[PERF] mail: remove extra ACLs check in message_post

An explicit access check when posting a message has been added at odoo/odoo@9920f20e4c
when adding notably computation of display_name as sudo. However this is not
the role of ``message_post`` to check access for such an implementation
details.

Access is anyway already granted through the various browse and record access
done during the posting process. Moreover even message access (creation or
read) is protected notably through its related record ACLs.

Portal/Public access on message_post is anyway done through dedicated routes
using tokens or hash/pid that call message_post as sudo. We can therefore
remove the explicit access check added a bit wildly in the middle of the code.

Task-2710804 (Mail: Clean MailThread API)

closes odoo/odoo#99654

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
This commit is contained in:
Thibault Delavallée
2022-09-09 11:12:29 +02:00
parent 17bf3d9134
commit 24f2f03047
-4
View File
@@ -1942,10 +1942,6 @@ class MailThread(models.AbstractModel):
self = self._fallback_lang() # add lang to context immediately since it will be useful in various flows latter.
# Explicit access rights check, because display_name is computed as sudo.
self.check_access_rights('read')
self.check_access_rule('read')
# Find the message's author
if self.env.user._is_public() and 'guest' in self.env.context:
author_guest_id = self.env.context['guest'].id