diff --git a/05_activity_log/2026-07-31.md b/05_activity_log/2026-07-31.md index 4d8d727..7047331 100644 --- a/05_activity_log/2026-07-31.md +++ b/05_activity_log/2026-07-31.md @@ -1,5 +1,74 @@ # Activity Log · 2026-07-31 · Claude Code DTP +## Session `20260731_012944` · Buffer S8 · Reproductibilité en CHECKOUT PROPRE — le hand-off out/ des 4 générateurs RBAC était `.gitignore`é → gate rouge en CI, vert en local seulement + +**Tâche** : **Sprint 8 · buffer L75 (« Regression tests exhaustifs » · DevOps +CI/CD)**. Roadmap fonctionnellement close (21/21 modules 100/100, 534 tests verts, +6 gates statiques). Poursuite de la série anti-dérive : recherche d'un **écart +green-local / red-en-CI réel** (même classe que le bug `regression_run.json` +corrigé plus tôt aujourd'hui) plutôt qu'un correctif cosmétique. + +### Défaut trouvé — 2 gates ROUGES en checkout propre (`check-artifacts` + `check-regression`) + +- **Méthode** : test au sol par `git archive HEAD | tar -x` (= exactement ce que + voit le runner Gitea), et non `bash ci/*.sh` dans l'arbre de travail. +- **Constat** : les 4 générateurs RBAC (`rbac/fixtures_gen`, `userperm_gen`, + `roleprofile_gen`, `apply_plan`) **`.gitignore`aient leur `out/`** (« re-générable + à la demande ») — alors qu'ils sont audités en archétype **`generator`** (critère + **HANDOFF** = `out/MANIFEST.json` + ≥1 artefact JSON). En checkout **propre**, + leur `out/` est **absent** → l'audit 4Big (`qa/audit_4big`, dont le `build` + **relit le `out/` de CHAQUE module**) les note **80 < 95** ⇒ **INV7** ⇒ build + **refusé**. Cascade : `check-artifacts` **rouge** (rebuild audit_4big + demo + échouent) et `check-regression` **rouge**. Ça ne « passait » qu'en **local**, + grâce aux `out/` **non suivis** laissés sur disque par des `build` manuels — + **exactement** la classe du bug `regression_run.json` (green-local/red-CI). +- **Preuve au sol** : `git archive` de `HEAD` → `check_artifacts` **exit 1** + (`INV7 rbac-* note 80 < 95` · `demo/scenarios build a échoué`) et + `check_regression` **exit 1**. Les 15 autres générateurs commettent bien leur + `out/` → seuls les 4 RBAC étaient l'exception. + +### Fix (2 solutions · CLAUDE.md #4 — retenu : aligner sur les 15 autres modules) + +- **Correctif de fond** : **committer** le `out/` des 4 générateurs RBAC (retrait + de `out/` des 4 `.gitignore` + `git add`). Faisabilité **prouvée** : chaque + `build` est **byte-déterministe** (2 builds successifs identiques ; tri stable, + zéro horodatage). `apply_plan` lit ses frères **en process** (imports), pas via + leur `out/` — committer le `out/` sert **uniquement** le contrat HANDOFF audité. + L'audit note désormais les 4 modules **100/100** en checkout propre. *(Alt. + écartée : reclasser les 4 en archétype sans HANDOFF — diverge du reste des + générateurs et laisse `check_artifacts` les ignorer, moins cohérent · #5.)* +- **Durcissement du gate (empêche la récidive)** : `ci/check_artifacts.sh` + comparait le build frais au fichier de l'**arbre de travail** — donc un `out/` + **non suivi** (ignoré / jamais `git add`) le rendait **vert en local** alors + qu'il serait **absent en CI**. Ajout d'une assertion **`git ls-files + --error-unmatch`** : tout fichier produit par `build` DOIT être **suivi par git** + → l'écart devient une **erreur locale honnête**, plus une surprise en CI. +- **Régénération des consommateurs (mémoire projet)** : l'édition des 4 README RBAC + (en-tête `out/` « non commité » → « commité · byte-déterministe », +18 o chacun) + a fait dériver `qa/audit_4big/out/quality_report.json` (evidence DOC = taille + README) — **régénéré** (PASS · 21/21 · min 100). `demo` + `regression run` + rejoués : **inchangés** (ils lisaient déjà l'état correct). + +**Preuve de morsure du durcissement** : `git rm --cached role.json` (fichier laissé +sur disque, simulant un `out/` ignoré) ⇒ `check_artifacts` **exit 1** (`✗ … NON +SUIVI par git → absent en CI propre`) ; re-`git add` ⇒ **exit 0**. Avant le +durcissement, ce même état passait **vert**. + +**Vérifs** : **6 gates verts sur `git archive` propre** (guard/json/docs/artifacts/ +regression/ci_integrity) ; suites harnais **OK** (fixtures/userperm/roleprofile/ +apply_plan/audit_4big/regression/demo · 32/32) ; matrice **534/21** **inchangée** ; +build de TOUS les consommateurs → **zéro dérive résiduelle**. + +**Anti-invention (#6)** : rien inventé — `out/` RBAC = sortie déterministe des +générateurs ; `quality_report` recalculé depuis les faits du dépôt. + +**Hors périmètre worker (VPS · #8)** : néant (stdlib pur en-repo ; les fixtures +Frappe côté VPS restent `.gitignore`ées, hors de ce correctif). + +**Auto-score 4Big** : 96/100. + +--- + ## Session `20260731_005934` · Buffer S8 · Intégrité du câblage CI — le gate d'agrégat verrouille TOUS les jobs (gates statiques compris) **Tâche** : **Sprint 8 · buffer L75 (« Regression tests exhaustifs » · DevOps diff --git a/05_deliverables_mvp/qa/audit_4big/out/quality_report.json b/05_deliverables_mvp/qa/audit_4big/out/quality_report.json index 81c69c0..5ea0f3a 100644 --- a/05_deliverables_mvp/qa/audit_4big/out/quality_report.json +++ b/05_deliverables_mvp/qa/audit_4big/out/quality_report.json @@ -150,7 +150,7 @@ "criterion": "DOC", "weight": 20, "passed": true, - "evidence": "README.md (5249 octets)" + "evidence": "README.md (5267 octets)" }, { "criterion": "CONTRAT", @@ -192,7 +192,7 @@ "criterion": "DOC", "weight": 20, "passed": true, - "evidence": "README.md (3858 octets)" + "evidence": "README.md (3876 octets)" }, { "criterion": "CONTRAT", @@ -234,7 +234,7 @@ "criterion": "DOC", "weight": 20, "passed": true, - "evidence": "README.md (5358 octets)" + "evidence": "README.md (5376 octets)" }, { "criterion": "CONTRAT", @@ -276,7 +276,7 @@ "criterion": "DOC", "weight": 20, "passed": true, - "evidence": "README.md (5241 octets)" + "evidence": "README.md (5259 octets)" }, { "criterion": "CONTRAT", diff --git a/05_deliverables_mvp/rbac/apply_plan/.gitignore b/05_deliverables_mvp/rbac/apply_plan/.gitignore index 3b6ddac..cd00c00 100644 --- a/05_deliverables_mvp/rbac/apply_plan/.gitignore +++ b/05_deliverables_mvp/rbac/apply_plan/.gitignore @@ -1,4 +1,7 @@ -# Sortie re-générable à la demande (déterministe) — non commitée. -out/ +# Artefacts Python (jamais commit — reproductibles). __pycache__/ *.pyc +# NB : out/ EST commité (hand-off audité · archétype `generator` · critère +# HANDOFF · CLAUDE.md #5). `build` est byte-déterministe → out/ se régénère à +# l'identique par `python3 rbac_apply_plan.py build -o out` et est gardé par +# ci/check_artifacts.sh (build frais == commité). diff --git a/05_deliverables_mvp/rbac/apply_plan/README.md b/05_deliverables_mvp/rbac/apply_plan/README.md index f8bc88b..8546828 100644 --- a/05_deliverables_mvp/rbac/apply_plan/README.md +++ b/05_deliverables_mvp/rbac/apply_plan/README.md @@ -27,7 +27,7 @@ de portée `equipe`). L'agrégateur matérialise ce **graphe de dépendances** e **recoupe la cohérence** des trois volets (même contrat, même cible 50 rôles, couverture bijective) — un seul artefact à lire pour l'agent ERPNext. -## Ce qui est généré (`out/`, non commité) +## Ce qui est généré (`out/`, commité · byte-déterministe) | Fichier | Rôle | |---|---| diff --git a/05_deliverables_mvp/rbac/apply_plan/out/MANIFEST.json b/05_deliverables_mvp/rbac/apply_plan/out/MANIFEST.json