[FIX] calendar: allow internal users to download invitation.ics

Access rights on ir.attachment depend on the record it is linked to.

steps to reproduce:
- log as admin
- create a calendar event and invite marc demo
- log as marc demo
- check discuss notifications and try to download "invite.ics"

before this commit:
- file can not be downloaded from the webclient (access error appear in logs)

after this commit:
- file can be downloaded from the webclient

opw-3754798

closes odoo/odoo#162694

X-original-commit: 6a698ef3ee99af45251156279c9a5af6185f5dd1
Signed-off-by: Arnaud Joset (arj) <arj@odoo.com>
Signed-off-by: Nicolas Danhier (nda) <nda@odoo.com>
This commit is contained in:
nda
2024-04-22 13:39:50 +00:00
parent 96ac5c0770
commit 1b746c0e2c
2 changed files with 20 additions and 1 deletions
@@ -131,6 +131,8 @@ class Attendee(models.Model):
'datas': base64.b64encode(ics_file), 'datas': base64.b64encode(ics_file),
'description': 'invitation.ics', 'description': 'invitation.ics',
'mimetype': 'text/calendar', 'mimetype': 'text/calendar',
'res_id': event_id,
'res_model': 'calendar.event',
'name': 'invitation.ics', 'name': 'invitation.ics',
}).ids }).ids
+18 -1
View File
@@ -6,7 +6,7 @@ from datetime import date, datetime, timedelta
from odoo import fields, Command from odoo import fields, Command
from odoo.addons.base.tests.common import HttpCaseWithUserDemo from odoo.addons.base.tests.common import HttpCaseWithUserDemo
from odoo.tests import Form, HttpCase, tagged from odoo.tests import Form, tagged, new_test_user
from odoo.addons.base.tests.common import SavepointCaseWithUserDemo from odoo.addons.base.tests.common import SavepointCaseWithUserDemo
import freezegun import freezegun
@@ -381,6 +381,23 @@ class TestCalendar(SavepointCaseWithUserDemo):
# no more email should be sent # no more email should be sent
_test_one_mail_per_attendee(self, partners) _test_one_mail_per_attendee(self, partners)
def test_event_creation_internal_user_invitation_ics(self):
""" Check that internal user can read invitation.ics attachment """
internal_user = new_test_user(self.env, login='internal_user', groups='base.group_user')
partner = internal_user.partner_id
self.event_tech_presentation.write({
'partner_ids': [(4, partner.id)],
})
msg = self.env['mail.message'].search([
('notified_partner_ids', 'in', partner.id),
])
msg.invalidate_recordset()
# internal user can read the attachment without errors
self.assertEqual(msg.with_user(internal_user).attachment_ids.name, 'invitation.ics')
def test_event_creation_sudo_other_company(self): def test_event_creation_sudo_other_company(self):
""" Check Access right issue when create event with sudo """ Check Access right issue when create event with sudo