[FIX] base: clear cache before read access check
When reading binary content such as `image_128` on `res.users`,
`AccessError` should be raised when necessary.
Steps to reproduce:
- Populate cache in superuser mode.
- Access cached field with public user.
- Read access is allowed but should not.
Concrete example:
- Unpublish `demo` user.
- Access `/slides` with `public` user.
- The template data is generated as `sudo`.
- The same data is then accessed as `public`.
- AccessError should be raised when requesting
`/profile/avatar/<int:user_id>` but is not.
Closes #43826
closes odoo/odoo#45033
X-original-commit: e0112db4d6131751475365ab4c42de848f925dce
Signed-off-by: Christophe Simonis <chs@odoo.com>
This commit is contained in:
@@ -312,13 +312,13 @@ class IrHttp(models.AbstractModel):
|
||||
# eg: Allow to download an attachment on a task from /my/task/task_id
|
||||
record.check('read')
|
||||
record = record_sudo
|
||||
|
||||
# check read access
|
||||
try:
|
||||
# We have prefetched some fields of record, among which the field
|
||||
# 'write_date' used by '__last_update' below. In order to check
|
||||
# access on record, we have to invalidate its cache first.
|
||||
record._cache.clear()
|
||||
|
||||
# check read access
|
||||
try:
|
||||
record['__last_update']
|
||||
except AccessError:
|
||||
return None, 403
|
||||
|
||||
Reference in New Issue
Block a user