[FIX] web_editor: review public_render_template
The normal flow to render a template is now to use `render_public_asset` which bypasses the read access rights if the user matches the groups the view declares. For public users, we still cannot use that as they do not have access to calling model methods at all. The route `public_render_template` is thus still needed, but it should use the `render_public_asset` util. Related to task-2412544 closes odoo/odoo#64167 X-original-commit: 3fd40ba2030fef7dccf4046a932e3b3a172dc53f Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
This commit is contained in:
@@ -472,10 +472,7 @@ class Web_Editor(http.Controller):
|
||||
values = len_args > 1 and args[1] or {}
|
||||
|
||||
View = request.env['ir.ui.view']
|
||||
if request.env.user._is_public() \
|
||||
and xmlid in request.env['web_editor.assets']._get_public_asset_xmlids():
|
||||
View = View.sudo()
|
||||
return View._render_template(xmlid, {k: values[k] for k in values if k in trusted_value_keys})
|
||||
return View.render_public_asset(xmlid, {k: values[k] for k in values if k in trusted_value_keys})
|
||||
|
||||
@http.route('/web_editor/modify_image/<model("ir.attachment"):attachment>', type="json", auth="user", website=True)
|
||||
def modify_image(self, attachment, res_model=None, res_id=None, name=None, data=None, original_id=None):
|
||||
|
||||
@@ -273,6 +273,3 @@ class Assets(models.AbstractModel):
|
||||
dict
|
||||
"""
|
||||
return {}
|
||||
|
||||
def _get_public_asset_xmlids(self):
|
||||
return ["web_editor.compiled_assets_wysiwyg"]
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
<t t-call-assets="web_editor.assets_wysiwyg"/>
|
||||
</template>
|
||||
|
||||
<template id="compiled_assets_wysiwyg" name="Wysiwyg Editor" groups="base.group_user,base.group_portal">
|
||||
<template id="compiled_assets_wysiwyg" name="Wysiwyg Editor" groups="base.group_public,base.group_portal,base.group_user">
|
||||
<t t-call-assets="web_editor.assets_wysiwyg"/>
|
||||
</template>
|
||||
|
||||
|
||||
Reference in New Issue
Block a user