Files
odoo_source/addons/mail/security/ir.model.access.csv
T
0903ef7bb2 [MOV] *: move all PWA to community
In this commit, we moved all features related to the PWA and the PWA
itself to the community.

This includes:
* PWA
* Web Push Notification
* VCARD

Note from original commits:
===========================

PWA (part 1)
------------
This commit adds a ServiceWorker to complement the WebManifest to
complete the setup of the backend as a Progressive Web App.

More precisely, it adds the route, registration and the most basic
ServiceWorker to allow the backend to be recognized as an installable
PWA.

References:
- https://web.dev/install-criteria/
- https://developer.mozilla.org/en-US/docs/Web/Progressive_web_apps/Installable_PWAs
- https://developer.mozilla.org/en-US/docs/Web/API/Service_Worker_API/Using_Service_Workers

Task ID: 3063485

PWA (part 2)
------------
This commit adds a WebManifest as a first step toward setuping the
backend as a Progressive Web App.

In a nutshell:
- the web app's name is configurable through a config parameter
  (available in the Settings, in debug); defaulting to "Odoo".
- the web app's icon has been revamped to accommodate the required sizes;
  also its design matches the one from the Android app.
- "theme-color" is used to color part of the browser/system UI to match
  Enterprise brand color; also supports the dark mode.

References:
- https://web.dev/learn/pwa/web-app-manifest/
- https://web.dev/install-criteria/
- https://developer.mozilla.org/en-US/docs/Web/Manifest

Task ID: 3063485

PWA shortcuts
-------------
The main goal of this commit is like we did inside the `Android Odoo
Mobile App`, allowing users to have some Odoo application shortcuts.
We added the following apps in the key `shortcuts` on `web.manifest` in
these orders: `Discuss`, `CRM`, `Project`, `To-Do` (old `Notes`).

Links:
- https://w3c.github.io/manifest/#shortcuts-member
- https://developer.mozilla.org/en-US/docs/Web/Manifest/shortcuts

Task ID: 3123607

Offline mode
------------
This commit introduces a way to notify the user that he's "offline"
(aka. cannot reach its Odoo server) and that Odoo doesn't work in a
graceful way in this circumstance.

To do so, the Service-Worker will return the response of the
´web/offline´ route, which is cached at its setup.

Note: this screen is only show when launched while "offline" and fails
to load the requested page. It does not "interrupt" the WebClient to
show this screen when the connection drops off (cf. not a replacement
for the existing notification).

Task ID: 3203639

WebPush
-------

WebPush allows sending data to the user browser/app(PWA) even when
tab/app is closed. Web push is a "constant" link between the
ServiceWorker of browser/app and a WebPush server.

Note that each browser has its own custom WebPush server.
e.g.:
Chrome: https://fcm.googleapis.com/
Firefox: https://updates.push.services.mozilla.com/
Safari: https://web.push.apple.com/
Edge: https://wns2-ln2p.notify.windows.com/
WebPush introduces some cryptographic notion to ensure some the
reliability of the data sent:

VAPID: "Voluntary Application Server Identification" is the standard
used to generate the public and the private to sign the message
between the browser and the WebPush server
JWT: "JSON Web Token" is the standard used to sign the payload to the
WebPush server
ECE: "Encrypted Content-Encoding" is the standard used by WebPush to
encrypt the data of the payload to avoid sending RAW data
outside trusted network.
Simplified steps how to WebPush works:

The Javascript code of a web page subscribes to the WebPush server
(using the VAPID key generated at mail_entreprise install).
The WebPush server replay with a subscription (and some other info
like the unique URL endpoint per subscription where to send a
notification)
The application (odoo-bin in our case) sends a post request to the
WebPush server using the specific URL endpoint of the user (using JWT
and ECE).
The WebPush server sends back to the browser the encrypted payload.
The browser decrypts the payload and sends it to the ServiceWorker
linked to the subscription.
Here is a Sequence diagram of all interactions to process a web push
notification.
In Odoo, we use WebPush to send Notification to the user.

This commit aims to have a parity with the Android/iOS Mobile App at
the notification level.

Notes:

There are some ways to encrypt (ECE) the message for WebPush:

AESGCM128: this is a draft
AESGCM: very well documented
AES128GCM: RFC8188 Standard encoding
We implement only the RFC one as it is the only one implemented in all
major updated browsers (Chrome, Firefox, Safari, Edge, ...)
You need to allow the desktop "Notification" and "Push" inside your
browser. For iOS Devices, it only works on iOS 16.4+ and it's requiring
Odoo to first be added to the Home Screen. It's delivered silently,
meaning no sound, vibration, haptics or screen wake.

Note:
Notifications are sent directly if there are less than five
notifications, otherwise we use a cron triggered immediately.
Also, we have changed the value of the "QueryCount" as mail_enterprise
executes a new query to search the devices associated with the partner.

We have added a "try/except" for any Exception before the
push_to_end_point method as we want to avoid blocking a normal flow
just for a not mandatory push notification if something happens during
the push to the endpoint.
See: odoo/enterprise@d0ae70103d

Links:
https://www.rfc-editor.org/rfc/rfc8030
https://www.rfc-editor.org/rfc/rfc8188
https://www.rfc-editor.org/rfc/rfc8291
https://www.rfc-editor.org/rfc/rfc8292
https://w3c.github.io/push-api/index.html
https://autopush.readthedocs.io/en/latest/http.html
https://web.dev/push-notifications-web-push-protocol/
https://github.com/web-push-libs/encrypted-content-encoding
https://github.com/web-push-libs/pywebpush
https://github.com/web-push-libs/vapid
https://caniuse.com/push-api
Task ID: 3123678

VCARD
-----
In the process of replacing the native methods exposed in the mobile
apps, this commit implements the download of a vCard containing a
partner's information.

By using this standard format, both regular web users and mobile ones
are now able to save the partner's details to use them with their usual
address book software.

On a mobile device, the actual import of those informations is delegated
to the operating system.

References:
- https://datatracker.ietf.org/doc/html/rfc6350
- https://en.wikipedia.org/wiki/VCard
- https://github.com/eventable/vobject#vcards

Task ID: 2583916

===========
End of note
===========

Task ID: 3478014

closes odoo/odoo#133560

Related: odoo/enterprise#46530
Related: odoo/upgrade#5086
Signed-off-by: Adrien Dieudonné (adr) <adr@odoo.com>
Co-authored-by: Romeo Fragomeli <rfr@odoo.com>
Co-authored-by: Romain Estievenart <res@odoo.com>
Co-authored-by: Pierre Paridans <app@odoo.com>
2023-09-11 16:32:30 +00:00

7.2 KiB

1idnamemodel_id:idgroup_id:idperm_readperm_writeperm_createperm_unlink
2access_fetchmail_serverfetchmail.servermodel_fetchmail_serverbase.group_system1111
3access_mail_message_allmail.message.allmodel_mail_messagebase.group_public1000
4access_mail_message_portalmail.message.portalmodel_mail_messagebase.group_portal1111
5access_mail_message_usermail.message.usermodel_mail_messagebase.group_user1111
6access_mail_message_scheduled_allmail.message.scheduled.allmodel_mail_message_schedule0000
7access_mail_message_scheduled_systemmail.message.scheduled.systemmodel_mail_message_schedulebase.group_system1111
8access_mail_mail_allmail.mail.allmodel_mail_mail0000
9access_mail_mail_portalmail.mail.portalmodel_mail_mailbase.group_portal0000
10access_mail_mail_usermail.mail.usermodel_mail_mailbase.group_user0000
11access_mail_mail_systemmail.mail.systemmodel_mail_mailbase.group_system1111
12access_mail_followers_allmail.followers.allmodel_mail_followers0000
13access_mail_followers_usermail.followers.usermodel_mail_followersbase.group_user1000
14access_mail_followers_systemmail.followers.systemmodel_mail_followersbase.group_system1111
15access_mail_notification_portalmail.notification.portalmodel_mail_notificationbase.group_portal1000
16access_mail_notification_usermail.notification.usermodel_mail_notificationbase.group_user1110
17access_mail_notification_systemmail.notification.systemmodel_mail_notificationbase.group_system1111
18access_discuss_channel_publicdiscuss.channel.allmodel_discuss_channelbase.group_public1000
19access_discuss_channel_portaldiscuss.channel.allmodel_discuss_channelbase.group_portal1000
20access_discuss_channel_userdiscuss.channel.usermodel_discuss_channelbase.group_user1110
21access_discuss_channel_admindiscuss.channel.systemmodel_discuss_channelbase.group_system1111
22access_discuss_channel_member_publicdiscuss.channel.member.publicmodel_discuss_channel_memberbase.group_public1000
23access_discuss_channel_member_portaldiscuss.channel.member.portalmodel_discuss_channel_memberbase.group_portal1111
24access_discuss_channel_member_userdiscuss.channel.member.usermodel_discuss_channel_memberbase.group_user1111
25access_discuss_channel_rtc_session_alldiscuss.channel.rtc.session.allmodel_discuss_channel_rtc_session0000
26access_discuss_channel_rtc_session_systemdiscuss.channel.rtc.session.systemmodel_discuss_channel_rtc_sessionbase.group_system1111
27access_mail_alias_allmail.alias.allmodel_mail_alias0000
28access_mail_alias_usermail.alias.usermodel_mail_aliasbase.group_user1000
29access_mail_alias_systemmail.alias.systemmodel_mail_aliasbase.group_system1111
30access_mail_gateway_allowed_systemmail.gateway.allowed.systemmodel_mail_gateway_allowedbase.group_system1111
31access_mail_message_reaction_allmail.message.reaction.allmodel_mail_message_reaction0000
32access_mail_message_reaction_systemmail.message.reaction.systemmodel_mail_message_reactionbase.group_system1111
33access_mail_message_subtype_publicmail.message.subtype.allmodel_mail_message_subtypebase.group_public1000
34access_mail_message_subtype_portalmail.message.subtype.allmodel_mail_message_subtypebase.group_portal1000
35access_mail_message_subtype_usermail.message.subtype.usermodel_mail_message_subtypebase.group_user1000
36access_mail_message_subtype_systemmail.message.subtype.systemmodel_mail_message_subtypebase.group_system1111
37access_mail_tracking_value_allmail.tracking.value.allmodel_mail_tracking_value0000
38access_mail_tracking_value_portalmail.tracking.value.portalmodel_mail_tracking_valuebase.group_portal0000
39access_mail_tracking_value_usermail.tracking.value.usermodel_mail_tracking_valuebase.group_user0000
40access_mail_tracking_value_systemmail.tracking.value.systemmodel_mail_tracking_valuebase.group_system1111
41access_publisher_warranty_contract_allpublisher.warranty.contract.allmodel_publisher_warranty_contractbase.group_system1111
42access_mail_templatemail.templatemodel_mail_templatebase.group_user1111
43access_mail_template_editormail.template_editormodel_mail_templatemail.group_mail_template_editor1111
44access_mail_template_systemmail.template_systemmodel_mail_templatebase.group_system1111
45access_mail_shortcodemail.shortcodemodel_mail_shortcodebase.group_user1111
46access_mail_shortcode_portalmail.shortcode.portalmodel_mail_shortcodebase.group_portal1000
47access_mail_activity_allmail.activity.allmodel_mail_activity0000
48access_mail_activity_usermail.activity.usermodel_mail_activitybase.group_user1111
49access_mail_activity_type_allmail.activity.type.allmodel_mail_activity_type0000
50access_mail_activity_type_usermail.activity.type.usermodel_mail_activity_typebase.group_user1000
51access_mail_activity_type_systemmail.activity.type.systemmodel_mail_activity_typebase.group_system1111
52access_mail_blacklist_systemaccess_mail_blacklist_systemmodel_mail_blacklistbase.group_system1111
53access_mail_wizard_inviteaccess.mail.wizard.invitemodel_mail_wizard_invitebase.group_user1110
54access_mail_compose_messageaccess.mail.compose.messagemodel_mail_compose_messagebase.group_user1110
55access_mail_compose_message_portalaccess.mail.compose.message.portalmodel_mail_compose_messagebase.group_portal1110
56access_mail_resend_messageaccess.mail.resend.messagemodel_mail_resend_messagebase.group_user1110
57access_mail_resend_partneraccess.mail.resend.partnermodel_mail_resend_partnerbase.group_user1110
58access_mail_template_previewaccess.mail.template.previewmodel_mail_template_previewbase.group_user1110
59access_mail_blacklist_remove_systemacesss.mail.blacklist.remove.systemmodel_mail_blacklist_removebase.group_system1111
60access_mail_guest_allmail.guestmodel_mail_guest0000
61access_mail_guest_usermail.guestmodel_mail_guestbase.group_user1000
62access_mail_guest_systemmail.guestmodel_mail_guestbase.group_system1111
63access_mail_ice_server_allmail.ice.server.allmodel_mail_ice_server0000
64access_mail_ice_server_systemmail.ice.server.systemmodel_mail_ice_serverbase.group_system1111
65access_res_users_settings_volumes_allres.users.settings.volumesmodel_res_users_settings_volumes0000
66access_res_users_settings_volumes_userres.users.settings.volumesmodel_res_users_settings_volumesbase.group_user1111
67access_mail_template_resetaccess.mail.template.resetmodel_mail_template_resetmail.group_mail_template_editor1111
68ir_actions_report_access_userir.actions.report.access.userbase.model_ir_actions_reportbase.group_user1000
69access_mail_link_preview_adminmail.link.preview.adminmodel_mail_link_previewbase.group_erp_manager1111
70access_discuss_gif_favoritediscuss.gif.favoritemodel_discuss_gif_favoritebase.group_user1111
71access_discuss_voice_metadata_userdiscuss.voice.metadata.usermodel_discuss_voice_metadata0000
72access_mail_partner_deviceaccess_mail_partner_devicemail.model_mail_partner_devicebase.group_user0000
73access_mail_notification_web_pushaccess_mail_notification_web_pushmail.model_mail_notification_web_pushbase.group_user0000