Commit Graph
21 Commits
Author SHA1 Message Date
Florent de Labarre b6fc5ef468 [FIX] hr_expense: Team Approver have acces to all accounting
1. Apply same logic for sale and purchase user.
2. The group Expense Team Approuver can write/create/unlink,
it is opposite than https://github.com/odoo/odoo/blob/13.0/addons/hr_expense/security/ir.model.access.csv#L15
and https://github.com/odoo/odoo/blob/13.0/addons/hr_expense/security/ir.model.access.csv#L16

opw:2275116

closes odoo/odoo#53405

Signed-off-by: Simon Goffin (sig) <sig@openerp.com>
2020-06-22 11:23:34 +00:00
Victor Feyens a3ded9043d [IMP] *: declare ir.rule in noupdate
ir.rule are default values but can be customized based on the
company's policy and needs.
This is typically a record that is in noupdate as should be
customization-friendly.
2020-03-20 16:21:25 +01:00
Yannick Tivisse a5b6f31cf2 [IMP] base: Contextualize the multi company
Purpose
=======

Allow the user to select the allowed companies for which he wants to see records
on top of selecting his current company.

It is confusing for users to see the records from the company he is connected to
and the records of the children companies.

Instead of using the hierarchy of companies to access records across companies,
the user can now select (from his set of allowed companies) the companies for
which he wants to access records.

/!\ This means that the user will interact with records from company A when in
company B.
Example: a SO has been created and confirmed in A. When in B, I create the
invoice from it.

Specifications
==============

1/ Deprecate the parent/children hierarchy on the res.company model. The fields are
kept on the res.company model to ensure the retro-compatibility, but won't be used
accross the standard code anymore. The only functional usage for this mechanism
was to allow to see records from several companies by creating a virtual parent
company, which will be possible with the new mechanism.

2/ By default, a user will only see the records of the company he is connected
to (or records without a company). (It is still editable by the user if needed).
For that, put this information in the user context, to allow having different
configurations on different browser tabs. Instead of having domains like
['|',
('company_id', '=', False),
('company_id', 'child_of', user.company_id.id)]
you'll have something like
['|',
('company_id', '=', False),
('company_id', 'in', company_ids)]
Note that the 'company_ids' is a value that is passed in the evaluation
context on the record rule, as we already have user, or time.
company_ids is a list of the ids of all the enabled companies in the
user's context.

3/ Out of the generic improvements brought by this task, this will illustrate
issues that could exist since several versions. For example, it should not be
possible to create a scrap order for the company A with a package of the company
B, or it should not be possible to create an invoice on the company A with
payment terms from the company B. Before the version 12.0, it was easy to
encounter this kind of issues as the admin was the SUPERUSER_ID. A positive side
effect of the fact that the SUPERUSER_ID has become an inactive user was to
make it more difficult to introduce mismatch on the records, but haven't solved
the issue, as it was still possible to do it with parent companies
configuration. Some of these issues have been fixed in this commit, but all the
business flows should be re-tested to check if an ir.rule should be introduced
(eg: a multi company rule for stock.quand.package), if the company of a record
is correctly transfered to another record created from the first record (eg:
From a SO, create an invoice and a payment, the company of the sales order
should be transfered on the invoice and the payment, even if the company of the
sales order is A and I'm logged into the company B with the company A enabled.

4/ Currently, if I click on a button on a notification email (example 'View
Task'), I face a traceback if I'm not logged into the company of the record.
Now, if you click on a button and if you have access to the record, the correct
company will be automatically set.

5/ If I display a kanban view with several records from several companies (and
an image), all the images should be displayed.

6/ Currently if you copy paste an url, this will crash if you're not in the
correct company. This won't be fixed because it's quite impossible to do it in
a clean way. This task brings a workaround. Copy/Paste -> Traceback -> Log into
the correct company, re-copy/paste -> Ok.

7/ 2 property methods have been added on the environment to retrieve the company
on which the user is logged in and the companies the user enabled, on a specific
tab.
That way, when creating a record, instead of doing
default=lambda self: self.env.user.company_id
do
default=lambda self: self.env.company_id
On the other hand, to retrieve the enabled companies, do
companies = self.env.company_ids

8/ Modify the Company Switcher widget to allow to log into another company
WITHOUT writing on the res.users (and thus bringing cache invalidation issues
and so on). Also allow to enable several companies and see records from several
companies, and independantly of the other browser's tabs.

9/ When focusing on a tab, save the current company configuration on the local
storage. That way, when doing 'CTRL+T' or a middle click, the context is
propagated to the new tab.

10/ Improve the error message in case of multi company access errors. Now, when
the user is in debug mode, display the related names of the records and the name
of the user who brings the issue.

11/ Remove the context erasing when writing on a res.users
This is probably coming from the migration to new API of the base module.
The context was not propagated at this moment, which was a common mistake at
that time. When migrating the module, probably by using the 'black box' method,
as the context was not propagated, it was erased on the new version. This is
now an issue because the context (i.e. the enabled companies) was erased when
writing on a res.users, leading to tracebacks.
See: https://github.com/odoo/odoo/commit/7eab8e26d3d46c53f4be924d6a34e80a66e74960#diff-4c2e738ee8f64f11806c889ea097b5e7R624

12/ Fix the crash manager on redirect warnings. The issue is the following
- Create an invoice on a company without a configured CoA.
- Set a partner
- On the onchange_partner_id, a redirect warning is raised to propose you
to configure a CoA
- Click on 'Go to the configuration panel'
- A generic warning says something like 'Do you want to discard your changes?'
- Click on yes, the page refreshes, but not on the redirect action.
Now, set correctly the action on the hash, and reload instead. The breadcrumb is
lost for example, but you reach the correct action at least.

13/ Introduce a res.group to enable/disable the multi company per tab
feature.

14/ To help the users to know which tab is in which company, add the
possibility to have a favicon per company. When creating a company,
the classical 'O' icon is colored by default in a random color.

15/ Remove the company switcher on the frontend. This was mainly there
to allow a user to swicth to the company linked to the website.
This behavior is now transparent to the user. If the website A is
activated, then the company set on the context is the company of the
website.

16/ Deprecated the _company_default_get method on the res.company
model. Remove the method _get_company on the res.users model.

17/ Add 'allowed_company_ids' and 'current_company_id' on the pyeval
context. You can now use those variables on domains in the views to
access directly to the activated company.ies on the current tab.

TaskID: 1960971

closes odoo/odoo#32341

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-05-13 08:57:49 +00:00
jbm-odoo ec07e72845 [IMP] base,*: Reorganize access rights groups
Purpose
=======

Access group terminology is missleading. Yous have to be manager to administrate
an application. This task consists to rename groups to be understandable for everyone.

Groups should be reorganised on the users form to be more explicit.

Specification
=============

1/ Rename 'Manager' to 'Administrator' in users groups.
2/ Define a hierarchy on access groups by using the category_id in the manifests
   A category 'Operations/Project' will create a category Project with a parent
   category 'Operations', and something smart is already developed (in modules/db.py)
   to avoid duplicating categories.
3/ Add a group in expenses to be able to approve expenses reports for my team.
4/ Add a group in timesheets to be able to approve timesheets for my team.
5/ Remove partially the useless crap in ir_module_category_data.xml
6/ Sort access rights groups on users form according to its parent category

closes odoo/odoo#29362

Signed-off-by: "Yannick Tivisse (yti)" <yti@odoo.com>
2019-03-05 09:08:12 +00:00
RomainLibert 5c24368e33 [IMP] hr_expense : improve access rights of manager/officer
Currently the distinction between expense officers and expense managers
doesn't make sense because they both have the same rights.

This commit aims at making a clear difference between an officer and a
manager.

After this commit the rights will look like this :

  * Expense Manager :
  	- See and approve any expense

  * Expense Officer :
  	- Can see and approve the expenses of employees in his department
	  or employees for which he is the manager (field parent_id on
	  hr_employee)

	- Cannot approve his own expenses

  * Simple user :
  	- Can only see his own expenses

	- Can only send his expenses to a manager (either the manager of
	  his department, his direct manager [parent_id field] or an
	  expense manager)

Related to task #51520
Closes #23033
2018-05-25 11:52:17 +02:00
Christophe Simonis d5382abeaa [MERGE] forward port branch saas-17 up to b8dd34fcbb 2017-09-06 17:40:59 +02:00
Nicolas Martinelli 5d1dafbf9b [FIX] hr_expense: prevent deletion of posted expense
Prevent the deletion of expense or expense sheet if they are linked to a
journal entry.

Closes #19128
Closes #19044

opw-767549
2017-09-04 08:22:40 +02:00
d-fence c030213fa3 [IMP] hr_expense: Allow a user to refuse an expense sheet from a line
Purpose
=======

Currently, a manager or a accountant can only refuse one expense report with a justification message.

If there are a lot of lines too comment individually or if only one line should be modified, the manager or the accountant can now refused one line and give a reason for it. That will refused the expense report automatically while waiting the employee to make the modifications.

