Commit Graph
64 Commits
Author SHA1 Message Date
std-odoo 83e22fd063 [IMP] portal: improve the "grant access wizard" usability
Purpose
=======
Improve the "grant access wizard" usability, allow to re-invite the
partners and grant / access per partner and not in batch.

Specifications
==============
Add 3 buttons to grant / revoke the access and to re-invite the partner.
When the partner has an internal user linked, do not allow to manage
him in the view (disable the button) because we do not want to remove
the "internal user group" in the wizard, but only the "portal user
group".

When we revoke the access to a partner, if the corresponding user
belong only to the portal group, we archive it instead of deleting it.
So if we re-grant the portal access, he will have the same user as
before and keep his preference, etc.

Task 2381921

closes odoo/odoo#63024

Related: odoo/upgrade#2011
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-02-18 08:37:04 +00:00
Xavier Morel ee1b67d607 [IMP] portal: /my/security page
* allows portal users to update their password
* and manage their API keys
* any anything technical / security related we may need to add in the
  future

Also bridge module for the password meter (auth password policy).
2020-08-14 23:06:11 +00:00
Yannick Tivisse d360c49a5a [IMP] portal: Adapt tests to work with/without demo data 2019-11-05 13:08:04 +01:00
Sébastien Theys 3620cb68a0 [FIX] mail, portal, account: clean up portal attachment
Follow up of 61de1c263a

- Remove the dangerous **kw from the route in favor of specifying useful args.

- Use the existing method to link attachments to message instead of duplicating
the logic in an incomplete manner.

- Fix an issue where the actual email would not be sent if the message was empty
but an attachment was defined.

- Ensure the send attempt is done immediately instead of after the cr commit.
The goal is to show potential error messages correctly to the user with the
crash manager instead of a generic error page.

This also increases the send timeout and prevents the error in the first
place in most situations.

closes odoo/odoo#35263

Signed-off-by: Christophe Simonis <chs@odoo.com>
2019-08-12 16:27:00 +00:00
Pratima GuptaandSébastien Theys 61de1c263a [IMP] portal: allow attachment upload from portal chatter
Before this commit, it was only possible to add attachments on documents from
the backend or by sending them by email.

It is now possible to add them also from the portal chatter, including for
portal/public users who have a valid access_token.

Part of task-37264

closes odoo/odoo#34526

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>


Co-authored-by: Pratima Gupta <pgu@odoo.com>
Co-authored-by: Sébastien Theys <seb@odoo.com>
2019-07-24 12:30:31 +00:00
Sébastien Theys df7326f0be [IMP] tests, *: add start_tour helper
Before this commit, the syntax to start a tour was extremely verbose.
With this new method, it is possible to start a tour by just giving the
essential parameter: the tour name.
The full set of features from browser_js are kept by using **kwargs.

closes odoo/odoo#32316

Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2019-04-04 08:44:59 +00:00
Christophe Monniez b356b19033 [IMP] tests: Add the possibility to tag tests
Purpose: When running tests, all the tests for the installed/updated
files are done. This commit adds a 'tagged' decorator that can be used to
tag tests. Combined with a new 'test-tags' CLI option, it adds the ability
to filter which tests are executed. For example, @tagged('slow') will
add a tag 'slow' to the test. The CLI option 'test-tags="slow"' will
only run tests tagged 'slow'.

One can use prefixes to select cases with tags.
'+' or no prefix means that the tests tagged with this tag are selected
for execution. '-' prefix will exclude the tests tagged with this tag.
Exclusion takes precedence over inclusion.

Also, by default, all Odoo tests cases are tagged 'standard' and with
the technical name of the module.
This means that when selecting tests with the 'test-tags'
parameter, if '-standard' is not specified, all tests tags are
going to be executed.
When tagging tests, one can remove such automatic tag by prefixing the
tag name with '-'. E.g. @tagged('-standard') will remove the standard
tag from the test.

