[FIX] base: don't check access rules on new records

This fixes an issue where access rules are checked on a new record: the
rule domains are evaluated with method filtered_domain(), and one rule
uses the operator 'child_of', which is implemented with a call to
search().  When used with a new record, filtered_domain() returns an
empty recordset instead of the record itself.

By design, the ORM doesn't check security on new records.  A base
automation of type 'onchange' will run some server action on a new
record.  The server action may still check access rights on the model,
but should not check access rules.

closes odoo/odoo#158309

Signed-off-by: Rémy Voet (ryv) <ryv@odoo.com>
This commit is contained in:
Raphael Collet
2024-03-20 19:56:40 +00:00
parent 43d150902f
commit 268d8b830e
+3 -1
View File
@@ -924,7 +924,9 @@ class IrActionsServer(models.Model):
eval_context = self._get_eval_context(action)
records = eval_context.get('record') or eval_context['model']
records |= eval_context.get('records') or eval_context['model']
if records:
if records.ids:
# check access rules on real records only; base automations of
# type 'onchange' can run server actions on new records
try:
records.check_access_rule('write')
except AccessError: