[FIX] website: don't error on inaccessible model

When deleting a page, `search_url_dependencies` tries to trawl through
all models to see if they might have a link to the page being deleted.

However if the user invoking that function does not have access to a
model with an HTML field, it raises an error. Given pages are managed
by website designers which are *not administrators* there is no reason
to believe the current user has access to every model in the
database (not that even admins do these days). Since
`search_url_dependencies` is a best-effort search anyway, just ignore
any model to which the current user doesn't have access.

An alternative would be to do the search in sudo mode, but that
doesn't seem necessary, and could even be problematic if a match is
found:

- it might leak information the user should not access (because the
  record name is returned, as well as the model & field names)
- it will trigger further access errors (because links to problematic
  records are provided, on which the user might want to click)

closes odoo/odoo#127973

X-original-commit: 47a69a186bc415bf61a523da9686ca96c0beb74e
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
This commit is contained in:
Xavier Morel
2023-07-10 18:16:31 +02:00
committed by Romain Derie
parent b29733ce37
commit 489566d4bb
+3
View File
@@ -862,6 +862,9 @@ class Website(models.Model):
]
for model, _table, column, _translate in html_fields_attributes:
Model = self.env[model]
if not Model.check_access_rights('read', raise_exception=False):
continue
# Generate the exact domain to search for the URL in this field
domains = []
for url, website_domain in search_criteria: