From 24f2f030478f2ff2d9e7ee3dac2b6ebad1145878 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thibault=20Delavall=C3=A9e?= Date: Tue, 6 Sep 2022 15:23:29 +0000 Subject: [PATCH] [PERF] mail: remove extra ACLs check in message_post An explicit access check when posting a message has been added at odoo/odoo@9920f20e4c7753bc17bea71dea3a90f7de687196 when adding notably computation of display_name as sudo. However this is not the role of ``message_post`` to check access for such an implementation details. Access is anyway already granted through the various browse and record access done during the posting process. Moreover even message access (creation or read) is protected notably through its related record ACLs. Portal/Public access on message_post is anyway done through dedicated routes using tokens or hash/pid that call message_post as sudo. We can therefore remove the explicit access check added a bit wildly in the middle of the code. Task-2710804 (Mail: Clean MailThread API) closes odoo/odoo#99654 Signed-off-by: Thibault Delavallee (tde) --- addons/mail/models/mail_thread.py | 4 ---- 1 file changed, 4 deletions(-) diff --git a/addons/mail/models/mail_thread.py b/addons/mail/models/mail_thread.py index 8b07bf381b8..a0e84dfacb1 100644 --- a/addons/mail/models/mail_thread.py +++ b/addons/mail/models/mail_thread.py @@ -1942,10 +1942,6 @@ class MailThread(models.AbstractModel): self = self._fallback_lang() # add lang to context immediately since it will be useful in various flows latter. - # Explicit access rights check, because display_name is computed as sudo. - self.check_access_rights('read') - self.check_access_rule('read') - # Find the message's author if self.env.user._is_public() and 'guest' in self.env.context: author_guest_id = self.env.context['guest'].id