new file mode 100644 index 0000000..de05b5b --- /dev/null +++ b/05_deliverables_mvp/rbac/apply_plan/out/MANIFEST.json @@ -0,0 +1,42 @@ +{ + "generated_from": "rbac_50_roles.json", + "source_version": "1.0.0", + "cible_rbac_roles": 50, + "counts": { + "roles": 50, + "custom_docperm": 116, + "doctypes_uniques": 45, + "user_permission_templates": 28, + "role_profiles": 6 + }, + "confirmations_vps": { + "custom_doctypes": [ + "API Access", + "CONFOTUR Application", + "Faisabilité", + "Publiciste Log" + ], + "companies": [ + "AC Arias Cuevas", + "Consortium ECR DR", + "Helios RD", + "Ploutos", + "WA SRL" + ], + "roles_scope_equipe": [ + "OTO Construction Chef Projet", + "OTO Construction Ingénieur", + "OTO Construction Sous-traitants", + "OTO Ventes Chef Équipe" + ] + }, + "consistency": { + "sources_coherentes": true, + "source_version": "1.0.0", + "cible_rbac_roles": 50, + "roles_fixtures": 50, + "userperm_plan_entries": 50, + "roleprofile_roles_couverts": 50, + "couverture_bijective": true + } +} diff --git a/05_deliverables_mvp/rbac/apply_plan/out/apply_plan.json b/05_deliverables_mvp/rbac/apply_plan/out/apply_plan.json new file mode 100644 index 0000000..38e495b --- /dev/null +++ b/05_deliverables_mvp/rbac/apply_plan/out/apply_plan.json @@ -0,0 +1,98 @@ +[ + { + "order": 1, + "id": "fixtures-generate", + "titre": "Générer les fixtures Role + Custom DocPerm", + "responsable": "worker", + "statut": "livré", + "commande": "python3 fixtures_gen/rbac_fixtures_gen.py build", + "produces": [ + "role.json", + "custom_docperm.json" + ], + "depends_on": [], + "confirmations": [], + "doc": "../fixtures_gen/README.md" + }, + { + "order": 2, + "id": "custom-doctypes-create", + "titre": "Créer les DocTypes DTP custom manquants (après confirmation)", + "responsable": "vps", + "statut": "à faire VPS", + "commande": null, + "produces": [], + "depends_on": [ + "fixtures-generate" + ], + "confirmations": [ + "custom_doctypes" + ], + "doc": "../RBAC_50_ROLES_SPEC.md" + }, + { + "order": 3, + "id": "fixtures-migrate", + "titre": "Déposer role.json + custom_docperm.json dans fixtures/ puis bench migrate", + "responsable": "vps", + "statut": "à faire VPS", + "commande": null, + "produces": [], + "depends_on": [ + "fixtures-generate", + "custom-doctypes-create" + ], + "confirmations": [], + "doc": "../fixtures_gen/README.md" + }, + { + "order": 4, + "id": "userperm-apply", + "titre": "Matérialiser les User Permission row-level par utilisateur", + "responsable": "worker+vps", + "statut": "plan livré · matérialisation VPS", + "commande": "python3 userperm_gen/userperm_gen.py build", + "produces": [ + "user_permission_plan.json" + ], + "depends_on": [ + "fixtures-migrate" + ], + "confirmations": [ + "companies", + "roles_scope_equipe" + ], + "doc": "../userperm_gen/README.md" + }, + { + "order": 5, + "id": "roleprofile-apply", + "titre": "Importer les Role Profile (après les Role) puis affecter User.role_profile_name", + "responsable": "worker+vps", + "statut": "bundle livré · affectation VPS", + "commande": "python3 roleprofile_gen/roleprofile_gen.py build", + "produces": [ + "role_profile.json" + ], + "depends_on": [ + "fixtures-migrate" + ], + "confirmations": [], + "doc": "../roleprofile_gen/README.md" + }, + { + "order": 6, + "id": "verify-http-qa", + "titre": "Vérification HTTP post-déploiement + audit QA 4Big", + "responsable": "vps", + "statut": "à faire VPS", + "commande": null, + "produces": [], + "depends_on": [ + "userperm-apply", + "roleprofile-apply" + ], + "confirmations": [], + "doc": "../RBAC_50_ROLES_SPEC.md" + } +] diff --git a/05_deliverables_mvp/rbac/fixtures_gen/.gitignore b/05_deliverables_mvp/rbac/fixtures_gen/.gitignore index a449a97..bbbd397 100644 --- a/05_deliverables_mvp/rbac/fixtures_gen/.gitignore +++ b/05_deliverables_mvp/rbac/fixtures_gen/.gitignore @@ -1,5 +1,7 @@ -# Artefacts de génération locale (jamais commités — produits à la demande par -# `python3 rbac_fixtures_gen.py build`, re-générables en CI). +# Artefacts Python (jamais commit — reproductibles). __pycache__/ *.pyc -out/ +# NB : out/ EST commité (hand-off audité · archétype `generator` · critère +# HANDOFF · CLAUDE.md #5). `build` est byte-déterministe → out/ se régénère à +# l'identique par `python3 rbac_fixtures_gen.py build -o out` et est gardé par +# ci/check_artifacts.sh (build frais == commité). diff --git a/05_deliverables_mvp/rbac/fixtures_gen/README.md b/05_deliverables_mvp/rbac/fixtures_gen/README.md index f4bc1e7..1a109ff 100644 --- a/05_deliverables_mvp/rbac/fixtures_gen/README.md +++ b/05_deliverables_mvp/rbac/fixtures_gen/README.md @@ -9,7 +9,7 @@ incrément » annoncé au §7 de [`../RBAC_50_ROLES_SPEC.md`](../RBAC_50_ROLES_S > Ce worker **n'écrit jamais sur le VPS** (contrainte #8). Il produit les > fichiers en-repo ; l'application réelle (`bench migrate`) reste côté serveur. -## Ce qui est généré (`out/`, non commité) +## Ce qui est généré (`out/`, commité · byte-déterministe) | Fichier | DocType Frappe | Rôle | |---|---|---| diff --git a/05_deliverables_mvp/rbac/fixtures_gen/out/MANIFEST.json b/05_deliverables_mvp/rbac/fixtures_gen/out/MANIFEST.json new file mode 100644 index 0000000..5c9aa66 --- /dev/null +++ b/05_deliverables_mvp/rbac/fixtures_gen/out/MANIFEST.json @@ -0,0 +1,16 @@ +{ + "generated_from": "rbac_50_roles.json", + "source_version": "1.0.0", + "cible_rbac_roles": 50, + "counts": { + "role": 50, + "custom_docperm": 116, + "doctypes_uniques": 45 + }, + "custom_doctypes_a_confirmer": [ + "API Access", + "CONFOTUR Application", + "Faisabilité", + "Publiciste Log" + ] +} diff --git a/05_deliverables_mvp/rbac/fixtures_gen/out/custom_docperm.json b/05_deliverables_mvp/rbac/fixtures_gen/out/custom_docperm.json new file mode 100644 index 0000000..5769372 --- /dev/null +++ b/05_deliverables_mvp/rbac/fixtures_gen/out/custom_docperm.json @@ -0,0 +1,2786 @@ +[ + { + "doctype": "Custom DocPerm", + "parent": "Material Request", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Acheteur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Order", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Acheteur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Request for Quotation", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Acheteur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Material Request", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Order", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 1, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Supplier", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Contact", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Fournisseurs", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Supplier", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Fournisseurs", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Item", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Magasinier", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Stock Entry", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Magasinier", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Order", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Réception", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Receipt", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Achat Réception", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "GL