View rendering from javascript has recently been made to check permissions (See commits64d0dab0a6throughccc98e0169). Some assets required by the iframe editor are rendered in JS so that they can be injected into the iframe, but their permissions had not been updated, causing a crash when trying to create or edit a mass_mailing campaign. This commit fixes that by adding groups="base.group_user" to the required templates. closes odoo/odoo#51598 Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>