[FIX] web_editor: review public_render_template

The normal flow to render a template is now to use `render_public_asset`
which bypasses the read access rights if the user matches the groups
the view declares.

For public users, we still cannot use that as they do not have access
to calling model methods at all. The route `public_render_template` is
thus still needed, but it should use the `render_public_asset` util.

Related to task-2412544

closes odoo/odoo#64167

X-original-commit: 3fd40ba2030fef7dccf4046a932e3b3a172dc53f
Signed-off-by: Quentin Smetz (qsm) <qsm@odoo.com>
This commit is contained in:
Benoit Socias
2021-01-06 17:01:34 +00:00
committed by qsm-odoo
parent fc348de003
commit 1feebf2a4d
3 changed files with 2 additions and 8 deletions
+1 -4
View File
@@ -472,10 +472,7 @@ class Web_Editor(http.Controller):
values = len_args > 1 and args[1] or {}
View = request.env['ir.ui.view']
if request.env.user._is_public() \
and xmlid in request.env['web_editor.assets']._get_public_asset_xmlids():
View = View.sudo()
return View._render_template(xmlid, {k: values[k] for k in values if k in trusted_value_keys})
return View.render_public_asset(xmlid, {k: values[k] for k in values if k in trusted_value_keys})
@http.route('/web_editor/modify_image/<model("ir.attachment"):attachment>', type="json", auth="user", website=True)
def modify_image(self, attachment, res_model=None, res_id=None, name=None, data=None, original_id=None):
-3
View File
@@ -273,6 +273,3 @@ class Assets(models.AbstractModel):
dict
"""
return {}
def _get_public_asset_xmlids(self):
return ["web_editor.compiled_assets_wysiwyg"]
+1 -1
View File
@@ -7,7 +7,7 @@
<t t-call-assets="web_editor.assets_wysiwyg"/>
</template>
<template id="compiled_assets_wysiwyg" name="Wysiwyg Editor" groups="base.group_user,base.group_portal">
<template id="compiled_assets_wysiwyg" name="Wysiwyg Editor" groups="base.group_public,base.group_portal,base.group_user">
<t t-call-assets="web_editor.assets_wysiwyg"/>
</template>