Entry", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Audit UAF", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 1, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Payment Entry", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Audit UAF", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Sales Invoice", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Audit UAF", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Payment Entry", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Clients AR", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Sales Invoice", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Clients AR", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Budget", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Contrôle Gestion", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Cost Center", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Contrôle Gestion", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "GL Entry", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Contrôle Gestion", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 1, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Invoice", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Fiscaliste eCF", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 1, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Sales Invoice", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Fiscaliste eCF", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 1, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Payment Entry", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Fournisseurs AP", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Invoice", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Fournisseurs AP", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Account", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Général", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Journal Entry", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Général", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Employee", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Paie", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Salary Slip", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Paie", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Bank Transaction", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Trésorier", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Payment Entry", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Compta Trésorier", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 1, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Faisabilité", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Conseil Administration", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Sales Invoice", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Conseil Administration", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Faisabilité", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Architecte", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Project", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Architecte", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Faisabilité", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction BIM", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "File", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction BIM", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Material Request", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Chef Projet", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Project", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Chef Projet", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Task", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Chef Projet", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Project", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Order", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Task", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Task", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Ingénieur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Timesheet", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Ingénieur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Quality Inspection", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction QAQC", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Task", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction QAQC", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Order", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Sous-traitants", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Task", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Construction Sous-traitants", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Lead", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Commerciale", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Opportunity", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Commerciale", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 1, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Quotation", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Commerciale", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Journal Entry", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Financière", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 1, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Payment Entry", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Financière", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 1, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Invoice", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Financière", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 1, + "amend": 0, + "report": 1, + "export": 1, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Sales Invoice", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Financière", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 1, + "amend": 0, + "report": 1, + "export": 1, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Project", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Générale", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Order", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Générale", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 1, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Quotation", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Générale", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 1, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Sales Order", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Générale", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 1, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Project", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Opérations", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Order", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Opérations", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Task", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Opérations", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Faisabilité", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Président", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Opportunity", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Président", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Purchase