[FIX] base: clear cache before read access check

When reading binary content such as `image_128` on `res.users`,
`AccessError` should be raised when necessary.

Steps to reproduce:
  - Populate cache in superuser mode.
  - Access cached field with public user.
  - Read access is allowed but should not.

Concrete example:
  - Unpublish `demo` user.
  - Access `/slides` with `public` user.
  - The template data is generated as `sudo`.
  - The same data is then accessed as `public`.
  - AccessError should be raised when requesting
    `/profile/avatar/<int:user_id>` but is not.

Closes #43826

closes odoo/odoo#45033

X-original-commit: e0112db4d6131751475365ab4c42de848f925dce
Signed-off-by: Christophe Simonis <chs@odoo.com>
This commit is contained in:
Johan Demaret Rivarola
2020-02-10 17:43:11 +00:00
parent 7cc6fdf365
commit 0d5fcdc1c7
+3 -3
View File
@@ -312,13 +312,13 @@ class IrHttp(models.AbstractModel):
# eg: Allow to download an attachment on a task from /my/task/task_id
record.check('read')
record = record_sudo
# check read access
try:
# We have prefetched some fields of record, among which the field
# 'write_date' used by '__last_update' below. In order to check
# access on record, we have to invalidate its cache first.
record._cache.clear()
# check read access
try:
record['__last_update']
except AccessError:
return None, 403