[FIX] base: allow fetching property field definition on unacessible parent record

When the user creates a new record having a property field, the system
fetches the property definition of the parent record to retrieve the
field's default values (see: `_add_default_values`). If the user lacks
read access on the parent record, the user gets an access error when
retrieving the property definition of the parent record.

To prevent this error, we will perform a sudo call on the parent record
before reading the property definition of the parent record. This allow
the user to create a new record, even if they do not have access to the
parent record.

task-3594814

closes odoo/odoo#155178

X-original-commit: 6f0fb8579d8230f91b7eefc5d29f8d61390dacc4
Signed-off-by: Warnon Aurélien (awa) <awa@odoo.com>
Signed-off-by: Julien Banken (jbn) <jbn@odoo.com>
This commit is contained in:
Julien Banken
2024-02-23 16:43:35 +00:00
parent 4f7bc691fe
commit 1324bc72bb
3 changed files with 34 additions and 2 deletions
@@ -166,7 +166,7 @@ class Message(models.Model):
@api.constrains('author', 'discussion')
def _check_author(self):
for message in self.with_context(active_test=False):
if message.discussion and message.author not in message.discussion.participants:
if message.discussion and message.author not in message.discussion.sudo().participants:
raise ValidationError(_("Author must be among the discussion participants."))
@api.depends('author.name', 'discussion.name')
@@ -1651,6 +1651,38 @@ class PropertiesCase(TestPropertiesMixin):
values = message.read(['attributes'])[0]['attributes'][0]
self.assertEqual(values['value'], (tag.id, 'Test Tag'))
@users('test')
def test_properties_field_no_parent_access(self):
"""We can read the child, but not the definition record.
Check that the user does not get an `AccessError` when creating a new
record having a property field whose property definition is stored on
a record the user does not have access to. The newly created record
should have the right schema and should be populated with the default
values stored on the property definition.
"""
def _mocked_check_access_rights(records, operation, raise_exception=True):
if records.env.su:
return True
if raise_exception:
raise AccessError('')
return False
self.env.invalidate_all()
with patch('odoo.addons.test_new_api.models.test_new_api.Discussion.check_access_rights', _mocked_check_access_rights):
message = self.env['test_new_api.message'].create({
'name': 'Test Message',
'discussion': self.discussion_1.id,
'author': self.user.id,
'attributes': {
'moderator_partner_id': self.partner.id,
}
})
self.assertEqual(message.attributes, {
'discussion_color_code': 'blue',
'moderator_partner_id': self.partner.id
})
def test_properties_inherits(self):
email = self.env['test_new_api.emailmessage'].create({
'discussion': self.discussion_1.id,
+1 -1
View File
@@ -3573,7 +3573,7 @@ class Properties(Field):
current_model = env[self.model_name]
definition_record_field = current_model._fields[self.definition_record]
container_model_name = definition_record_field.comodel_name
container_id = env[container_model_name].browse(container_id)
container_id = env[container_model_name].sudo().browse(container_id)
properties_definition = container_id[self.definition_record_field]
if not (properties_definition or (