Commit Graph
6 Commits
Author SHA1 Message Date
Patrick Hoste d9247094c2 [FIX] rating: fix search on rating
Fix the access error you could get when filtering on ratings when not logged
in or when the user has no rights to access ratings.

How to reproduce: filter on channel review ratings in eLearning frontend
when being anonymous le portal.

As rating is a technical model, we have to first retrieve messages linked
to that rating value and afterwards return a new domain used to build
the final search.

Task ID : 2167776
PR : #42847

closes odoo/odoo#44380

X-original-commit: 7a241e9c21046dababc2744dd94b0c47e2d8a931
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2020-01-31 12:38:33 +00:00
ryv-odoo c7a1a2d964 [REF] rating, various: improve rating.rating ACLs
PURPOSE

Rating model should be available only for internal users. External users
access them only through dedicated routes or controllers using sudo and/or
granting access through tokens. Therefore simplifying ACLs should be feasible.

SPECIFICATIONS

Remove access to rating.rating for public and portal users. Only employees
can access it, with full access given to system admins.

Update various functional flows to use sudo() and check that access is
verified before using sudo.

Impacted modules

  * rating / mail: add groups on some rating related fields as only
    internal users should access them now;
  * rating / mail: set some statistics fields using compute_sudo as their
    value should be accessible for external people even without access to
    the underlying rating.rating records;
  * project: makes some use of rating and has to be updated, notably for
    the public rating page;
  * website_{livechat, rating, slides}: add sudo in public routes as access
    is already granted;
  * website_slides: set statistics field using compute_sudo as their
    value should be accessible for external people;

TASK ID 2053096
PR #36592

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2019-11-19 15:46:51 +00:00
Adrian Torres 4b38cc6590 [REM] *: calls to @api.multi
Multi is the default api for methods, it is not necessary to explicitly
decorate methods with it, adds clutter and most people use it because
they see that the rest of the code uses it.

Done with `find . -type f -name '*.py' | xargs sed -i '/@api.multi/d'`
2019-07-17 14:13:12 +02:00
Nans Lefebvre cb9466cf9c [FIX] rating: add search method on non-stored rating attribute
Commit f727e9d9b6 made the rating field
of mail.message non-stored for performance reasons.
When the rating is activated on the website, it adds the possibility to filter
product reviews by rating (1 to 5 stars).
It does so by searching the messages that have a given rating value.
However the osv complains that you can't search on a non-stored field.
As a result, instead of displaying messages filtered by ratings,
it would always display all of them.

We add a search='_search_rating_value' on the field to allow that field to be
searched anyway.

opw 1931038

closes odoo/odoo#30499
2019-01-24 07:09:00 +00:00
Thibault Delavallée f727e9d9b6 [REF] rating: avoid storing rating_value on mail.message
Currently the rating value coming from the rating application is stored
on the message it belongs to. However storing it is not necessary as
there is no direct search using it. Having a computed field is sufficient
for all use cases we currently have in Odoo.

Removing the store allow to gain queries. Indeed the field is not
computed anymore after each message creation meaning we save queries
by not having to check existing ratings. It allows to gain a lot of
computation as mail.message is a critical model.

On the whole community runbot when installing all modules this leads to
a gain of more than 14K queries on 585K which means 2.4% of performances
increase. Considering the code size of this optimization this is quite an
interesting result.

Looking at test_mail performance tests we gain several queries (2/3) for
each new message which is coherent with the model change.

Finally it allows to lessen the performance difference between tests done
with test mail only and tests done with other modules already installed.
This is especially simple mail thread-enable records.

Related to task ID 51523. #Closes #23294. Done with blessing of @jem-odoo .
2018-02-26 16:58:35 +01:00
Jérome Maes f447e9679f [IMP] rating: message_post with rating value
rating module provide now post a message with a
rating value, though `message_post` method.
'mail.message' also has now a `rating_value` field
to ease searching and filtering.

This will help the ecommerce (and other website modules)
to post a comment associate with a rating.
2017-06-30 11:06:32 +02:00