[FIX] base: don't check access rules on new records
This fixes an issue where access rules are checked on a new record: the rule domains are evaluated with method filtered_domain(), and one rule uses the operator 'child_of', which is implemented with a call to search(). When used with a new record, filtered_domain() returns an empty recordset instead of the record itself. By design, the ORM doesn't check security on new records. A base automation of type 'onchange' will run some server action on a new record. The server action may still check access rights on the model, but should not check access rules. closes odoo/odoo#158309 Signed-off-by: Rémy Voet (ryv) <ryv@odoo.com>
This commit is contained in:
@@ -924,7 +924,9 @@ class IrActionsServer(models.Model):
|
||||
eval_context = self._get_eval_context(action)
|
||||
records = eval_context.get('record') or eval_context['model']
|
||||
records |= eval_context.get('records') or eval_context['model']
|
||||
if records:
|
||||
if records.ids:
|
||||
# check access rules on real records only; base automations of
|
||||
# type 'onchange' can run server actions on new records
|
||||
try:
|
||||
records.check_access_rule('write')
|
||||
except AccessError:
|
||||
|
||||
Reference in New Issue
Block a user