[FIX] calendar: allow internal users to download invitation.ics
Access rights on ir.attachment depend on the record it is linked to. steps to reproduce: - log as admin - create a calendar event and invite marc demo - log as marc demo - check discuss notifications and try to download "invite.ics" before this commit: - file can not be downloaded from the webclient (access error appear in logs) after this commit: - file can be downloaded from the webclient opw-3754798 closes odoo/odoo#162694 X-original-commit: 6a698ef3ee99af45251156279c9a5af6185f5dd1 Signed-off-by: Arnaud Joset (arj) <arj@odoo.com> Signed-off-by: Nicolas Danhier (nda) <nda@odoo.com>
This commit is contained in:
@@ -131,6 +131,8 @@ class Attendee(models.Model):
|
|||||||
'datas': base64.b64encode(ics_file),
|
'datas': base64.b64encode(ics_file),
|
||||||
'description': 'invitation.ics',
|
'description': 'invitation.ics',
|
||||||
'mimetype': 'text/calendar',
|
'mimetype': 'text/calendar',
|
||||||
|
'res_id': event_id,
|
||||||
|
'res_model': 'calendar.event',
|
||||||
'name': 'invitation.ics',
|
'name': 'invitation.ics',
|
||||||
}).ids
|
}).ids
|
||||||
|
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ from datetime import date, datetime, timedelta
|
|||||||
|
|
||||||
from odoo import fields, Command
|
from odoo import fields, Command
|
||||||
from odoo.addons.base.tests.common import HttpCaseWithUserDemo
|
from odoo.addons.base.tests.common import HttpCaseWithUserDemo
|
||||||
from odoo.tests import Form, HttpCase, tagged
|
from odoo.tests import Form, tagged, new_test_user
|
||||||
from odoo.addons.base.tests.common import SavepointCaseWithUserDemo
|
from odoo.addons.base.tests.common import SavepointCaseWithUserDemo
|
||||||
|
|
||||||
import freezegun
|
import freezegun
|
||||||
@@ -381,6 +381,23 @@ class TestCalendar(SavepointCaseWithUserDemo):
|
|||||||
# no more email should be sent
|
# no more email should be sent
|
||||||
_test_one_mail_per_attendee(self, partners)
|
_test_one_mail_per_attendee(self, partners)
|
||||||
|
|
||||||
|
def test_event_creation_internal_user_invitation_ics(self):
|
||||||
|
""" Check that internal user can read invitation.ics attachment """
|
||||||
|
internal_user = new_test_user(self.env, login='internal_user', groups='base.group_user')
|
||||||
|
|
||||||
|
partner = internal_user.partner_id
|
||||||
|
self.event_tech_presentation.write({
|
||||||
|
'partner_ids': [(4, partner.id)],
|
||||||
|
})
|
||||||
|
msg = self.env['mail.message'].search([
|
||||||
|
('notified_partner_ids', 'in', partner.id),
|
||||||
|
])
|
||||||
|
msg.invalidate_recordset()
|
||||||
|
|
||||||
|
|
||||||
|
# internal user can read the attachment without errors
|
||||||
|
self.assertEqual(msg.with_user(internal_user).attachment_ids.name, 'invitation.ics')
|
||||||
|
|
||||||
def test_event_creation_sudo_other_company(self):
|
def test_event_creation_sudo_other_company(self):
|
||||||
""" Check Access right issue when create event with sudo
|
""" Check Access right issue when create event with sudo
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user