[FIX] mail: customers should not follow default internal subtypes

Currently when someone is added as follow to a document default subtypes
are computed if no specific subtypes are given to the subscription. However
if internal subtypes are set as default those are added to all new
followers. It should take into account customers and shared users and avoid
adding them internal subtypes.

Customers and shared users are not notified of messages using an internal
subtype. So currently there is no information leak. However with this fix
we ensure internal subtypes are not followed by external people even if
no notification is created.
This commit is contained in:
Thibault Delavallée
2016-12-13 12:57:58 +01:00
parent 8942a73fb3
commit 03ac47b9d7
2 changed files with 22 additions and 1 deletions
+6 -1
View File
@@ -61,11 +61,16 @@ class Followers(models.Model):
default_subtypes = self.env['mail.message.subtype'].search([
('default', '=', True),
'|', ('res_model', '=', res_model), ('res_model', '=', False)])
external_default_subtypes = default_subtypes.filtered(lambda subtype: not subtype.internal)
if force_mode:
employee_pids = self.env['res.users'].sudo().search([('partner_id', 'in', partner_data.keys()), ('share', '=', False)]).mapped('partner_id').ids
for pid, data in partner_data.iteritems():
if not data:
partner_data[pid] = default_subtypes.ids
if pid not in employee_pids:
partner_data[pid] = external_default_subtypes.ids
else:
partner_data[pid] = default_subtypes.ids
for cid, data in channel_data.iteritems():
if not data:
channel_data[cid] = default_subtypes.ids
+16
View File
@@ -77,6 +77,22 @@ class TestMailFollowers(TestMail):
self.assertEqual(len(follower), 1)
self.assertEqual(follower.subtype_ids, self.default_group_subtypes)
def test_followers_subtypes_default_internal(self):
mt_mg_def_int = self.env['mail.message.subtype'].create({'name': 'mt_mg_def', 'default': True, 'res_model': 'mail.channel', 'internal': True})
self.group_pigs.message_subscribe_users(user_ids=[self.user_employee.id])
follower = self.env['mail.followers'].search([
('res_model', '=', 'mail.channel'),
('res_id', '=', self.group_pigs.id),
('partner_id', '=', self.user_employee.partner_id.id)])
self.assertEqual(follower.subtype_ids, self.default_group_subtypes | mt_mg_def_int)
self.group_pigs.message_subscribe_users(user_ids=[self.user_portal.id])
follower = self.env['mail.followers'].search([
('res_model', '=', 'mail.channel'),
('res_id', '=', self.group_pigs.id),
('partner_id', '=', self.user_portal.partner_id.id)])
self.assertEqual(follower.subtype_ids, self.default_group_subtypes)
def test_followers_subtypes_specified(self):
self.group_pigs.sudo(self.user_employee).message_subscribe_users(subtype_ids=[self.mt_mg_nodef.id])
self.assertEqual(self.group_pigs.message_follower_ids.mapped('partner_id'), self.user_employee.partner_id)