010-12-30 13:24:28 +01:00
François Degrave 50cf154537 [IMP] HR employee dashboard in webclient
bzr revid: fde@openerp.com-20101229143849-03lpmdpu5fkc6e86
2010-12-29 15:38:49 +01:00
Harry (OpenERP) 20ab1d1df4 [FIX] account: security
bzr revid: hmo@tinyerp.com-20101229085716-y13ctpn3ptenrfl0
2010-12-29 14:27:16 +05:30
AMP (OpenERP) 1c251e2f10 [MOD/IMP] hr_expense : Usability Improvement in groups nad access rights
bzr revid: amp@tinyerp.com-20101022085331-qqvd1wj9io4y3di1
2010-10-22 14:23:31 +05:30
DBR (OpenERP) 389a623545 [MOD/IMP] hr_* : Usability Improvement in Accessrights
bzr revid: dbr@tinyerp.com-20101007071157-z52414z1sz9h85qh
2010-10-07 12:41:57 +05:30
DBR (OpenERP) a3efd4f1a0 [MOD/IMP] hr_expence : Usability Improvement in Accessrights
bzr revid: dbr@tinyerp.com-20101006125128-85urgfc27zuhvcx7
2010-10-06 18:21:28 +05:30
AMP (OpenERP) 3076f2e33a [MOD]hr_*: usability improvement in access rights
bzr revid: amp@tinyerp.com-20100913131824-1au2kx7na9czsh4z
2010-09-13 18:48:24 +05:30
AMP (OpenERP) 0a8c9772b6 [MOD]hr_* : usability improvement in employee access rights
bzr revid: amp@tinyerp.com-20100906063006-gcuxdswiunwokvn4
2010-09-06 12:00:06 +05:30
AMP (OpenERP) 1d15f71146 [MOD] project_timesheet,hr_* : usability improvement in access rights
bzr revid: amp@tinyerp.com-20100901132905-hslnywxf4zxogxdo
2010-09-01 18:59:05 +05:30
AMP(Open ERP) aff16ab9a5 [MOD/IMP] hr_* : Improvement in access rights
bzr revid: vir@tinyerp.com-20100813133645-w8nex9k1he2zjq9h
2010-08-13 19:06:45 +05:30
DBR (OpenERP) 9261375e2e [MOD/IMP]hr_* modules access right changes
bzr revid: dbr@tinyerp.com-20100804085628-58nplf4yw8zp80dj
2010-08-04 14:26:28 +05:30
DBR (OpenERP) a446dfb18e [MOD] hr_* :Improvement in hr_* modules groups and accessright
bzr revid: dbr@tinyerp.com-20100803131117-jkvf2a7pe955en2u
2010-08-03 18:41:17 +05:30
AMP (OpenERP) 6eb86abda3 [MOD] usability improvement in access rights
bzr revid: amp@tinyerp.com-20100723072243-kpex4cdgckhga46d
2010-07-23 12:52:43 +05:30
Rvo (Open ERP) 5fd39ca156 [ADD]: access rights for osv_memory and osv_osv objects
bzr revid: rvo@tinyerp.co.in-20100421111435-v4u8cemnfir19kh0
2010-04-21 16:44:35 +05:30
Christophe Simonis 123a99c39a fix access rules
bzr revid: christophe@tinyerp.com-20081021153441-af1qtobtazu7rs28
2008-10-21 17:34:41 +02:00
Fabien Pinckaers 51f8c2b263 Better Security Rules
bzr revid: fp@tinyerp.com-20080903224650-u1oadqv9x75atmyl
2008-09-04 00:46:50 +02:00
Fabien Pinckaers b4d6690794 Improved Security
bzr revid: fp@tinyerp.com-20080903180400-df7l6wxg1zpirmmi
2008-09-03 20:04:00 +02:00