Specification
=============

- Rename wizard files, models and ids according to the model

- Allow to refuse one or several lines with a reason

- Use a qweb template to log messages, use message_post_with_view instead of message_post

- Print expense name instead of sheet name. In the log when expense is refused, it prints expense report name instead of expense

- Prevent modifying approved expenses
	* A user should not be able to modify an expense once approved
	* Method refuse_expense renamed to refuse_sheet when applied to a whole
	expense report/sheet
	* 'model' dict key renamed to something more explicit and less prone to
	confusion (passed in context to the refuse wizard)
	* Usage of explicit fields in the wizard to avoid confusion
	* Overriding 'default_get' to get default values for those fields

- When an expense is paid or reported, it must be impossible to refuse it.

- Replace refused expenses tree
	Purpose: The menu 'Refused expenses' is confusing. This improvement
	replaces it by 'Refused Reports' and leads to the refused reports tree
	view. That way, it's easier for the user to find back his refused
	expenses reports.

- Hide create button on refused
2017-09-01 15:30:30 +02:00
Nicolas Martinelli c478e94450 [FIX] hr_expense: delete expense
A regular employee is allowed to delete an expense reported already
approved. This should not be possible, only an officer could do it.

Fixes #19044
opw-767549
2017-08-28 13:30:10 +02:00
Goffin Simon 8eb759dcff [FIX] hr_expense: Multi company rule for hr.expense.sheet
To apply to multi company rule on hr.expense.sheet
Inspired from Expense multi company rule

opw:709834
2017-03-07 13:51:02 +01:00
Yannick Tivisse 7fa2691175 [IMP] hr_*: Split the HR access rights by application
PURPOSE
=======

For each and every Hr application there should be one user category (One app = one category).

SPECIFICATION
=============

HR remains as it is : Employee, Officer, Manager

Each Application should have 2 access rights: User and Manager. Example for Recruitment:
- The user has access to the recruitment process
- The manager has access to the job position configuration

Each Application should grant the employee user access right (Namely the 'HR Officer')
2016-09-06 14:35:09 +02:00
Martin Trigaux 11812b0b9e [FIX] all: remove external ids fakely from base
Several modules defines records with the external ID `base.foo_bar` while it is
created inside this module (typically menus and groups).
While there is no technical reasons to do so but this may introduce issues:

- these records will not be deleted during uninstall
- if a language is loaded before the installation of the module, it won't be
  translated

The uninstallation will only remove the records with an external id linked to
this module (these would only be removed when removing base).

Installing a language before the module will drop the translations not linked
to an existing external id (as it can not be resolved).

This commit correct all the external ids tagged as from base or other incorrect
modules.
2016-09-02 16:14:26 +02:00
Foram Katharotiya 52d72e61de [MERGE] hr_expense: module rewritten for more easiness and a better usability. Concept of expense sheet removed. Was PR #7387. 2015-09-04 17:23:19 +02:00
Xavier Morel 7a2d912964 [REM] bunch of nonsensical @model + @ref
bzr revid: xmo@openerp.com-20130429124333-p1h11fpy04y3sljy
2013-04-29 14:43:33 +02:00
Ujjvala Collins (OpenERP) 060b488478 [FIX] hr_xxx: Improved record rules for HR Officer to give him rights to see timesheet, attendance, expense and holidays of other users.
lp bug: https://launchpad.net/bugs/856422 fixed

bzr revid: uco@tinyerp.com-20110929092802-ohpa8xt6at02h449
2011-09-29 14:58:02 +05:30
mtr 5bac583ce7 [FIX] analytic,hr,hr_evaluation,hr_expense,hr_recruitment: added multi-company access rules
lp bug: https://launchpad.net/bugs/788139 fixed

bzr revid: mtr@mtr-20110608072935-blig6ejq1oa36un5
2011-06-08 12:59:35 +05:30
Mustufa Rangwala 2f09faba42 [MERGE] an employee shouldn't be able to see expenses and holidays of others employee
bzr revid: mra@mra-laptop-20110117102556-evp00eqczxuy5l5z
2011-01-17 15:55:56 +05:30
mtr 028530f9eb [FIX] hr_attendance,hr_expense,hr_holidays: added 'ir.rule' for group 'Employee'
lp bug: https://launchpad.net/bugs/702805 fixed

bzr revid: mtr@mtr-20110117084537-jrsy3wg68io8z8e8
2011-01-17 14:15:37 +05:30
husen f433b959c2 merged with trunk
bzr revid: husen@husen-laptop-20101230095809-cl6dkve1odgdtqtv
2010-12-30 15:28:09 +05:30
Fabien Pinckaers 1b69a14e74 fixes
bzr revid: fp@tinyerp.com-20101018143305-mw79ewcj4q0t8t17
2010-10-18 16:33:05 +02:00
Fabien Pinckaers 37680303df [IMP] ir.rule reviewed
bzr revid: fp@tinyerp.com-20101018092840-7a6wv2vw2s6a1a2s
2010-10-18 11:28:40 +02:00