For bugfix purposes, app administration groups have been given to (implied by) the "Settings" group because without those rights, opening/saving the settings crashed. 1) Do not load hidden view content This commit uses the conditional inheritance of views (depending on user groups) to avoid loading unnecessary view & record content client-side. This improves performance for admins without the specific application admin rights, but also fixes the main bugfix problem, caused by the webclient querying name_get for the records in relational fields content. Example: sale_management adds a res.config.settings field to specify the default sale.order.template for the current company. If a 'Settings' user without 'sale.group_sale_manager' opens the settings, he won't see this setting, but if a default template is specified for the current company, the webclient will still request the name_get of this template to the server, because the field was present in the view, only hidden with a groups attribute. With this commit change in sale, the field won't be in the view unless you have the Sale manager group, avoiding the error/traceback/bug. 2) Remove implied application administration groups Do not force the specific application groups on all 'Settings' user, they globally do not need those rights, and if they need it, they can add it to their account themselves. 3) Add a test to make sure settings user are able to manage settings. 4) Enforce 'settings' -> 'access rights' -> 'internal user' groups As the previous test highlighted some 'false positives' because it considered a settings user unable to read `crm.team` and `stock.warehouse` records, we also took the opportunity to enforce the fact that 'Settings' & 'Access rights' users must be internal users. It makes no sense for a portal/public user to have access to the settings, and didn't work anyway. Part-of: odoo/odoo#91909
110 lines
5.1 KiB
XML
110 lines
5.1 KiB
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<odoo>
|
|
<data noupdate="0">
|
|
|
|
<record id="base.module_category_manufacturing_manufacturing" model="ir.module.category">
|
|
<field name="description">Helps you manage your manufacturing processes and generate reports on those processes.</field>
|
|
<field name="sequence">5</field>
|
|
</record>
|
|
|
|
<record id="group_mrp_user" model="res.groups">
|
|
<field name="name">User</field>
|
|
<field name="implied_ids" eval="[(4, ref('stock.group_stock_user'))]"/>
|
|
<field name="category_id" ref="base.module_category_manufacturing_manufacturing"/>
|
|
</record>
|
|
<record id="group_mrp_manager" model="res.groups">
|
|
<field name="name">Administrator</field>
|
|
<field name="category_id" ref="base.module_category_manufacturing_manufacturing"/>
|
|
<field name="implied_ids" eval="[(4, ref('group_mrp_user'))]"/>
|
|
<field name="users" eval="[(4, ref('base.user_root')), (4, ref('base.user_admin'))]"/>
|
|
</record>
|
|
|
|
|
|
<record id="group_mrp_routings" model="res.groups">
|
|
<field name="name">Manage Work Order Operations</field>
|
|
<field name="category_id" ref="base.module_category_hidden"/>
|
|
</record>
|
|
|
|
<record id="group_mrp_byproducts" model="res.groups">
|
|
<field name="name">Produce residual products</field>
|
|
<field name="category_id" ref="base.module_category_hidden"/>
|
|
</record>
|
|
|
|
<record id="group_unlocked_by_default" model="res.groups">
|
|
<field name="name">Unlocked by default</field>
|
|
<field name="category_id" ref="base.module_category_hidden"/>
|
|
</record>
|
|
|
|
<record id="group_mrp_reception_report" model="res.groups">
|
|
<field name="name">Use Reception Report with Manufacturing Orders</field>
|
|
<field name="category_id" ref="base.module_category_hidden"/>
|
|
</record>
|
|
|
|
<record id="group_mrp_workorder_dependencies" model="res.groups">
|
|
<field name="name">Use Operation Dependencies</field>
|
|
<field name="category_id" ref="base.module_category_hidden"/>
|
|
</record>
|
|
|
|
</data>
|
|
<data noupdate="1">
|
|
<record id="base.default_user" model="res.users">
|
|
<field name="groups_id" eval="[(4,ref('mrp.group_mrp_manager'))]"/>
|
|
</record>
|
|
<!-- Multi -->
|
|
<record model="ir.rule" id="mrp_production_rule">
|
|
<field name="name">mrp_production multi-company</field>
|
|
<field name="model_id" search="[('model','=','mrp.production')]" model="ir.model"/>
|
|
<field name="domain_force">[('company_id', 'in', company_ids)]</field>
|
|
</record>
|
|
|
|
<record model="ir.rule" id="mrp_unbuild_rule">
|
|
<field name="name">mrp_unbuild multi-company</field>
|
|
<field name="model_id" search="[('model','=','mrp.unbuild')]" model="ir.model"/>
|
|
<field name="domain_force">[('company_id', 'in', company_ids)]</field>
|
|
</record>
|
|
|
|
<record model="ir.rule" id="mrp_workcenter_rule">
|
|
<field name="name">mrp_workcenter multi-company</field>
|
|
<field name="model_id" search="[('model','=','mrp.workcenter')]" model="ir.model"/>
|
|
<field name="domain_force">['|',('company_id', 'in', company_ids),('company_id','=',False)]</field>
|
|
</record>
|
|
|
|
<record model="ir.rule" id="mrp_workorder_rule">
|
|
<field name="name">mrp_workorder multi-company</field>
|
|
<field name="model_id" search="[('model','=','mrp.workorder')]" model="ir.model"/>
|
|
<field name="domain_force">[('company_id', 'in', company_ids)]</field>
|
|
</record>
|
|
|
|
<record model="ir.rule" id="mrp_bom_rule">
|
|
<field name="name">mrp_bom multi-company</field>
|
|
<field name="model_id" search="[('model','=','mrp.bom')]" model="ir.model"/>
|
|
<field name="domain_force">['|',('company_id', 'in', company_ids),('company_id','=',False)]</field>
|
|
</record>
|
|
|
|
<record model="ir.rule" id="mrp_bom_line_rule">
|
|
<field name="name">mrp_bom_line multi-company</field>
|
|
<field name="model_id" search="[('model','=','mrp.bom.line')]" model="ir.model"/>
|
|
<field name="domain_force">['|',('company_id', 'in', company_ids),('company_id','=',False)]</field>
|
|
</record>
|
|
|
|
<record model="ir.rule" id="mrp_bom_byproduct_rule">
|
|
<field name="name">mrp_bom_byproduct multi-company</field>
|
|
<field name="model_id" search="[('model','=','mrp.bom.byproduct')]" model="ir.model"/>
|
|
<field name="domain_force">['|',('company_id', 'in', company_ids),('company_id','=',False)]</field>
|
|
</record>
|
|
|
|
<record model="ir.rule" id="mrp_routing_workcenter_rule">
|
|
<field name="name">mrp_routing_workcenter multi-company</field>
|
|
<field name="model_id" search="[('model','=','mrp.routing.workcenter')]" model="ir.model"/>
|
|
<field name="domain_force">['|',('company_id', 'in', company_ids),('company_id','=',False)]</field>
|
|
</record>
|
|
|
|
<record model="ir.rule" id="mrp_workcenter_productivity">
|
|
<field name="name">mrp_workcenter_productivity multi-company</field>
|
|
<field name="model_id" search="[('model','=','mrp.workcenter.productivity')]" model="ir.model"/>
|
|
<field name="domain_force">[('company_id', 'in', company_ids)]</field>
|
|
</record>
|
|
|
|
</data>
|
|
</odoo>
|