Another example, if one wants to test the 'sale' module alone,
even without adding any 'tagged' decorator thos tests can be selected
like that: --test-tags="sale"

Tests are selected or deselected using a TagsSelector. When instanciated,
 a string is passed with comma separated tests selectors like
'+slow,-standard'. When the 'check' method is called  with a test as argument,
it returns True or False if the test has to be executed or not.
2018-01-18 13:20:37 +01:00
Thibault Delavallée ee4cf1eae3 [MOV] website_portal: move mail portal tests directly to mail
Those belong to mail, not website_portal.
2017-08-08 15:05:11 +02:00
Thibault Delavallée ea27c1b7a3 [MOV] website_portal, portal: move customer portal to portal module
This commit moves the whole customer portal to the portal module.
It now completely uses portal and http_routing features and is not
dependent on website anymore.

An override of web controller is added in portal in order to redirect
portal users to /my instead of /web. That way once having the customer
portal installed all share users are correctly redirected to their
account.

All modules defining customer portal templates and controllers are
updated accordingly.
2017-08-08 14:58:49 +02:00
Jérome Maes 2b4eeb908f [MOV] portal,website_portal: move wizard and tests into website_portal
The goal is to prepare the removal of
'portal' module.

Converting a partner into a portal user,
though the wizard is moved in website_portal.

'base' will manage portal user and group, but if
website_portal is not installed, there is nothing
to display for portal user.
2017-03-23 09:59:58 +01:00
Thibault Delavallée 927fbe8845 [IMP] mail: make tests less dependent on mail.channel model
Currently almost all mail tests run on mail.channel model. Indeed it is
the only model inheriting from mail.thread and mail.alias when having only
mail installed. However channel model have several specific features and
is not totally a standard mail.thread model. For example notification
recipients are computed a bit differently.

Since 4f9105a4ef mail module has a test
model allowing to perform tests on a very simple mail.thread-like model.
This commit make mail tests use this test model instead of mail.channel
everywhere it is possible. Channel model should be used only when tests
are channel-dependent.
2017-02-21 16:41:14 +01:00
Raphael Collet 0783318f97 [FIX] adapt logger names 2016-09-02 17:28:13 +02:00
Rutul Raval a9d11f1175 [MIG] portal : migration to new api 2016-05-31 14:16:58 +02:00
Thibault Delavallée 01ab75f597 [IMP] mail: notification emails with button
Notification emails have been redesigned. They notably include buttons
allowing to perform some action directly from the email.

The notification creation and sending has been partially rewritten
and improved. The purpose is to lessen the number of rendering to perform
when sending emails to recipients. Recipients are first categorized into
groups. Basic groups are partners and users. The notification template
is then rendered twice, one for followers and one for not-followers. In most
cases there will be few rendering to perform. Through inheritance it
is possible to further categorize users. For example HR users / officers
that have approve / refuse buttons in their email.

A custom data structure is used to store data about buttons and actions.
URLs, follow / unfollow are added in the structure and used in the
template to render the email for a given group.

New routes are added in mail. Those allow to perform some action, like
going to a form in create mode, following / unfollowing, executing a method,
sending a signal for a workflow. Those routes are for users only and rely
on classic access rights.

A generic route for viewing records is added. It replaces the old redirect
action. According to some specific action given by the already-existing
get_access_action, the record will be visible for everybody (forum, blog)
or restricted (going on the Inbox / login / form view, according to access
rights).

The next commit will add the various inherits necessary to add the actions
in the main addons.
2015-08-28 17:30:42 +02:00
Thibault Delavallée c02982b4c4 [REF] mail: mail_channel update
Some features from live_chat have been moved to the mail module :
- channels now have members, replacing followers;
- a decorated m2m is used to link channels and members. It stores the last
seen message on the channel for a specific partner;
- channels do not create menu entries anymore, because the
NewChatter will have its own display and use of channels;
- access rights have been updated accordingly, using members instead of
followers
2015-08-21 12:11:56 +02:00
Thibault Delavallée e6f038a821 [REF] mail: mail_thread: followers update
Followers can now be partners or channels. Partners following a document
will receive needaction, as previously. However people can follow documents
through channels. Members of a channel are able to listen to a stream
of messages using the channel. Those messages do not create needaction
messages. It is therefore possible to follow documents without receiving
too much notifications. For interesting documents subscribing with its
partner will create notification.

message_follower_ids fields is udpated. It is now a many2many to
mail.followers, not to res.partner anymore. A subscription can be either
a partner (partner_id) or a channel (channel_id).

