Commit Graph
14 Commits
Author SHA1 Message Date
Thibault Francois 458c26ae18 [FIX] website_sale, payment: perf issue when displaying tokens
Problem:
the controller rely on record rules to select the payment.token
to be displayed on the payment page.
This works fine with portal user, but internal user
will face client side performance issue
as they can see all the token of the database

Solution:
Don't rely on record.rule in the controller. Use the domain
from the portal user rule in the search.

To make the search of token working for partners with more than
2 levels of hierachy, use child_of operator

closes odoo/odoo#56326

X-original-commit: 3999e249ea9902e009f0366949886e14e3d7fdf4
Related: odoo/enterprise#12579
Signed-off-by: Damien Bouvy (dbo) <dbo@odoo.com>
2020-08-21 15:33:06 +00:00
Damien Bouvy ba93b4a243 [IMP] payment: ir rules in payment module for invoicing users
Security rules are added in the sale module for transactions and tokens,
but it is entirely possible to have the payment module without those,
and preventing invcoicing users from accessing transactions is
functionnaly stupid - they are often required to check payment statuses,
references, etc.

closes odoo/odoo#52139

Signed-off-by: Damien Bouvy (dbo) <dbo@odoo.com>
2020-05-28 14:32:58 +00:00
Victor Feyens a3ded9043d [IMP] *: declare ir.rule in noupdate
ir.rule are default values but can be customized based on the
company's policy and needs.
This is typically a record that is in noupdate as should be
customization-friendly.
2020-03-20 16:21:25 +01:00
Goffin Simon 4c8c996f4d [FIX] payment: Deleting payment tokens from website
When deleting payment tokens from website, in My account, by clicking
on button "Manage your payment methods", the public user, the user and
the portal user got a 403 error. But when creating a subscription
for a customer with admin user and setting a payment token for
the company of this customer. This payment token could not be deleted
or modified by its users. In a few cases, it's needed to delete or
modify a payment token, for example, when the expiration date of
the payment token is expired.

opw:740169
2017-04-25 09:53:18 +02:00
Thibault Delavallée a969931f9c [MIG] payment: new API
No functional change.
2016-07-06 15:10:45 +02:00
Joren Van Onder e3730cf1f2 [IMP] payment*,website: rename payment.method -> payment.token
payment.method was not a good name because it was too easy to confuse
with account.payment.method.
2016-06-17 13:09:18 +02:00
Yannick Tivisse 9e57185449 [IMP] base,sales_team: Move res_groups and menuitems to sales_team
Purpose:
Having the res_group defined in base and sales_team auto installed
with mail doens't make sense.

- Move the empty res_config class and the related view from
  base_setup to sales_team (base_setup only contains the 'General Settings'
  model and views
- Move the 'sale' related content from product to sale module (Access rights,
  menuitems,...)
- Set sales_team at autoinstall False. The module is installed when needed by
  crm or sale for example
- Set sales_team as a dependency of voip. (Access rights defined for configuration
  purpose)
- Set sales_team ad a dependency of subscription (Access rights issue too)

[FIX] account: move some ir.model.access to sale module
[FIX] payment: Move some ir.rule to website_sale
[FIX] stock: move some ir.model.access rule to sale_stock
[FIX] project: Move some ir.model.access rules to crm_project_issue
[FIX] mrp: Move some ir.model.access rules to sale_mrp
[FIX] calendar: move some ir.model.access rules to crm

Rename xmlids accordingly. Example: 'base.group_sale_manager' becomes
sales_team.group_sale_manager.

[ADD] sales_team: See own documents => See only his sales team
Moved the "User: Own Leads Only", "User: All Leads" and "Manager" groups from sale and crm
into sales_team module. Add the record rules so that user can see only his Own Sales Team
if "See Own Leads" is sales right and can see all sales teams if he is having sales rights
of "See All Leads" or manager.
2016-06-09 16:05:25 +02:00
Yannick Tivisse ccdb5cbfc0 Revert "[IMP] base,sales_team: Move res_groups and menuitems to sales_team"
This branch need more testing instead of doing 10 fixes. A lot of issues are occuring
when installing modules in different orders.

This reverts commit fa6e415cdb.
2016-06-06 17:26:30 +02:00
Yannick Tivisse caf1e4dd70 Revert "[FIX] payment: Move some ir.rule to website_sale"
This reverts commit 930bea9758.
2016-06-06 17:26:12 +02:00
Yannick Tivisse 930bea9758 [FIX] payment: Move some ir.rule to website_sale
The group group_sale_salesman has been moved from base to
sales_team.
2016-06-06 16:47:18 +02:00
Yannick Tivisse fa6e415cdb [IMP] base,sales_team: Move res_groups and menuitems to sales_team
Purpose:
Having the res_group defined in base and sales_team auto installed
with mail doens't make sense.

- Move the empty res_config class and the related view from
  base_setup to sales_team (base_setup only contains the 'General Settings'
  model and views
- Move the 'sale' related content from product to sale module (Access rights,
  menuitems,...)
- Set sales_team at autoinstall False. The module is installed when needed by
  crm or sale for example
- Set sales_team as a dependency of voip. (Access rights defined for configuration
  purpose)
- Set sales_team ad a dependency of subscription (Access rights issue too)

Rename xmlids accordingly. Example: 'base.group_sale_manager' becomes
sales_team.group_sale_manager.
2016-06-06 15:46:52 +02:00
Damien Bouvy dbd3efef1f [IMP] payment: add support for server2server payments
This commit adds a new model, Payment Method, which stores
a reference to the payment acquirer's database and a reference to
a partner. Each payment module must have its own implementation.

The implementation is completely abstract but may not suit every
provider's way of implementing recurring payments.
2015-06-15 14:57:14 +02:00
Martin Trigaux 28a27a9f91 [IMP] payment: simplify rev d99835e
The group public is defined in base so no need to add security rule in website_payment module (same as for portal)
2014-09-17 11:05:32 +02:00
Martin Trigaux d99835ee9c [FIX] payment: access rights limitation
Do not allow everybody to access account.transactions.
Restrict by default to readonly and even restrict the access with a record rule, give access to salesman.
2014-09-16 16:44:42 +02:00