Show the purchase orders which are in state "RFQ sent" on the portal
using two separate blocks (Requests for Quotation & Purchase Orders)
as done in Sales (Quotations & Sales Orders)
closesodoo/odoo#61035
Task: 2035476
Signed-off-by: William Henrotin <Whenrow@users.noreply.github.com>
What are the steps to reproduce your issue ?
1. Create two companies on a multi-company database without Website installed.
For this use case, install Purchase
2. Configure two distinct logos per company
3. Create a Purchase Order with the second company.
4. Send PO from second company over as email.
5. Check recipient email (or mailhog for Runbot) for the email
6. Find that while the PDF report reflects second company's logo,
the header navigation bar in the client email when clicking "View Request
for Quotation" reflects company_id=1's logo.
What is currently happening ?
The displayed logo is not the correct one.
What are you expecting to happen ?
Display the right logo.
Why is this happening ?
Because when rendering the view. The value of 'res_company' declared in the context has as value the id of the default company of the user
How to fix the bug ?
Specify the current company.
opw-2380274
closesodoo/odoo#62066
X-original-commit: 044bca5e64451d86c6f7c9dbb919c0c319a37bd5
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
Signed-off-by: Achraf <abz-odoo@users.noreply.github.com>
- Install account / purchase / sale
- Ceate an internal user without any access rights
- Go to `/my`
A 500 error is raised because of an AccessError.
When the user has no access rights to any of the mentioned applications,
the `search` call returns an AccessError.
We prevent the access error and return 0 as a fallback.
opw-2367559
closesodoo/odoo#60849
X-original-commit: 54ef98c613219aba3bda41817f7767261b8092d2
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
This commit adapts the business code in which
class/module/function/method redefinition took place so that it no
longer happens and the pylint test passes.
PURPOSE
Clean code and be and more performance oriented.
SPECIFICATIONS
Various portal pages hold references to archive_groups. It was a summary
of customer documents for portal, containing a count of all documents split
by model.
Currently its computation is not used. Indeed archive_groups is displayed
only in 'my_details' page that does not hold any document-based reference
or code call. Other calls to archive_groups are dead code as the result is
not used. Since 13.0 it is even not computed on standard pages to speedup
their load (as it was not used).
It is not used anymore and its computation and references can be removed
safely, especially with v14 in mind for which we want to remove dead code
to maintain.
Followup of odoo/odoo#55228
LINKS
Task ID-2329081
PR odoo/odoo#55800
PR #12368closesodoo/odoo#56859
X-original-commit: e75086000ee4317b2ad2994db5d906fbcbd5081f
Related: odoo/enterprise#12830
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
- Avoid to truncate the hour/min/sec in the computation of the
effective date which is related to the `date_done`
of the first incoming picking.
- With manufacturing in 3-step (pbm_sam), the store picking
had a source document == "New". It was the case because
the `_get_move_finished_values` was call before the create
and the name is set only on create.
To fix this issue, during the `create` set the origin of all move.
- To avoid to maintain old views unused,
remove unused view of stock move.
- The computation of the products_availability json is too expensive
to be in tree view (2.5 times long with it) of picking.
It will be hard to optimize because the half the time
is due to _get_report_lines method - already in batch (on 80 records).
- Review buttons of the replenishment list to be more Odooer.
- In some cases the delay alert date was wrongly compute:
- If we new dest_move_ids of a existant move, the delay alert date
won't be compute.
- If the state (to done) and the date are save in same write call
the alert date of next move won't be reset.
To avoids these issues, refactor the alert date to be a compute stored
fields.
- To avoid any confusion between date expected in the replenishement
(in date) and the purchase order receipt date (datetime),
we put the receipt date at the middle of the day.
Also On-Time Delivery Rate computation counts
only when date are bigger effective date trunced to date.
Also used the timezone of the company by default (if not user timezone)
task-2246665
closesodoo/odoo#55379
Related: odoo/upgrade#1586
Related: odoo/enterprise#12309
Signed-off-by: Arnold Moyaux <amoyaux@users.noreply.github.com>
Before this commit, the time to compute all counters was making the rendering
of the portal page slow.
Now the count is done in rpc after the loading of the page.
Now you can decide which part you want to show on the portal, and only compute
for these one.
It is not because you have purchase installed for your internal process, that
it means that your supplier use your portal and it avoid the computation for
all end users.
We parallelize the counters in arbitrary 3 rpcs.
closesodoo/odoo#55999
Related: odoo/enterprise#12456
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
The archive groups feature allows the user to have fast access to
records of a given month, under its details information.
But since the details section isn't shown anymore on portal sub-pages,
the feature is computed for nothing on (most) pages.
Removing this computation avoids a read_group call on portal subpages
(multiple potential queries).
This commit disables the feature until a total removal in master.
my_details is only truthy on the /my/account portal page, where no
archive_groups is given anyway (and the value is set to True only in the
rendered tempate itself).
X-original-commit: 40c57fafdd5651a522891ab68affe38933ea5202
The record counts are only useful for the badges displayed in /my &
/my/home.
By avoiding those counts on subpages, we gain a lot of useless queries,
improving the loading speed of those sub-pages.
X-original-commit: 79c8384f1bcbcdede030e187008319a70c664571
1. Show only date not datetime on update portal. When update the
scheduled date, set it to be the last minute of that date.
2. Send updated date immediately when user pick a date.
3. If an activity for update the date already exist, update the
note instead of creating a new one.
