metatroncubeswdev d05d80c4df feat(tncsc_deployment): TNCSC client configuration (Phase 7)
Data-only deployment layer seeding TNCSC's branding (navy/orange/electric-
blue from the plan), 5 membership tiers in CAD (Individual $50, Family $80,
Student $20, Senior $30, Life $500 - the plan's own example figures;
update via Settings once TNCSC confirms real pricing), the
'TNCSC-{year}-{seq}' member-ID format, a Canadian (Ontario/HST) chart of
accounts via l10n_ca plus non-profit-specific accounts (Membership Dues/
Event/Sponsorship/School Fees/Donations Revenue, Deferred Event Revenue
liability, a Stripe clearing account) and a Donations journal, bilingual
EN/Tamil overrides of two membership email templates (Tamil text is a
best-effort draft only, explicitly flagged as needing native-speaker
review before go-live), five placeholder website pages (Home/About/Tamil
School/Sponsors/Contact), and TNCSC-named role groups (Board Admin,
Treasurer, Events Officer, School Coordinator, Teacher, Classifieds
Moderator) that imply the existing generic product-layer groups rather
than defining new permission logic.

Chasing the chart-of-accounts setup down to a genuinely working state
took real digging: setting company.country_id on a brand-new company
auto-schedules this Odoo build's own chart-template installer via a
precommit hook (res.company.install_l10n_modules), which races an
explicit try_loading('ca_2023', ...) call made in the same install
transaction and silently replaces its result afterwards (reverting
currency to USD, chart_template to 'generic_coa', and deleting the custom
accounts) - confirmed via raw SQL checks that the correct state exists
right up until the post_init_hook transaction commits, and is gone by the
time the install process exits. Since the precommit auto-trigger only
ever fires once per company (guarded by chart_template being unset), a
second call from a separate transaction is immune to the race. The fix:
the actual setup logic lives in an idempotent res.company._tncsc_setup_
accounting() method (models/res_company.py - a narrow, documented
exception to "no models" in the deployment layer, since cramming this
into a sandboxed ir.cron code string wasn't practical), called as a
best-effort from post_init_hook and guaranteed by a daily safety-net cron
que runs in its own transaction. Also hit two smaller, separate bugs on
the way: ir.cron code execution forbids direct attribute assignment
(STORE_ATTR) in its sandbox, and Html config_parameter fields must not be
wrapped in CDATA in data XML.

Verified end-to-end on a genuinely fresh database (not the long-lived dev
DB, which already has posted entries and correctly refuses a currency
change): installed tncsc_deployment alone, pulling in all 8 product
modules plus l10n_ca as dependencies, confirmed the post-install state via
raw SQL, manually triggered the safety-net cron and confirmed it reached
the fully-correct state (CAD, ca_2023, 355 accounts including all 7
custom ones, the Donations journal, tier products linked to the dues
account), confirmed the cron is idempotent on a second run, and ran the
full test suite (9/9 passing) with the same deterministic setup called
from the test transaction directly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-18 00:53:17 -04:00

70 lines
3.4 KiB
XML

<?xml version="1.0" encoding="utf-8"?>
<odoo noupdate="1">
<!-- TNCSC-branded role names. Each is a thin wrapper implying the
generic product-layer groups - the actual access control logic
lives entirely in the community_* modules; these just give board
members role labels they recognize in Settings > Users. -->
<record id="module_category_tncsc_roles" model="ir.module.category">
<field name="name">TNCSC Roles</field>
<field name="sequence">5</field>
</record>
<record id="privilege_tncsc_roles" model="res.groups.privilege">
<field name="name">TNCSC Roles</field>
<field name="category_id" ref="module_category_tncsc_roles"/>
</record>
<record id="group_tncsc_board_admin" model="res.groups">
<field name="name">Board Admin</field>
<field name="privilege_id" ref="privilege_tncsc_roles"/>
<field name="comment">Full access across membership, school, classifieds, benefits, events, and Interac payments.</field>
<field name="implied_ids" eval="[
(4, ref('community_membership.group_membership_manager')),
(4, ref('community_school.group_school_coordinator')),
(4, ref('community_classifieds.group_classifieds_moderator')),
(4, ref('community_benefits.group_benefits_manager')),
(4, ref('community_interac.group_interac_verifier')),
(4, ref('event.group_event_manager')),
]"/>
</record>
<record id="group_tncsc_treasurer" model="res.groups">
<field name="name">Treasurer</field>
<field name="privilege_id" ref="privilege_tncsc_roles"/>
<field name="comment">Confirms Interac e-Transfer payments and manages accounting.</field>
<field name="implied_ids" eval="[
(4, ref('community_interac.group_interac_verifier')),
(4, ref('account.group_account_invoice')),
]"/>
</record>
<record id="group_tncsc_events_officer" model="res.groups">
<field name="name">Events Officer</field>
<field name="privilege_id" ref="privilege_tncsc_roles"/>
<field name="comment">Manages events and staffs the check-in desk.</field>
<field name="implied_ids" eval="[(4, ref('event.group_event_manager'))]"/>
</record>
<record id="group_tncsc_school_coordinator" model="res.groups">
<field name="name">School Coordinator</field>
<field name="privilege_id" ref="privilege_tncsc_roles"/>
<field name="comment">Manages Tamil School terms, classes, students, and enrollment.</field>
<field name="implied_ids" eval="[(4, ref('community_school.group_school_coordinator'))]"/>
</record>
<record id="group_tncsc_teacher" model="res.groups">
<field name="name">Teacher</field>
<field name="privilege_id" ref="privilege_tncsc_roles"/>
<field name="comment">Takes attendance for their own Tamil School classes.</field>
<field name="implied_ids" eval="[(4, ref('community_school.group_school_teacher'))]"/>
</record>
<record id="group_tncsc_classifieds_moderator" model="res.groups">
<field name="name">Classifieds Moderator</field>
<field name="privilege_id" ref="privilege_tncsc_roles"/>
<field name="comment">Reviews and publishes classified listings.</field>
<field name="implied_ids" eval="[(4, ref('community_classifieds.group_classifieds_moderator'))]"/>
</record>
</odoo>