From 627d78b34fdf1014f6a8436296db3996c6d703f4 Mon Sep 17 00:00:00 2001 From: Hpar Date: Fri, 12 Aug 2016 16:40:17 +0200 Subject: [PATCH 1/2] [CLA] Update akretion + hparfr --- doc/cla/corporate/akretion.md | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/cla/corporate/akretion.md b/doc/cla/corporate/akretion.md index 61932b3fe8b..156b24ff4d5 100644 --- a/doc/cla/corporate/akretion.md +++ b/doc/cla/corporate/akretion.md @@ -33,6 +33,7 @@ Cilene Oliveira cilene.oliveira@akretion.com https://github.com/cileneoliveira David Beal david.beal@akretion.com https://github.com/bealdav Florian da Costa florian.dacosta@akretion.com https://github.com/florian-dacosta Magno Barcelo da Costa magno.costa@akretion.com.br https://github.com/mbcosta +Raphaël Reverdy raphael.reverdy@akretion.com https://github.com/hparfr Raphaël Valyi raphael.valyi@akretion.com https://github.com/rvalyi Renato Lima renato.lima@akretion.com https://github.com/renatonlima Sebastien Beau sebastien.beau@akretion.com https://github.com/sebastienbeau From a989680b60c7b12a21fd60a132e923b40c67bd6c Mon Sep 17 00:00:00 2001 From: Hparfr Date: Fri, 12 Aug 2016 16:20:46 +0200 Subject: [PATCH 2/2] [FIX] stock: remove eval from search method Using a safe_eval is overkill and can nicely be replaced by operator Closes #13138 --- addons/stock/models/product.py | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/addons/stock/models/product.py b/addons/stock/models/product.py index cfadaf0c1d3..49d1a4c70b1 100644 --- a/addons/stock/models/product.py +++ b/addons/stock/models/product.py @@ -4,9 +4,17 @@ from odoo import api, fields, models, _ from odoo.addons import decimal_precision as dp from odoo.exceptions import UserError -from odoo.tools.safe_eval import safe_eval as eval from odoo.tools.float_utils import float_round +import operator as py_operator +OPERATORS = { + '<': py_operator.lt, + '>': py_operator.gt, + '<=': py_operator.le, + '>=': py_operator.ge, + '==': py_operator.eq, + '!=': py_operator.ne +} class Product(models.Model): _inherit = "product.product" @@ -238,7 +246,7 @@ class Product(models.Model): # TODO: Still optimization possible when searching virtual quantities ids = [] for product in self.search([]): - if eval(str(product[field]) + operator + str(value)): + if OPERATORS[operator](product[field], value): ids.append(product.id) return [('id', 'in', ids)] @@ -261,7 +269,7 @@ class Product(models.Model): domain_quant.append(('package_id', '=', package_id)) quants_groupby = self.env['stock.quant'].read_group(domain_quant, ['product_id', 'qty'], ['product_id']) for quant in quants_groupby: - if eval('%s %s %s' % (quant['qty'], operator, value)): + if OPERATORS[operator](quant['qty'], value): product_ids.add(quant['product_id'][0]) return list(product_ids)