From 347d0e5b468cf042cb6ea431c367bbbd54bdb39b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thibault=20Delavall=C3=A9e?= Date: Wed, 12 Dec 2012 13:55:18 +0100 Subject: [PATCH] [IMP] portal removed access rights of portal user on res_partner and derived tables. Updated several accesses to bypass the security issues. Updated portal tests to have a more complete test scenario. bzr revid: tde@openerp.com-20121212125518-k0s07niojr8a1xtu --- addons/mail/mail_thread.py | 5 +- .../mail/wizard/mail_compose_message_view.xml | 2 +- addons/portal/mail_mail.py | 4 +- addons/portal/security/ir.model.access.csv | 8 +-- addons/portal/tests/test_portal.py | 67 +++++++++++++------ addons/portal_crm/contact.py | 6 +- 6 files changed, 62 insertions(+), 30 deletions(-) diff --git a/addons/mail/mail_thread.py b/addons/mail/mail_thread.py index bb5d94843fc..ac2b0efb670 100644 --- a/addons/mail/mail_thread.py +++ b/addons/mail/mail_thread.py @@ -213,8 +213,11 @@ class mail_thread(osv.AbstractModel): def create(self, cr, uid, vals, context=None): """ Override to subscribe the current user. """ + if context is None: + context = {} thread_id = super(mail_thread, self).create(cr, uid, vals, context=context) - self.message_subscribe_users(cr, uid, [thread_id], [uid], context=context) + if not context.get('mail_nosubscribe'): + self.message_subscribe_users(cr, uid, [thread_id], [uid], context=context) return thread_id def unlink(self, cr, uid, ids, context=None): diff --git a/addons/mail/wizard/mail_compose_message_view.xml b/addons/mail/wizard/mail_compose_message_view.xml index c0b329690e3..3b8e51f35d6 100644 --- a/addons/mail/wizard/mail_compose_message_view.xml +++ b/addons/mail/wizard/mail_compose_message_view.xml @@ -14,7 +14,7 @@