From 52f4e26076bea0c93c56b4408664639e0b63374f Mon Sep 17 00:00:00 2001 From: tsm-odoo Date: Tue, 9 Apr 2024 12:26:13 +0200 Subject: [PATCH] [FIX] mail: improve public page error wording MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Before this PR, the error displayed in the public page was quite cryptic. It was hard for the user to understand that error and even harder to report it if needed. This PR makes the error more user friendly. task-3850559 closes odoo/odoo#160947 Signed-off-by: Sébastien Theys (seb) --- addons/mail/controllers/discuss/public_page.py | 3 +++ .../tests/discuss/test_discuss_channel_as_guest.py | 10 ++++++++++ 2 files changed, 13 insertions(+) diff --git a/addons/mail/controllers/discuss/public_page.py b/addons/mail/controllers/discuss/public_page.py index 57169b8f1e9..4d7a71d8f46 100644 --- a/addons/mail/controllers/discuss/public_page.py +++ b/addons/mail/controllers/discuss/public_page.py @@ -84,6 +84,9 @@ class PublicPageController(http.Controller): return self._response_discuss_channel_invitation(channel_sudo.sudo(False), is_channel_token_secret=False) def _response_discuss_channel_invitation(self, channel, is_channel_token_secret=True): + # group restriction takes precedence over token + if channel.group_public_id and channel.group_public_id not in request.env.user.groups_id: + raise request.not_found() discuss_public_view_data = { "isChannelTokenSecret": is_channel_token_secret, } diff --git a/addons/mail/tests/discuss/test_discuss_channel_as_guest.py b/addons/mail/tests/discuss/test_discuss_channel_as_guest.py index 48f0d92fe98..d934ccb030c 100644 --- a/addons/mail/tests/discuss/test_discuss_channel_as_guest.py +++ b/addons/mail/tests/discuss/test_discuss_channel_as_guest.py @@ -89,3 +89,13 @@ class TestMailPublicPage(HttpCaseWithUserPortal, HttpCaseWithUserDemo): self.url_open('/chat/xyz') channel = self.env['discuss.channel'].search([('uuid', '=', 'xyz')]) self.assertEqual(len(channel), 1) + + def test_channel_invitation_from_token(self): + public_channel = self.env["discuss.channel"].channel_create(name="Public Channel", group_id=None) + internal_channel = self.env["discuss.channel"].channel_create(name="Internal Channel", group_id=self.env.ref("base.group_user").id) + + public_response = self.url_open(public_channel.invitation_url) + self.assertEqual(public_response.status_code, 200) + + internal_response = self.url_open(internal_channel.invitation_url) + self.assertEqual(internal_response.status_code, 404)