From 5f74235d4d209d0745be7b58a7702cd372677cfb Mon Sep 17 00:00:00 2001 From: "Thomas Lefebvre (thle)" Date: Thu, 11 Jan 2024 09:55:17 +0100 Subject: [PATCH] [FIX] base, hr: avoid invalid access error in onchange() when editing user Steps to reproduce: ------------------- - install the "hr" module; - remove access rights for "Employees"; - change language on the user profile. Issue: ------ There's an Access Error because we can't read the `private_street` field on the employee that corresponds to the user. Cause: ------ The new version of onchange fetches the record values on the server side, unlike the old version which used the values in the view. In the old version, as we were using view values, this didn't cause any problems, as the values came from a read that which took into account `SELF_READABLE_FIELDS`. Note: We do not have access to the value of the `private_street` field because it is a related field with the attribute `related_sudo=False` and we do not have access rights for the `hr.employee` model. Solution: --------- Use the cache and place the values of the fields in `SELF_READABLE_FIELDS` in it before performing the onchange logic. opw-3664929 closes odoo/odoo#148997 Signed-off-by: Raphael Collet --- addons/hr/models/res_users.py | 1 - addons/hr/tests/test_self_user_access.py | 14 ++++++++++++++ odoo/addons/base/models/res_users.py | 7 +++++++ 3 files changed, 21 insertions(+), 1 deletion(-) diff --git a/addons/hr/models/res_users.py b/addons/hr/models/res_users.py index a5d5edd2912..3ee7c689684 100644 --- a/addons/hr/models/res_users.py +++ b/addons/hr/models/res_users.py @@ -53,7 +53,6 @@ HR_WRITABLE_FIELDS = [ 'km_home_work', 'marital', 'mobile_phone', - 'notes', 'employee_parent_id', 'passport_id', 'permit_no', diff --git a/addons/hr/tests/test_self_user_access.py b/addons/hr/tests/test_self_user_access.py index 2eb5094f930..cdeae64a59f 100644 --- a/addons/hr/tests/test_self_user_access.py +++ b/addons/hr/tests/test_self_user_access.py @@ -216,3 +216,17 @@ class TestSelfAccessRights(TestHrCommon): def testSearchUserEMployee(self): # Searching user based on employee_id field should not raise bad query error self.env['res.users'].with_user(self.richard).search([('employee_id', 'ilike', 'Hubert')]) + + def test_onchange_readable_fields_with_no_access(self): + """ + The purpose is to test that the onchange logic takes into account `SELF_READABLE_FIELDS`. + + The view contains fields that are in `SELF_READABLE_FIELDS` (example: `private_street`). + Even if the user does not have read access to the employee, + it should not cause an access error if these fields are in `SELF_READABLE_FIELDS`. + """ + self.env['res.lang']._activate_lang("fr_FR") + with Form(self.richard.with_user(self.richard), view='hr.res_users_view_form_profile') as form: + # triggering an onchange should not trigger some access error + form.lang = "fr_FR" + form.tz = "Europe/Brussels" diff --git a/odoo/addons/base/models/res_users.py b/odoo/addons/base/models/res_users.py index 8ed172cbf91..9957aff815f 100644 --- a/odoo/addons/base/models/res_users.py +++ b/odoo/addons/base/models/res_users.py @@ -560,6 +560,13 @@ class Users(models.Model): user.partner_id.toggle_active() super(Users, self).toggle_active() + def onchange(self, values, field_names, fields_spec): + # Hacky fix to access fields in `SELF_READABLE_FIELDS` in the onchange logic. + # Put field values in the cache. + if self == self.env.user: + [self.sudo()[field_name] for field_name in self.SELF_READABLE_FIELDS] + return super().onchange(values, field_names, fields_spec) + def read(self, fields=None, load='_classic_read'): readable = self.SELF_READABLE_FIELDS if fields and self == self.env.user and all(key in readable or key.startswith('context_') for key in fields):