In mail, changing the setting "Restrict mail templates edition and
QWEB placeholders usage" to false should remove all users but admins
from the group, including the template user.
Before this commit, you could have weird behaviou such as
1. Disable the restrictiong (group_mail_template_editor in
group_user.implied_ids)
2. Install mass_mailing (group_mail_template_editor in
group_mass_mailing_user.implied_ids)
3. Create a user test with minimum employee roles (still has
group_mail_template_editor as employee)
4. Check the box "Restrict mail templates edition and QWEB
placeholders usage"
-> test still has the template group nothing implied it
The issue was a combinaison of recomputation of implied groups
https://github.com/odoo/odoo/blob/b2f760cae74201d1622e56a0027dae67dcff9e33/odoo/addons/base/models/res_users.py#L1292-L1295
that triggered the synchronisation of groups on template user
https://github.com/odoo/odoo/blob/b2f760cae74201d1622e56a0027dae67dcff9e33/odoo/addons/base/models/res_users.py#L611-L616
By removing the users already in a group, we avoid falling into the
condition added at 121cd0d608 where the default user gets a
group removed, readded, hence added for everybody.
closes odoo/odoo#115108
X-original-commit: 6398dd287f07641c85807f291d9fe078fcb8a231
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
38 lines
1.6 KiB
Python
38 lines
1.6 KiB
Python
# -*- coding: utf-8 -*-
|
|
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
|
|
|
from odoo import api, models
|
|
|
|
|
|
class IrConfigParameter(models.Model):
|
|
_inherit = 'ir.config_parameter'
|
|
|
|
@api.model_create_multi
|
|
def create(self, vals_list):
|
|
for vals in vals_list:
|
|
if vals.get('key') in ['mail.bounce.alias', 'mail.catchall.alias']:
|
|
vals['value'] = self.env['mail.alias']._clean_and_check_unique([vals.get('value')])[0]
|
|
return super().create(vals_list)
|
|
|
|
def write(self, vals):
|
|
for parameter in self:
|
|
if 'value' in vals and parameter.key in ['mail.bounce.alias', 'mail.catchall.alias'] and vals['value'] != parameter.value:
|
|
vals['value'] = self.env['mail.alias']._clean_and_check_unique([vals.get('value')])[0]
|
|
return super().write(vals)
|
|
|
|
@api.model
|
|
def set_param(self, key, value):
|
|
if key == 'mail.restrict.template.rendering':
|
|
group_user = self.env.ref('base.group_user')
|
|
group_mail_template_editor = self.env.ref('mail.group_mail_template_editor')
|
|
|
|
if not value and group_mail_template_editor not in group_user.implied_ids:
|
|
group_user.implied_ids |= group_mail_template_editor
|
|
|
|
elif value and group_mail_template_editor in group_user.implied_ids:
|
|
# remove existing users, including inactive template user
|
|
# admin will regain the right via implied_ids on group_system
|
|
group_user._remove_group(group_mail_template_editor)
|
|
|
|
return super(IrConfigParameter, self).set_param(key, value)
|