diff --git a/partner_readonly_security/README.rst b/partner_readonly_security/README.rst new file mode 100644 index 00000000000..bd5c5c978f2 --- /dev/null +++ b/partner_readonly_security/README.rst @@ -0,0 +1,100 @@ +========================= +Partner Readonly Security +========================= + +.. + !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! + !! This file is generated by oca-gen-addon-readme !! + !! changes will be overwritten. !! + !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! + !! source digest: sha256:3d6246358978797b076968ddd67431d45985450a8ca6132a0cea259afbd8e162 + !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! + +.. |badge1| image:: https://img.shields.io/badge/maturity-Beta-yellow.png + :target: https://odoo-community.org/page/development-status + :alt: Beta +.. |badge2| image:: https://img.shields.io/badge/licence-AGPL--3-blue.png + :target: http://www.gnu.org/licenses/agpl-3.0-standalone.html + :alt: License: AGPL-3 +.. |badge3| image:: https://img.shields.io/badge/github-OCA%2Fpartner--contact-lightgray.png?logo=github + :target: https://github.com/OCA/partner-contact/tree/17.0/partner_readonly_security + :alt: OCA/partner-contact +.. |badge4| image:: https://img.shields.io/badge/weblate-Translate%20me-F47D42.png + :target: https://translation.odoo-community.org/projects/partner-contact-17-0/partner-contact-17-0-partner_readonly_security + :alt: Translate me on Weblate +.. |badge5| image:: https://img.shields.io/badge/runboat-Try%20me-875A7B.png + :target: https://runboat.odoo-community.org/builds?repo=OCA/partner-contact&target_branch=17.0 + :alt: Try me on Runboat + +|badge1| |badge2| |badge3| |badge4| |badge5| + +This module creates a specific permission to allow modification of +partners. + +**Table of contents** + +.. contents:: + :local: + +Use Cases / Context +=================== + +Example use case: sales manager doesn't edit partners. + +Usage +===== + +1. Create or edit a user and uncheck the 'Partner edition' permission. +2. Go to any contact. +3. None can be created, modified or deleted. + +Bug Tracker +=========== + +Bugs are tracked on `GitHub Issues `_. +In case of trouble, please check there if your issue has already been reported. +If you spotted it first, help us to smash it by providing a detailed and welcomed +`feedback `_. + +Do not contact contributors directly about support or help with technical issues. + +Credits +======= + +Authors +------- + +* Tecnativa + +Contributors +------------ + +- `Tecnativa `__: + + - Víctor Martínez + - Pedro M. Baeza + +Maintainers +----------- + +This module is maintained by the OCA. + +.. image:: https://odoo-community.org/logo.png + :alt: Odoo Community Association + :target: https://odoo-community.org + +OCA, or the Odoo Community Association, is a nonprofit organization whose +mission is to support the collaborative development of Odoo features and +promote its widespread use. + +.. |maintainer-victoralmau| image:: https://github.com/victoralmau.png?size=40px + :target: https://github.com/victoralmau + :alt: victoralmau + +Current `maintainer `__: + +|maintainer-victoralmau| + +This module is part of the `OCA/partner-contact `_ project on GitHub. + +You are welcome to contribute. To learn how please visit https://odoo-community.org/page/Contribute. diff --git a/partner_readonly_security/__init__.py b/partner_readonly_security/__init__.py new file mode 100644 index 00000000000..0650744f6bc --- /dev/null +++ b/partner_readonly_security/__init__.py @@ -0,0 +1 @@ +from . import models diff --git a/partner_readonly_security/__manifest__.py b/partner_readonly_security/__manifest__.py new file mode 100644 index 00000000000..8145754ff59 --- /dev/null +++ b/partner_readonly_security/__manifest__.py @@ -0,0 +1,14 @@ +# Copyright 2024 Tecnativa - Víctor Martínez +# License AGPL-3.0 or later (https://www.gnu.org/licenses/agpl). +{ + "name": "Partner Readonly Security", + "author": "Tecnativa, Odoo Community Association (OCA)", + "website": "https://github.com/OCA/partner-contact", + "version": "17.0.1.0.0", + "depends": ["base"], + "license": "AGPL-3", + "category": "Customer Relationship Management", + "data": ["security/partner_readonly_security_security.xml"], + "installable": True, + "maintainers": ["victoralmau"], +} diff --git a/partner_readonly_security/i18n/es.po b/partner_readonly_security/i18n/es.po new file mode 100644 index 00000000000..2cd5fabdeaa --- /dev/null +++ b/partner_readonly_security/i18n/es.po @@ -0,0 +1,38 @@ +# Translation of Odoo Server. +# This file contains the translation of the following modules: +# * partner_readonly_security +# +msgid "" +msgstr "" +"Project-Id-Version: Odoo Server 15.0\n" +"Report-Msgid-Bugs-To: \n" +"POT-Creation-Date: 2024-05-30 12:08+0000\n" +"PO-Revision-Date: 2024-05-30 14:09+0200\n" +"Last-Translator: \n" +"Language-Team: \n" +"Language: es\n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: 8bit\n" +"Plural-Forms: \n" +"X-Generator: Poedit 3.0.1\n" + +#. module: partner_readonly_security +#: model:ir.model,name:partner_readonly_security.model_res_partner +msgid "Contact" +msgstr "Contacto" + +#. module: partner_readonly_security +#: model:res.groups,name:partner_readonly_security.group_partner_edition +msgid "Partner edition" +msgstr "Edición de contactos" + +#. module: partner_readonly_security +#: code:addons/partner_readonly_security/models/res_partner.py:0 +#, python-format +msgid "" +"Sorry, you are not allowed to create/edit partners. Please contact your " +"administrator for further information." +msgstr "" +"Lo sentimos, no tiene permiso para crear/editar contactos. Para más " +"información, póngase en contacto con su administrador." diff --git a/partner_readonly_security/i18n/partner_readonly_security.pot b/partner_readonly_security/i18n/partner_readonly_security.pot new file mode 100644 index 00000000000..e1ee38373d3 --- /dev/null +++ b/partner_readonly_security/i18n/partner_readonly_security.pot @@ -0,0 +1,32 @@ +# Translation of Odoo Server. +# This file contains the translation of the following modules: +# * partner_readonly_security +# +msgid "" +msgstr "" +"Project-Id-Version: Odoo Server 15.0\n" +"Report-Msgid-Bugs-To: \n" +"Last-Translator: \n" +"Language-Team: \n" +"MIME-Version: 1.0\n" +"Content-Type: text/plain; charset=UTF-8\n" +"Content-Transfer-Encoding: \n" +"Plural-Forms: \n" + +#. module: partner_readonly_security +#: model:ir.model,name:partner_readonly_security.model_res_partner +msgid "Contact" +msgstr "" + +#. module: partner_readonly_security +#: model:res.groups,name:partner_readonly_security.group_partner_edition +msgid "Partner edition" +msgstr "" + +#. module: partner_readonly_security +#: code:addons/partner_readonly_security/models/res_partner.py:0 +#, python-format +msgid "" +"Sorry, you are not allowed to create/edit partners. Please contact your " +"administrator for further information." +msgstr "" diff --git a/partner_readonly_security/models/__init__.py b/partner_readonly_security/models/__init__.py new file mode 100644 index 00000000000..88fed2832a0 --- /dev/null +++ b/partner_readonly_security/models/__init__.py @@ -0,0 +1,3 @@ +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl). + +from . import res_partner diff --git a/partner_readonly_security/models/res_partner.py b/partner_readonly_security/models/res_partner.py new file mode 100644 index 00000000000..d56b051301f --- /dev/null +++ b/partner_readonly_security/models/res_partner.py @@ -0,0 +1,38 @@ +# Copyright 2024 Tecnativa - Víctor Martínez +# License AGPL-3 - See http://www.gnu.org/licenses/agpl-3.0.html + +from odoo import _, api, models +from odoo.exceptions import AccessError +from odoo.tools import config + + +class ResPartner(models.Model): + _inherit = "res.partner" + + @api.model + def check_access_rights(self, operation, raise_exception=True): + """Simulate that you do not have ACLs so that the create, edit and delete + buttons are not displayed.""" + user = self.env.user + group = "partner_readonly_security.group_partner_edition" + test_condition = not config["test_enable"] or ( + config["test_enable"] + and self.env.context.get("test_partner_readonly_security") + ) + if ( + test_condition + and operation != "read" + and not self.env.su + and not user.has_group(group) + ): + if raise_exception: + raise AccessError( + _( + "Sorry, you are not allowed to create/edit partners. Please " + "contact your administrator for further information." + ) + ) + return False + return super().check_access_rights( + operation=operation, raise_exception=raise_exception + ) diff --git a/partner_readonly_security/pyproject.toml b/partner_readonly_security/pyproject.toml new file mode 100644 index 00000000000..4231d0cccb3 --- /dev/null +++ b/partner_readonly_security/pyproject.toml @@ -0,0 +1,3 @@ +[build-system] +requires = ["whool"] +build-backend = "whool.buildapi" diff --git a/partner_readonly_security/readme/CONTEXT.md b/partner_readonly_security/readme/CONTEXT.md new file mode 100644 index 00000000000..f4680bc4b3e --- /dev/null +++ b/partner_readonly_security/readme/CONTEXT.md @@ -0,0 +1 @@ +Example use case: sales manager doesn't edit partners. diff --git a/partner_readonly_security/readme/CONTRIBUTORS.md b/partner_readonly_security/readme/CONTRIBUTORS.md new file mode 100644 index 00000000000..5fee3904270 --- /dev/null +++ b/partner_readonly_security/readme/CONTRIBUTORS.md @@ -0,0 +1,3 @@ +- [Tecnativa](https://www.tecnativa.com): + - Víctor Martínez + - Pedro M. Baeza diff --git a/partner_readonly_security/readme/DESCRIPTION.md b/partner_readonly_security/readme/DESCRIPTION.md new file mode 100644 index 00000000000..1c269b0893e --- /dev/null +++ b/partner_readonly_security/readme/DESCRIPTION.md @@ -0,0 +1,2 @@ +This module creates a specific permission to allow modification of +partners. diff --git a/partner_readonly_security/readme/USAGE.md b/partner_readonly_security/readme/USAGE.md new file mode 100644 index 00000000000..99e47fe9756 --- /dev/null +++ b/partner_readonly_security/readme/USAGE.md @@ -0,0 +1,3 @@ +1. Create or edit a user and uncheck the 'Partner edition' permission. +2. Go to any contact. +3. None can be created, modified or deleted. diff --git a/partner_readonly_security/security/partner_readonly_security_security.xml b/partner_readonly_security/security/partner_readonly_security_security.xml new file mode 100644 index 00000000000..14ac2387758 --- /dev/null +++ b/partner_readonly_security/security/partner_readonly_security_security.xml @@ -0,0 +1,8 @@ + + + + Partner edition + + + + diff --git a/partner_readonly_security/static/description/icon.png b/partner_readonly_security/static/description/icon.png new file mode 100644 index 00000000000..3a0328b516c Binary files /dev/null and b/partner_readonly_security/static/description/icon.png differ diff --git a/partner_readonly_security/static/description/index.html b/partner_readonly_security/static/description/index.html new file mode 100644 index 00000000000..85c1217b77d --- /dev/null +++ b/partner_readonly_security/static/description/index.html @@ -0,0 +1,444 @@ + + + + + +Partner Readonly Security + + + +
+

Partner Readonly Security

+ + +

Beta License: AGPL-3 OCA/partner-contact Translate me on Weblate Try me on Runboat

+

This module creates a specific permission to allow modification of +partners.

+

Table of contents

+ +
+

Use Cases / Context

+

Example use case: sales manager doesn’t edit partners.

+
+
+

Usage

+
    +
  1. Create or edit a user and uncheck the ‘Partner edition’ permission.
  2. +
  3. Go to any contact.
  4. +
  5. None can be created, modified or deleted.
  6. +
+
+
+

Bug Tracker

+

Bugs are tracked on GitHub Issues. +In case of trouble, please check there if your issue has already been reported. +If you spotted it first, help us to smash it by providing a detailed and welcomed +feedback.

+

Do not contact contributors directly about support or help with technical issues.

+
+
+

Credits

+
+

Authors

+
    +
  • Tecnativa
  • +
+
+
+

Contributors

+
    +
  • Tecnativa:
      +
    • Víctor Martínez
    • +
    • Pedro M. Baeza
    • +
    +
  • +
+
+
+

Maintainers

+

This module is maintained by the OCA.

+ +Odoo Community Association + +

OCA, or the Odoo Community Association, is a nonprofit organization whose +mission is to support the collaborative development of Odoo features and +promote its widespread use.

+

Current maintainer:

+

victoralmau

+

This module is part of the OCA/partner-contact project on GitHub.

+

You are welcome to contribute. To learn how please visit https://odoo-community.org/page/Contribute.

+
+
+
+ + diff --git a/partner_readonly_security/tests/__init__.py b/partner_readonly_security/tests/__init__.py new file mode 100644 index 00000000000..425316b079e --- /dev/null +++ b/partner_readonly_security/tests/__init__.py @@ -0,0 +1,3 @@ +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl). + +from . import test_partner_readonly_security diff --git a/partner_readonly_security/tests/test_partner_readonly_security.py b/partner_readonly_security/tests/test_partner_readonly_security.py new file mode 100644 index 00000000000..3a8fe650e03 --- /dev/null +++ b/partner_readonly_security/tests/test_partner_readonly_security.py @@ -0,0 +1,62 @@ +# Copyright 2024 Tecnativa - Víctor Martínez +# License AGPL-3 - See http://www.gnu.org/licenses/agpl-3.0.html + + +from odoo.exceptions import AccessError +from odoo.tests import common, new_test_user +from odoo.tests.common import users +from odoo.tools import mute_logger + + +class TestPartnerReadonlySecurity(common.TransactionCase): + @classmethod + def setUpClass(cls): + super().setUpClass() + cls.env = cls.env( + context=dict( + cls.env.context, + mail_create_nolog=True, + mail_create_nosubscribe=True, + mail_notrack=True, + no_reset_password=True, + tracking_disable=True, + test_partner_readonly_security=True, + ) + ) + cls.user_admin = new_test_user( + cls.env, + login="test_user_admin", + groups=""" + base.group_user,base.group_partner_manager, + partner_readonly_security.group_partner_edition + """, + ) + cls.user_readonly = new_test_user( + cls.env, + login="test_user_readonly", + groups="base.group_user,base.group_partner_manager", + ) + cls.partner = cls.env["res.partner"].sudo().create({"name": "Test partner"}) + + @users("test_user_admin") + @mute_logger("odoo.models.unlink") + def test_partner_admin(self): + """Read, write, unlink and create allowed.""" + partners = self.env["res.partner"].search([]) + self.assertIn(self.partner, partners) + self.partner.with_user(self.env.user).write({"name": "new-name"}) + self.partner.with_user(self.env.user).unlink() + new_partner = self.env["res.partner"].create({"name": "Test partner 2"}) + self.assertTrue(new_partner.exists()) + + @users("test_user_readonly") + def test_partner_readonly(self): + """Read allowed. Write, unlink and create not allowed.""" + partners = self.env["res.partner"].search([]) + self.assertIn(self.partner, partners) + with self.assertRaises(AccessError): + self.partner.with_user(self.env.user).write({"name": "new-name"}) + with self.assertRaises(AccessError): + self.partner.with_user(self.env.user).unlink() + with self.assertRaises(AccessError): + self.env["res.partner"].create({"name": "Test partner 2"})