Some access rules have been updated accordingly.
2015-08-21 12:11:56 +02:00
Thibault Delavallée d52bf613d6 [CLEAN] mail: tests: reduce a bit the boilerplate of tests to lessen
the testing time.
2015-07-09 11:13:03 +02:00
Thibault Delavallée d931aa3825 [RENAME] mail, portal: updated actions and views xml ids
for channel-related stuff. mail.channel views as well as timeline views
and actions have been renamed. Now the names follow the guidelines and
will be used in the upcoming refactoring of mail and chat.
2015-07-09 11:13:02 +02:00
Thibault Delavallée 2c36354ca9 [RENAME] mail, website_mail, website_mail_group, various: mail.group
model has been renamed to mail.channel to prepare the slack modeling.

In future commits the mail.group model will be merged with the channel
model from im_chat. The first move is to rename mail.group into
mail.channel to have a model that will unite both features.
2015-07-09 11:12:50 +02:00
Thibault Delavallée 9cd9aaaa17 [IMP] mail: new internal-only subtype feature.
Starting from now, subtypes can be internal. This means that only employees
(group_user members) can see the messages with this subtype. This feature
replaces and enhances the 'log a note = no subtype = internal only'
feature.

Public and portal users cannot see internal messages. This allows to have
subtypes and a follow mechanism that works for employees and is not
visible for external people.

Its first use will be for Crm Activities, allowing to have custom
subtypes visible only for salesman and not send to the customer.
2015-07-01 12:52:52 +02:00
Valerie Pirenne c24332e6da [IMP][ADD] mail, various: timeline view.
This commit introduces a new view type, the timeline view. This view is
intended to display messages like the previous chatter. This is now a view
like the form or list view. Like other views it will be possible to have
custom templates for some specific needs, allowing customization.

[IMP] mail: the value tracking is modified. Previously messages were created
containing the modified values. Those values are now stored, using a new
model mail.tracking.value. The message body is dynamically build based on
the values. Tests have been updated.

This version is temporary. Indeed two main modifications will come in a short
future :

 - the new design will improve the display
 - the slack mode will change the way the Inbox and notifications are managed

All glory to the Hypnotoad.

Special thanks to Valerie Pirenne (vpi), Jerome Maes (jem) and Richat Mathot
(rim) that did not code but said a lot of things. Martin Trigaux (mat) did
nothing, a bit like for the slides modules, but he is busy sending emails.
2015-05-21 12:10:25 +02:00
Thibault Delavallée 9d3a5ec72a [IMP][FIX] mail: tests: updated mute loggers (moved files) + added loggers were necessary. 2015-05-19 16:05:32 +02:00
Thibault Delavallée 4b122ad41d [MIGR] mail: migration to the new API 2015-04-27 10:36:15 +02:00
Jignesh Rathod b55969a577 [REF] mail: migrated tests to the new API and refactored them.
Tests have been migrated to the new api to prepare the migration of the
mail module itself. Moreover tests have been cleaned: redundant tests
and unnecessary tests have been removed.

As the base test class in mail is used in other addons, other addons
have been updated :
- portal
- project
- portal_project
- website_project_issue
- sale
- purchase

Future commits will come with somes fixes for issues detected when cleaning
the tests.
2015-03-24 10:18:16 +01:00
Christophe Simonis 18e22be138 [MERGE] forward port of branch 8.0 up to 0aab81c 2015-01-19 17:15:56 +01:00
Goffin Simon 0fd773a486 [IMP] Cleanup and refactoring of exception handling
Unify and refactor exception handling in framework and addons.

The generic `except_osv` is now deprecated, and replaced by more specialized exception subtypes:
 - `UserError` (renamed from Warning, as it conflicts with the built-in `Warning`) raised when a non-technical error occurs during a business operation. It could be a missing information in the data provided by the user, or a misconfiguration.
 - `AccessError`: raised when any operation is denied because the user conducting it does not have the required access rights.
 - `AccessDenied`: raised when an operation that requires authenticated access is attempted via an unauthenticated request.
 - `MissingError`: raised when an operation is attempted on a record that does not exist.
 - `ValidationError`: raised when an operation violates a SQL or Python constraint.
 - All other exceptions are internal errors due to a system problem or bug, and raised untouched to the client-side, which should display a traceback.

All exceptions take a single message argument.

The `test_exceptions` module has been updated to showcase both new and old (deprecated) exceptions.

