Commit Graph
56 Commits
Author SHA1 Message Date
William Braeckman 3d10c7c708 [IMP] project,*: improve project UX
* = hr_timesheet, sale_project, test_main_flows

Smaller changes:
 - Projects created on the fly (through `name_create`) will now come with a
   default `new` stage in order for them to not be empty.
 - Removed task auto assign upon creation besides in FSM's 'My tasks' menu.
 - Allow the reordering of projects without needing to group by
   anything.
 - Make `project.task`.`description` and `project.tags`.`name`
   translatable.
 - Disable the creation of records in the view when clicking on `Tasks
   in recurrence` stat button.
 - Track the planned date of the task in the chatter
 - Disable the creation of records in the view when clicking on
   'invoices' stat button and add the kanban view to that action.
 - Make milestones completely available to regular project users.
 - Remove the 'Documents' button in the project's kanban settings menu.
 - Add kanban, pivot and graph views to the 'Hours Recorded' stat button
   on projects
 - Add the calendar view on the 'Hours Forecast' stat button on projects
 - The 'Sales Orders' stat button on the `project.project`'s form view
   will now display the amount of sales order linked to the whole
   project. So the one linked to the project itself if it exists + all
   the tasks. It will also open them, form view if 1 else list view.
 - Fix a typo in the settings 'projets' => 'projects'
 - The analytic account  of the project will now be assigned to the
   sales order when a task is created through the 'Create a task in an
   existing project' option.

Changed the portal task view to include a sidebar similar to sales
orders, with a simple menu leading to different parts of the screen.

Changed the `project.task` 'rating' stat button:
 - The icon will now represent the latest review.
 - The action will directly lead to the record's form view if there is
   only 1 rating.
 - Make some fields readonly in the form view.
 - Display the % of satisfaction instead of the number of ratings.

Reorder all stat buttons on the `project.task` form view in this order:
 - Products, Worksheet, Sales Order(s), Invoices, Ratings, Hours
   Forecast, Parent Task, Tasks in recurrence, Tickets, Quotations and
   lastly Customer Preview

Make the status of the project editable directly through the kanban
view. A new widget has been added to handle that properly. When editing
the status through that means, a `project.update` will be created with
the current date and the appropriate status. In addition to that a new
status has been added (only on `project.task`, not `project.status`)
namely `to_define` in order to differentiate new and running projects.
Projects now start with the `to_define` status.

The `project.project`'s  rating stat button has been changed in the
following ways:
 - The icon will now change in function of the satisfaction percentage,
   smile above 66%, meh between 33% and 66% and frown below 33%.
 - The color will also change depending on the rate, smile is green, meh
   is orange and frown is red.
 - The ratings will now be in function of the last 30 days instead of
   all time and the action will also filter on those 30 days.
 - Change the action name from 'Rating' to 'Ratings'.

`project.project` ticket stat button:
 - Will now open the form view when there is only one record.
 - Added the activity view.
 - Disable the creation of new records.
 - Rename the action to 'Tickets'.

Closes: odoo/odoo#75269

See: odoo/enterprise#20334

Task ID: 2611006

Signed-off-by: Laurent Stukkens (ltu) <ltu@odoo.com>
2021-10-28 15:27:36 +00:00
Xavier BOL (xbo) 1e71ba3995 [FIX] project: access error when internal user is in project sharing form view
Before this commit, when the internal user is not follower of the
project and enter in the project sharing feature. If he wants to see the
form view of a task, he cannot and have a Session expired error.
This issue arrives because in the chatter we check is the user is a
follower of the project shared.

This commit fixes this issue by just using the _document_check_access
method to check if the user can access to the document. Indeed, we don't
need to check if user is a follower because the _document_check_access
does it with the `ir.rules`.

