[FIX] crm: Access rights issues in contact merging

- When merging partners with fields restricted to certain groups which the user doesn't belong, an access error is raised.
  To avoid this, we only merge fields that are accessible by the user. We do so by using the method fields_get() that only returns the fields accessible by the current user.
This commit is contained in:
Toufik Benjaa
2018-05-14 17:04:46 +02:00
parent 2787de8c68
commit 2b771757e2
+3 -2
View File
@@ -223,7 +223,7 @@ class MergePartnerAutomatic(models.TransientModel):
"""
_logger.debug('_update_values for dst_partner: %s for src_partners: %r', dst_partner.id, src_partners.ids)
model_fields = dst_partner._fields
model_fields = dst_partner.fields_get().keys()
def write_serializer(item):
if isinstance(item, models.BaseModel):
@@ -232,7 +232,8 @@ class MergePartnerAutomatic(models.TransientModel):
return item
# get all fields that are not computed or x2many
values = dict()
for column, field in model_fields.items():
for column in model_fields:
field = dst_partner._fields[column]
if field.type not in ('many2many', 'one2many') and field.compute is None:
for item in itertools.chain(src_partners, [dst_partner]):
if item[column]: