[IMP] portal: Partial revert of #37312
Purpose ======= This fix makes no sense because it exposes some private data to portal users. Fortunately it was only introduced in the master branch. closes odoo/odoo#40710 Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
This commit is contained in:
@@ -11,8 +11,7 @@ class PortalAccount(CustomerPortal):
|
||||
|
||||
def _prepare_portal_layout_values(self):
|
||||
values = super(PortalAccount, self)._prepare_portal_layout_values()
|
||||
# An internal user could not have access to the account.move model
|
||||
invoice_count = request.env['account.move'].sudo().search_count([
|
||||
invoice_count = request.env['account.move'].search_count([
|
||||
('type', 'in', ('out_invoice', 'in_invoice', 'out_refund', 'in_refund', 'out_receipt', 'in_receipt')),
|
||||
])
|
||||
values['invoice_count'] = invoice_count
|
||||
|
||||
@@ -18,7 +18,7 @@ class CustomerPortal(CustomerPortal):
|
||||
|
||||
def _prepare_portal_layout_values(self):
|
||||
values = super(CustomerPortal, self)._prepare_portal_layout_values()
|
||||
values['purchase_count'] = request.env['purchase.order'].sudo().search_count([
|
||||
values['purchase_count'] = request.env['purchase.order'].search_count([
|
||||
('state', 'in', ['purchase', 'done', 'cancel'])
|
||||
])
|
||||
return values
|
||||
|
||||
@@ -19,11 +19,11 @@ class CustomerPortal(CustomerPortal):
|
||||
partner = request.env.user.partner_id
|
||||
|
||||
SaleOrder = request.env['sale.order']
|
||||
quotation_count = SaleOrder.sudo().search_count([
|
||||
quotation_count = SaleOrder.search_count([
|
||||
('message_partner_ids', 'child_of', [partner.commercial_partner_id.id]),
|
||||
('state', 'in', ['sent', 'cancel'])
|
||||
])
|
||||
order_count = SaleOrder.sudo().search_count([
|
||||
order_count = SaleOrder.search_count([
|
||||
('message_partner_ids', 'child_of', [partner.commercial_partner_id.id]),
|
||||
('state', 'in', ['sale', 'done'])
|
||||
])
|
||||
|
||||
Reference in New Issue
Block a user