Files
odoo_source/addons/hr/security/hr_security.xml
T
RomainLibert c9ca376146 [IMP] hr: Introduce the public employee profile
Purpose
=======

1/ Robustness & security: right now it is not easy to understand and do something
   clean in term of security (hr people vs employees, private info vs public). A
   HR officer doesn't know if he can write something on the chatter. Currently, a
   note will be visible for all the employees who have access to the employee form
   view for example.
2/ In term of business, it makes sense to let a hr manages payroll stuff (contract,
   employees private information, ... and other employee see public information
   (résumé and work information)

Specification
=============

Introduce 2 new models:

- hr.employee.base (AbstractModel): This represents the basic skeleton
  model on which the shared fields and methods between the public and
  the private employees models.
- hr.employee.public (_auto=False): This is a sql view based on the
  employee values, readable for an internal user (i.e. an employee).

The model hr.employee is not readable anymore for an employee.

There are now 3 ways to access the employee data:
1/ From the hr.employee views. HR officer access rights are required
2/ From the public profile. The public data for an employee are accessible
   but can't be modified.
3/ From the 'My Profile' menu. A classic employee can access its own
   data from there, and can modify them.
2019-05-31 10:21:20 +02:00

59 lines
2.7 KiB
XML

<?xml version="1.0" encoding="utf-8"?>
<odoo>
<record id="base.module_category_human_resources_employees" model="ir.module.category">
<field name="description">Helps you manage your employees.</field>
<field name="sequence">9</field>
</record>
<record id="group_hr_user" model="res.groups">
<field name="name">Officer</field>
<field name="category_id" ref="base.module_category_human_resources_employees"/>
<field name="implied_ids" eval="[(6, 0, [ref('base.group_private_addresses'), ref('base.group_user')])]"/>
<field name="comment">The user will be able to approve document created by employees.</field>
</record>
<record id="group_hr_manager" model="res.groups">
<field name="name">Administrator</field>
<field name="comment">The user will have access to the human resources configuration as well as statistic reports.</field>
<field name="category_id" ref="base.module_category_human_resources_employees"/>
<field name="implied_ids" eval="[(4, ref('group_hr_user'))]"/>
<field name="users" eval="[(4, ref('base.user_root')), (4, ref('base.user_admin'))]"/>
</record>
<data noupdate="1">
<record id="base.default_user" model="res.users">
<field name="groups_id" eval="[(4,ref('group_hr_manager'))]"/>
</record>
<record id="hr_employee_comp_rule" model="ir.rule">
<field name="name">Employee multi company rule</field>
<field name="model_id" ref="model_hr_employee"/>
<field name="global" eval="True"/>
<field name="domain_force">['|',('company_id','=',False),('company_id', 'in', company_ids)]</field>
</record>
<record id="hr_dept_comp_rule" model="ir.rule">
<field name="name">Department multi company rule</field>
<field name="model_id" ref="model_hr_department"/>
<field name="global" eval="True"/>
<field name="domain_force">['|',('company_id','=',False),('company_id', 'in', company_ids)]</field>
</record>
<record id="hr_employee_public_comp_rule" model="ir.rule">
<field name="name">Employee multi company rule</field>
<field name="model_id" ref="model_hr_employee_public"/>
<field name="global" eval="True"/>
<field name="domain_force">['|',('company_id','=',False),('company_id', 'in', company_ids)]</field>
</record>
<record id="hr_job_comp_rule" model="ir.rule">
<field name="name">Job multi company rule</field>
<field name="model_id" ref="model_hr_job"/>
<field name="global" eval="True"/>
<field name="domain_force">['|',('company_id','=',False),('company_id', 'in', company_ids)]</field>
</record>
</data>
</odoo>