[FIX] website: don't error on inaccessible model
When deleting a page, `search_url_dependencies` tries to trawl through all models to see if they might have a link to the page being deleted. However if the user invoking that function does not have access to a model with an HTML field, it raises an error. Given pages are managed by website designers which are *not administrators* there is no reason to believe the current user has access to every model in the database (not that even admins do these days). Since `search_url_dependencies` is a best-effort search anyway, just ignore any model to which the current user doesn't have access. An alternative would be to do the search in sudo mode, but that doesn't seem necessary, and could even be problematic if a match is found: - it might leak information the user should not access (because the record name is returned, as well as the model & field names) - it will trigger further access errors (because links to problematic records are provided, on which the user might want to click) closes odoo/odoo#127973 X-original-commit: 47a69a186bc415bf61a523da9686ca96c0beb74e Signed-off-by: Romain Derie (rde) <rde@odoo.com>
This commit is contained in:
committed by
Romain Derie
parent
b29733ce37
commit
489566d4bb
@@ -862,6 +862,9 @@ class Website(models.Model):
|
||||
]
|
||||
for model, _table, column, _translate in html_fields_attributes:
|
||||
Model = self.env[model]
|
||||
if not Model.check_access_rights('read', raise_exception=False):
|
||||
continue
|
||||
|
||||
# Generate the exact domain to search for the URL in this field
|
||||
domains = []
|
||||
for url, website_domain in search_criteria:
|
||||
|
||||
Reference in New Issue
Block a user