Related PR: #73341

Part of task-2633229

closes #76098
2021-09-07 17:03:05 +00:00
Priyanka KakadiyaandXavier BOL ebf163c6a4 [IMP] hr_timesheet, portal, {sale_}project: few improvements for portal
PURPOSE

Generic UX improvements for the portal

SPECIFICATIONS

For projects list view,

- clicking on the project should open the list view of tasks with groupby stage
- the number of tasks should not be clickable

For tasks list view,

- display the fa-star of the priority field on the left of the name of the task
- add the following fields on the right of the name:
  user_id, time spent, kanban_state
- for the kanban_state,
  only display the colored dot and indicate the name of the state on hover
- for the time spent:
  indicate the nb of hours recorded / nb of planned hours(or days(as per unit))
  (if the nb of planned hours = 0, only display the nb of hours recorded)

For tasks search view,

- add a group by priority and status and reorder accordingly
- add a quick search on status and priority and reorder accordingly
- add a sort by priority, assigned to and status and reorder accordingly

For task form view,

- display the fa-star icon of the priority field on the left of the name of task
- add the kanban state in the top right corner

the kanban_state field should be editable by portal users
increase nb of items displayed in the list view to 80 items per page(generic)

Task-2613330

closes odoo/odoo#74996

Signed-off-by: LTU-Odoo <IT-Ideas@users.noreply.github.com>
Co-authored-by: Xavier BOL (xbo) <xbo@odoo.com>
2021-09-03 15:45:24 +00:00
Xavier BOL (xbo) 7fd05a3864 [IMP] project: review content in '/my/project/<id>' route
Before this commit, this route displayed the portal form view of the
project. This view does not seem useful for the external user and prefer
directly see the tasks of this project.

This commit replaces the portal form view of the project by the tasks
list containing in the project. Moreover, another route has been added
to allow the external user to go to the portal form view of the task
selected in ths list.
This route is called '/my/project/<project_id>/task/<task_id>'.

We decide to replace the content of the route because we want to allow
the public user to access to the tasks list of the project with the
access_token of the project. Also, with this same token, the public
could access to the form view of the selected task and send a message if
he needs.

task-2379518

closes #73341
2021-08-26 16:57:23 +02:00
Xavier BOL (xbo) a28cc6333a [REV] project: select access rights in project sharing
This reverts commit fc7778f8c512202dc3361d6b87be8c28b299c3c8 because of
a change in the spec.
The access mode are removed and replaced by this access mode for portal
user:
- read: the user goes to the classic portal view
- edit: the user is added as collaborator of the shared project and can
access to project sharing views.

To do this, the portal share is inherited by the project share wizard.
This new wizard can be open to share in readonly and open to share in
edit mode via 2 buttons in the form view of the shared project.
A new stat button is added to form view of project to see the
collaborators of this project. That is, the ones can access to the
project sharing views. The project manager will can remove or also add
new collaborators via the views in this stat button.

task-2379518

closes #73341
2021-08-26 16:57:23 +02:00
Xavier BOL (xbo) 19a8bf9527 [IMP] project: check portal user can access to project sharing chatter
Before this commit, when we change the access right to the portal user
and this user is in task form view with chatter. He can send message
even we remove the access right.

This commit checks if the user has the access before sending the
message.

task-2379518
2021-08-26 14:59:33 +02:00
Xavier BOL (xbo) a60aaa3910 [IMP] project: use project sharings in portal route
Before this commit, when the portal user can access to project sharing
and click on the shared link of the project. He is redirected to the
`/project_sharing/<int:project_id>` route. Since only the portal user
can access and no public users, we could directly redirect to the portal
route and display project sharing views.

This commit removes the `/project_sharing/<int:project_id>` route.
The main route will always be the `/my/project/<int:project_id>` and
we check if the user can access project before rendering.

If the user can access to the project via the shared link:

1. If he is a public user then we render the classic portal view.
2. If he is a portal user then
    - we check if he is an access to project sharing, if yes then we
      render project sharing views otherwise we display the classic
      portal views.

task-2379518

closes #73341
2021-08-26 14:59:33 +02:00
Xavier BOL (xbo)andYannick Tivisse 5ea5ddafea [IMP] project: select access rights in project sharing
Before this commit, when the portal user can access to project sharing
views, he can just read. If we just add ir.rule to allow the edition,
the portal could create/edit. We have to allow the project manager to
define the access rights of portal users when he want to share them a
project with the project sharing feature.

