You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Added
Security › user search: find any user by name or login in a search box (matches listed under it, ↑ ↓ Enter or a click), instead of a long select. My User comes back to yours.
Security › Groups: the picked user's groups, with one filter box that also lists the groups they don't have while typing, each with + Add. Remove shows on the groups nothing else implies; an implied group is marked as such and says which group implies it (Odoo would add it back). Writing needs Access Rights and asks first.
Changed
Access and Security are one tab (Security), in three parts: User (search, groups, risks), the current model for that user (why allowed / blocked, ACLs, fields hidden by groups=, configuration audit) and the Instance (session with Become Superuser, system parameters, checks). Another user's groups, ACLs and record rules can be read, not only yours.
Why allowed / blocked shows the server's exact has_access answer next to each simulated verdict when the picked user is you (the separate Effective access card is gone). The Access tab's record rules table is gone too: this card lists every rule for the picked user.
Removed
Account switching in the Security tab: Switch to This User (incognito login) and Impersonate in This Session (OCA impersonate_login). Become Superuser stays, in the Session card (Settings users only).
Fixed
Security › Why allowed / blocked: the four verdict boxes no longer overflow the panel when an ACL or model name is long.