Coming from a bug in web_settings_dashboard. Invited user didn't have any rights when created from the dashboard, which was leading to an error. This bug leaded to a new discussion. Better to have basic employee having user rights for all main applications. For bigger entreprises there is an admin that will carefully remove extra rights, if necessary. The target is small businesses, it makes sense that every way to create a user gives the same result. In conclusion, each new user has a full access to the applications by default How is it implemented ? We added an inactive default user which original access right to the groups 'base.group_user' and 'base.group_partner_manager' in base. Each application will extend the default user's access right by adding the maximal access right for this application. On user creation, we will use by default the 'group_id' field from the default user. We will in the same time remove the ugly 'default_groups_ref' key which was passed sometimes in the context for some fields in some views, and sometimes nothing. So, the user can modify the access rights for the default user, but he should be aware that removing project user access rights for a default user will prevent a *created on the fly in a task* user will not be able to access the task.
80 lines
3.7 KiB
XML
80 lines
3.7 KiB
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<openerp>
|
|
<data noupdate="1">
|
|
<!-- Survey users -->
|
|
<record model="res.groups" id="base.group_survey_user">
|
|
<field name="name">User</field>
|
|
<field name="category_id" ref="base.module_category_survey"/>
|
|
</record>
|
|
|
|
<!-- Survey managers -->
|
|
<record model="res.groups" id="base.group_survey_manager">
|
|
<field name="name">Manager</field>
|
|
<field name="category_id" ref="base.module_category_survey"/>
|
|
<field name="implied_ids" eval="[(4, ref('base.group_survey_user'))]"/>
|
|
<field name="users" eval="[(4, ref('base.user_root'))]"/>
|
|
</record>
|
|
|
|
<record id="base.default_user" model="res.users">
|
|
<field name="groups_id" eval="[(4,ref('base.group_survey_manager'))]"/>
|
|
</record>
|
|
|
|
<!-- Record rules -->
|
|
<record id="survey_users_access" model="ir.rule">
|
|
<field name="name">Access to survey for regular users</field>
|
|
<field name="model_id" ref="survey.model_survey_survey"/>
|
|
<field name="domain_force">[('stage_id.closed', '=', False)]</field>
|
|
<field name="groups" eval="[(4, ref('base.group_survey_user'))]"/>
|
|
<field eval="0" name="perm_unlink"/>
|
|
<field eval="0" name="perm_write"/>
|
|
<field eval="1" name="perm_read"/>
|
|
<field eval="0" name="perm_create"/>
|
|
</record>
|
|
|
|
<record id="survey_manager_access" model="ir.rule">
|
|
<field name="name">Survey Manager access rights</field>
|
|
<field name="model_id" ref="survey.model_survey_survey"/>
|
|
<field name="domain_force">[(1, '=', 1)]</field>
|
|
<field name="groups" eval="[(4, ref('base.group_survey_manager'))]"/>
|
|
<field eval="1" name="perm_unlink"/>
|
|
<field eval="1" name="perm_write"/>
|
|
<field eval="1" name="perm_read"/>
|
|
<field eval="1" name="perm_create"/>
|
|
</record>
|
|
|
|
<record id="survey_input_public_access" model="ir.rule">
|
|
<field name="name">Public access to user_input</field>
|
|
<field name="model_id" ref="survey.model_survey_user_input"/>
|
|
<field name="domain_force">[('create_uid', '=', user.id)]</field>
|
|
<field name="groups" eval="[(4, ref('base.group_public'))]"/>
|
|
<field eval="0" name="perm_unlink"/>
|
|
<field eval="0" name="perm_write"/>
|
|
<field eval="1" name="perm_read"/>
|
|
<field eval="0" name="perm_create"/>
|
|
</record>
|
|
|
|
<record id="survey_input_users_access" model="ir.rule">
|
|
<field name="name">Access to user_input for regular users</field>
|
|
<field name="model_id" ref="survey.model_survey_user_input"/>
|
|
<field name="domain_force">['|', ('create_uid', '=', user.id), ('partner_id', '=', user.partner_id.id)]</field>
|
|
<field name="groups" eval="[(4, ref('base.group_survey_user'))]"/>
|
|
<field eval="0" name="perm_unlink"/>
|
|
<field eval="0" name="perm_write"/>
|
|
<field eval="1" name="perm_read"/>
|
|
<field eval="0" name="perm_create"/>
|
|
</record>
|
|
|
|
<record id="survey_input_manager_access" model="ir.rule">
|
|
<field name="name">Survey Manager access rights</field>
|
|
<field name="model_id" ref="survey.model_survey_user_input"/>
|
|
<field name="domain_force">[(1, '=', 1)]</field>
|
|
<field name="groups" eval="[(4, ref('base.group_survey_manager'))]"/>
|
|
<field eval="1" name="perm_unlink"/>
|
|
<field eval="1" name="perm_write"/>
|
|
<field eval="1" name="perm_read"/>
|
|
<field eval="1" name="perm_create"/>
|
|
</record>
|
|
|
|
</data>
|
|
</openerp>
|