Files
odoo_source/addons/utm/security/ir.model.access.csv
T
Aurélien Warnon 1e25946a76 [IMP] utm: globally improve UTM records management across all apps
PURPOSE

This commit consolidates UTM usage across all applications.

Global purpose is to avoid having undesired side-effects, such as unlinking an
utm.source/utm.medium/utm.campaign and at the same time cascading the deletion
to various records without noticing.

SPECS

ALLOW MORE PEOPLE TO CLEAN UTM RECORDS

Currently, not even the system administrator can delete utm.mediums and
utm.sources (he can only delete campaigns).

These were considered as "technical records", but allowing some cleanup is
a good idea since these records are often automatically generated and can
create a lot of unnecessary noise in the database.

That's why we now allow the following groups to delete all UTM records
(sources, mediums and campaigns):
- group_system
- group_mass_mailing_user
- group_social_manager (enterprise)

PREVENT DELETION

For some use cases, removing an utm.source/utm.medium/utm.campaign would
cascade delete the related record, which was unintended / hidden side effect.

These combinations were secured by preventing to unlink:
- mailing.mailing source_id field
  Trying to delete the utm.source will throw an error message
- mailing.mailing medium_id field
  Trying to delete the utm.medium will throw an error message
- hr.recruitment.source source_id field
  Trying to delete the utm.source will throw an error message

ADDING CLEAN ERROR MESSAGES

When trying to delete an UTM record that is linked with ondelete="restrict", we
improved the error message to give a clear explication to the user, e.g:

"You can't delete these UTM sources as they are linked to the following
mailings in the Mass Mailing APP, and deleting the source would break the
statistics: Newsletter"

SPECIFY 'ondelete' strategy

For a lot of uses of sources/mediums/campaigns, the 'ondelete' strategy was not
specified, leading to the confusion of "is this really how we want to handle
this?".

A lot of ondelete="set null" have been added in various field definitions to
ensure that this is the desired and logical strategy we want for that
specific model.

PREVENT REMOVING HARDCODED UTM RECORDS

In some functional flows, UTM records are hardcoded using their direct
record reference.
This is notably the case for the recruitment process and its creation of
aliases, and for the Email / SMS Marketing flows.

As deleting them would break these flows, we prevent their deletion in a
"api.ondelete" method.

ENFORCE NEW RULES WITH TESTS

A lot of python tests have been added to make sure we enforce the decisions
taken here above.

LINKS

ENT PR odoo/enterprise#19048
Task-2459480

closes odoo/odoo#72239

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-11-23 11:12:04 +00:00

1.1 KiB

1idnamemodel_id:idgroup_id:idperm_readperm_writeperm_createperm_unlink
2access_utm_campaign_useraccess_utm_campaign_usermodel_utm_campaignbase.group_user1110
3access_utm_campaign_systemutm.campaign.systemmodel_utm_campaignbase.group_system1111
4access_utm_medium_useraccess_utm_medium_usermodel_utm_mediumbase.group_user1110
5access_utm_medium_systemutm.medium.systemmodel_utm_mediumbase.group_system1111
6access_utm_source_useraccess_utm_source_usermodel_utm_sourcebase.group_user1110
7access_utm_source_systemutm.source.systemmodel_utm_sourcebase.group_system1111
8access_utm_stage_usermail.utm.stagemodel_utm_stagebase.group_user1000
9access_utm_stage_systemmail.utm.stagemodel_utm_stagebase.group_system1111
10access_utm_campaignaccess_utm_campaignmodel_utm_campaign1010
11access_utm_mediumaccess_utm_mediummodel_utm_medium1010
12access_utm_sourceaccess_utm_sourcemodel_utm_source1010
13access_utm_tag_userutm.tagmodel_utm_tagbase.group_user1000
14access_utm_tag_systemutm.tagmodel_utm_tagbase.group_system1111