From 12dc06ebef180ae71cc2c50f86b6b1db70e6cd39 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Luis=20Gonz=C3=A1lez?= Date: Sat, 23 Jul 2022 19:17:08 +0000 Subject: [PATCH] [FIX] base: don't lose sudo when searching partners Currently, when searching a partner through a related record using `sudo()`, the superuser privileges are used when searching the record, but not when searching the related partner. That's because the su flag is lost during the call to with_user, even if it was to keep the same user. For instance, a code like the following wouldn't work if the current user has no enough rights (e.g. the public user): self.sudo().search([('partner_id', 'ilike', 'John Doe')]) To solve the above, the with_user is called only when a specific name_get_uid is given, as done in the _search implementation. closes odoo/odoo#97920 X-original-commit: e5e12681437ae562517cc058e4ce0fab90cd0ae7 Signed-off-by: Raphael Collet --- odoo/addons/base/tests/test_res_partner.py | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/odoo/addons/base/tests/test_res_partner.py b/odoo/addons/base/tests/test_res_partner.py index fe0ebe56ca4..579d2d005ee 100644 --- a/odoo/addons/base/tests/test_res_partner.py +++ b/odoo/addons/base/tests/test_res_partner.py @@ -3,7 +3,7 @@ from odoo.tests import Form from odoo.tests.common import TransactionCase -from odoo.exceptions import UserError +from odoo.exceptions import AccessError, UserError class TestPartner(TransactionCase): @@ -20,6 +20,13 @@ class TestPartner(TransactionCase): ns_res = self.env['res.partner'].name_search('Vlad', args=[('user_ids.email', 'ilike', 'vlad')]) self.assertEqual(set(i[0] for i in ns_res), set(test_user.partner_id.ids)) + # Check a partner may be searched when current user has no access but sudo is used + public_user = self.env.ref('base.public_user') + with self.assertRaises(AccessError): + test_partner.with_user(public_user).check_access_rule('read') + ns_res = self.env['res.partner'].with_user(public_user).sudo().name_search('Vlad', args=[('user_ids.email', 'ilike', 'vlad')]) + self.assertEqual(set(i[0] for i in ns_res), set(test_user.partner_id.ids)) + def test_name_get(self): """ Check name_get on partner, especially with different context Check name_get correctly return name with context. """