This commit adds 3 access modes portal users in project sharing views.
1. **Readonly**: the portal can only see the tasks in the different views.
2. **Comment**: the portal can use the chatter in task form view.
3. **Edit**: the portal user can create and edit tasks.

task-2379518

closes #73341

Co-Authored-by: Yannick Tivisse (yti) <yti@odoo.com>
2021-08-26 14:59:33 +02:00
Xavier BOL (xbo) 0c7b99987a [IMP] project,portal: allow portal user not follow task to use chatter
Before this commit, if the portal user is a follower of the project he
can use the chatter of new tasks in the project sharing feature since
the follower of the project is automatically the follower of new tasks.
But if he is not a follower of the task (for instance, old task in the
project) then we have to check if the
access token is the one of the shared project to give the access to
the chatter.

This commit checks the `access_token` of the project when we are in the
project sharing form view to allow the portal user to use the chatter.

task-2379518

closes #73341

Co-authored: Yannick Tivisse (yti) <yti@odoo.com>
2021-08-26 14:59:33 +02:00
Xavier BOL (xbo) 2bbb038f22 [IMP] project: replace the basic portal views when project selected
Before this commit, when the portal user is connected and selects a project
in the list when he is in `/my/projects` route, we redirect him in the
task list of this project.

This commit replaces the basic portal view by the project sharing views
if the Project Sharing feature is enabled for this project.

task-2379518

closes #73341
2021-08-26 14:59:33 +02:00
Xavier BOL (xbo) e50bc12002 [IMP] project: add Project Sharing feature
Purpose:
=======

This commit adds the project sharing feature. This feature consists to
share the backend views about project.task to portal users.

About the access rights:
- The project manager can share a project with project sharing feature.
  To do this, he need to give access to portal users that we want their access in project sharing views.
  He can choose between 3 differents accesses:
    1. Readonly: the portal with this access right will only have read access to the project
        sharing views of the project shared.
    2. Comment: the portal with this access right will can use the chatter in task form view.
    3. Edit: the portal with this access right will can edit some fields of `project.task` model.

The difference between the classic backend views and the project sharing
views is in the project sharing views, we list the fields that the user
can read/write, so the portal users can see only the fields in
our list.
Moreover, the actions and the contextual menu (actions dropdown) are not
available in the project sharing views and the stat buttons are visible
but the click on these buttons are disabled.

Implementation details:
======================

This commit is realized in many steps:

- create the webclient and routes.
- create own qweb bundle.
- add project sharing views.
- use the session to define the action and active_id
- create public fields for project sharing: in this step, we lists all field
names of the `project.task` model that we want to display for the
portal user. Two lists are created, one for only readable field names
and the other one for the writable field names.
Moreover, two properties are defined in the `project.task` model to use the
both lists.
- use `access_token` and check model in project sharing route: in this
step we check if the model is `project.project` and the `access_token`
is the one set in the project since we have the id of the project in the
params url.
- allow only `GET` method to enter project_sharing routes: the
`/my/project/<int:project_id>/project_sharing` route must only be
called with a `GET` method because this route is only used to have the template
to render the project sharing webclient.

task-2379518

closes #73341
2021-08-26 14:59:32 +02:00
Cedric Prieels (cpr) 3bcb88f410 [IMP] {hr_,sale_}timesheet,{sale_}project: improve the tasks portal
Generic UX improvements for the task portal.
Added new sort by, group by and searches options in the tasks portal.
Some options have been renamed as well, while the style has been slightly revised.
The timesheet details of each sub-task from the parent form view has also been removed.

task-2508883

closes odoo/odoo#70305

Related: odoo/upgrade#2580
Signed-off-by: LTU-Odoo <IT-Ideas@users.noreply.github.com>
2021-06-24 15:39:40 +00:00
Xavier Morel c7002c7be7 [FIX] portal: de-t-raw-ify
As part of that, also mark one of the searchbar_inputs label as markup-safe.
2021-04-29 05:34:21 +00:00
Adrian Torres b7017e58cc [FIX] *: adapt business code to function-redefined error
This commit adapts the business code in which
class/module/function/method redefinition took place so that it no
longer happens and the pylint test passes.
2020-10-16 12:56:52 +00:00
Victor Feyens 2da7bc2adb [REM] portal, *: remove archive_groups dead code
PURPOSE

Clean code and be and more performance oriented.

SPECIFICATIONS

Various portal pages hold references to archive_groups. It was a summary
of customer documents for portal, containing a count of all documents split
by model.

