96669c74f86cec60ce979fb59da265b1491c2edb
This commit allows to share spreadsheets to other users (public, portal or internal without the required access rights) See Enterprise commit. This commit prepares the ground to sharing `documents.document` spreadsheets. (I expect dashboard spreadsheet sharing in the near future which will use the same generic code) The challenges of sharing odoo spreadsheets ------------------------------------------- Odoo spreadsheets can have any data from the database. ODOO.PIVOT and ODOO.LIST functions specifically can target *any model* and *any field*. The values are dynamically loaded with RPC calls when the spreadsheet is open. Normal access rights apply to load this kind of "embeded" data. A user can open a spreadsheet if he can read the `documents.document` record, but odoo specific functions might result in errors if the user doesn't have the access rights on the underlying model. That's obviously not what we want when sharing a spreadsheet to an external person. We want this person to see the values and not a spreadsheet full of errors. Giving access to external user? --------------------------------- Users must have a very clear understanding what they are "leaking" when they share a spreadsheet. Sharing a spreadsheet should not open any door the user wouldn't think of or wouldn't understand. The best way is to be very strict with the data we are sharing. That means: only the specific models, specific fields and specific records visible in the spreadsheet by the user who is sharing (different users can see different values for the same spreadsheet, depending on their access rights). We also want to consider the following scenario: Alice is a newcomer (with very limited access rights) and she shares a spreadsheet to a customer. A few years later, she is manager and has a lot more access rights (groups, ir.rules, etc.). The forgotten spreadsheet shared years ago should not leak more data because Alice now has access to all company data. Specification ============= With all those challenges in mind, here is a first approach of shared spreadsheet: Readonly freezed spreadsheet for external users ----------------------------------------------- When sharing a spreadsheet, we actually copy and freeze the spreadsheet at that time. Odoo formulas are replaced with their value. This is the easiest and safest way to deal with access rights to other models: there's no access to other models at all ^^ The spreadsheet is displayed in readonly since it would only be editing a copy. If the external person wants data to be updated, he can ask a new sharing link. Read/Write for internal users ----------------------------- The situation for internal users is different. We can rely on their actual access rights. When an internal user opens a spreadsheet sharing link, he is redirected to the regular spreadsheet client action. A token is used to read/write the `documents.document` record (and other linked models such as `spreadsheet.revision`), but the data for pivots, lists, etc. is loaded with the user's own access rights. If the user doesn't have the rights to read a model or field, the function results in an error and that's the expected behavior. This sharing strategy is perfectly fine for all spreadsheets that doesn't contain any odoo data (think of all the Google Sheets we receive internally by email to register to an event or any other stuff). Future work ----------- From a functional point of view, the spec is far from perfect. Users would probably expect the data to "update" itself (not freezed). People will want write access for external users as well. Given the complexity of getting it right (from a tecnical, security and functional POV), this is left for a later work closes odoo/odoo#114040 Task: 3045808 Related: odoo/enterprise#37687 Signed-off-by: Rémi Rahir (rar) <rar@odoo.com>
…
…
Odoo
Odoo is a suite of web based open source business apps.
The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...
Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.
Getting started with Odoo
For a standard installation please follow the Setup instructions from the documentation.
To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials
Languages
Python
49.6%
JavaScript
47.8%
SCSS
2%
CSS
0.3%
HTML
0.2%