A great many old `except_osv` had a useless title with "Error!" or "Warning", those have been removed, as this is handled by the client-side widget that displays the messages.

This commit introduces a more consistent policy for logging errors and warnings:
 - All messages that do not require administrator attention should be logged at INFO level or lower. This includes all errors that are notified to the user in a friendly manner, even for access right problems or validation errors during business operations.
 - All messages that indicate a likely misconfiguration or malicious use by the users should be logged at WARNING level, as they typically require administrator attention.
 - All other unhandled internal errors cannot typically be handled by the user and should be logged at ERROR or higher level, as they require immediate administrator attention.
2015-01-16 17:15:18 +01:00
Xavier Morel 65cd4a2a33 [FIX] remove deprecated checks/fast_suite test attributes from standard modules 2015-01-15 14:31:40 +01:00
Leonardo Donelli 4a0b13ed92 [REF] remove vim modelines and resulting trailing blank lines
Let 2015 be a year without modelines!
cf #4174
2014-12-31 15:52:13 +01:00
Thibault Delavallée 2e5412fc1d [FIX] mail, BaseModel, portal_sale: fixes and improvements in the URL
management to access documents in notification emails, as well as for the
'view quotation' link in portal_sale module.

models: added a get_access_action method: basically, returns the action to
access a document. It uses the get_formview_action by default (form view
of the document). However for some documents we want to directly go to the
website, leading to an act_url action for some documents. This method allows
this behavior.

portal_sale: get_signup_url now uses the mail.action_mail_redirect method
instead of directly redirecting towards a portal menu. This allows to fall
back on a standard behavior.

portal_sale: get_formview_action updated, to match actions tailored for
portal users.

website_quote: get_access_action of sale order updated. If the sale order
has a template defined, the returned action is an act_url (website view
of the quotation), not the form action anymore.

mail: fixed signature + company signature in notification emails. Even without
user signature, the company signature + access link should be correct.

portal: signup url in notification emali was not using the mail redirection
as action. It is now the case.
2014-08-07 16:47:59 +02:00
Raphael Collet cbe2dbb672 [MERGE] new v8 api by rco
A squashed merge is required as the conversion of the apiculture branch from
bzr to git was not correctly done. The git history contains irrelevant blobs
and commits. This branch brings a lot of changes and fixes, too many to list
exhaustively.

- New orm api, objects are now used instead of ids
- Environements to encapsulates cr uid context while maintaining backward compatibility
- Field compute attribute is a new object oriented way to define function fields
- Shared browse record cache
- New onchange protocol
- Optional copy flag on fields
- Documentation update
- Dead code cleanup
- Lots of fixes
2014-07-06 17:05:41 +02:00
Fabien Meghazi 13504b180e [FIX] Broken portal test
bzr revid: fme@openerp.com-20140319173204-8a93hww2clvw3ljy
2014-03-19 18:32:04 +01:00
Thibault Delavallée d10f471019 [FIX] [TESTS] mail, portal: fixed tests, because the error raised by the OROM has changed in some cases.
bzr revid: tde@openerp.com-20131206121432-mz2jpj535tmcmftl
2013-12-06 13:14:32 +01:00
Christophe Matthieu fd2821086f [MERGE] sync with trunk
bzr revid: chm@openerp.com-20131202150925-eqsi0uu0fqtwimhj
2013-12-02 16:09:25 +01:00
Olivier Dony 44664076da [MERGE] Forward-port of latest 7.0 fixes up to rev 9618 rev-id: dle@openerp.com-20131120142131-s333lyva85cyn41o
bzr revid: odo@openerp.com-20131120144059-yyh7emvgdarff09b
bzr revid: odo@openerp.com-20131120144318-11nmn1zj00zmi10z
2013-11-20 15:43:18 +01:00
Olivier Dony 2a209aa75d [FIX] portal: mail access right test is not totally accurate
The access right test expect an exception
to be raised when accessing any of the
followers, but this is not 100% correct,
as the test user (Chell) should be able to
read her own record.
This worked by chance because the ORM
prefetching was triggering an access error
whenever any follower was accessed, but
this was a bug, now fixed in server at
rev-id odo@openerp.com-20131119153700-5sbo2cl13vvqsgz5
revno 5136

