[MERGE] forward port branch 10.0 up to ea4ddff117

This commit is contained in:
Christophe Simonis
2019-06-26 11:12:36 +02:00
6 changed files with 47 additions and 16 deletions
+6 -4
View File
@@ -580,8 +580,9 @@ class Message(models.Model):
WHERE message.message_type = %%s AND (message.subtype_id IS NULL OR subtype.internal IS TRUE) AND message.id = ANY (%%s)''' % (self._table), ('comment', self.ids,))
if self._cr.fetchall():
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') %
(self._description, operation))
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
)
# Read mail_message.ids to have their values
message_values = dict((res_id, {}) for res_id in self.ids)
@@ -680,8 +681,9 @@ class Message(models.Model):
if not other_ids:
return
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') %
(self._description, operation))
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('Records:'), list(other_ids)[:6], _('User:'), self._uid)
)
@api.model
def _get_record_name(self, values):
@@ -2095,6 +2095,10 @@ var set_fiscal_position_button = ActionButtonWidget.extend({
confirm: function (fiscal_position) {
var order = self.pos.get_order();
order.fiscal_position = fiscal_position;
// Fix the taxes on existing lines
_.each(order.get_orderlines(), function (line) {
order.fix_tax_included_price(line);
});
order.trigger('change');
}
});
+4 -1
View File
@@ -54,7 +54,10 @@ class MailMessage(models.Model):
if self.user_has_groups('base.group_public'):
self.env.cr.execute('SELECT id FROM "%s" WHERE website_published IS FALSE AND id = ANY (%%s)' % (self._table), (self.ids,))
if self.env.cr.fetchall():
raise AccessError(_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation))
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
)
return super(MailMessage, self).check_access_rule(operation=operation)
+4 -1
View File
@@ -359,7 +359,10 @@ class IrActionsActWindow(models.Model):
existing = self.filtered(lambda rec: rec.id in ids)
if len(existing) < len(self):
# mark missing records in cache with a failed value
exc = MissingError(_("Record does not exist or has been deleted."))
exc = MissingError(
_("Record does not exist or has been deleted.")
+ '\n\n({} {}, {} {})'.format(_('Records:'), (self - existing).ids[:6], _('User:'), self._uid)
)
(self - existing)._cache.update(fields.FailedValue(exc))
return existing
+1
View File
@@ -965,6 +965,7 @@ class IrModelAccess(models.Model):
else:
msg_tail = _("Please contact your system administrator if you think this is an error.") + "\n\n(" + _("Document model") + ": %s)"
msg_params = (model,)
msg_tail += ' - ({} {}, {} {})'.format(_('Operation:'), mode, _('User:'), self._uid)
_logger.info('Access Denied by ACLs for operation: %s, uid: %s, model: %s', mode, self._uid, model)
msg = '%s %s' % (msg_heads[mode], msg_tail)
raise AccessError(msg % msg_params)
+28 -10
View File
@@ -2993,9 +2993,13 @@ class BaseModel(object):
if invalid_fields:
_logger.info('Access Denied by ACLs for operation: %s, uid: %s, model: %s, fields: %s',
operation, self._uid, self._name, ', '.join(invalid_fields))
raise AccessError(_('The requested operation cannot be completed due to security restrictions. '
'Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
(self._description, operation))
raise AccessError(
_(
'The requested operation cannot be completed due to security restrictions. '
'Please contact your system administrator.\n\n(Document type: %s, Operation: %s)'
) % (self._description, operation)
+ ' - ({} {}, {} {})'.format(_('User:'), self._uid, _('Fields:'), ', '.join(invalid_fields))
)
return fields
@@ -3209,8 +3213,8 @@ class BaseModel(object):
if forbidden:
# store an access error exception in existing records
exc = AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
(self._name, 'read')
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, 'read')
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
)
forbidden._cache.update(FailedValue(exc))
@@ -3294,8 +3298,10 @@ class BaseModel(object):
if self._uid == SUPERUSER_ID:
return
_logger.info('Access Denied by record rules for operation: %s on record ids: %r, uid: %s, model: %s', operation, forbidden_ids, self._uid, self._name)
raise AccessError(_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
(self._description, operation))
raise AccessError(
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
+ ' - ({} {}, {}, {})'.format(_('Records:'), forbidden_ids[:6], _('User:'), self._uid)
)
else:
# If we get here, the missing_ids are not in the database
if operation in ('read','unlink'):
@@ -3304,7 +3310,13 @@ class BaseModel(object):
# errors for non-transactional search/read sequences coming from clients
return
_logger.info('Failed operation on deleted record(s): %s, uid: %s, model: %s', operation, self._uid, self._name)
raise MissingError(_('Missing document(s)') + ':' + _('One of the documents you are trying to access has been deleted, please try again after refreshing.'))
raise MissingError(
_('Missing document(s)') + ':' + _('One of the documents you are trying to access has been deleted, please try again after refreshing.')
+ '\n\n({} {}, {} {}, {} {}, {} {})'.format(
_('Document type:'), self._description, _('Operation:'), operation,
_('Records:'), missing_ids[:6], _('User:'), self._uid,
)
)
@api.model
def check_access_rights(self, operation, raise_exception=True):
@@ -3645,7 +3657,10 @@ class BaseModel(object):
for sub_ids in cr.split_for_in_conditions(set(self.ids)):
cr.execute(query, params + (sub_ids,))
if cr.rowcount != len(sub_ids):
raise MissingError(_('One of the records you are trying to modify has already been deleted (Document type: %s).') % self._description)
raise MissingError(
_('One of the records you are trying to modify has already been deleted (Document type: %s).') % self._description
+ '\n\n({} {}, {} {})'.format(_('Records:'), sub_ids[:6], _('User:'), self._uid)
)
# TODO: optimize
for name in direct:
@@ -4422,7 +4437,10 @@ class BaseModel(object):
existing = self.browse(ids + new_ids)
if len(existing) < len(self):
# mark missing records in cache with a failed value
exc = MissingError(_("Record does not exist or has been deleted."))
exc = MissingError(
_("Record does not exist or has been deleted.")
+ '\n\n({} {}, {} {})'.format(_('Records:'), (self - existing).ids[:6], _('User:'), self._uid)
)
(self - existing)._cache.update(FailedValue(exc))
return existing