Commit Graph
5 Commits
Author SHA1 Message Date
Thibault Delavallée 0ec82bd566 [FIX] sms: ensure group system has full rights on sms.template model
As no global rule is defined for system, people belonging to both system
and a functional group may be limited in their rights about sms templates.

For example install event_sms -> admin is member of system and event manager
groups. He cannot edit templates other than related to event.

With this commit members of system may write, create or unlink all templates
independently from their functinal groups.

Task ID-2495426
Followup of odoo/odoo#64626

closes odoo/odoo#68535

X-original-commit: e0c1563993da918a0fbc2e31a13f3fe6a7ea2916
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-03-30 10:57:12 +00:00
Martin Trigaux 65530dfd6a [ADD] *: add ir.model.access on all transient models
Following changes needing ir.model.access on transient models too.
Remove groups declaration on the action to move it to ir.model.access
when possible.
Rules are strict by default with no unlink access by default and high
priviledge asked. Adaptations may be needed later.
Write access is given as a wizard may need to be modified in case the
action triggers an error and the user has to correct a value

account*: use account.group_account_user for all transient by default
	  remove account.print.journal relic
stock*: use stock.group_stock_user by default
survey: survey user can send invitations
mail: allow any employee to execute wizards
      additional verifications are made to ensure they are executed
      only on the documents the user has access to you
      give portal access to mail.compose.message as portal still does
      some actions like posting messages on the forum
      add ir.rule to avoid reading somebody else messages
      increase the query count because of undeterminist count
crm: saleman for lead2opp, manager for massmailing
     partner manager for actions linked to partners
     avoid a write in test_lead_lost
sms: any employee can send sms
mrp: mrp user can execute wizards
     give unlink access as making write during do_produce operation
base_import: employees can import files
delivery: stock user can deliver
event_sale: sale user can configure the wizards
	    event user inherit from  sale rights
gamification: employee can give badge
google_service: resolve FIXME
hr: add specific rights
    manager can set a plan according to group on button
    anyone who can write on an employee can register a departure
hr_expense: set rights based on buttons
hr_holidays: an approver can make a summary report
hr_recruitment: recruiter can refuse a candidate
hr_timesheet: can use the wizard if can create a timesheet
l10n_eu_service: managers can create fiscal positions
mass_mailing: same group as on mass.mailing.list
membership: accountant can create invoice from membership
payment: accountant can create a link
	 as the source is an account.move
	 keep the payment.acquirer.onboarding.wizard to system user
	 only as it is called during company configuration
point_of_sale: PoS manager only can use wizards
	       never create closing_balance_confirm_wizard records
product_expiry: stock user has rights on stock.picking
product_margin: access from accounting menus
repair: same rules as for above models
sale: set ir.rule for self wizard only
      add rule from model introduced in payment to add salesman group
sale_crm: saleman can create a quotation from a lead
sale_coupon: any saleman can generate coupon
	     add self ir.rule
sale_product_configurator: salesman can select product variants
snailmail: employee can send letters
website: designers can write on website
website_crm_partner_assign: same rule as group on action
website_sale: sale ACL as for payment.acquirer.onboarding.wizard
website_slides: anyone can send invitation

base: base.language.*: allow employee (cf lang_install)
      change.password.user: can not read change password wizard of
      other users
      test.*: no access is needed

Courtesy of Damien Bouvy, William Andre and Antoine Prieëls for review
of acl
2020-02-04 17:54:18 +01:00
Thibault Delavallée 1a8530a178 [FIX] sms: allow system users to unlink sms templates
PURPOSE

Allow people to edit sms templates. Limit that rights to some main
application managers.

SPECIFICATIONS

SMS Template access rights
GROUP-------------R-W-C-D-Note
Internal User-----X
​​​Admin / Settings--X-X-X-X
Stock Manager-----X-X-X-stock.picking
Sales Manager-----X-X-X-crm.lead, res.partner
Event Manager-----X-X-X-event.registration
Sub Manager-------X-X-X-sale.subscription, res.partner
MarkAut Manager---X-X-X-no limit
Account Manager---X-X-X-res.partner (followup)

Other groups
  * Online Appointment NO TEMPLATE USED
  * Accounting Manager NO TEMPLATE USED
  * SMS Marketing NO TEMPLATE USED
  * Studio Automated Action Need Technical Settings Anyway
  * Scheduled Actions Need Technical Settings Anyway
  * Server Action Need Technical Settings Anyway

LINKS

Task 2076366 (send now)
Task 2067873 (template access)
PR #37298
PR odoo/enterprise#5750
2019-09-25 11:13:07 +00:00
Pierre RousseauandThibault Delavallee 9ad7a88a08 [IMP] sms: add SMS template and its support in SMS composer
Purpose of this commit is to provide users templates to use when sending
SMS. It is inspired from what already exists for mail templates. This commit

  * adds templates for SMS

    * users can now create template for SMS Text messages similar to mail
      templates;
    * jinja syntax is supported for body like mail templates, which is why
      templates are linked to a given model;

  * refactor the SMS composer

    * templates are supported in composer like the message composer. This is
      supported only in mass mode to avoid bloating the interface in standard
      composition mode;
    * composer code is rewritten to support various use cases (comment, mass
      sms, numbers, ...) and better fits all use cases;
    * composer is extended to support notably mass SMS without posting messages;

Templates will also be used in a near future in mass sms sending (mass
mailing application improvement) and in marketing automation (for enterprise).
Tests are updated and added to ensure feature works.

Related to task 1922163
Linked to PR #33510

Co-Authored-By: Thibault Delavallee <tde@odoo.com>
Co-Authored-By: Pierre Rousseau <pro@odoo.com>
2019-07-12 14:54:11 +00:00
Thibault DelavalléeandPierre Rousseau bdebcab0ce [REF] sms: refactor message_post using SMS notifications
Purpose of this commit is to better include SMS notifications when posting a
message. SMS is now just another way of notifying people along with Inbox and
email. Following recent mail merge improving notification mechanism [1] we
have to define a _notify_record_by_sms method on mail.thread.

When a message_post is done using message_type being ``sms`` notification type
of customers is set to sms. Customers can be computed on model (generally based
on partner_id field) or directly set usign partner°ids. Notification model is
updated to store this information directly inside the notification itself.

An new ``_message_sms`` helper method is introduced in SMS module allowing
to send messages using sms type and notification with a reduced parameters
number. It is just a shortcut to message_post, easier to use. Either it
computes default recipients on the record set, either it is based on given
partners and numbers to notify.

The following use cases are notably supported

  * default computation: find customer, notify by sms;
  * force recipients to notify by sms (partner_ids);
  * give a set of numbers to notify by sms (sms_nubmers), not necessarily
    linked to existing partners;
  * force number / customer relationship independently of mobile number defined
    on customer (for example when sending an SMS directly from a mobile field
    on a lead linked to a customer);

Tests are updated accordingly. Performance tests are added in order to have
some insights on queries generated when sending SMS, like already done for
mail.thread alone.

Related to task 1922163
Linked to PR #33510

[1] see be27955136: performance and notification code improvements

Co-Authored-By: Thibault Delavallee <tde@odoo.com>
Co-Authored-By: Pierre Rousseau <pro@odoo.com>
2019-07-12 14:54:11 +00:00