Files
Odoo-Modules/fusion_plating/fusion_plating_quality/views/fp_avl_views.xml
gsinghpal 269f9984ef feat(plating-views): Layer 3 — field/button gates per role
Phase D Task D5 of permissions overhaul. Adds explicit groups= to
form-level elements so non-matching roles don't even SEE the buttons
they can't use:

- SO Confirm button → group_fp_sales_manager (Sales Rep sees the SO
  in draft but no Confirm button — matches model-level gate from Phase G)
- SO pricing fields (price_unit/subtotal/total/untaxed/tax) →
  group_fp_sales_rep (Technician/Shop Manager don't see pricing if
  they navigate to an SO)
- Partner Account Hold tab → group_fp_manager (was the fold-in
  group_fp_accounting; the audit-finding-11 _administrator typo lives
  in res_partner.py and is Phase G's fix)
- CAPA Close + all state-transition buttons → group_fp_quality_manager;
  edit fields use readonly="not user_has_groups(...)" so Manager
  retains read+comment per spec section 2.C
- Audit Start/Findings/Close buttons → group_fp_quality_manager
- AVL Approve/Suspend/Reinstate/Remove → group_fp_quality_manager
  (model uses Suspend+Remove instead of spec's literal 'Disqualify';
  both surfaces gated, semantics match)
- Customer Spec edit fields → readonly for non-QM (Manager keeps
  read access per spec; only inputs lock)
- FAIR Approve/Reject buttons → group_fp_quality_manager (Submit-
  for-Review and Reset stay open to whoever created the FAIR)
- Certificate Issue button — Strategy B chosen: single button hidden
  when cert_type=nadcap_cert AND user is not QM. Cleaner than splitting
  into two buttons; no separate action_sign exists on fp.certificate
  (Issue is the sign+publish action). FAIR lives in its own model;
  fp.certificate only has nadcap_cert as a special type. The ir.rule
  from Phase C enforces model-level writes independently.
- CGP form buttons (7 view files: ai, controlled_good, psa,
  receipt_shipment, registration, security_incident, visitor) →
  group_fp_quality_manager on every action button

Defense in depth: ir.rules and ACLs (from Phases B + C) already
restrict model access. These view gates are the UI layer that
matches.

Concerns:
- Spec line 192 names 'sale.order view — x_fc_account_hold_override'
  but no such field exists in the codebase. Closest practical match
  was the partner-side Account Hold management tab, which already had
  a group= attribute. Re-gated there; no SO-side field to gate.
- AVL model has no action_disqualify per spec; uses suspend+remove.
  Both gated to QM.
- fp.certificate has no action_sign (only action_issue). FAIR's
  approve/reject covers the FAIR side; nadcap-cert Issue covers the
  cert side via Strategy B.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-24 01:45:39 -04:00

121 lines
5.6 KiB
XML

<?xml version="1.0" encoding="utf-8"?>
<!--
Copyright 2026 Nexa Systems Inc.
License OPL-1 (Odoo Proprietary License v1.0)
Part of the Fusion Plating product family.
-->
<odoo>
<record id="view_fp_avl_list" model="ir.ui.view">
<field name="name">fp.avl.list</field>
<field name="model">fusion.plating.avl</field>
<field name="arch" type="xml">
<list string="Approved Vendors"
decoration-success="state == 'approved'"
decoration-info="state == 'pending'"
decoration-warning="state == 'conditional'"
decoration-muted="state in ('suspended','removed')"
decoration-danger="is_expired == True">
<field name="name"/>
<field name="partner_id"/>
<field name="category"/>
<field name="approved_for"/>
<field name="approval_date"/>
<field name="approval_expiry"/>
<field name="is_expired" optional="hide"/>
<field name="scorecard_rating"/>
<field name="state" widget="badge"
decoration-success="state == 'approved'"
decoration-warning="state == 'conditional'"
decoration-muted="state in ('suspended','removed')"/>
</list>
</field>
</record>
<record id="view_fp_avl_form" model="ir.ui.view">
<field name="name">fp.avl.form</field>
<field name="model">fusion.plating.avl</field>
<field name="arch" type="xml">
<form string="Approved Vendor">
<header>
<!-- Phase D5 — AVL state transitions are QM-only per spec
section 2.C (Manager has read; QM owns Add/Approve/
Disqualify). Spec lists "Approve / Disqualify"; this
model uses Approve + Suspend + Reinstate + Remove,
which together implement the disqualify path. All
four are gated. -->
<button name="action_approve" string="Approve" type="object"
class="oe_highlight" invisible="state == 'approved'"
groups="fusion_plating.group_fp_quality_manager"/>
<button name="action_suspend" string="Suspend" type="object"
invisible="state in ('suspended','removed')"
groups="fusion_plating.group_fp_quality_manager"/>
<button name="action_reinstate" string="Reinstate" type="object"
invisible="state != 'suspended'"
groups="fusion_plating.group_fp_quality_manager"/>
<button name="action_remove" string="Remove" type="object"
invisible="state == 'removed'"
groups="fusion_plating.group_fp_quality_manager"/>
<field name="state" widget="statusbar"
statusbar_visible="pending,approved,conditional,suspended,removed"/>
</header>
<sheet>
<div class="oe_title">
<label for="partner_id"/>
<h1><field name="partner_id"/></h1>
</div>
<group>
<group>
<field name="category"/>
<field name="approved_for"/>
<field name="scorecard_rating"/>
</group>
<group>
<field name="approval_date"/>
<field name="approval_expiry"/>
<field name="is_expired" readonly="1"/>
</group>
</group>
<notebook>
<page string="Notes">
<field name="notes"/>
</page>
</notebook>
</sheet>
<chatter/>
</form>
</field>
</record>
<record id="view_fp_avl_search" model="ir.ui.view">
<field name="name">fp.avl.search</field>
<field name="model">fusion.plating.avl</field>
<field name="arch" type="xml">
<search string="AVL">
<field name="name"/>
<field name="partner_id"/>
<field name="approved_for"/>
<separator/>
<filter string="Approved" name="approved" domain="[('state','=','approved')]"/>
<filter string="Pending" name="pending" domain="[('state','=','pending')]"/>
<filter string="Suspended" name="suspended" domain="[('state','=','suspended')]"/>
<filter string="Expired" name="expired" domain="[('is_expired','=',True)]"/>
<separator/>
<filter string="Archived" name="inactive" domain="[('active','=',False)]"/>
<group>
<filter string="Status" name="group_state" context="{'group_by':'state'}"/>
<filter string="Category" name="group_category" context="{'group_by':'category'}"/>
</group>
</search>
</field>
</record>
<record id="action_fp_avl" model="ir.actions.act_window">
<field name="name">Approved Vendor List</field>
<field name="res_model">fusion.plating.avl</field>
<field name="view_mode">list,form</field>
<field name="search_view_id" ref="view_fp_avl_search"/>
</record>
</odoo>