From 1324bc72bb9a784e5f0ece78df0941ab89a8e4fc Mon Sep 17 00:00:00 2001 From: Julien Banken Date: Wed, 24 Jan 2024 09:39:29 +0000 Subject: [PATCH] [FIX] base: allow fetching property field definition on unacessible parent record MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit When the user creates a new record having a property field, the system fetches the property definition of the parent record to retrieve the field's default values (see: `_add_default_values`). If the user lacks read access on the parent record, the user gets an access error when retrieving the property definition of the parent record. To prevent this error, we will perform a sudo call on the parent record before reading the property definition of the parent record. This allow the user to create a new record, even if they do not have access to the parent record. task-3594814 closes odoo/odoo#155178 X-original-commit: 6f0fb8579d8230f91b7eefc5d29f8d61390dacc4 Signed-off-by: Warnon Aurélien (awa) Signed-off-by: Julien Banken (jbn) --- .../test_new_api/models/test_new_api.py | 2 +- .../test_new_api/tests/test_properties.py | 32 +++++++++++++++++++ odoo/fields.py | 2 +- 3 files changed, 34 insertions(+), 2 deletions(-) diff --git a/odoo/addons/test_new_api/models/test_new_api.py b/odoo/addons/test_new_api/models/test_new_api.py index 4a22fe542ce..e961886c86c 100644 --- a/odoo/addons/test_new_api/models/test_new_api.py +++ b/odoo/addons/test_new_api/models/test_new_api.py @@ -166,7 +166,7 @@ class Message(models.Model): @api.constrains('author', 'discussion') def _check_author(self): for message in self.with_context(active_test=False): - if message.discussion and message.author not in message.discussion.participants: + if message.discussion and message.author not in message.discussion.sudo().participants: raise ValidationError(_("Author must be among the discussion participants.")) @api.depends('author.name', 'discussion.name') diff --git a/odoo/addons/test_new_api/tests/test_properties.py b/odoo/addons/test_new_api/tests/test_properties.py index bc1cff2461e..1fd8224955a 100644 --- a/odoo/addons/test_new_api/tests/test_properties.py +++ b/odoo/addons/test_new_api/tests/test_properties.py @@ -1651,6 +1651,38 @@ class PropertiesCase(TestPropertiesMixin): values = message.read(['attributes'])[0]['attributes'][0] self.assertEqual(values['value'], (tag.id, 'Test Tag')) + @users('test') + def test_properties_field_no_parent_access(self): + """We can read the child, but not the definition record. + + Check that the user does not get an `AccessError` when creating a new + record having a property field whose property definition is stored on + a record the user does not have access to. The newly created record + should have the right schema and should be populated with the default + values stored on the property definition. + """ + def _mocked_check_access_rights(records, operation, raise_exception=True): + if records.env.su: + return True + if raise_exception: + raise AccessError('') + return False + + self.env.invalidate_all() + with patch('odoo.addons.test_new_api.models.test_new_api.Discussion.check_access_rights', _mocked_check_access_rights): + message = self.env['test_new_api.message'].create({ + 'name': 'Test Message', + 'discussion': self.discussion_1.id, + 'author': self.user.id, + 'attributes': { + 'moderator_partner_id': self.partner.id, + } + }) + self.assertEqual(message.attributes, { + 'discussion_color_code': 'blue', + 'moderator_partner_id': self.partner.id + }) + def test_properties_inherits(self): email = self.env['test_new_api.emailmessage'].create({ 'discussion': self.discussion_1.id, diff --git a/odoo/fields.py b/odoo/fields.py index abab0f4c85b..d824450a915 100644 --- a/odoo/fields.py +++ b/odoo/fields.py @@ -3573,7 +3573,7 @@ class Properties(Field): current_model = env[self.model_name] definition_record_field = current_model._fields[self.definition_record] container_model_name = definition_record_field.comodel_name - container_id = env[container_model_name].browse(container_id) + container_id = env[container_model_name].sudo().browse(container_id) properties_definition = container_id[self.definition_record_field] if not (properties_definition or (