bzr revid: odo@openerp.com-20131119175658-1nv5c9iwfizkrasc
2013-11-19 18:56:58 +01:00
Thibault Delavallée 5bb4fa2b43 [MERGE] Sync with trunk
bzr revid: tde@openerp.com-20131028163321-5o81wa1m7rzdp1dz
2013-10-28 17:33:21 +01:00
Denis Ledoux d15798786a [FIX]project_issue: add onchange_partner_id which was inherited before with base_stage, but the inheritance has been removed
bzr revid: dle@openerp.com-20131017121013-mtzvjogi2hxgfcpq
2013-10-17 14:10:13 +02:00
Thibault Delavallée e541755ae4 [MOV] portal: moved portal group into base.
Updated security rules. Basic res_partner rules are moved into base. Added rule with website_published.

bzr revid: tde@openerp.com-20131008113545-gpqydx0b199lcqpy
2013-10-08 13:35:45 +02:00
Thibault Delavallée b35a44f66d [IMP] mail_mail, mail_message: various improvements to try to improve message creation time
Replaced some read by browse
Moved get_reply_to from mail_mail to mail_message
Hint: specifying email_from, reply_to help to enhance computation time

[REF] mail: cleaned some tests, renamed a file, moved mail_group tests into a dedicated file

bzr revid: tde@openerp.com-20130827133058-ko0g0ib0f0jihmdk
2013-08-27 15:30:58 +02:00
Thibault Delavallée cd278d83ab [MERGE] Sync with trunk
bzr revid: tde@openerp.com-20130522103305-yi5ql1chdx9qxxlx
bzr revid: tde@openerp.com-20130522114236-qi2s3i2dl2lemdvh
2013-05-22 13:42:36 +02:00
Thibault Delavallée a05b0bebbe [FORWARD] Forward port of 7.0 branch until revision 9143.
bzr revid: tde@openerp.com-20130521122359-b5vii7gv8arluz06
2013-05-21 14:23:59 +02:00
Thibault Delavallée 18ad74bef3 [FIX] portal: mail_message: fixed wrong condition for check_access_rule introduced at revision 9117. Added tests by the way.
bzr revid: tde@openerp.com-20130514113859-3yucygu3pkav7qbt
2013-05-14 13:38:59 +02:00
Thibault Delavallée 8beab22311 [IMP] mail_message for portal users: actually only comment without subtype are not shown (internal notes).
bzr revid: tde@openerp.com-20130514104521-e8pbgvgn2xtmyr5o
2013-05-14 12:45:21 +02:00
Thibault Delavallée b61c12d28e [MERGE] Revisions 9000 ... 9002 of 7.0 branch
bzr revid: tde@openerp.com-20130426132847-mr8e0yuxao582bs6
2013-04-26 15:28:47 +02:00
Thibault Delavallée 4387187b8b [IMP] mail: invite: slighty updated invite message. Updated tests accordingly.
bzr revid: tde@openerp.com-20130315110554-rszi5u1c9dybzq46
2013-03-15 12:05:54 +01:00
Christophe Matthieu aaf7949b42 [FIX] portal: mail_fallowers invite
bzr revid: chm@openerp.com-20130305130228-0ebmc26lbd9s6c4t
2013-03-05 14:02:28 +01:00
Christophe Matthieu a3d22b6b71 [FIX] portal mail invite: add send_mail inside test
bzr revid: chm@openerp.com-20130227151349-ioxe034seo68i14x
2013-02-27 16:13:49 +01:00
Thibault Delavallée 347d0e5b46 [IMP] portal removed access rights of portal user on res_partner and derived tables. Updated several accesses to bypass the security issues. Updated portal tests to have a more complete test scenario.
bzr revid: tde@openerp.com-20121212125518-k0s07niojr8a1xtu
2012-12-12 13:55:18 +01:00
Thibault Delavallée db32d98b7a [REF] [TESTS] mail, portal: refactored a bit the various mail and invite tests: moved some tests into dedicated files, added some new tests, removed duplicates.
bzr revid: tde@openerp.com-20121211144650-kpy7noe082e3xvoo
2012-12-11 15:46:50 +01:00
Vo Minh Thu 724f452f1e [IMP] fleet/porta/account_budget: removed some initialization warnings.
bzr revid: vmt@openerp.com-20121115160643-lc0b07n6xiaq1rl3
2012-11-15 17:06:43 +01:00