[FIX] base: handle database.secret parameter while deletion

An error occurs when the user attempts to delete the 'database.secret' record,
either by following these steps:
- Enable developer mode.
- Go to Settings > Technical > System Parameters.
- Select the 'database.secret' record and attempt to delete it.

Or when the user tries to update the key for the 'database.secret' record using
the following steps:
- Open the 'database.secret' record.
- Update the value of the key field.
-  Save the record.
- The server will stop running and not be accessible.

Error: ValueError: CSRF protection requires a configured database secret

sentry - 4291267997

closes odoo/odoo#131460

X-original-commit: fe694e5b8285ceed99b321c22af534eee25cf282
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
This commit is contained in:
Om Rabara
2023-08-10 17:02:15 +02:00
parent 2136b32b95
commit 52a204f3da
4 changed files with 47 additions and 1 deletions
+14
View File
@@ -31119,6 +31119,13 @@ msgid ""
"Linked active users : %(names)s"
msgstr ""
#. module: base
#. odoo-python
#: code:addons/base/models/ir_config_parameter.py:0
#, python-format
msgid "You cannot delete the %s record."
msgstr ""
#. module: base
#. odoo-python
#: code:addons/base/models/res_lang.py:0
@@ -31149,6 +31156,13 @@ msgid ""
" an accounting entry."
msgstr ""
#. module: base
#. odoo-python
#: code:addons/base/models/ir_config_parameter.py:0
#, python-format
msgid "You cannot rename config parameters with keys %s"
msgstr ""
#. module: base
#. odoo-python
#: code:addons/models.py:0
+11 -1
View File
@@ -7,7 +7,8 @@ Store database-specific configuration parameters
import uuid
import logging
from odoo import api, fields, models
from odoo import api, fields, models, _
from odoo.exceptions import ValidationError
from odoo.tools import config, ormcache, mute_logger
_logger = logging.getLogger(__name__)
@@ -106,9 +107,18 @@ class IrConfigParameter(models.Model):
return super(IrConfigParameter, self).create(vals_list)
def write(self, vals):
if 'key' in vals:
illegal = _default_parameters.keys() & self.mapped('key')
if illegal:
raise ValidationError(_("You cannot rename config parameters with keys %s", ', '.join(illegal)))
self.env.registry.clear_cache()
return super(IrConfigParameter, self).write(vals)
def unlink(self):
self.env.registry.clear_cache()
return super(IrConfigParameter, self).unlink()
@api.ondelete(at_uninstall=False)
def unlink_default_parameters(self):
for record in self.filtered(lambda p: p.key in _default_parameters.keys()):
raise ValidationError(_("You cannot delete the %s record.", record.key))
+1
View File
@@ -60,3 +60,4 @@ from . import test_cloc
from . import test_profiler
from . import test_pdf
from . import test_neutralize
from . import test_config_parameter
@@ -0,0 +1,21 @@
# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
from odoo.addons.base.models.ir_config_parameter import _default_parameters
from odoo.exceptions import ValidationError
from odoo.tests.common import TransactionCase
class TestIrConfigParameter(TransactionCase):
def test_default_parameters(self):
""" Check the behavior of _default_parameters
when updating keys and deleting records. """
for key in _default_parameters:
config_parameter = self.env['ir.config_parameter'].search([('key', '=', key)], limit=1)
with self.assertRaises(ValidationError):
config_parameter.unlink()
new_key = f"{key}_updated"
with self.assertRaises(ValidationError):
config_parameter.write({'key': new_key})