From 132157fc2ae802e4147c11944dd7aa20093b3115 Mon Sep 17 00:00:00 2001 From: Stephane Debauche Date: Fri, 26 Mar 2021 08:47:48 +0000 Subject: [PATCH] [FIX] website_mail_channel: fix archive groups statistics computation Compute reliable statistics independently from actual ACLs. Task ID-2078313 closes odoo/odoo#68450 X-original-commit: fa42fd0575769d737112125dded63eef05a6dd3d Signed-off-by: Thibault Delavallee (tde) --- addons/mail/i18n/mail.pot | 12 ++++++++++++ addons/mail/models/mail_message.py | 16 ++++++++++++++++ addons/website_mail_channel/controllers/main.py | 6 ++++-- 3 files changed, 32 insertions(+), 2 deletions(-) diff --git a/addons/mail/i18n/mail.pot b/addons/mail/i18n/mail.pot index d3302287f19..c27211981f2 100644 --- a/addons/mail/i18n/mail.pot +++ b/addons/mail/i18n/mail.pot @@ -4362,6 +4362,18 @@ msgstr "" msgid "Online" msgstr "" +#. module: mail +#: code:addons/mail/models/mail_message.py:0 +#, python-format +msgid "Only administrators are allowed to export mail message" +msgstr "" + +#. module: mail +#: code:addons/mail/models/mail_message.py:0 +#, python-format +msgid "Only administrators are allowed to use grouped read on message model" +msgstr "" + #. module: mail #: code:addons/mail/models/mail_channel.py:0 #, python-format diff --git a/addons/mail/models/mail_message.py b/addons/mail/models/mail_message.py index a586fd2bc3b..0256079892b 100644 --- a/addons/mail/models/mail_message.py +++ b/addons/mail/models/mail_message.py @@ -700,6 +700,22 @@ class Message(models.Model): elem._invalidate_documents() return super(Message, self).unlink() + @api.model + def _read_group_raw(self, domain, fields, groupby, offset=0, limit=None, orderby=False, lazy=True): + if not self.env.is_admin(): + raise AccessError(_("Only administrators are allowed to use grouped read on message model")) + + return super(Message, self)._read_group_raw( + domain=domain, fields=fields, groupby=groupby, offset=offset, + limit=limit, orderby=orderby, lazy=lazy, + ) + + def export_data(self, fields_to_export): + if not self.env.is_admin(): + raise AccessError(_("Only administrators are allowed to export mail message")) + + return super(Message, self).export_data(fields_to_export) + # ------------------------------------------------------ # DISCUSS API # ------------------------------------------------------ diff --git a/addons/website_mail_channel/controllers/main.py b/addons/website_mail_channel/controllers/main.py index 143b6f08e37..0237ef4dc1d 100644 --- a/addons/website_mail_channel/controllers/main.py +++ b/addons/website_mail_channel/controllers/main.py @@ -17,7 +17,8 @@ class MailGroup(http.Controller): def _get_archives(self, group_id): MailMessage = request.env['mail.message'] - groups = MailMessage._read_group_raw( + # use sudo to avoid side-effects due to custom ACLs + groups = MailMessage.sudo()._read_group_raw( [('model', '=', 'mail.channel'), ('res_id', '=', group_id), ('message_type', '!=', 'notification')], ['subject', 'date'], groupby=["date"], orderby="date desc") @@ -44,7 +45,8 @@ class MailGroup(http.Controller): # compute statistics month_date = datetime.today() - relativedelta.relativedelta(months=1) - messages = request.env['mail.message'].read_group([ + # use sudo to avoid side-effects due to custom ACLs + messages = request.env['mail.message'].sudo().read_group([ ('model', '=', 'mail.channel'), ('date', '>=', fields.Datetime.to_string(month_date)), ('message_type', '!=', 'notification'),