THese are rarely intended for all users but often intended only for employees. account: account.incoterms: only used within internal business models account.journal.group: same as account.journal, add sudo in computed field account_edi: need access to accounting objects base_address_extended: res.city: only employees should access address data board: only employees uses this (old) module crm: crm.stage: internal users business object hr_recruitment: employees can read im_livechat: apply same as for the steps l10n_ar: used on partner, not only invoices l10n_ec: accessed only through account.move l10n_latam: accessed on res.partner mail: publisher.warrenty.contract: no data, only static models mail.channel: group_user has already his own rule mail.group: group_user has already his own rule mail.message.subtype: group_user has already his own rule mail.message.all: remove, already has a portal and employee rule partner_autocomplete: no interaction with public project: project.tags: only needed for project sharing sale_management: sale.order.option: same as sale.order utm: employee already has write access web_editor: test models that have nothing to do here web_tour: only employees uses tours website_sale: product.ribbon: add sudo for access base: ir.default: only employees uses set (could probably be converted to group_system) ir.ui.view.custom: same as ir.ui.view, add sudo when needed report.*: portal users don't configure reports res.users.log: create in sudo, no access needed (adapt test to use another model) res.lang: still needed for public closes odoo/odoo#118701 Related: odoo/enterprise#41285 Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
45 lines
2.0 KiB
Python
45 lines
2.0 KiB
Python
# -*- coding: utf-8 -*-
|
|
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
|
|
|
from lxml import etree as ElementTree
|
|
|
|
from odoo.http import Controller, route, request
|
|
|
|
|
|
class Board(Controller):
|
|
|
|
@route('/board/add_to_dashboard', type='json', auth='user')
|
|
def add_to_dashboard(self, action_id, context_to_save, domain, view_mode, name=''):
|
|
# Retrieve the 'My Dashboard' action from its xmlid
|
|
action = request.env.ref('board.open_board_my_dash_action').sudo()
|
|
|
|
if action and action['res_model'] == 'board.board' and action['views'][0][1] == 'form' and action_id:
|
|
# Maybe should check the content instead of model board.board ?
|
|
view_id = action['views'][0][0]
|
|
board_view = request.env['board.board'].get_view(view_id, 'form')
|
|
if board_view and 'arch' in board_view:
|
|
board_arch = ElementTree.fromstring(board_view['arch'])
|
|
column = board_arch.find('./board/column')
|
|
if column is not None:
|
|
# We don't want to save allowed_company_ids
|
|
# Otherwise on dashboard, the multi-company widget does not filter the records
|
|
if 'allowed_company_ids' in context_to_save:
|
|
context_to_save.pop('allowed_company_ids')
|
|
new_action = ElementTree.Element('action', {
|
|
'name': str(action_id),
|
|
'string': name,
|
|
'view_mode': view_mode,
|
|
'context': str(context_to_save),
|
|
'domain': str(domain)
|
|
})
|
|
column.insert(0, new_action)
|
|
arch = ElementTree.tostring(board_arch, encoding='unicode')
|
|
request.env['ir.ui.view.custom'].sudo().create({
|
|
'user_id': request.session.uid,
|
|
'ref_id': view_id,
|
|
'arch': arch
|
|
})
|
|
return True
|
|
|
|
return False
|