From 1feebf2a4deea3b7664d2fbcbd050c85b8d9017e Mon Sep 17 00:00:00 2001 From: Benoit Socias Date: Wed, 6 Jan 2021 10:12:07 +0000 Subject: [PATCH] [FIX] web_editor: review `public_render_template` The normal flow to render a template is now to use `render_public_asset` which bypasses the read access rights if the user matches the groups the view declares. For public users, we still cannot use that as they do not have access to calling model methods at all. The route `public_render_template` is thus still needed, but it should use the `render_public_asset` util. Related to task-2412544 closes odoo/odoo#64167 X-original-commit: 3fd40ba2030fef7dccf4046a932e3b3a172dc53f Signed-off-by: Quentin Smetz (qsm) --- addons/web_editor/controllers/main.py | 5 +---- addons/web_editor/models/assets.py | 3 --- addons/web_editor/views/editor.xml | 2 +- 3 files changed, 2 insertions(+), 8 deletions(-) diff --git a/addons/web_editor/controllers/main.py b/addons/web_editor/controllers/main.py index b84a1537e43..b768540f55e 100644 --- a/addons/web_editor/controllers/main.py +++ b/addons/web_editor/controllers/main.py @@ -472,10 +472,7 @@ class Web_Editor(http.Controller): values = len_args > 1 and args[1] or {} View = request.env['ir.ui.view'] - if request.env.user._is_public() \ - and xmlid in request.env['web_editor.assets']._get_public_asset_xmlids(): - View = View.sudo() - return View._render_template(xmlid, {k: values[k] for k in values if k in trusted_value_keys}) + return View.render_public_asset(xmlid, {k: values[k] for k in values if k in trusted_value_keys}) @http.route('/web_editor/modify_image/', type="json", auth="user", website=True) def modify_image(self, attachment, res_model=None, res_id=None, name=None, data=None, original_id=None): diff --git a/addons/web_editor/models/assets.py b/addons/web_editor/models/assets.py index 425c5376293..4178335624c 100644 --- a/addons/web_editor/models/assets.py +++ b/addons/web_editor/models/assets.py @@ -273,6 +273,3 @@ class Assets(models.AbstractModel): dict """ return {} - - def _get_public_asset_xmlids(self): - return ["web_editor.compiled_assets_wysiwyg"] diff --git a/addons/web_editor/views/editor.xml b/addons/web_editor/views/editor.xml index 3d87ba2d34f..7332a718b2c 100644 --- a/addons/web_editor/views/editor.xml +++ b/addons/web_editor/views/editor.xml @@ -7,7 +7,7 @@ -