The ERP managers (users with 'Access Rights' rights) cannot even click on
the Settings app menuitem. Because of 2 things:
- The Dashboard settings is accessing the model ir_module_module. So
we set a groups 'group_settings' on it.
- The Users view is accessing the model ir_module_category to groups
the aggregate and display the settings. So we change the security rules
by giving the access to the group_erp_manager instead of group_settings
- The global rules opn companies was applied to the erp managers. We
splitted this ir.rules into three new ones on portal,public and employee
users to allow the erp managers to access the companies
- Writing on the res_groups was calling the method _update_user_groups_view
in all the cases. This method should be called only when the view was
needed to be modified, i.e. when the category_id is modified for this
group.