From 489566d4bb5f63b5391b18c5e4c02c821e69ddeb Mon Sep 17 00:00:00 2001 From: Xavier Morel Date: Wed, 31 May 2023 08:17:40 +0000 Subject: [PATCH] [FIX] website: don't error on inaccessible model When deleting a page, `search_url_dependencies` tries to trawl through all models to see if they might have a link to the page being deleted. However if the user invoking that function does not have access to a model with an HTML field, it raises an error. Given pages are managed by website designers which are *not administrators* there is no reason to believe the current user has access to every model in the database (not that even admins do these days). Since `search_url_dependencies` is a best-effort search anyway, just ignore any model to which the current user doesn't have access. An alternative would be to do the search in sudo mode, but that doesn't seem necessary, and could even be problematic if a match is found: - it might leak information the user should not access (because the record name is returned, as well as the model & field names) - it will trigger further access errors (because links to problematic records are provided, on which the user might want to click) closes odoo/odoo#127973 X-original-commit: 47a69a186bc415bf61a523da9686ca96c0beb74e Signed-off-by: Romain Derie (rde) --- addons/website/models/website.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/addons/website/models/website.py b/addons/website/models/website.py index b73abcd19c3..c0d95a79b58 100644 --- a/addons/website/models/website.py +++ b/addons/website/models/website.py @@ -862,6 +862,9 @@ class Website(models.Model): ] for model, _table, column, _translate in html_fields_attributes: Model = self.env[model] + if not Model.check_access_rights('read', raise_exception=False): + continue + # Generate the exact domain to search for the URL in this field domains = [] for url, website_domain in search_criteria: