Serves Demo Scene 2 end to end: mc.applicant with the stage pipeline (Applied -> Document Verification -> Interview -> Offered -> Accepted -> Enrolled/Rejected) on mail.thread, a public admission page on the website, and a convert wizard that turns an accepted applicant into a real mc.student + mc.enrollment with zero re-typing. The public form uses Odoo's stock /website/form/<model> mechanism, not a custom controller (CLAUDE.md sec 1.3 - writing a custom version of stock infrastructure is a bug). Verified the real mechanism against core source first rather than assuming: website_hr_recruitment's own data/config_data.xml is the template this follows (ir.model. website_form_access + ir.model.fields.formbuilder_whitelist()). This is the module's actual security boundary, and it's worth being explicit about why it holds. The generic controller creates the record as SUPERUSER - normal ir.model.access rows do not apply to it at all. The only thing stopping a submitter from setting state, student_id, application_no or company_id is that those fields are not in the formbuilder_whitelist() call in data/mc_applicant_website_form_data.xml (every field defaults to website_form_blacklisted=True and stays that way unless explicitly opted in). Confirmed this isn't just theoretical: posted state=enrolled and application_no=HACKED-0001 directly at /website/form/mc.applicant on a live instance, and the resulting record came back with the model's own default state=applied and a server-generated APP20260004 - the injected values were silently dropped, exactly as the whitelist should do. Also exercised a real file upload (birth certificate) and the full convert-to-student path (guardian dedup by email, application_no -> student.application_no, enrollment, attachment reparenting) via odoo shell against the live container, not just read by inspection. mc.student gets a new application_no field (_inherit from this module, not O1 - it only makes sense where admission is installed) so "the application number persists on the student" is a stored fact, not just a claim in the demo script. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
24 lines
783 B
Python
24 lines
783 B
Python
{
|
|
"name": "School ERP - Admission",
|
|
"version": "19.0.1.0.0",
|
|
"category": "Education",
|
|
"summary": "Public admission form through to an enrolled student, zero re-typing.",
|
|
"author": "Metatroncube Software Solutions LLP",
|
|
"license": "Other proprietary",
|
|
"depends": ["mc_education_base", "website"],
|
|
"data": [
|
|
"security/ir.model.access.csv",
|
|
"data/mc_applicant_sequence_data.xml",
|
|
"data/mc_applicant_website_form_data.xml",
|
|
"views/mc_applicant_views.xml",
|
|
"views/mc_applicant_convert_wizard_views.xml",
|
|
"views/website_admission_templates.xml",
|
|
"views/website_admission_menu.xml",
|
|
],
|
|
"demo": [
|
|
"demo/mc_applicant_demo.xml",
|
|
],
|
|
"installable": True,
|
|
"application": False,
|
|
}
|