[PERF] mail: remove extra ACLs check in message_post
An explicit access check when posting a message has been added at odoo/odoo@9920f20e4c when adding notably computation of display_name as sudo. However this is not the role of ``message_post`` to check access for such an implementation details. Access is anyway already granted through the various browse and record access done during the posting process. Moreover even message access (creation or read) is protected notably through its related record ACLs. Portal/Public access on message_post is anyway done through dedicated routes using tokens or hash/pid that call message_post as sudo. We can therefore remove the explicit access check added a bit wildly in the middle of the code. Task-2710804 (Mail: Clean MailThread API) closes odoo/odoo#99654 Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
This commit is contained in:
@@ -1942,10 +1942,6 @@ class MailThread(models.AbstractModel):
|
||||
|
||||
self = self._fallback_lang() # add lang to context immediately since it will be useful in various flows latter.
|
||||
|
||||
# Explicit access rights check, because display_name is computed as sudo.
|
||||
self.check_access_rights('read')
|
||||
self.check_access_rule('read')
|
||||
|
||||
# Find the message's author
|
||||
if self.env.user._is_public() and 'guest' in self.env.context:
|
||||
author_guest_id = self.env.context['guest'].id
|
||||
|
||||
Reference in New Issue
Block a user