Unify and refactor exception handling in framework and addons. The generic `except_osv` is now deprecated, and replaced by more specialized exception subtypes: - `UserError` (renamed from Warning, as it conflicts with the built-in `Warning`) raised when a non-technical error occurs during a business operation. It could be a missing information in the data provided by the user, or a misconfiguration. - `AccessError`: raised when any operation is denied because the user conducting it does not have the required access rights. - `AccessDenied`: raised when an operation that requires authenticated access is attempted via an unauthenticated request. - `MissingError`: raised when an operation is attempted on a record that does not exist. - `ValidationError`: raised when an operation violates a SQL or Python constraint. - All other exceptions are internal errors due to a system problem or bug, and raised untouched to the client-side, which should display a traceback. All exceptions take a single message argument. The `test_exceptions` module has been updated to showcase both new and old (deprecated) exceptions. A great many old `except_osv` had a useless title with "Error!" or "Warning", those have been removed, as this is handled by the client-side widget that displays the messages. This commit introduces a more consistent policy for logging errors and warnings: - All messages that do not require administrator attention should be logged at INFO level or lower. This includes all errors that are notified to the user in a friendly manner, even for access right problems or validation errors during business operations. - All messages that indicate a likely misconfiguration or malicious use by the users should be logged at WARNING level, as they typically require administrator attention. - All other unhandled internal errors cannot typically be handled by the user and should be logged at ERROR or higher level, as they require immediate administrator attention.
90 lines
4.6 KiB
Python
90 lines
4.6 KiB
Python
# -*- coding: utf-8 -*-
|
|
##############################################################################
|
|
#
|
|
# OpenERP, Open Source Management Solution
|
|
# Copyright (C) 2013-Today OpenERP SA (<http://www.openerp.com>).
|
|
#
|
|
# This program is free software: you can redistribute it and/or modify
|
|
# it under the terms of the GNU Affero General Public License as
|
|
# published by the Free Software Foundation, either version 3 of the
|
|
# License, or (at your option) any later version.
|
|
#
|
|
# This program is distributed in the hope that it will be useful,
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
# GNU Affero General Public License for more details.
|
|
#
|
|
# You should have received a copy of the GNU Affero General Public License
|
|
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
#
|
|
##############################################################################
|
|
|
|
from openerp import SUPERUSER_ID
|
|
from openerp.tools import html2plaintext
|
|
from openerp.tools.translate import _
|
|
from openerp.osv import osv, fields, expression
|
|
from openerp.exceptions import AccessError
|
|
|
|
class MailMessage(osv.Model):
|
|
_inherit = 'mail.message'
|
|
|
|
def _get_description_short(self, cr, uid, ids, name, arg, context=None):
|
|
res = dict.fromkeys(ids, False)
|
|
for message in self.browse(cr, uid, ids, context=context):
|
|
if message.subject:
|
|
res[message.id] = message.subject
|
|
else:
|
|
plaintext_ct = '' if not message.body else html2plaintext(message.body)
|
|
res[message.id] = plaintext_ct[:30] + '%s' % (' [...]' if len(plaintext_ct) >= 30 else '')
|
|
return res
|
|
|
|
_columns = {
|
|
'description': fields.function(
|
|
_get_description_short, type='char',
|
|
help='Message description: either the subject, or the beginning of the body'
|
|
),
|
|
'website_published': fields.boolean(
|
|
'Published', help="Visible on the website as a comment", copy=False,
|
|
),
|
|
}
|
|
|
|
def default_get(self, cr, uid, fields_list, context=None):
|
|
defaults = super(MailMessage, self).default_get(cr, uid, fields_list, context=context)
|
|
|
|
# Note: explicitly implemented in default_get() instead of _defaults,
|
|
# to avoid setting to True for all existing messages during upgrades.
|
|
# TODO: this default should probably be dynamic according to the model
|
|
# on which the messages are attached, thus moved to create().
|
|
if 'website_published' in fields_list:
|
|
defaults.setdefault('website_published', True)
|
|
|
|
return defaults
|
|
|
|
def _search(self, cr, uid, args, offset=0, limit=None, order=None,
|
|
context=None, count=False, access_rights_uid=None):
|
|
""" Override that adds specific access rights of mail.message, to restrict
|
|
messages to published messages for public users. """
|
|
if uid != SUPERUSER_ID:
|
|
group_ids = self.pool.get('res.users').browse(cr, uid, uid, context=context).groups_id
|
|
group_user_id = self.pool.get("ir.model.data").get_object_reference(cr, uid, 'base', 'group_public')[1]
|
|
if group_user_id in [group.id for group in group_ids]:
|
|
args = expression.AND([[('website_published', '=', True)], list(args)])
|
|
|
|
return super(MailMessage, self)._search(cr, uid, args, offset=offset, limit=limit, order=order,
|
|
context=context, count=count, access_rights_uid=access_rights_uid)
|
|
|
|
def check_access_rule(self, cr, uid, ids, operation, context=None):
|
|
""" Add Access rules of mail.message for non-employee user:
|
|
- read:
|
|
- raise if the type is comment and subtype NULL (internal note)
|
|
"""
|
|
if uid != SUPERUSER_ID:
|
|
group_ids = self.pool.get('res.users').browse(cr, uid, uid, context=context).groups_id
|
|
group_user_id = self.pool.get("ir.model.data").get_object_reference(cr, uid, 'base', 'group_public')[1]
|
|
if group_user_id in [group.id for group in group_ids]:
|
|
cr.execute('SELECT id FROM "%s" WHERE website_published IS FALSE AND id = ANY (%%s)' % (self._table), (ids,))
|
|
if cr.fetchall():
|
|
raise AccessError(_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation))
|
|
return super(MailMessage, self).check_access_rule(cr, uid, ids=ids, operation=operation, context=context)
|
|
|