Files
odoo_source/odoo/addons/base/security/base_groups.xml
T
Victor Feyens fba6ea5a47 [IMP] *: do not force admins to be app admins
For bugfix purposes, app administration groups have been given to
(implied by) the "Settings" group because without those rights,
opening/saving the settings crashed.

1) Do not load hidden view content

This commit uses the conditional inheritance of views
(depending on user groups) to avoid loading unnecessary view
& record content client-side.

This improves performance for admins without the specific application
admin rights, but also fixes the main bugfix problem,
caused by the webclient querying name_get for the records in relational
fields content.

Example:

sale_management adds a res.config.settings field to specify
the default sale.order.template for the current company.

If a 'Settings' user without 'sale.group_sale_manager' opens the
settings, he won't see this setting, but if a default template is
specified for the current company, the webclient will still request
the name_get of this template to the server, because the field
was present in the view, only hidden with a groups attribute.

With this commit change in sale, the field won't be in the view unless
you have the Sale manager group, avoiding the error/traceback/bug.

2) Remove implied application administration groups

Do not force the specific application groups on all 'Settings' user,
they globally do not need those rights, and if they need it, they
can add it to their account themselves.

3) Add a test to make sure settings user are able to manage settings.

4) Enforce 'settings' -> 'access rights' -> 'internal user' groups

As the previous test highlighted some 'false positives' because
it considered a settings user unable to read `crm.team`
and `stock.warehouse` records, we also took the opportunity to enforce
the fact that 'Settings' & 'Access rights' users must be internal users.

It makes no sense for a portal/public user to have access to the
settings, and didn't work anyway.

Part-of: odoo/odoo#91909
2022-06-23 23:48:29 +02:00

97 lines
4.1 KiB
XML

<?xml version="1.0"?>
<odoo>
<data>
<!--
Users Groups
Note that the field 'category_id' is set later in
base/data/ir_module_category_data.xml
-->
<record model="res.groups" id="group_erp_manager">
<field name="name">Access Rights</field>
<field name="implied_ids" eval="[Command.link(ref('group_user'))]"/>
</record>
<record model="res.groups" id="group_system">
<field name="name">Settings</field>
<field name="implied_ids" eval="[Command.link(ref('group_erp_manager'))]"/>
<field name="users" eval="[Command.link(ref('base.user_root')), Command.link(ref('base.user_admin'))]"/>
</record>
<record model="res.groups" id="group_user">
<field name="name">Internal User</field>
</record>
<record id="default_user" model="res.users">
<field name="groups_id" eval="[Command.link(ref('base.group_user'))]"/>
</record>
<record model="res.groups" id="group_multi_company">
<field name="name">Multi Companies</field>
</record>
<record model="res.groups" id="group_multi_currency">
<field name="name">Multi Currencies</field>
</record>
<record model="res.groups" id="group_no_one">
<field name="name">Technical Features</field>
</record>
<record id="group_allow_export" model="res.groups">
<field name="name">Access to export feature</field>
<field name="category_id" ref="base.module_category_hidden"/>
<field name="users" eval="[Command.link(ref('base.user_root')), Command.link(ref('base.user_admin'))]"/>
</record>
<record model="res.groups" id="group_user">
<field name="implied_ids" eval="[Command.link(ref('group_no_one'))]"/>
<field name="users" eval="[Command.link(ref('base.user_root')), Command.link(ref('base.user_admin'))]"/>
</record>
<record model="res.groups" id="group_partner_manager">
<field name="name">Contact Creation</field>
<field name="users" eval="[Command.link(ref('base.user_root')), Command.link(ref('base.user_admin'))]"/>
</record>
<record id="default_user" model="res.users">
<field name="groups_id" eval="[Command.link(ref('base.group_partner_manager')), Command.link(ref('base.group_allow_export'))]"/>
</record>
<!--
A group dedicated to the portal users, making groups
restrictions more convenient.
-->
<record id="group_portal" model="res.groups">
<field name="name">Portal</field>
<field name="comment">Portal members have specific access rights (such as record rules and restricted menus).
They usually do not belong to the usual Odoo groups.</field>
</record>
<!--
A group dedicated to the public user only, making groups
restrictions more convenient.
-->
<record id="group_public" model="res.groups">
<field name="name">Public</field>
<field name="comment">Public users have specific access rights (such as record rules and restricted menus).
They usually do not belong to the usual Odoo groups.</field>
</record>
<record id="public_user" model="res.users">
<field name="groups_id" eval="[Command.link(ref('base.group_public'))]"/>
</record>
<!-- Default template user for new users signing in -->
<record id="template_portal_user_id" model="res.users">
<field name="name">Portal User Template</field>
<field name="login">portaltemplate</field>
<field name="active" eval="False"/>
<field name="groups_id" eval="[Command.set([ref('base.group_portal')])]"/>
</record>
<record id="default_template_user_config" model="ir.config_parameter">
<field name="key">base.template_portal_user_id</field>
<field name="value" ref="template_portal_user_id"/>
</record>
</data>
</odoo>