Invoice", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Président", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 1, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Sales Invoice", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Direction Président", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 1, + "import": 0, + "print": 1, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Faisabilité", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Faisabilité Analyste", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Project", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Faisabilité Analyste", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Faisabilité", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Faisabilité IFC Speckle", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "File", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Faisabilité IFC Speckle", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Faisabilité", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Faisabilité Rendu 3D", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "File", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Faisabilité Rendu 3D", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Faisabilité", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Faisabilité Économiste", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Item", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Faisabilité Économiste", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "CONFOTUR Application", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Legal Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Contract", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Legal Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "CONFOTUR Application", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Legal ONAPI", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Publiciste Log", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Marketing Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Web Page", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Marketing Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Publiciste Log", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Marketing Publiciste", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Web Page", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Marketing Publiciste", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Web Page", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Marketing SEO", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Lead", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Marketing Social", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Dashboard", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme BI", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Report", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme BI", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 1, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Scheduled Job Type", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme DevOps", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Server Script", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme DevOps", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "API Access", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme Mobile", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Faisabilité", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme OTOIA", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Publiciste Log", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme OTOIA", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Error Log", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme QA", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Report", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme QA", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 1, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Role", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme RBAC Admin", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Role Profile", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme RBAC Admin", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "User", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme RBAC Admin", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 1 + }, + { + "doctype": "Custom DocPerm", + "parent": "User Permission", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Plateforme RBAC Admin", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 1, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Customer", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Après-Vente", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Issue", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Après-Vente", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "CONFOTUR Application", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes CONFOTUR", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 1, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Customer", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes CONFOTUR", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Lead", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Chef Équipe", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Opportunity", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Chef Équipe", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Quotation", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Chef Équipe", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Lead", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Conseiller", + "permlevel": 0, + "if_owner": 1, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Opportunity", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Conseiller", + "permlevel": 0, + "if_owner": 1, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Quotation", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Conseiller", + "permlevel": 0, + "if_owner": 1, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 1, + "email": 1, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Sales Invoice", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Contrats", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 1, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Sales Order", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Contrats", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 1, + "email": 1, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Lead", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Courtier Externe", + "permlevel": 0, + "if_owner": 1, + "select": 0, + "read": 1, + "write": 0, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Opportunity", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Courtier Externe", + "permlevel": 0, + "if_owner": 1, + "select": 0, + "read": 1, + "write": 0, + "create": 0, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Lead", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 1, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Opportunity", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 1, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Quotation", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 1, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Sales Order", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Directeur", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 0, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 1, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Payment Entry", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Réservations", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 0, + "create": 1, + "delete": 0, + "submit": 0, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + }, + { + "doctype": "Custom DocPerm", + "parent": "Sales Order", + "parenttype": "DocType", + "parentfield": "permissions", + "role": "OTO Ventes Réservations", + "permlevel": 0, + "if_owner": 0, + "select": 0, + "read": 1, + "write": 1, + "create": 1, + "delete": 0, + "submit": 1, + "cancel": 0, + "amend": 0, + "report": 0, + "export": 0, + "import": 0, + "print": 0, + "email": 0, + "share": 0, + "set_user_permissions": 0 + } +] diff --git a/05_deliverables_mvp/rbac/fixtures_gen/out/role.json b/05_deliverables_mvp/rbac/fixtures_gen/out/role.json new file mode 100644 index 0000000..2d82c4a --- /dev/null +++ b/05_deliverables_mvp/rbac/fixtures_gen/out/role.json @@ -0,0 +1,452 @@ +[ + { + "doctype": "Role", + "name": "OTO Achat Acheteur", + "role_name": "OTO Achat Acheteur", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Achat Directeur", + "role_name": "OTO Achat Directeur", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Achat Fournisseurs", + "role_name": "OTO Achat Fournisseurs", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Achat Magasinier", + "role_name": "OTO Achat Magasinier", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Achat Réception", + "role_name": "OTO Achat Réception", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Compta Audit UAF", + "role_name": "OTO Compta Audit UAF", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Compta Clients AR", + "role_name": "OTO Compta Clients AR", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Compta Contrôle Gestion", + "role_name": "OTO Compta Contrôle Gestion", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Compta Fiscaliste eCF", + "role_name": "OTO Compta Fiscaliste eCF", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Compta Fournisseurs AP", + "role_name": "OTO Compta Fournisseurs AP", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Compta Général", + "role_name": "OTO Compta Général", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Compta Paie", + "role_name": "OTO Compta Paie", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Compta Trésorier", + "role_name": "OTO Compta Trésorier", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Conseil Administration", + "role_name": "OTO Conseil Administration", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Construction Architecte", + "role_name": "OTO Construction Architecte", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Construction BIM", + "role_name": "OTO Construction BIM", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Construction Chef Projet", + "role_name": "OTO Construction Chef Projet", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Construction Directeur", + "role_name": "OTO Construction Directeur", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Construction Ingénieur", + "role_name": "OTO Construction Ingénieur", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Construction QAQC", + "role_name": "OTO Construction QAQC", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Construction Sous-traitants", + "role_name": "OTO Construction Sous-traitants", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Direction Commerciale", + "role_name": "OTO Direction Commerciale", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Direction Financière", + "role_name": "OTO Direction Financière", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Direction Générale", + "role_name": "OTO Direction Générale", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Direction Opérations", + "role_name": "OTO Direction Opérations", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Direction Président", + "role_name": "OTO Direction Président", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Faisabilité Analyste", + "role_name": "OTO Faisabilité Analyste", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Faisabilité IFC Speckle", + "role_name": "OTO Faisabilité IFC Speckle", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Faisabilité Rendu 3D", + "role_name": "OTO Faisabilité Rendu 3D", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Faisabilité Économiste", + "role_name": "OTO Faisabilité Économiste", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Legal Directeur", + "role_name": "OTO Legal Directeur", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Legal ONAPI", + "role_name": "OTO Legal ONAPI", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Marketing Directeur", + "role_name": "OTO Marketing Directeur", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Marketing Publiciste", + "role_name": "OTO Marketing Publiciste", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Marketing SEO", + "role_name": "OTO Marketing SEO", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Marketing Social", + "role_name": "OTO Marketing Social", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Plateforme BI", + "role_name": "OTO Plateforme BI", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Plateforme DevOps", + "role_name": "OTO Plateforme DevOps", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Plateforme Mobile", + "role_name": "OTO Plateforme Mobile", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Plateforme OTOIA", + "role_name": "OTO Plateforme OTOIA", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Plateforme QA", + "role_name": "OTO Plateforme QA", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Plateforme RBAC Admin", + "role_name": "OTO Plateforme RBAC Admin", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Ventes Après-Vente", + "role_name": "OTO Ventes Après-Vente", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Ventes CONFOTUR", + "role_name": "OTO Ventes CONFOTUR", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Ventes Chef Équipe", + "role_name": "OTO Ventes Chef Équipe", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Ventes Conseiller", + "role_name": "OTO Ventes Conseiller", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Ventes Contrats", + "role_name": "OTO Ventes Contrats", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Ventes Courtier Externe", + "role_name": "OTO Ventes Courtier Externe", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Ventes Directeur", + "role_name": "OTO Ventes Directeur", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + }, + { + "doctype": "Role", + "name": "OTO Ventes Réservations", + "role_name": "OTO Ventes Réservations", + "desk_access": 1, + "disabled": 0, + "two_factor_auth": 0, + "restrict_to_domain": null + } +] diff --git a/05_deliverables_mvp/rbac/roleprofile_gen/.gitignore b/05_deliverables_mvp/rbac/roleprofile_gen/.gitignore index bb7490a..97687fc 100644 --- a/05_deliverables_mvp/rbac/roleprofile_gen/.gitignore +++ b/05_deliverables_mvp/rbac/roleprofile_gen/.gitignore @@ -1,5 +1,7 @@ -# Artefacts de génération locale (jamais commités — produits à la demande par -# `python3 roleprofile_gen.py build`, re-générables en CI). +# Artefacts Python (jamais commit — reproductibles). __pycache__/ *.pyc -out/ +# NB : out/ EST commité (hand-off audité · archétype `generator` · critère +# HANDOFF · CLAUDE.md #5). `build` est byte-déterministe → out/ se régénère à +# l'identique par `python3 roleprofile_gen.py build -o out` et est gardé par +# ci/check_artifacts.sh (build frais == commité). diff --git a/05_deliverables_mvp/rbac/roleprofile_gen/README.md b/05_deliverables_mvp/rbac/roleprofile_gen/README.md index c376544..645c3a2 100644 --- a/05_deliverables_mvp/rbac/roleprofile_gen/README.md +++ b/05_deliverables_mvp/rbac/roleprofile_gen/README.md @@ -22,7 +22,7 @@ nommé de rôles (`Has Role`) qu'on affecte en un champ. Les **5 portails métie donnent **6 profils** couvrant les 50 rôles de façon **bijective** (chaque rôle dans exactement un profil, puisque chaque rôle a exactement un `portail`). -## Ce qui est généré (`out/`, non commité) +## Ce qui est généré (`out/`, commité · byte-déterministe) | Fichier | Rôle | |---|---| diff --git a/05_deliverables_mvp/rbac/roleprofile_gen/out/MANIFEST.json b/05_deliverables_mvp/rbac/roleprofile_gen/out/MANIFEST.json new file mode 100644 index 0000000..9511cc1 --- /dev/null +++ b/05_deliverables_mvp/rbac/roleprofile_gen/out/MANIFEST.json @@ -0,0 +1,49 @@ +{ + "generated_from": "rbac_50_roles.json", + "source_version": "1.0.0", + "cible_rbac_roles": 50, + "counts": { + "role_profiles": 6, + "portails_metier": 5, + "portails_techniques": 1, + "roles_couverts": 50 + }, + "profiles": [ + { + "portail": "achat", + "role_profile": "OTO Portail Achat", + "metier": true, + "nb_roles": 5 + }, + { + "portail": "compta", + "role_profile": "OTO Portail Compta", + "metier": true, + "nb_roles": 8 + }, + { + "portail": "construction", + "role_profile": "OTO Portail Construction", + "metier": true, + "nb_roles": 10 + }, + { + "portail": "direction", + "role_profile": "OTO Portail Direction", + "metier": true, + "nb_roles": 9 + }, + { + "portail": "plateforme", + "role_profile": "OTO Portail Plateforme", + "metier": false, + "nb_roles": 6 + }, + { + "portail": "ventes", + "role_profile": "OTO Portail Ventes", + "metier": true, + "nb_roles": 12 + } + ] +} diff --git a/05_deliverables_mvp/rbac/roleprofile_gen/out/role_profile.json b/05_deliverables_mvp/rbac/roleprofile_gen/out/role_profile.json new file mode 100644 index 0000000..fac7ff4 --- /dev/null +++ b/05_deliverables_mvp/rbac/roleprofile_gen/out/role_profile.json @@ -0,0 +1,344 @@ +[ + { + "doctype": "Role Profile", + "name": "OTO Portail Achat", + "role_profile": "OTO Portail Achat", + "roles": [ + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Achat Acheteur" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Achat Directeur" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Achat Fournisseurs" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Achat Magasinier" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Achat Réception" + } + ] + }, + { + "doctype": "Role Profile", + "name": "OTO Portail Compta", + "role_profile": "OTO Portail Compta", + "roles": [ + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Compta Audit UAF" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Compta Clients AR" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Compta Contrôle Gestion" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Compta Fiscaliste eCF" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Compta Fournisseurs AP" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Compta Général" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Compta Paie" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Compta Trésorier" + } + ] + }, + { + "doctype": "Role Profile", + "name": "OTO Portail Construction", + "role_profile": "OTO Portail Construction", + "roles": [ + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Construction Architecte" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Construction BIM" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Construction Chef Projet" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Construction Directeur" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Construction Ingénieur" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Construction QAQC" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Construction Sous-traitants" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Faisabilité IFC Speckle" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Faisabilité Rendu 3D" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Faisabilité Économiste" + } + ] + }, + { + "doctype": "Role Profile", + "name": "OTO Portail Direction", + "role_profile": "OTO Portail Direction", + "roles": [ + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Conseil Administration" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Direction Commerciale" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Direction Financière" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Direction Générale" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Direction Opérations" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Direction Président" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Faisabilité Analyste" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Legal Directeur" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Legal ONAPI" + } + ] + }, + { + "doctype": "Role Profile", + "name": "OTO Portail Plateforme", + "role_profile": "OTO Portail Plateforme", + "roles": [ + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Plateforme BI" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Plateforme DevOps" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Plateforme Mobile" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Plateforme OTOIA" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Plateforme QA" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Plateforme RBAC Admin" + } + ] + }, + { + "doctype": "Role Profile", + "name": "OTO Portail Ventes", + "role_profile": "OTO Portail Ventes", + "roles": [ + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Marketing Directeur" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Marketing Publiciste" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Marketing SEO" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Marketing Social" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Ventes Après-Vente" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Ventes CONFOTUR" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Ventes Chef Équipe" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Ventes Conseiller" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Ventes Contrats" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Ventes Courtier Externe" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Ventes Directeur" + }, + { + "doctype": "Has Role", + "parentfield": "roles", + "parenttype": "Role Profile", + "role": "OTO Ventes Réservations" + } + ] + } +] diff --git a/05_deliverables_mvp/rbac/userperm_gen/.gitignore b/05_deliverables_mvp/rbac/userperm_gen/.gitignore index 74b7ff0..6a667ed 100644 --- a/05_deliverables_mvp/rbac/userperm_gen/.gitignore +++ b/05_deliverables_mvp/rbac/userperm_gen/.gitignore @@ -1,5 +1,7 @@ -# Artefacts de génération locale (jamais commités — produits à la demande par -# `python3 userperm_gen.py build`, re-générables en CI). +# Artefacts Python (jamais commit — reproductibles). __pycache__/ *.pyc -out/ +# NB : out/ EST commité (hand-off audité · archétype `generator` · critère +# HANDOFF · CLAUDE.md #5). `build` est byte-déterministe → out/ se régénère à +# l'identique par `python3 userperm_gen.py build -o out` et est gardé par +# ci/check_artifacts.sh (build frais == commité). diff --git a/05_deliverables_mvp/rbac/userperm_gen/README.md b/05_deliverables_mvp/rbac/userperm_gen/README.md index 1a30edb..29d0278 100644 --- a/05_deliverables_mvp/rbac/userperm_gen/README.md +++ b/05_deliverables_mvp/rbac/userperm_gen/README.md @@ -21,7 +21,7 @@ produire qu'un **template par rôle** dont le champ `user` est une sentinelle (`__ASSIGN_PER_USER__`). L'agent ERPNext clone ce template une fois par utilisateur assigné au rôle et remplace la sentinelle par son e-mail, côté VPS. -## Ce qui est généré (`out/`, non commité) +## Ce qui est généré (`out/`, commité · byte-déterministe) | Fichier | Rôle | |---|---| diff --git a/05_deliverables_mvp/rbac/userperm_gen/out/MANIFEST.json b/05_deliverables_mvp/rbac/userperm_gen/out/MANIFEST.json new file mode 100644 index 0000000..4054634 --- /dev/null +++ b/05_deliverables_mvp/rbac/userperm_gen/out/MANIFEST.json @@ -0,0 +1,28 @@ +{ + "generated_from": "rbac_50_roles.json", + "source_version": "1.0.0", + "cible_rbac_roles": 50, + "counts": { + "plan_entries": 50, + "user_permission_templates": 28, + "by_mechanism": { + "docperm_if_owner": 2, + "user_permission_company": 28, + "none_consolidated": 16, + "vps_confirm_team": 4 + } + }, + "companies_a_confirmer": [ + "AC Arias Cuevas", + "Consortium ECR DR", + "Helios RD", + "Ploutos", + "WA SRL" + ], + "roles_scope_equipe_a_confirmer": [ + "OTO Construction Chef Projet", + "OTO Construction Ingénieur", + "OTO Construction Sous-traitants", + "OTO Ventes Chef Équipe" + ] +} diff --git a/05_deliverables_mvp/rbac/userperm_gen/out/user_permission_plan.json b/05_deliverables_mvp/rbac/userperm_gen/out/user_permission_plan.json new file mode 100644 index 0000000..32fc0d8 --- /dev/null +++ b/05_deliverables_mvp/rbac/userperm_gen/out/user_permission_plan.json @@ -0,0 +1,576 @@ +[ + { + "erpnext_role_name": "OTO Achat Acheteur", + "scope_donnees": "entite", + "entite_principale": "WA SRL", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "WA SRL", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Achat Directeur", + "scope_donnees": "entite", + "entite_principale": "WA SRL", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "WA SRL", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Achat Fournisseurs", + "scope_donnees": "entite", + "entite_principale": "WA SRL", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "WA SRL", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Achat Magasinier", + "scope_donnees": "entite", + "entite_principale": "AC Arias Cuevas", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "AC Arias Cuevas", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Achat Réception", + "scope_donnees": "entite", + "entite_principale": "AC Arias Cuevas", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "AC Arias Cuevas", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Compta Audit UAF", + "scope_donnees": "groupe", + "entite_principale": "Groupe", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Compta Clients AR", + "scope_donnees": "entite", + "entite_principale": "Helios RD", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "Helios RD", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Compta Contrôle Gestion", + "scope_donnees": "groupe", + "entite_principale": "Groupe", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Compta Fiscaliste eCF", + "scope_donnees": "entite", + "entite_principale": "WA SRL", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "WA SRL", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Compta Fournisseurs AP", + "scope_donnees": "entite", + "entite_principale": "WA SRL", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "WA SRL", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Compta Général", + "scope_donnees": "entite", + "entite_principale": "WA SRL", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "WA SRL", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Compta Paie", + "scope_donnees": "entite", + "entite_principale": "Consortium ECR DR", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "Consortium ECR DR", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Compta Trésorier", + "scope_donnees": "entite", + "entite_principale": "Ploutos", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "Ploutos", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Conseil Administration", + "scope_donnees": "groupe", + "entite_principale": "Groupe", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Construction Architecte", + "scope_donnees": "entite", + "entite_principale": "AC Arias Cuevas", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "AC Arias Cuevas", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Construction BIM", + "scope_donnees": "entite", + "entite_principale": "AC Arias Cuevas", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "AC Arias Cuevas", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Construction Chef Projet", + "scope_donnees": "equipe", + "entite_principale": "AC Arias Cuevas", + "mechanism": "vps_confirm_team", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Construction Directeur", + "scope_donnees": "entite", + "entite_principale": "AC Arias Cuevas", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "AC Arias Cuevas", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Construction Ingénieur", + "scope_donnees": "equipe", + "entite_principale": "AC Arias Cuevas", + "mechanism": "vps_confirm_team", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Construction QAQC", + "scope_donnees": "entite", + "entite_principale": "AC Arias Cuevas", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "AC Arias Cuevas", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Construction Sous-traitants", + "scope_donnees": "equipe", + "entite_principale": "AC Arias Cuevas", + "mechanism": "vps_confirm_team", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Direction Commerciale", + "scope_donnees": "groupe", + "entite_principale": "Groupe", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Direction Financière", + "scope_donnees": "groupe", + "entite_principale": "Groupe", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Direction Générale", + "scope_donnees": "groupe", + "entite_principale": "Groupe", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Direction Opérations", + "scope_donnees": "groupe", + "entite_principale": "Groupe", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Direction Président", + "scope_donnees": "groupe", + "entite_principale": "WAF", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Faisabilité Analyste", + "scope_donnees": "entite", + "entite_principale": "WA SRL", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "WA SRL", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Faisabilité IFC Speckle", + "scope_donnees": "entite", + "entite_principale": "WA SRL", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "WA SRL", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Faisabilité Rendu 3D", + "scope_donnees": "entite", + "entite_principale": "WA SRL", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "WA SRL", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Faisabilité Économiste", + "scope_donnees": "entite", + "entite_principale": "AC Arias Cuevas", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "AC Arias Cuevas", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Legal Directeur", + "scope_donnees": "groupe", + "entite_principale": "WAF", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Legal ONAPI", + "scope_donnees": "groupe", + "entite_principale": "WAF", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Marketing Directeur", + "scope_donnees": "entite", + "entite_principale": "Helios RD", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "Helios RD", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Marketing Publiciste", + "scope_donnees": "entite", + "entite_principale": "Helios RD", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "Helios RD", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Marketing SEO", + "scope_donnees": "entite", + "entite_principale": "Helios RD", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "Helios RD", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Marketing Social", + "scope_donnees": "entite", + "entite_principale": "Helios RD", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "Helios RD", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Plateforme BI", + "scope_donnees": "groupe", + "entite_principale": "Groupe", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Plateforme DevOps", + "scope_donnees": "groupe", + "entite_principale": "9060 QC", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Plateforme Mobile", + "scope_donnees": "groupe", + "entite_principale": "9060 QC", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Plateforme OTOIA", + "scope_donnees": "groupe", + "entite_principale": "9060 QC", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Plateforme QA", + "scope_donnees": "groupe", + "entite_principale": "9060 QC", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Plateforme RBAC Admin", + "scope_donnees": "groupe", + "entite_principale": "9060 QC", + "mechanism": "none_consolidated", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Ventes Après-Vente", + "scope_donnees": "entite", + "entite_principale": "Helios RD", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "Helios RD", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Ventes CONFOTUR", + "scope_donnees": "entite", + "entite_principale": "WA SRL", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "WA SRL", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Ventes Chef Équipe", + "scope_donnees": "equipe", + "entite_principale": "Helios RD", + "mechanism": "vps_confirm_team", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Ventes Conseiller", + "scope_donnees": "own", + "entite_principale": "Helios RD", + "mechanism": "docperm_if_owner", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Ventes Contrats", + "scope_donnees": "entite", + "entite_principale": "WA SRL", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "WA SRL", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Ventes Courtier Externe", + "scope_donnees": "own", + "entite_principale": "Helios RD", + "mechanism": "docperm_if_owner", + "user_permission_template": null + }, + { + "erpnext_role_name": "OTO Ventes Directeur", + "scope_donnees": "entite", + "entite_principale": "Helios RD", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "Helios RD", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + }, + { + "erpnext_role_name": "OTO Ventes Réservations", + "scope_donnees": "entite", + "entite_principale": "Helios RD", + "mechanism": "user_permission_company", + "user_permission_template": { + "doctype": "User Permission", + "user": "__ASSIGN_PER_USER__", + "allow": "Company", + "for_value": "Helios RD", + "apply_to_all_doctypes": 1, + "is_default": 0, + "hide_descendants": 0 + } + } +] diff --git a/ci/README.md b/ci/README.md index e82d754..cc1f20a 100644 --- a/ci/README.md +++ b/ci/README.md @@ -52,9 +52,13 @@ Un JSON cassé casse le pipeline aval → attrapé ici. ### `check_artifacts.sh` Régénère chaque artefact `05_deliverables_mvp/**/out/` versionné depuis son -générateur (`build -o `) et exige une **égalité byte-for-byte** avec le -fichier commité. Découverte automatique (zéro liste à la main · #6) : tout module -avec un `out/` et un générateur `build` entre dans le gate. +générateur (`build -o `) et exige que tout fichier produit soit (a) **suivi +par git** — jamais un artefact seulement sur disque (`out/` `.gitignore`-é ou +non-`git add`), qui serait **absent en CI propre** et rendrait le gate « vert en +local » par artefact fantôme (même classe que le bug `regression_run.json`) — et +(b) en **égalité byte-for-byte** avec le fichier commité. Découverte automatique +(zéro liste à la main · #6) : tout module avec un `out/` et un générateur `build` +entre dans le gate. Cible la **dérive silencieuse** : un module auto-résout des valeurs depuis les artefacts d'**autres** modules (ex. `demo/scenarios` lit diff --git a/ci/check_artifacts.sh b/ci/check_artifacts.sh index 6e1ef51..0d04c9a 100755 --- a/ci/check_artifacts.sh +++ b/ci/check_artifacts.sh @@ -16,8 +16,10 @@ # # Contrat vérifié : pour chaque `05_deliverables_mvp/**/out/`, le générateur # racine (le .py portant une sous-commande `build`) est ré-exécuté vers un -# répertoire temporaire ; tout fichier produit DOIT exister et être identique -# à son jumeau commité. Les artefacts d'EXÉCUTION (non produits par `build`, +# répertoire temporaire ; tout fichier produit DOIT (a) être SUIVI par git — +# jamais un simple artefact sur disque `.gitignore`-é qui serait absent en CI +# propre — et (b) être identique à son jumeau commité. Les artefacts d'EXÉCUTION +# (non produits par `build`, # p.ex. qa/regression/out/regression_run.json issu de `run`) ne sont pas # comparés — le gate n'assert que ce que `build` (déterministe) produit. # @@ -72,6 +74,16 @@ for outdir in "${outdirs[@]}"; do if [[ ! -f "$committed" ]]; then report "$rel/$bn — produit par 'build' mais ABSENT du dépôt (non commité)" drift=1 + elif ! git ls-files --error-unmatch "$committed" >/dev/null 2>&1; then + # Présent sur disque mais NON SUIVI par git (out/ .gitignore-é, ou jamais + # `git add`). En checkout CI propre le fichier serait ABSENT — donc tout + # consommateur à build reproductible qui lit ce out/ (ex. l'audit 4Big, + # critère HANDOFF, lit le out/ de CHAQUE module) casserait, tandis que le + # gate resterait « vert en local » grâce à un artefact fantôme laissé par + # un build manuel. C'est la classe de bug regression_run.json : on la + # refuse. Un hand-off audité DOIT être commité, jamais seulement sur disque. + report "$rel/$bn — produit par 'build' mais NON SUIVI par git (out/ ignoré ? → absent en CI propre, vert local trompeur)" + drift=1 elif ! diff -q "$f" "$committed" >/dev/null 2>&1; then report "$rel/$bn — DÉRIVE : le fichier commité diffère du build frais (régénérer)" drift=1