[FIX] fleet: Fix access error on assign driver linked to internal user

Currently, Failing at base/models/res_partner.py#L535
We write on the partner because of the related `plan_to_change_car`

When Assign driver linked to internal user without admin rights
it gives an error in security rules due to write on partner.

So while creating the vehicle when driver is assigned pop the value
for related field plan_to_change_car and rewrite the same with sudo.

closes odoo/odoo#60358

Issue: #54199
Taskid: 2309192
X-original-commit: af21dba516de688743f75e6ffb3bc3341578e37a
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
Co-authored-by: LucasLefevre <lul@odoo.com>
This commit is contained in:
uso-odoo
2020-10-20 10:43:36 +00:00
committed by Barad Mahendra
co-authored by LucasLefevre
parent b1654e5b2b
commit 28a9e90dce
3 changed files with 31 additions and 0 deletions
+5
View File
@@ -214,7 +214,12 @@ class FleetVehicle(models.Model):
@api.model
def create(self, vals):
# Fleet administrator may not have rights to create the plan_to_change_car value when the driver_id is a res.user
# This trick is used to prevent access right error.
ptc_value = 'plan_to_change_car' in vals.keys() and {'plan_to_change_car': vals.pop('plan_to_change_car')}
res = super(FleetVehicle, self).create(vals)
if ptc_value:
res.sudo().write(ptc_value)
if 'driver_id' in vals and vals['driver_id']:
res.create_driver_history(vals['driver_id'])
if 'future_driver_id' in vals and vals['future_driver_id']:
+4
View File
@@ -0,0 +1,4 @@
# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
from . import test_access_rights
+22
View File
@@ -0,0 +1,22 @@
# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
from odoo.tests import common, new_test_user
class TestFleet(common.SavepointCase):
def test_manager_create_vehicle(self):
manager = new_test_user(self.env, "test fleet manager", groups="fleet.fleet_group_manager,base.group_partner_manager")
user = new_test_user(self.env, "test base user", groups="base.group_user")
brand = self.env["fleet.vehicle.model.brand"].create({
"name": "Audi",
})
model = self.env["fleet.vehicle.model"].create({
"brand_id": brand.id,
"name": "A3",
})
self.env["fleet.vehicle"].with_user(manager).create({
"model_id": model.id,
"driver_id": user.partner_id.id,
"plan_to_change_car": False
})