Currently its computation is not used. Indeed archive_groups is displayed
only in 'my_details' page that does not hold any document-based reference
or code call. Other calls to archive_groups are dead code as the result is
not used. Since 13.0 it is even not computed on standard pages to speedup
their load (as it was not used).

It is not used anymore and its computation and references can be removed
safely, especially with v14 in mind for which we want to remove dead code
to maintain.

Followup of odoo/odoo#55228

LINKS

Task ID-2329081
PR odoo/odoo#55800
PR #12368

closes odoo/odoo#56859

X-original-commit: e75086000ee4317b2ad2994db5d906fbcbd5081f
Related: odoo/enterprise#12830
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2020-09-01 10:30:32 +00:00
Andrea Grazioso (agr-odoo) eda684fc61 [FIX] portal,project: allow other company users to correctly access my/tasks page
In multi-company configuration setup, Company A and Company B.
Have a project in Company A that I want to share with a user in
Company B. The user only has access to Company B.
Share using the project link and open using the user

Traceback error will raise.

Adding a default value to retrieve in case the filter option is used
but the user has no permissions on the records.

opw-2322236

closes odoo/odoo#57090

X-original-commit: bcb62e8f6e20bccc2f2350bdc1268c495b7103da
Signed-off-by: agr-odoo <agr-odoo@users.noreply.github.com>
2020-09-04 13:54:45 +00:00
Jeremy Kersten 73b4e9b1b6 [IMP] portal,*: /my counter async
Before this commit, the time to compute all counters was making the rendering
of the portal page slow.

Now the count is done in rpc after the loading of the page.

Now you can decide which part you want to show on the portal, and only compute
for these one.

It is not because you have purchase installed for your internal process, that
it means that your supplier use your portal and it avoid the computation for
all end users.

We parallelize the counters in arbitrary 3 rpcs.

closes odoo/odoo#55999

Related: odoo/enterprise#12456
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2020-08-17 15:59:03 +00:00
Victor Feyens 71f3fa991c [IMP] *: disable unused archive_groups feature in portal
The archive groups feature allows the user to have fast access to
records of a given month, under its details information.

But since the details section isn't shown anymore on portal sub-pages,
the feature is computed for nothing on (most) pages.
Removing this computation avoids a read_group call on portal subpages
(multiple potential queries).

This commit disables the feature until a total removal in master.
my_details is only truthy on the /my/account portal page, where no
archive_groups is given anyway (and the value is set to True only in the
rendered tempate itself).

X-original-commit: 40c57fafdd5651a522891ab68affe38933ea5202
2020-08-03 07:23:30 +00:00
Victor Feyens 34fb9f3159 [IMP] portal,*: do not compute record counts for portal subpages.
The record counts are only useful for the badges displayed in /my &
/my/home.
By avoiding those counts on subpages, we gain a lot of useless queries,
improving the loading speed of those sub-pages.

X-original-commit: 79c8384f1bcbcdede030e187008319a70c664571
2020-08-03 07:23:29 +00:00
Benjamin Frantzen (bfr) e4a4ffb974 [IMP] customer ratings flow improvements
- Rename the 'Use Rating on Project' feature into 'Customer Ratings'
- Rename the 'Set Email Template to Stages' link to 'Set a Rating Email Template on Stages'
- Add an optional list view for the Stages menu
- display warning if the rating_template_id field is set and if one of the selected project_ids doesn't have the rating_status field set to true
- Project form view revamp
- rename the '% on tasks' stat button into 'Customer Satisfaction'
- Remove the 'no option' for the rating frequency field because it is required
- project form : Add a 'Go to Website' stat button
- Project dashboard: remove the 'Customer Ratings' menu item in more
- Ratings page: the 'Last 30 days' filter include ratings from today
- remove the Appointment / Helpdesk Customer Satisfaction / Live Support menu items

TASK ID : 1251
2020-05-08 12:17:20 +00:00
Nicolas Lempereur 525e3626be [FIX] project: access to portal task give access to attachment
If a visitor has access to a task through access_token, he should have
access to the task attachments. He already see the list of attachment
and their name, but since the task access_token is not propagated to the
attachment he doesn't have the rights to see them.

In this PR, we generate the attachments access_token and provide them to
the user that is viewing a task with an access_token.

opw-2125252
closes #41881

closes odoo/odoo#42121

X-original-commit: e7984c4968cde2019edca6c767d2acce2f7fe3f4
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2019-12-17 17:27:26 +00:00
laa 9cfb6c05a4 [FIX] Portal : missing url args
on the portal:
- in Timesheets, when search something, the text of the search must remain displayed
- in Tasks, when search something, the text of the search must remain displayed
- in Purchase Orders, "Sort By" and "Filter By" selectors shouldn't change when going to next page
- in Timesheets, the "Group By" selector shouldn't change when going to next page

closes odoo/odoo#40278

Related: odoo/enterprise#6787
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-11-28 15:39:03 +00:00
laa cbc93d0d11 [IMP] project: Add a group by stage for tasks on the portal
A group by stage on the portal would allow the customer to have an overview of his tasks' progress, which is especially useful in a multi-project setting.

- add a "Project" column
- rearrange columns in the order: Ref -> Task -> Project -> Stage

- add a group by stage for Tasks on the portal
- hide "Stage" column when group by stage is selected
- hide "Project" column when group by project is selected

- add a sort by project for Tasks on the portal
- when sort by Stage sub-sort by Project
- when sort by Project sub-sort by Stage

- add a 'Search in Project' for Tasks on the portal

- the "Group By" selector shouldn't change when going to next pages
2019-11-28 09:54:12 +00:00
ryv-odoo c7a1a2d964 [REF] rating, various: improve rating.rating ACLs
PURPOSE

Rating model should be available only for internal users. External users
access them only through dedicated routes or controllers using sudo and/or
granting access through tokens. Therefore simplifying ACLs should be feasible.

SPECIFICATIONS

Remove access to rating.rating for public and portal users. Only employees
can access it, with full access given to system admins.

Update various functional flows to use sudo() and check that access is
verified before using sudo.

Impacted modules

  * rating / mail: add groups on some rating related fields as only
    internal users should access them now;
  * rating / mail: set some statistics fields using compute_sudo as their
    value should be accessible for external people even without access to
    the underlying rating.rating records;
  * project: makes some use of rating and has to be updated, notably for
    the public rating page;
  * website_{livechat, rating, slides}: add sudo in public routes as access
    is already granted;
  * website_slides: set statistics field using compute_sudo as their
    value should be accessible for external people;

TASK ID 2053096
PR #36592

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2019-11-19 15:46:51 +00:00
Jeremy Kersten e19227d3ba [IMP] website*: clean sitemap
From now, you need to explicitely add sitemap=True if you want your controller
into the sitemap.

It's the default value, but if you forgot it, it will raise a Warning on runbot.
It will avoid wrong controller in sitemap and duplicate (empty) content.

From now, if your model contains a field website_id, the modelConverter for
sitemap will automatically add the domain:
   "[('website_id', 'in', (False, current_website_id))]"

It avoid redundant declaration and ugly url in redirect/rewrite view.

Migration: need to remove it from url_from in website.rewrite

task-2065018

closes odoo/odoo#39427

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-28 10:36:56 +00:00
Jeremy Kersten fef7ec7c97 [FIX] website,*: remove useless route from sitemap
preparation for cleaning of v13
task-2065018

closes odoo/odoo#39051

X-original-commit: 8a0fc6476c70a4126043de3b3efbd1096e41f968
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2019-10-18 14:59:02 +00:00
Raphael Collet b7fd679a6c [FIX] *: sudo() -> with_user() 2019-07-04 11:32:22 +00:00
Nans Lefebvre 9d1b07f97b [FIX] project, rating: use rating last update to compute satisfaction percentage
The function _compute_parent_rating_percentage_satisfaction used the creation
date of the rating to compute the percentage.
However when a client give a new rating, it updates the old one.
As a result it doesn't give the recent satisfaction percentage,
but the satisfaction percentage of recently created tickets.
In other words recently angry clients from old projects would not appear.

Similarly this method is somewhat reimplemented directly in SQL in the rating
route, which happens to be in the project controller.

opw 1921486

closes odoo/odoo#30752
2019-02-01 09:01:27 +00:00
Christophe Simonis 069278b652 [MERGE] forward port branch saas-11.3 up to 55dafc20f6 2018-12-11 18:51:05 +01:00
Christophe Simonis 55dafc20f6 [MERGE] forward port branch 11.0 up to 7e5d5045bf 2018-12-11 17:06:48 +01:00
Christophe Simonis 7e5d5045bf [MERGE] forward port branch saas-15 up to 1ace2ed88b 2018-12-11 16:20:34 +01:00
Nicolas Seinlet 37306b85de [FIX] project: project var is not defined
closes odoo/odoo#28678
2018-11-14 13:22:55 +00:00
Martin Trigaux 9f209dd77e [FIX] project: do not crash when no result
If the selected project has no task (e.g. new project), still make a search.
The previous code was making a KeyError on the filterby as the read_group
returned no result.
Introduced at d5bc0e57cd

As a portal, a user may have access to some projects (when set explicitly as
the customer on the project configuration).
Make this with a first search and add the other tasks also with the read_group
in case the user has access to some tasks but not the project.

Fixes #27457

closes odoo/odoo#27581
2018-10-09 14:14:31 +00:00
XavierDo d5bc0e57cd [FIX] project: use user right on portal task
The search on project were done as sudo with a domain matching the
"project_task_rule_portal" rule. This commits remove the sudo call
and corresponding domains.

This replace lpe's fix b8fe404e, and user connected to portal to see
his tasks, avoiding an error during crawling tests:

Error use case:
User try to access a task list from /my/projects with a filter on a project.
The project filter does not exist in task list since the rules applied are for
portal user -> an error is raised

Now, project list on /my/projects and the filter available on /my/tasks should
be the same.
2018-09-11 12:22:40 +02:00
Christophe Simonis 68d36512ef [MERGE] forward port branch saas-11.4 up to d78f23df84 2018-09-07 20:20:45 +02:00
Christophe Simonis 49c3264ce0 [MERGE] forward port branch saas-11.3 up to 4850fb0838 2018-09-07 14:43:48 +02:00
Christophe Simonis f19e6ce561 [MERGE] forward port branch 11.0 up to 213759b03e 2018-09-05 18:52:27 +02:00
Lucas Perais (lpe) b8fe404eae [FIX] project: portal should see projects only when he has tasks
before this commit, on /my/tasks, in the filter dropdown, every project that had visibility = portal was displayed
regardless of whether the portal user was a follower or not

After this commit, we search project in a more clever manner

OPW 1878187
closes #26615
2018-08-30 09:17:23 +02:00
Pragya ladda 00ffef800a [FIX] project: fix sql injection in rating public controller 2018-08-24 17:08:22 +02:00
Sébastien Theys 82a46db2de [FIX] portal,sale,sale_management: raise if no document
Before this commit, the method _document_check_access would succeed if it was called with a non-existing id.

Now it will raise a MissingError.

PR: none
Task: none
2018-08-17 10:40:07 +02:00
Mitali Patel 84f528bcff [IMP] Portal - Share link : Easily share the url of a document
Purpose
=======
- Quickly share the url to someone else (a client, a colleague,...)
- Ensure that the recipient can access at least
  the portal view of the shared record.
- Typically used when a client cannot retrieve the mail to access his order.
  The share link can be used in this case.

Specifications
==============
For any object inheriting form portal.mixin:
    - Add a button SHARE (not visible in edit mode)
    - When clicking on this button, a popup opens with :
        - A warning message for tasks and projects only (see below)
        - the link (like in gmail) that can be copied
        - Recipients
        - mail composer (with preselected template) ==> see below
        - button [Send Link] [Copy Link] Discard
        - After sharing document, put internal note like
          "Document shared to xyz,...." with template message
    - Anyone with the link, even anonymous user (not logged in) can have access
      to the document with the access token provided in the url.

Impacted models:
    - account.invoice (Community)
    - project.project (Community)
    - project.task (Community)
    - purchase.order (Community)
    - sale.order (Community)
    - helpdesk.ticket (Enterprise)

Warning messages and access rules:
    Allowed :
        - SO canceled or draft will be accessible with the link
          with access_token
        - If the customer account is B2B (signup not enabled), the recipient
          will anyway see the document as the user specifically wants the
          recipient to see the document.
    Restrictions :
        - For Project and Task, if the privacy is not public, then, there is a
          contradiction between the access_token mechanism
          and the privacy of the document.
        - A warning message will be displayed in the share wizard to inform the
          user if the document cannot be visible by the recipients and to
          ask him to set the privacy to 'Visible by following customer'.
          The send button will, in that case, be hidden.
        - To avoid to block the share for a new project, default privacy value
          is now set to 'Visible by followong customer'

Technical implementation
========================
- Move the access_token mechanism (field + methods + mail controller)
  to the portal.mixin to be able to use it in a generic way for each object
  inheriting the portal.mixin
- Generalise a part of the _*model*_get_page_view_values method
  into a single one in portal
- Generalize the _*model*_check_access into the portal controller of the
  portal module
- Remove the init_column + default value for the access_token
  > old records have an access_token,
  > new one won't but it will be generated on demand via the get_access_token
  Done for performance reasons
- Add share button into action menu separately. + kanban view context menu
  (except for task and project where button not in action menu but 'simple'
  button for task and project because other modules already provide action
  to send documents by email, which is not the case for project and task.)
- Add a sign_token used to authentify the recipient in the portal view chatter,
  if any. The message will be posted as if the user was logged in.
- Set the _get_share_url as private for security reason
- Add a redirect parameter to _get_share_url to get
    If false : The direct portal view url
    If True : The redirect url (mail/view/?)
- Cleaning up unnecessary code

- Bug fix :
    - Before, if user was not logged and record had partner_id,
      if partner id was null, post message was done as admin.
      Now, the post message is done as public user.
    - If the user had an uid but had no access_token, he could be able
      to gain the access token of the record.
      check_access_rights was missing in the get_access_action.

Task ID : 30985
Closes #25629
2018-08-03 15:20:42 +02:00
Christophe Simonis a719cf2563 [MERGE] forward port branch saas-11.3 up to b4555df336 2018-07-30 17:02:28 +02:00
Christophe Simonis 93e689d1c2 [MERGE] forward port branch 11.0 up to 1353abecbe 2018-07-26 12:58:46 +02:00
Lucas Perais (lpe) e6928a6c97 [FIX] project: proper access check on tasks
With the portal user, go on /my/task/1
(obviously provided that this task doesn't belong to portal user)

Before this commit, there is a 500 error

After this commit, the exceptions are handled and throws a 403

OPW 1867795
closes #25951
2018-07-25 09:48:03 +02:00
Christophe Simonis 73652a0b19 [MERGE] forward port branch saas-11.3 up to 50860317cc
Note: 1aacc96262 has been ignored and will
be forward-ported later
2018-06-15 13:27:27 +02:00
Christophe Simonis b170a753e1 [MERGE] forward port branch 11.0 up to b05e4d5f95 2018-06-15 10:15:27 +02:00
Toufik Benjaa 8354b34a4a [FIX] project: Keep your search filter on the tasks' portal
- Searches made on tickets using the portal aren't kept when changing page.
This commit makes sure the search is kept.

OPW-1857033
2018-06-12 18:05:36 +02:00
XavierDo d6a9a9bf4c [IMP] portal: clean portal task controller
Remove some code that was kept for retro-compatibility
while merging task 1827950 in 11.0 (stable)

Task #1838048
PR #24425
2018-04-27 10:11:06 +02:00
Christophe Simonis e8bf128318 [MERGE] forward port branch 11.0 up to 3ab25b60bc 2018-04-23 18:15:25 +02:00
XavierDo dea07fc291 [IMP] project, portal: group tasks by project on portal.
The portal view for tasks previously listed all task of all projects
without grouping them. It was a problem, mainly when we want to make
the distinction on project label_tasks, to make the difference
between tasks, issues, ... Grouping task by project by default allows
to show the label_tasks before each project.

Grouping the tasks removes the possibility to define a primary
ordering. We want to be able to ungroup the tasks in some cases.
The implentation was done in the portalsearch bar adding
a group by option. The portal proposes two grouping options,
project (by default) and none (to keep strict ordering).

Task: #1827950
PR #23769
2018-04-19 17:22:00 +02:00