Commit Graph
147 Commits
Author SHA1 Message Date
Julien Carion (juca) d1c6bc5d95 [FIX] mail, base: move user settings access rules
In b1e2c3453f50cc05a1b03dc1c8571a01ad7b7dd2, the `res.users.settings`
model was moved from `mail/` to `base/`, but its record rules remained
in `mail/`. This means that if `mail/` is not installed, users will be
able to access other users' `res.users.settings` records. In practice,
this is not a problem, as the only field that can exist in
`res.users.settings` without `mail/` is `homemenu_config`, which
contains nothing senstive.

This commit moves the forgotten record rules to `base/`, preventing
potential problems if new fields with sensitive information were to be
added to `res.users.settings` in the future.

Task-3461652

closes odoo/odoo#131538

X-original-commit: 5a79550c8e35ce733375c2ef7df2ea12e6added6
Signed-off-by: Louis Wicket (wil) <wil@odoo.com>
2023-08-10 18:14:36 +02:00
Maryam Kia 8d039cafe3 [IMP] mail: Send voice messages in discuss chats and channels
With this commit, users can send voice messages in channels and chat.
There's a new button in composer to record audio from the microphone,
up to 1 minute clip duration. This adds a voice attachment with its
dedicated voice player that shows waveforms and allows playback.

To ensure compatibility in all supported browsers, we choose to
encode voice recording with `audio/mp3` thanks to lib `lamejs`.

Task-3240168

closes odoo/odoo#117036

Related: odoo/enterprise#45482
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-08-09 13:20:46 +02:00
Martin Trigaux cd2f330bec [IMP] *: remove glocal ACL
Specify explicit route for each ,, line
This is part of task 3230280 where global ir.model.access will be
forbidden.
The goal is to make access to public/portal explicit. Too often,
global access was granted with only employees in mind.

Remove ,,0,0,0,0 lines

mail:
employee already had read access to mail.group
still needed to subtypes as in ir.rule domain

mail_group: employee already had read access
pos_mercury: only needed for employees

membership:
move public access for website_membership as needed in the controllers

website_customer: employee already had read access

website_event_booth: no need for category
website_event_exhibitor: retrieved in sudo
website_event_track: not needed for location

Part-of: odoo/odoo#125216
2023-07-11 22:33:47 +02:00
Astik Singh 200ccf1b10 [FIX] mail: prevent from modifying subtypes
Prior this commit:
In mail subtype, any users could have perform modification on it.

After this commit:
Now user have only access to read and only admin can do all the modifications.

Task-3245940

closes odoo/odoo#127539

X-original-commit: 1b99f9b6608793612dda72007a4ca2258373a97f
Signed-off-by: Stéphane Debauche (std) <std@odoo.com>
2023-07-06 13:39:52 +02:00
Didier (did)andBrieuc-brd 771477b9a7 [IMP] mail: Introduce gif picker in Discuss
This commit adds a GIF picker in discuss
app. GIF feature makes use of Tenor GIF API [1].
To enable GIF picker in discuss, you must provide
a Tenor GIF API key in the General Settings.
Then the GIF picker is visible in all channels
(chat window and discuss app), next to the emoji picker
button.

[1] https://tenor.com/gifapi/documentation

task-2365705

closes odoo/odoo#116060

Related: odoo/enterprise#41959
Signed-off-by: Alexandre Kühn (aku) <aku@odoo.com>
Co-authored-by: Brieuc-brd <brd@odoo.com>
2023-06-30 23:38:01 +02:00
Julien Carion (juca) 2a37a3d06f [REF] web, base, mail: move res.users.settings from mail to base
This commit moves and adapt the res.users.settings model from mail to base and
and allows to access and modify its content with web's user service.
This allows to access user settings without needing the mail module.

closes odoo/odoo#116005

Related: odoo/enterprise#38360
Signed-off-by: Michaël Mattiello (mcm) <mcm@odoo.com>
2023-06-22 15:40:43 +02:00
Martin Trigaux 604a47ead8 [IMP] *: remove global ACL
THese are rarely intended for all users but often intended only for
employees.

account:
account.incoterms: only used within internal business models
account.journal.group: same as account.journal, add sudo in computed field

account_edi: need access to accounting objects

base_address_extended:
res.city: only employees should access address data

board: only employees uses this (old) module

crm:
crm.stage: internal users business object

hr_recruitment: employees can read

im_livechat: apply same as for the steps

l10n_ar: used on partner, not only invoices
l10n_ec: accessed only through account.move
l10n_latam: accessed on res.partner

mail:
publisher.warrenty.contract: no data, only static models
mail.channel: group_user has already his own rule
mail.group: group_user has already his own rule
mail.message.subtype: group_user has already his own rule
mail.message.all: remove, already has a portal and employee rule

partner_autocomplete: no interaction with public

project:
project.tags: only needed for project sharing

sale_management:
sale.order.option: same as sale.order

utm: employee already has write access

web_editor: test models that have nothing to do here
web_tour: only employees uses tours

website_sale:
product.ribbon: add sudo for access

base:
ir.default: only employees uses set (could probably be converted to group_system)
ir.ui.view.custom: same as ir.ui.view, add sudo when needed
report.*: portal users don't configure reports
res.users.log: create in sudo, no access needed (adapt test to use another model)
res.lang: still needed for public

closes odoo/odoo#118701

Related: odoo/enterprise#41285
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-06-12 22:39:26 +02:00
Sébastien Theys 90cb44e1e1 [REF] mail, *: rename mail.channel to discuss.channel
* = bus, calendar, crm_livechat, hr, hr_holidays, im_livechat, mail_bot,
    mass_mailing, privacy_lookup, test_discuss_full, test_mail,
    test_mail_full, website_crm_livechat, website_livechat, base

In preparation of splitting discuss and mail modules.

Part of task-3265211

closes odoo/odoo#118354

Related: odoo/upgrade#4553
Related: odoo/enterprise#39661
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-04-21 02:21:53 +02:00
Zelong Lin d57c64f95b [IMP] mail, *: remove 'public' field in channel
*: im_livechat, website_livechat

Access right should be based on channel type and membership instead.
Chat always private, group always private, channel private should
disapear and be a group instead (migration needed), and other channel
always public (but they can still be further restricted with
the "allowed groups" feature)

task-2632861

closes odoo/odoo#90415

Related: odoo/enterprise#30980
Related: odoo/upgrade#3850
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-09-06 10:57:59 +02:00
Didier (did) 7ceb079455 [IMP] mail: implement link preview with OpenGraph Protocol
OpenGraph Protocol https://ogp.me/ allow us to get some data from the link that
are shared in message.

task-2365881

closes odoo/odoo#82641

Related: odoo/enterprise#30867
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-09-05 14:49:30 +02:00
std-odooandThibault Delavallée 9b11a9d82b [IMP] mail: schedule emails and notifications
Purpose
=======

Currently, only email sending can be scheduled with the `scheduled_date` field
defined on on <mail.mail>. It's not possible to delay the sending of
notifications.

We want to be able to delay the sending of the emails, but also the inbox
and bus bus notifications.

Technical
=========

For that purpose, we created a new model which stores the message we need to
notify with the scheduled date. When a scheduled_datetime is given we skip the
notification process. Instead an entry in that new model is created. A cron
regularly polls the scheduled message and launch the notification process on
messages that are ready to be sent.

Task-2207626 (Rating: Delay rating notification to ease feedback)

Part-of: odoo/odoo#95623
Co-authored-by: Thibault Delavallée <tde@odoo.com>
2022-08-25 19:57:16 +02:00
Nikunj Ladava c8cdd6f5a3 [IMP] mail,sms: reset template button
Before Commit :
- Sometimes user breaks their Mail/SMS templates and have no way to go back to the
original one easily. They don't have any option to reset the template.

After Commit :
- Added new "Reset Template" button
- now user can reset the Mail/SMS template to its first version.
- also it will update the translation of the template
- added New "Reset Mail Templates/Reset SMS Templates" action to edit multiple templates

task- 2231977

closes odoo/odoo#83759

Related: odoo/upgrade#3674
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-08-17 11:20:56 +02:00
MAHAMADASIF ANSARI 3bf88fcf79 [IMP] {fetch}mail, google_gmail, microsoft_outlook: merge fetchmail into mail
The `fetchmail` module is build on top of the `mail` module and enables
the incoming email capabilities. However, using the `mail` without
incoming email server is not a good use case.

This commit merges the `fetchmail` moudule into `mail` and lessens the module
complexity, along with adapting the xml/external ids in the dependent modules.

task-2797458

closes odoo/odoo#94143

Related: odoo/upgrade#3615
Related: odoo/enterprise#28659
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-07-20 10:58:56 +02:00
Louis Wicket (wil) fdcaa53ca0 [IMP] mail, *: rename mail.channel.partner to mail.channel.member
* = calendar, crm_livechat, hr_holidays, im_livechat, privacy_lookup,
privacy_lookup, test_discuss_full, test_mail_full, website_livechat

closes odoo/odoo#95912

Related: odoo/upgrade#3681
Related: odoo/enterprise#29433
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-07-19 11:50:37 +02:00
std-odoo f3f750b0f7 [FIX] mail: do not ignore email sent by mailing list
Bug
===
Since 9c1cdd330e we ignore all incoming
email sent by mailing lists.

They are real use case when people want to be able to receive email
from mailing list (e.g. if they subscribed to an automated service,
or if someone is in leave and has done a auto-replier for that, etc).

Add a model to whitelist some email address. The alias limit
does not apply for those emails.

Task-2862092

closes odoo/odoo#92015

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-06-07 10:16:18 +02:00
Xavier Morel 319f9bf5ea [IMP] mail: allow admins to remove channels they're not members of
The only mail.channel rule was that a user only had access to channels
they're members of, or can subscribe to (public, or group based).

This rule applied to admins as well, forcing them to switch to
super-admin mode in order to manage mail channels.

This is undesirable on lots of axis:

- superadmin mode is a bit of a last-ditch feature, as a result it's
  somewhat hidden
- there is a much higher risk of screwing up as superadmin mode
  basically lifts all the access rules, which can have correctness
  implications
- auditing completely breaks down when using superadmin mode, as the
  real identity of the user is lost

OPW-2857136

closes odoo/odoo#92299

X-original-commit: 1a77ab5726bbcc477d12f40f67433d474ea85316
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-05-30 09:28:49 +02:00
Denis Ledoux dd2958a760 [FIX] mail: allow regular users to create mail non-dynamic templates
closes odoo/odoo#90896

X-original-commit: 96770827e42615c43b70bdae6529fb76ac66c518
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
2022-05-09 17:05:43 +02:00
Sébastien Theys a29a7183a4 [IMP] mail, im_livechat: fix performance of channel access rule
Current access rule requires fetching all members of each channel, which does not scale.

Use is_member field instead, and make sure itself does not fetch all members.

task-2818759

closes odoo/odoo#88221

Related: odoo/upgrade#3422
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2022-04-08 15:52:31 +02:00
Pierre-Yves Dufays eca543ef40 [REM] mail, sms, snailmail: discard notifications without confirmation
Skip the confirmation step when wanting to get rid of a notification
for emails, sms or letters that were not sent.

Technical:
- All 3 wizards to confirm the discarding of the notification have been removed
(the ones for mail, sms and letter) have been removed
- The method to discard notification has been centralized in MailThread
(notify_cancel_by_type in addons/mail/models/mail_thread.py)
- This centralization has been done as well on the client code as the same
server code is called whether it is a mail, a sms or a letter
(in addons/mail/static/src/models/notification_group/notification_group.js)
- Existing front and back test have been adapted
- A test of notify_cancel_by_type for mail has been added
(addons/test_mail/tests/test_mail_management.py)
- add missing author_id in mail_notification demo data

Task-2752190

closes odoo/odoo#84452

Related: odoo/upgrade#3246
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-04-01 17:56:20 +02:00
Julien Giannone 19c364ea2d [IMP] mail: add model for message reactions
Add the model in the freeze for next version, the interface is not fully ready
to merge yet but it will be added in https://github.com/odoo/odoo/pull/75630

Part of task-2361194

closes odoo/odoo#75911

Signed-off-by: Samuel Degueldre <sdegueldre@users.noreply.github.com>
2021-09-04 13:01:02 +00:00
Thanh Dodeur ac99b09cdc [IMP] mail*: add audio and video conference with webRTC
*test_discuss_full,test_lint

This commit adds the audio and video conference feature to mail channels
and integrate it with the groupDM/guest features.

Adds new mp3 and ogg files (from task-2554674) for sound effects.

- Adds three new tables:
    * `mail.channel.rtc.session` to manage the peerToPeer interactions
      during rtc calls.
    * `mail.ice.server` to provide ICE servers necessary to establish
      peerToPeer connections with webRtc.
    * `res.users.settings.volumes` to hold the partner-to-partner volume
      settings, each partner can create one new setting per other
      partner to configure the volume coming from those partners during
      calls.

- changes res.config.settings:
    * Adds new fields for the Twilio credentials to use their STUN/TURN
      service.

- changes res.user.settings:
    * Adds 4 fields for the push to talk and voice activation.

- changes mail.channel:
    * Adds a new field `rtc_session_ids` that represents the active
      participants in a rtc call on that channel.

- changes mail.channel.partner:
    * Adds a new field `rtc_inviting_session_id` that represents the
      rtcSession of the user that is inviting that channelPartner to a
      call.

task-2366708

closes odoo/odoo#66611

Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2021-09-04 06:23:56 +00:00
std-odoo cc012a0864 [IMP] mail, various: add email templates management levels
Purpose
=======

Purpose of this commit is to add a new group for the mail template designer.
Goal is to make roles clearer: managers edit templates, users use them. This
commit allow some designers / managers to make email template and to let
others users use those email templates.

Specifications
==============

When this feature is enabled in the Settings page, a new group is required to
modify email templates in a composer like wizard or to make dynamic content.
This allows to separate managers editing / composing templates from standard
users that use them.

If the current does not have this group, the email body will be in readonly
mode if he selected an email template. That way we force him to use the email
template that the manager made.

Technical
=========

New Group
---------

Only users in this group will be able to create / write email template or
to write Jinja code in the mail composer (including other fields like subject
in mailing).

By default, all internal users have this group. Mass mailing users also have
this group as writing mailings is about the same management level as writing
templates.

Mail Composer Mixin
-------------------

In comment mode, the template is rendered and then saved on the body field
so non-"Mail Template Editor" users can load email templates.

But in mass mode, the body of the template is saved and then rendered and
many things change the body (HTML sanitizer, web editor move inline CSS
properties, add / remove spaces...). So in this case, we can not know if
the user changed the body or not. That is why we put the body field in
readonly mode so, it is not modified by the web editor.

Jinja code detection
--------------------

To detect dynamic Jinja content, we compile the template, and we browse the
AST. If we do not have a single "Template Data" node, we assume that the
template is dynamic.

When we detect the template as static, we do not render it. That way we
avoid unnecessary rendering.

Code cleaning
-------------

Move Jinja import into tools so that it is outside of mail framework code.

Task-2187263

closes odoo/odoo#75840

Related: odoo/enterprise#20547
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-09-02 03:42:54 +00:00
Louis Wicket (wil) 80d74e7ee0 [IMP] mail, web, *: add support for guest users
* = crm_livechat, hr, hr_holidays, im_livechat, mail_bot, purchase, sms,
    snailmail, survey, test_discuss_full, test_mail, web_editor, website,
    website_livechat

 - Create new model `mail.guest` for guests.
 - Rewrite some RPCs to target routes rather than model methods so that
   guests are able to use them.
 - Patch JS and python models to support guests.
 - Create a stand-alone page and boot the channel in it.

task-2494829

closes odoo/odoo#75496

Related: odoo/enterprise#20417
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2021-09-02 00:43:34 +00:00
Qiuyu (QHO) 463af6f61b [IMP] mail, im_livechat: improve Discuss sidebar
The commit is to refactor the discuss sidebar

 - threads are now organized in categories based on the thread type e.g. chat, channel
 - categories can be folded or unfolded by clicking the category title
 - for active thread, even if the category is folded, it remains under the category title
 - for channel category, a new cog button is added to view all channels
 - the active indicator bar is removed. The active item now is highlighted with a different background color
 - thread avatar is used for livechat, chat and channel
 - for livechat and chat, threads are now sorted by last activity time (pin or message exchange)

closes odoo/odoo#70986

Task-id: 2440073
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2021-08-25 17:00:06 +00:00
std-odoo 59d6bb23d7 [REM] mail: remove mail channel moderation
Rationale
=========

Currently, mail channels have 2 modes
- They can be used like Discuss channel (chat, livechat, group)
- They can be used like a Mailing List (with the "email_send" field)

The mix of both feature in the same model causes some code complexity.
Several fields are not used in both cases (moderation related field)
and the future "Discord like" Discuss will even push the mail channel
further than the usage of the mailing list.

Because of all those reasons, we want to split the 2 mains features of
the mail channels into 2 different modules and models.

Purpose
=======

This commit remove the moderation feature of the mail channel
(email_send=True). This will be re-implemented in a separate module
in the next commit.

Do not be able to check messages in Discuss anymore because this
feature is only used to moderate the message and this feature will be
spitted in a new module "mail_group".

Links
=====

Task-2510267
See odoo/odoo/pull/71599
See odoo/enterprise/pull/19296
See odoo/upgrade/pull/2600
2021-07-09 11:16:38 +00:00
Debauche Stéphane c7be144d58 [FIX] mail: make the current user member of the created channel
Forward port fixes done in stable versions and not correclty forward ported
into master at merge time.

ORIGINAL COMMIT

Purpose
=======
Before, by default, if a user create a channel, he will not be member
of this channel.

After, the current user will always be member of the new channel.

LINKS

Task ID-2421795
COM PR odoo/odoo#63677
X-Original-commit odoo/odoo@eda542c82f
X-Original-Task ID-1963414

X-original-commit: 1d5d7871d72c8b747ab2e1b3597f6b8b8e371b26
2020-12-23 15:16:15 +00:00
Julien Castiaux db9bf62431 [REF] mail: Use Command helper for x2many
closes odoo/odoo#60965

Task: 2366606
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
2020-11-30 10:16:09 +00:00
Thibault Delavallée 8ff7973e79 [FIX] base, mail: allow to use templates with reports
Since de4213b771 it is not possible to anyone except admin to use templates
with a report defined on it. This could be annoying.

X-original-commit: 47f5e14eca4e13010cc11f688ea92f65a2695d38
2020-08-24 08:14:43 +00:00
ryv-odooandThibault Delavallée 186cfb5ebd [REF] mail: make alias mixin multi-enabled
Purpose of this commit is to allow multi-create in alias mixin by correctly
creating / updating aliases in batch.

Task ID 1919277
Community PR odoo/odoo#41160
Enterprise PR odoo/enterprise#6983
Upgrade PR odoo/upgrade#872

Co-Authored-By: Rémy Voet <ryv@odoo.com>
Co-Authored-By: Thibault Delavallée <tde@odoo.com>
2020-04-17 06:52:09 +00:00
Tiffany Chang (tic) f9ff21a200 [IMP] mass_mailing_(sms): Add unblacklisting button
Previously a blacklisted phone number or email address could only be
removed from their respective blacklist by going to the corresponding
blacklist view [in mass_mailing_(sms)] and manually
archiving/deactiviting the entry. All users could see that an email was
blacklisted via an fa-ban icon added next to their corresponding field
in the modules: crm, mass_mailing, mass_mailing_sms, and contacts (via
extension).

This commit adds additional fa-ban icons next to blacklisted phone
numbers and makes all instances of these icons clickable to remove them
from their corresponding blacklist using a wizard. There are several
limitations to this implementation including:

1. If both a mobile and phone number field appear within a crm lead
instance, then only the mobile field will indicate if it is blacklisted
(due to current implementation of PhoneMixin which only checks 1 phone
value against the blacklist and "sms" which returns mobile numbers first).
I.e. if a phone field value is blacklisted, but a value is typed into the
mobile field, then the phone field will never indicate that it is blacklisted.

2. If someone clicks on a unblacklisting icon after changing the
corresponding field value without clicking off the field input, then the
latest typed in value will be the one submitted for unblacklisting,
which may not actually be blacklisted (due to "is_blacklisted" flag
being a computed field and it not having a chance to re-compute to hide
the button).

3. If someone changes values in the blacklist, then someone who already
has a form open will not see icon disappear until something triggers a
re-compute of the "phone_sanitized_blacklisted" flag (this was already the
case with the icon, but now a user may try to unblacklist a value that is
already unblacklisted.)

4. Since the icon needs to be visible by everyone to indicate whether or
not a phone/email is blacklisted, users without corresponding unblacklist
permissions will be able to click on the icon. When they click on it, they
will be informed they do not have permission to unblacklist. A wizard was
determined to be the best way to implement this unblacklisting for the
following reasons:
  - A "Unblacklisting Reason" is needed and will not be stored as a field.
  - A field widget is unable to do this due to security settings +
    inability to refresh view after unblacklisting with a
    "Unblacklisting Reason" without wiping unsaved changes.

Additionally, to better align with GDPR, the corresponding form view for
the phone/email blacklist has been updated to use the same wizard to
track "Reason for unblacklisting". Unfortunately there is no
straightforward way to prevent direct "Archive" action, so users are
still able to bypass unblacklisting without being asked for a "reason
for unblacklisting".

Supports task: 2117635
Upgrade PR: odoo/upgrade#939
COM PR: odoo/odoo#45315
2020-03-26 10:15:18 +00:00
Victor Feyens a3ded9043d [IMP] *: declare ir.rule in noupdate
ir.rule are default values but can be customized based on the
company's policy and needs.
This is typically a record that is in noupdate as should be
customization-friendly.
2020-03-20 16:21:25 +01:00
Victor Feyens 532c083cbb [IMP] *: remove global field definition in ir rules xml
It is a computed field, there is no need to manually set its value.
2020-03-20 16:15:40 +01:00
Martin Trigaux 65530dfd6a [ADD] *: add ir.model.access on all transient models
Following changes needing ir.model.access on transient models too.
Remove groups declaration on the action to move it to ir.model.access
when possible.
Rules are strict by default with no unlink access by default and high
priviledge asked. Adaptations may be needed later.
Write access is given as a wizard may need to be modified in case the
action triggers an error and the user has to correct a value

account*: use account.group_account_user for all transient by default
	  remove account.print.journal relic
stock*: use stock.group_stock_user by default
survey: survey user can send invitations
mail: allow any employee to execute wizards
      additional verifications are made to ensure they are executed
      only on the documents the user has access to you
      give portal access to mail.compose.message as portal still does
      some actions like posting messages on the forum
      add ir.rule to avoid reading somebody else messages
      increase the query count because of undeterminist count
crm: saleman for lead2opp, manager for massmailing
     partner manager for actions linked to partners
     avoid a write in test_lead_lost
sms: any employee can send sms
mrp: mrp user can execute wizards
     give unlink access as making write during do_produce operation
base_import: employees can import files
delivery: stock user can deliver
event_sale: sale user can configure the wizards
	    event user inherit from  sale rights
gamification: employee can give badge
google_service: resolve FIXME
hr: add specific rights
    manager can set a plan according to group on button
    anyone who can write on an employee can register a departure
hr_expense: set rights based on buttons
hr_holidays: an approver can make a summary report
hr_recruitment: recruiter can refuse a candidate
hr_timesheet: can use the wizard if can create a timesheet
l10n_eu_service: managers can create fiscal positions
mass_mailing: same group as on mass.mailing.list
membership: accountant can create invoice from membership
payment: accountant can create a link
	 as the source is an account.move
	 keep the payment.acquirer.onboarding.wizard to system user
	 only as it is called during company configuration
point_of_sale: PoS manager only can use wizards
	       never create closing_balance_confirm_wizard records
product_expiry: stock user has rights on stock.picking
product_margin: access from accounting menus
repair: same rules as for above models
sale: set ir.rule for self wizard only
      add rule from model introduced in payment to add salesman group
sale_crm: saleman can create a quotation from a lead
sale_coupon: any saleman can generate coupon
	     add self ir.rule
sale_product_configurator: salesman can select product variants
snailmail: employee can send letters
website: designers can write on website
website_crm_partner_assign: same rule as group on action
website_sale: sale ACL as for payment.acquirer.onboarding.wizard
website_slides: anyone can send invitation

base: base.language.*: allow employee (cf lang_install)
      change.password.user: can not read change password wizard of
      other users
      test.*: no access is needed

Courtesy of Damien Bouvy, William Andre and Antoine Prieëls for review
of acl
2020-02-04 17:54:18 +01:00
15c934a1ab [IMP] (website_)mail: improve routes and management of mail followers
Purpose of this commit is to improve model of followers, notably management
code and its use in routes. Indeed it is quite an old model and code had
to be cleaned a bit to improve code readability and maintenance.

In this commit we

  * remove unnecessary code examples in gamification about followers: using
    that model as example of code for goals is probably not a good idea as it
    is technical;
  * rewrite routes called by JS are simplified to better match JS
    implementation;
  * introduce computed fields to fetch related partner or channel name,
    email (partner only) and active status;

LINKS

Task 1933771
Task 2078313

closes odoo/odoo#39808

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Co-authored-by: Remy Voet <ryv@odoo.com>
Co-authored-by: jgi-odoo <jgi@odoo.com>
Co-authored-by: Xavier-Do <xdo@odoo.com>
2020-01-21 16:40:06 +00:00
mcm-odoo fea8d452b2 [FIX] im_livechat: allow manager to read all sessions
Managers could see only their sessions like other operators.
Now they can see all the sessions so they can check and help the operators.

task-2048498

closes odoo/odoo#41175

X-original-commit: 6ae791335a1986aa4cc72f7ed9aadd471c1774c5
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2019-11-22 14:27:10 +00:00
Thibault Delavallée 69ccabb212 [FIX] mail: restrict access to mail.mail model
From now on mail.mail is considered as a technical model. Indeed people should
not really manually craft mails by hand. Instead various functional flows
should either send mails, either craft mails based on some user input.

We therefore make mail restricted to admin users. Flows creating mail.mail
are updated to use sudo, and ensure it was done in a context that makes
sense to delegate this power to the user.

Task ID 1853147
PR #32243
2019-11-29 13:35:14 +00:00
Christophe Simonis d74b451805 [MERGE] forward port branch 13.0 up to f4105eb9c7 2019-10-09 02:08:17 +02:00
Luis González 13e14cf764 [FIX] board,mail,project: remove spaces from external IDs
This was already performed on 3c568aec0b, but there still are some
remnants on model access records.

Fixes odoo/odoo#25408
Closes odoo/odoo#37946

closes odoo/odoo#37958

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2019-10-04 08:51:01 +00:00
Thibault Delavallée 60f9c85a8c [FIX] mail: make mail.mail an internal model by default
Task 2078313
2019-09-03 14:01:00 +02:00
Thibault Delavallée abc212f59a [REF] mail: remove create_user_id field on activity
As activities are created using the current user there is no need anymore to
have another field to store the activity creator. We can therefore remove
create_user_id and replace its use by the magic create_uid field.

This commit is linked to task ID 1856417 and PR #27619.
2018-12-12 12:45:24 +00:00
Sébastien TheysandThibault Delavallée b9c8ba83e6 [IMP] mail: clean activities access rights
This commit improves code of access rights checks when creating or updating
activities. Several points triggers this commit

 * we would like to use _filter_access_rules and override it on activities
   model in order to be more standard;
 * we would like to get rid of sudo used in various CRUD overrides as using
   standard ORM method allows to correctly use current user;
 * we would like to get rid of create_user_id field once we can keep the
   current user as create_uid;

Access rights are a bit updated. They are now the following

 * you can create activities for documents like posting messages (using
   _mail_post_access attribute; if not defined, write access on document
   is required);
 * you can read activities for documents you can read;
 * you can write and unlink activities either following the defined access
   rule (created OR assigned), and otherwise like posting messages (
   using _mail_post_access attribute; if not defined, write access on
   document is required);

In this commit we also hide edit / mark as done / cancel buttons for
activities the current user cannot modify.

This commit is linked to task ID 1856417 and PR #27619.

Co-Authored-By: Sébastien Theys <seb@odoo.com>
Co-Authored-By: Thibault Delavallée <tde@odoo.com>
2018-12-12 12:44:03 +00:00
Gert PellinandRichard Mathot 76a557c9ac [IMP] hr,mail: auto-subscribe departments to channels
Purpose of this commit is to allow to make private channels linked to
an HR department with an auto subscription.

It will ease the use of discussion channels among employees of a given
department. Moreover auto subscription is useful to avoid having to
manually synchronize channel members and department members.

This commit is linked to task ID 1848526 and closes PR #26650 .

Co-authored-by: Gert Pellin <gpe@odoo.com>
Co-authored-by: Richard Mathot <rim@odoo.com>
2018-09-17 13:56:39 +02:00
David Beguin 98ce81cac5 [IMP] mail - mail.blacklist: Not send mass_mail to recipient that does't want to
Purpose
=======
Improve mailing subscription to be more compliant with the European GDPR law.
Keep a list of people who does not want to receive promotional emails
(or mass mailing in general) anymore.

Specifications
===========
This commit is regrouping some main changes on mass mailing.
- Added blacklist : Avoid sending mass mailing to blacklisted recipient
  (blacklisted = email address that doens't want to receive mass mailing anymore)

Detailed implementation
===================
Mail :
- Add Blacklist mechanism in mail module (NOT in mass-mailing) :
  as we can send mass-mail without the mass-mailing module
- Unicity in email -> To avoid error in import, override the create and return
  the existing record if any, else, create the record normally.
- Blacklisting is done by email address and is cross model.
  Will apply to model that inherit the blacklist.mixin.
- field 'is_blacklisted' -> computed : check if email is in blacklist
  + search method to be able to filter on is_blacklisted
- When a email address is blacklisted, it will never get mass mailings anymore.
  Even if the email address is added to another mailing lists
- Avoid sending notification to blacklisted recipients when sending email
  in mass mail mode. If the recipient is blacklisted, we should not even send a
  notification in the recipient's chatter for an email that he won't even
  receive.
- When a email address is blacklisted, it can still get 'normal' mailings.
- The blacklist shoud be accessible in
  Mass Mailing / Configuration / Blacklist
  and Settings / Technical / Email / Blacklist
  -> Renaming Settings / Technical / White / Black List config menu item
     into Channel Moderation to avoid confusion with Mass Mail Blacklist
- Add indexes to the blacklist table (on email) to make it fast for access for
  the different use cases
- _primary_email : attribute that must be overriden to specify which field must
  be used as email in the blacklist mechanism.
- Filtering the blacklisted recipient in mail composer :
  done in mail._get mail value()
  In case of real mass mailing, we need the statistics to be computed in order
  to know how many recipients were ignored in the mail.
  So we cannot avoid sending mail but instead flag the mail as canceled.

Task ID 33224
2018-08-10 17:46:08 +02:00
Mathieu Duckaerts-Antoine 299ebb2cdf [IMP] mail: add moderation on channels
Purpose of this commit is to allow moderation on incoming messages in
discussion channels. On some channels on which moderation is required
messages should be in a pending moderation stage. Moderators can accept
or refuse messages as well as always allow or ban messages coming from
a given set of emails.

Channels now have an option to be moderated. Moderators can be added on
channels. They have access to a specific UI in Discuss to see and take
action on messages waiting for moderation.

Concerning mail.thread message that are pending moderation are not notified.
It means nobody receives a notification about them. Moderation process calls
the notification once the message is validated.

Various features included in this commit :

 * a model is added to store the decision about emails, allow or ban;
 * access rights are updated so that only moderators can modify moderation
   fields on message;
 * specific bus notifications are send to moderated people as well as to
   moderators on incoming emails as well as when a decision is taken;
 * options are added on channels to send explanations to moderated emails;
 * options are added on channels to write and send guidelines explaining
   why and how moderation is performed;
 * a reminder is send daily to moderators with remaining messages to moderate;
 * discuss UI is adapted and a new channel is added below Inbox and Starred
   giving access to moderation tools;
 * chanenl UI is adapted allowing to moderate directly inside channels;

This commit is linked to task ID 29521. Closes #21921.
2018-06-06 16:01:33 +02:00
Thibault Delavallée 81d98f32a5 [IMP] mail: improve activity types behavior and access rights
First purpose of this commit is to limit access on activity types.
Employees can now only read activity types. Indeed defining or modifying
activity types should not be done by employees as it impacts daily work
of all other employees. Specific app-based rights are added for project
and sale managers. Those have a specific menu to configure activity
types, meaning they should also have the access rights to do so.

Also including :

 * ease default computation for res_model_id of activity types: using
   default_res_model in context it is possible to specify a default
   res_model_id. It is useful for example to give a specific context
   in configuration menus;
 * add a domain on res_model_id field in order to limit it to models
   inheriting from mail.thread and not being transient;
 * various improvement in activity type form view to ease configuration
   notably the # days renamed to planned in;
2017-12-22 10:30:02 +01:00
Christophe Simonis 2f99470458 [MERGE] forward port branch 11.0 up to c201cf2b77 2017-12-01 12:55:02 +01:00
Christophe Simonis 42264d8dcb [MERGE] forward port branch saas-16 up to 5d7ad2b16c 2017-11-30 18:43:08 +01:00
Christophe Simonis 98539336a5 [MERGE] forward port branch saas-14 up to b780e4a0e4 2017-11-30 14:44:49 +01:00
Christophe Simonis b780e4a0e4 [MERGE] forward port branch 10.0 up to ba73fd534d 2017-11-30 14:13:39 +01:00
Christophe Simonis ba73fd534d [MERGE] forward port branch 9.0 up to fe4bb49b21 2017-11-30 13:55:01 +01:00