Files
odoo_source/addons/project_mail_plugin/controllers/mail_plugin.py
T
std-odoo 5dd6c1f1d3 [FIX] *_mail_plugin: hide modules if the user doesn't have access
Bug
===
If the user doesn't have access to the project / CRM module, those
menus were visible on the addin side.

Now, the sections are not visible if the user doesn't have access to.

Task-2765323

closes odoo/odoo#89260

X-original-commit: 7b7aa72ecdc7e69e425ae08c28e1e7827e423548
Related: odoo/enterprise#26446
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2022-04-21 13:55:08 +02:00

61 lines
2.4 KiB
Python

# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
import logging
from odoo.http import request
from odoo.addons.mail_plugin.controllers import mail_plugin
_logger = logging.getLogger(__name__)
class MailPluginController(mail_plugin.MailPluginController):
def _get_contact_data(self, partner):
"""
Overrides the base module's get_contact_data method by Adding the "tasks" key within the initial contact
information dict loaded when opening an email on Outlook.
This is structured this way to enable the "project" feature on the Outlook side only if the Odoo version
supports it.
Return the tasks key only if the current user can create tasks. So, if he can not
create tasks, the section won't be visible on the addin side (like if the project
module was not installed on the database).
"""
contact_values = super(MailPluginController, self)._get_contact_data(partner)
if not request.env['project.task'].check_access_rights('create', raise_exception=False):
return contact_values
if not partner:
contact_values['tasks'] = []
else:
partner_tasks = request.env['project.task'].search(
[('partner_id', '=', partner.id)], offset=0, limit=5)
accessible_projects = partner_tasks.project_id._filter_access_rules('read').mapped("id")
tasks_values = [
{
'task_id': task.id,
'name': task.name,
'project_name': task.project_id.name,
} for task in partner_tasks if task.project_id.id in accessible_projects]
contact_values['tasks'] = tasks_values
return contact_values
def _mail_content_logging_models_whitelist(self):
models_whitelist = super(MailPluginController, self)._mail_content_logging_models_whitelist()
if not request.env['project.task'].check_access_rights('create', raise_exception=False):
return models_whitelist
return models_whitelist + ['project.task']
def _translation_modules_whitelist(self):
modules_whitelist = super(MailPluginController, self)._translation_modules_whitelist()
if not request.env['project.task'].check_access_rights('create', raise_exception=False):
return modules_whitelist
return modules_whitelist + ['project_mail_plugin']