Task #2265912
PR 52809
1. automatically send a reminder mail to vendor to confirm the receipt
date. If confirmed, (confirmed by vendor) will be added next to the
receipt date. If not, vendor can update the date on the portal website.
An warning activity will be set for the purchase representative for this
update.
2. Vendor can also comfirm recieption of the PO when we 'send PO by mail'.
If confirm, (confirmed by vendor) will be added next to the confirmation
date. An filter is added in the PO search view to show all unconfirmed
PO.
Task 2230811
PR #49921
Signed-off-by: Simon Lejeune (sle) <sle@openerp.com>
This commit splits the _content_image method to allow to call the
get response part individually.
This is needed because _content_image call binary_content using current user
access. But in some cases, we need to render a binary content even if the user
does not have access to the target model (typically for public users).
The binary_content is gotten in sudo mode where needed and the result can be
given to the _content_image_get_response.
This will avoid code duplication where the sudo use case is met.
Usage :
This commit prepare the redesign of survey. This _content_image_get_response
method will be called to grant access of background image even for public
users. Other modules will use this new method like elearning (website_slides)
to display karma ranking, etc.
Task ID: '2150291'
PR #43237
on the portal:
- in Timesheets, when search something, the text of the search must remain displayed
- in Tasks, when search something, the text of the search must remain displayed
- in Purchase Orders, "Sort By" and "Filter By" selectors shouldn't change when going to next page
- in Timesheets, the "Group By" selector shouldn't change when going to next page
closesodoo/odoo#40278
Related: odoo/enterprise#6787
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
Purpose
=======
This fix makes no sense because it exposes some private data to
portal users. Fortunately it was only introduced in the master branch.
closesodoo/odoo#40710
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
* = hr, im_livechat, mail, payment, purchase, web, web_editor, web_unsplash,
website_profile, website_slides
Since the merge of all image tools into one function, the intermediary functions
are not needed anymore.
task-1958000
PR: #31811
When a user accesses a PO through the portal thanks to an access token
(without being connected), the product image on each order line is
rendered using the image placeholder with a size of 48x48.
This raises a 403 Forbidden at image retrieval since the access token is
not passed as a parameter. This commit corrects that behavior by sending
the resized image along with the rendering of the template instead of an
url.
Another solution could be to generalize the access token check to any
model in:
https://github.com/odoo/odoo/blob/12.0/odoo/addons/base/models/ir_http.py#L303-L311
But this seems overkill regarding this specific error.
opw-1902741
closesodoo/odoo#28479
Before this commit, the method _document_check_access would succeed if it was called with a non-existing id.
Now it will raise a MissingError.
PR: none
Task: none
The list of visible records are anyway based on access_rights.
State has been removed from the domain.
If the portal must be customized for a model,
access rights / rules can be added to do so.
Task ID : 30985
Purpose
=======
- Quickly share the url to someone else (a client, a colleague,...)
- Ensure that the recipient can access at least
the portal view of the shared record.
- Typically used when a client cannot retrieve the mail to access his order.
The share link can be used in this case.
Specifications
==============
For any object inheriting form portal.mixin:
- Add a button SHARE (not visible in edit mode)
- When clicking on this button, a popup opens with :
- A warning message for tasks and projects only (see below)
- the link (like in gmail) that can be copied
- Recipients
- mail composer (with preselected template) ==> see below
- button [Send Link] [Copy Link] Discard
- After sharing document, put internal note like
"Document shared to xyz,...." with template message
- Anyone with the link, even anonymous user (not logged in) can have access
to the document with the access token provided in the url.
Impacted models:
- account.invoice (Community)
- project.project (Community)
- project.task (Community)
- purchase.order (Community)
- sale.order (Community)
- helpdesk.ticket (Enterprise)
Warning messages and access rules:
Allowed :
- SO canceled or draft will be accessible with the link
with access_token
- If the customer account is B2B (signup not enabled), the recipient
will anyway see the document as the user specifically wants the
recipient to see the document.
Restrictions :
- For Project and Task, if the privacy is not public, then, there is a
contradiction between the access_token mechanism
and the privacy of the document.
- A warning message will be displayed in the share wizard to inform the
user if the document cannot be visible by the recipients and to
ask him to set the privacy to 'Visible by following customer'.
The send button will, in that case, be hidden.
- To avoid to block the share for a new project, default privacy value
is now set to 'Visible by followong customer'
Technical implementation
========================
- Move the access_token mechanism (field + methods + mail controller)
to the portal.mixin to be able to use it in a generic way for each object
inheriting the portal.mixin
- Generalise a part of the _*model*_get_page_view_values method
into a single one in portal
- Generalize the _*model*_check_access into the portal controller of the
portal module
- Remove the init_column + default value for the access_token
> old records have an access_token,
> new one won't but it will be generated on demand via the get_access_token
Done for performance reasons
- Add share button into action menu separately. + kanban view context menu
(except for task and project where button not in action menu but 'simple'
button for task and project because other modules already provide action
to send documents by email, which is not the case for project and task.)
- Add a sign_token used to authentify the recipient in the portal view chatter,
if any. The message will be posted as if the user was logged in.
- Set the _get_share_url as private for security reason
- Add a redirect parameter to _get_share_url to get
If false : The direct portal view url
If True : The redirect url (mail/view/?)
- Cleaning up unnecessary code
- Bug fix :
- Before, if user was not logged and record had partner_id,
if partner id was null, post message was done as admin.
Now, the post message is done as public user.
- If the user had an uid but had no access_token, he could be able
to gain the access token of the record.
check_access_rights was missing in the get_access_action.
Task ID : 30985
Closes#25629