From 51884712cd7ddab49af56d2fb91bfbfa9e6a89f2 Mon Sep 17 00:00:00 2001 From: Jeremy Kersten Date: Wed, 29 Mar 2023 13:00:26 +0000 Subject: [PATCH] [FIX] mail: fix access rights for reaction in portal MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Before this commit, the portal user get a Access Error. After this commit, the portal user see the chatter without error. The code works with reaction browsed in sudo, but since we use a ior with a record not in sudo, we loose the sudo flag and so the right for portal user to read it. ```py x = record.sudo() y = record x |= y -> (x, y) in sudo y |= x -> (x, y) not in sudo ``` How to reproduce ? Assign lead to a portal user Post a message with another user like demo on the lead Add reaction with the admin user Open the opportunity on the portal with portal user -> access error opw-3215507 closes odoo/odoo#117313 X-original-commit: 2bde53541b7a0171c7d1b89e0e412d624f5eab37 Signed-off-by: Alexandre Kühn (aku) Signed-off-by: Jérémy Kersten --- addons/mail/models/mail_message.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/mail/models/mail_message.py b/addons/mail/models/mail_message.py index 1339f9fe5c9..1ced8572620 100644 --- a/addons/mail/models/mail_message.py +++ b/addons/mail/models/mail_message.py @@ -888,7 +888,7 @@ class Message(models.Model): else: record_name = False default_subject = False - reactions_per_content = defaultdict(lambda: self.env['mail.message.reaction']) + reactions_per_content = defaultdict(self.env['mail.message.reaction'].sudo().browse) for reaction in message_sudo.reaction_ids: reactions_per_content[reaction.content] |= reaction reaction_groups = [{