Commit Graph
12 Commits
Author SHA1 Message Date
Yannick Tivisse b1f7e56f79 [IMP] base: Remove private res.partner type
- Improve performances, as the ir.rule restricting private partners
  visibility is also applied on res.users by inheritance, on each
  prefetch.
- Solve the issue of partners set as followers on records (eg: application
  form) and then made private, making them impossible to contact via the
  chatter.
- Solve the multiple access issues when trying to access the bank
  account, or the private address for non HR people like the accountants
  forcing the usage of sudo in the business code.

TaskID: 3101400
2023-07-05 14:21:28 +02:00
Martin Trigaux 604a47ead8 [IMP] *: remove global ACL
THese are rarely intended for all users but often intended only for
employees.

account:
account.incoterms: only used within internal business models
account.journal.group: same as account.journal, add sudo in computed field

account_edi: need access to accounting objects

base_address_extended:
res.city: only employees should access address data

board: only employees uses this (old) module

crm:
crm.stage: internal users business object

hr_recruitment: employees can read

im_livechat: apply same as for the steps

l10n_ar: used on partner, not only invoices
l10n_ec: accessed only through account.move
l10n_latam: accessed on res.partner

mail:
publisher.warrenty.contract: no data, only static models
mail.channel: group_user has already his own rule
mail.group: group_user has already his own rule
mail.message.subtype: group_user has already his own rule
mail.message.all: remove, already has a portal and employee rule

partner_autocomplete: no interaction with public

project:
project.tags: only needed for project sharing

sale_management:
sale.order.option: same as sale.order

utm: employee already has write access

web_editor: test models that have nothing to do here
web_tour: only employees uses tours

website_sale:
product.ribbon: add sudo for access

base:
ir.default: only employees uses set (could probably be converted to group_system)
ir.ui.view.custom: same as ir.ui.view, add sudo when needed
report.*: portal users don't configure reports
res.users.log: create in sudo, no access needed (adapt test to use another model)
res.lang: still needed for public

closes odoo/odoo#118701

Related: odoo/enterprise#41285
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-06-12 22:39:26 +02:00
std-odoo df9e9ec261 [IMP] digest, *: compute the KPI in batch
*: account, crm, hr_recruitement, im_livechat, point_of_sale,
   project, sale_management, website_sale

Purpose
=======
Now, the KPI are computed based on their `company_id` and not based
on the current company. If no company is set on the digest, we compute
it based on the current company.

The KPIs are computed based on their company. Most of the time, they
will all belong to the same company so we can improve the performance
by computing them in batch.

Task-2827996
See odoo/enterprise/pull/27658

Part-of: odoo/odoo#91945
2023-04-05 15:11:06 +02:00
MAHAMADASIF ANSARI dd9abe6a76 [IMP] digest, test_mass_mailing: adapt test cases due to changes in templates
With this PR, the `digest_data` template is changed, so many test cases fail.
This commit adapts the test cases by changing the `data-field` from `div` to
`table`.

task-2717426

Part-of: odoo/odoo#89549
2023-03-31 15:51:58 +02:00
Pierre-Yves Dufays e1f86d3d80 [IMP] digest: ease the way people can unsubscribe from a digest
Ease the way people can unsubscribe from a digest by adding information
to the email enabling a user agent to present a button to the user that
automate the unsubscription.

Technical notes:
To ease the way people can unsubscribe from a digest, we have followed the
advice of rfc8058 by adding the following header to the email:
- List-Unsubscribe: https_URL_to_unsubscribe
- List-Unsubscribe-Post: List-Unsubscribe=One-Click

The https_URL_to_unsubscribe
- must work with the POST method but not the GET. The GET version is disabled
to avoid unintended unsubscription that could be triggered by an anti-spam
accessing the URLs in the headers.
- must unsubscribe the user without any additional steps (one click)
- should contain an opaque identifier hard-to-forge to identify the list and
the user (our token fulfills that goal). The goal is to avoid that someone
could unregister someone else easily.
- must fulfill other conditions like no cookie, no redirection, ...

It requires also that List-Unsubscribe and List-Unsubscribe-Post be covered by
a DKIM signature.

Task-2800499

closes odoo/odoo#86934

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-09-20 11:33:43 +02:00
Raphael Collet 6cf8db906f [REF] *: adapt code to new flush API
closes odoo/odoo#87527

Related: odoo/upgrade#3497
Related: odoo/enterprise#26939
Signed-off-by: Raphael Collet <rco@odoo.com>
2022-05-25 18:00:47 +02:00
Mitul Shah ab0d415263 [IMP] digest: fix tip description
Before this Commit, while sending the digest emails, the tip description was
incorrect due to sanitizing. Some jinja was also badly converted into
inline qweb instead of regular qweb.

After this Commit, we have fixed the tip description field value. We do the
html_sanitize after rendering the QWEB template. So, we get the proper values
of conditions and aliases. Replacing jinja with qweb template, should use
<t t-out="variable"/> to print the dynamic value so, remove the inline_template
expression `{{` and `}}` and put the <t t-out="variable"/>.

Task-2704083

closes odoo/odoo#88937

X-original-commit: c08cdc39965df1941b12a98dc80a015673f502e0
Related: odoo/enterprise#26293
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-04-15 21:01:56 +02:00
Thibault Delavallée 49085a1228 [FIX] digest: improve tone down
Currently digest sending is toned down when being sent if subscribed users
did not connect since more than 3 days. It allows to avoid spamming people
not being active or present anymore.

This is currently limited to daily digests that are set to weekly. However
it may continues to send digests each week until the digest is de-activated.

In this commit we tone down the digest from daily to quarterly depending
on users activity. It is still based on overall activity and not individual
users to avoid complex computation on heavy digests. This will be done in
further cleaning of digests.

Task-2688856 (Digest tone down improvement)

X-original-commit: f916354baec5bb69511069a829ab1648a5ebaccd
Part-of: odoo/odoo#79877
2021-11-16 16:58:39 +00:00
Fabio BarberoandThibault Delavallée 0ac3de16a9 [FIX] digest: ease unsubscribe
Purpose of this commit is to ease usage of unsubscribe button for periodic
digests for non-admins. Users land on page that says "You have unsubscribed
from ..." and not on digest form view anymore.

It is done using a public route with a token, allowing to unsubscribe even
when being not logged, for example when receiving digest emails that are
unwanted.

Task-2641394 (Digest emails sending improvement)
Task-2582128 (Digest onboarding and usage improvement)

X-original-commit: a4b98a82d04b398406958d82f466c09f6021a989
Part-of: odoo/odoo#79877
Co-authored-by: Thibault Delavallée <tde@odoo.com>
2021-11-16 16:58:39 +00:00
Thibault Delavallée 4ea673bfd8 [IMP] digest: add tests about tone down and unsubscribe
Purpose is to ensure behavior of digests and prepare future fixes and
improvements. Tone down and unsubscribe links are currently not tested.
This commit fixes that by adding relevant tests.

Task-2641394 (Digest emails sending improvement)
Task-2582128 (Digest onbarding and usage improvement)

X-original-commit: f340859a3508ebb369b7116f64c81d8f03774e61
Part-of: odoo/odoo#79877
2021-11-16 16:58:37 +00:00
Thibault Delavallée 9c25a65fa2 [FW][FIX] digest: use email queue to send digest emails (and improve tests)
When there is an issue updating digest state (concurrent access, or some other
error that may happen), digest emails may be sent in loop. Indeed they are
currently sent in the same transaction that the one that updates digest state.
This means that emails may be sent even if digest update fails.

As we do not think timing is so important, we now use the email queue to send
digest emails. That way email creation is rollbacked and they are not sent
if digest update fails for some reason.

Tests are updated to take into account we now create outgoing mail.mail. Some
tests are also added about mail values and subscription, and cleaned in a more
general way.

Task-2641394 (Digest emails sending improvement)
Task-2582128 (Digest onbarding and usage improvement)

X-original-commit: 96a14816cb48d9324482eec3de0ed3fccc0d7ecf
Part-of: odoo/odoo#79877
2021-11-16 16:58:37 +00:00
Xavier Morel c56e8c9f5a [FIX] digest: de-t-raw-ify
* fix generation of preferences markup so everything's properly
  safe (and flag as markup)
* tips should be the result of templates rendering and thus safe
* same for body
2021-04-29 05:34:20 +00:00