- Improve performances, as the ir.rule restricting private partners
visibility is also applied on res.users by inheritance, on each
prefetch.
- Solve the issue of partners set as followers on records (eg: application
form) and then made private, making them impossible to contact via the
chatter.
- Solve the multiple access issues when trying to access the bank
account, or the private address for non HR people like the accountants
forcing the usage of sudo in the business code.
TaskID: 3101400
THese are rarely intended for all users but often intended only for
employees.
account:
account.incoterms: only used within internal business models
account.journal.group: same as account.journal, add sudo in computed field
account_edi: need access to accounting objects
base_address_extended:
res.city: only employees should access address data
board: only employees uses this (old) module
crm:
crm.stage: internal users business object
hr_recruitment: employees can read
im_livechat: apply same as for the steps
l10n_ar: used on partner, not only invoices
l10n_ec: accessed only through account.move
l10n_latam: accessed on res.partner
mail:
publisher.warrenty.contract: no data, only static models
mail.channel: group_user has already his own rule
mail.group: group_user has already his own rule
mail.message.subtype: group_user has already his own rule
mail.message.all: remove, already has a portal and employee rule
partner_autocomplete: no interaction with public
project:
project.tags: only needed for project sharing
sale_management:
sale.order.option: same as sale.order
utm: employee already has write access
web_editor: test models that have nothing to do here
web_tour: only employees uses tours
website_sale:
product.ribbon: add sudo for access
base:
ir.default: only employees uses set (could probably be converted to group_system)
ir.ui.view.custom: same as ir.ui.view, add sudo when needed
report.*: portal users don't configure reports
res.users.log: create in sudo, no access needed (adapt test to use another model)
res.lang: still needed for public
closesodoo/odoo#118701
Related: odoo/enterprise#41285
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
*: account, crm, hr_recruitement, im_livechat, point_of_sale,
project, sale_management, website_sale
Purpose
=======
Now, the KPI are computed based on their `company_id` and not based
on the current company. If no company is set on the digest, we compute
it based on the current company.
The KPIs are computed based on their company. Most of the time, they
will all belong to the same company so we can improve the performance
by computing them in batch.
Task-2827996
See odoo/enterprise/pull/27658
Part-of: odoo/odoo#91945
With this PR, the `digest_data` template is changed, so many test cases fail.
This commit adapts the test cases by changing the `data-field` from `div` to
`table`.
task-2717426
Part-of: odoo/odoo#89549
Ease the way people can unsubscribe from a digest by adding information
to the email enabling a user agent to present a button to the user that
automate the unsubscription.
Technical notes:
To ease the way people can unsubscribe from a digest, we have followed the
advice of rfc8058 by adding the following header to the email:
- List-Unsubscribe: https_URL_to_unsubscribe
- List-Unsubscribe-Post: List-Unsubscribe=One-Click
The https_URL_to_unsubscribe
- must work with the POST method but not the GET. The GET version is disabled
to avoid unintended unsubscription that could be triggered by an anti-spam
accessing the URLs in the headers.
- must unsubscribe the user without any additional steps (one click)
- should contain an opaque identifier hard-to-forge to identify the list and
the user (our token fulfills that goal). The goal is to avoid that someone
could unregister someone else easily.
- must fulfill other conditions like no cookie, no redirection, ...
It requires also that List-Unsubscribe and List-Unsubscribe-Post be covered by
a DKIM signature.
Task-2800499
closesodoo/odoo#86934
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Before this Commit, while sending the digest emails, the tip description was
incorrect due to sanitizing. Some jinja was also badly converted into
inline qweb instead of regular qweb.
After this Commit, we have fixed the tip description field value. We do the
html_sanitize after rendering the QWEB template. So, we get the proper values
of conditions and aliases. Replacing jinja with qweb template, should use
<t t-out="variable"/> to print the dynamic value so, remove the inline_template
expression `{{` and `}}` and put the <t t-out="variable"/>.
Task-2704083
closesodoo/odoo#88937
X-original-commit: c08cdc39965df1941b12a98dc80a015673f502e0
Related: odoo/enterprise#26293
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Currently digest sending is toned down when being sent if subscribed users
did not connect since more than 3 days. It allows to avoid spamming people
not being active or present anymore.
This is currently limited to daily digests that are set to weekly. However
it may continues to send digests each week until the digest is de-activated.
In this commit we tone down the digest from daily to quarterly depending
on users activity. It is still based on overall activity and not individual
users to avoid complex computation on heavy digests. This will be done in
further cleaning of digests.
Task-2688856 (Digest tone down improvement)
X-original-commit: f916354baec5bb69511069a829ab1648a5ebaccd
Part-of: odoo/odoo#79877
Purpose of this commit is to ease usage of unsubscribe button for periodic
digests for non-admins. Users land on page that says "You have unsubscribed
from ..." and not on digest form view anymore.
It is done using a public route with a token, allowing to unsubscribe even
when being not logged, for example when receiving digest emails that are
unwanted.
Task-2641394 (Digest emails sending improvement)
Task-2582128 (Digest onboarding and usage improvement)
X-original-commit: a4b98a82d04b398406958d82f466c09f6021a989
Part-of: odoo/odoo#79877
Co-authored-by: Thibault Delavallée <tde@odoo.com>
Purpose is to ensure behavior of digests and prepare future fixes and
improvements. Tone down and unsubscribe links are currently not tested.
This commit fixes that by adding relevant tests.
Task-2641394 (Digest emails sending improvement)
Task-2582128 (Digest onbarding and usage improvement)
X-original-commit: f340859a3508ebb369b7116f64c81d8f03774e61
Part-of: odoo/odoo#79877
When there is an issue updating digest state (concurrent access, or some other
error that may happen), digest emails may be sent in loop. Indeed they are
currently sent in the same transaction that the one that updates digest state.
This means that emails may be sent even if digest update fails.
As we do not think timing is so important, we now use the email queue to send
digest emails. That way email creation is rollbacked and they are not sent
if digest update fails for some reason.
Tests are updated to take into account we now create outgoing mail.mail. Some
tests are also added about mail values and subscription, and cleaned in a more
general way.
Task-2641394 (Digest emails sending improvement)
Task-2582128 (Digest onbarding and usage improvement)
X-original-commit: 96a14816cb48d9324482eec3de0ed3fccc0d7ecf
Part-of: odoo/odoo#79877
* fix generation of preferences markup so everything's properly
safe (and flag as markup)
* tips should be the result of templates rendering and thus safe
* same for body