[MERGE] forward port branch 10.0 up to ea4ddff117
This commit is contained in:
@@ -580,8 +580,9 @@ class Message(models.Model):
|
||||
WHERE message.message_type = %%s AND (message.subtype_id IS NULL OR subtype.internal IS TRUE) AND message.id = ANY (%%s)''' % (self._table), ('comment', self.ids,))
|
||||
if self._cr.fetchall():
|
||||
raise AccessError(
|
||||
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') %
|
||||
(self._description, operation))
|
||||
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
|
||||
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
|
||||
)
|
||||
|
||||
# Read mail_message.ids to have their values
|
||||
message_values = dict((res_id, {}) for res_id in self.ids)
|
||||
@@ -680,8 +681,9 @@ class Message(models.Model):
|
||||
if not other_ids:
|
||||
return
|
||||
raise AccessError(
|
||||
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') %
|
||||
(self._description, operation))
|
||||
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
|
||||
+ ' - ({} {}, {} {})'.format(_('Records:'), list(other_ids)[:6], _('User:'), self._uid)
|
||||
)
|
||||
|
||||
@api.model
|
||||
def _get_record_name(self, values):
|
||||
|
||||
@@ -2095,6 +2095,10 @@ var set_fiscal_position_button = ActionButtonWidget.extend({
|
||||
confirm: function (fiscal_position) {
|
||||
var order = self.pos.get_order();
|
||||
order.fiscal_position = fiscal_position;
|
||||
// Fix the taxes on existing lines
|
||||
_.each(order.get_orderlines(), function (line) {
|
||||
order.fix_tax_included_price(line);
|
||||
});
|
||||
order.trigger('change');
|
||||
}
|
||||
});
|
||||
|
||||
@@ -54,7 +54,10 @@ class MailMessage(models.Model):
|
||||
if self.user_has_groups('base.group_public'):
|
||||
self.env.cr.execute('SELECT id FROM "%s" WHERE website_published IS FALSE AND id = ANY (%%s)' % (self._table), (self.ids,))
|
||||
if self.env.cr.fetchall():
|
||||
raise AccessError(_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation))
|
||||
raise AccessError(
|
||||
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
|
||||
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
|
||||
)
|
||||
return super(MailMessage, self).check_access_rule(operation=operation)
|
||||
|
||||
|
||||
|
||||
@@ -359,7 +359,10 @@ class IrActionsActWindow(models.Model):
|
||||
existing = self.filtered(lambda rec: rec.id in ids)
|
||||
if len(existing) < len(self):
|
||||
# mark missing records in cache with a failed value
|
||||
exc = MissingError(_("Record does not exist or has been deleted."))
|
||||
exc = MissingError(
|
||||
_("Record does not exist or has been deleted.")
|
||||
+ '\n\n({} {}, {} {})'.format(_('Records:'), (self - existing).ids[:6], _('User:'), self._uid)
|
||||
)
|
||||
(self - existing)._cache.update(fields.FailedValue(exc))
|
||||
return existing
|
||||
|
||||
|
||||
@@ -965,6 +965,7 @@ class IrModelAccess(models.Model):
|
||||
else:
|
||||
msg_tail = _("Please contact your system administrator if you think this is an error.") + "\n\n(" + _("Document model") + ": %s)"
|
||||
msg_params = (model,)
|
||||
msg_tail += ' - ({} {}, {} {})'.format(_('Operation:'), mode, _('User:'), self._uid)
|
||||
_logger.info('Access Denied by ACLs for operation: %s, uid: %s, model: %s', mode, self._uid, model)
|
||||
msg = '%s %s' % (msg_heads[mode], msg_tail)
|
||||
raise AccessError(msg % msg_params)
|
||||
|
||||
+28
-10
@@ -2993,9 +2993,13 @@ class BaseModel(object):
|
||||
if invalid_fields:
|
||||
_logger.info('Access Denied by ACLs for operation: %s, uid: %s, model: %s, fields: %s',
|
||||
operation, self._uid, self._name, ', '.join(invalid_fields))
|
||||
raise AccessError(_('The requested operation cannot be completed due to security restrictions. '
|
||||
'Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
|
||||
(self._description, operation))
|
||||
raise AccessError(
|
||||
_(
|
||||
'The requested operation cannot be completed due to security restrictions. '
|
||||
'Please contact your system administrator.\n\n(Document type: %s, Operation: %s)'
|
||||
) % (self._description, operation)
|
||||
+ ' - ({} {}, {} {})'.format(_('User:'), self._uid, _('Fields:'), ', '.join(invalid_fields))
|
||||
)
|
||||
|
||||
return fields
|
||||
|
||||
@@ -3209,8 +3213,8 @@ class BaseModel(object):
|
||||
if forbidden:
|
||||
# store an access error exception in existing records
|
||||
exc = AccessError(
|
||||
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
|
||||
(self._name, 'read')
|
||||
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, 'read')
|
||||
+ ' - ({} {}, {} {})'.format(_('Records:'), self.ids[:6], _('User:'), self._uid)
|
||||
)
|
||||
forbidden._cache.update(FailedValue(exc))
|
||||
|
||||
@@ -3294,8 +3298,10 @@ class BaseModel(object):
|
||||
if self._uid == SUPERUSER_ID:
|
||||
return
|
||||
_logger.info('Access Denied by record rules for operation: %s on record ids: %r, uid: %s, model: %s', operation, forbidden_ids, self._uid, self._name)
|
||||
raise AccessError(_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % \
|
||||
(self._description, operation))
|
||||
raise AccessError(
|
||||
_('The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: %s, Operation: %s)') % (self._description, operation)
|
||||
+ ' - ({} {}, {}, {})'.format(_('Records:'), forbidden_ids[:6], _('User:'), self._uid)
|
||||
)
|
||||
else:
|
||||
# If we get here, the missing_ids are not in the database
|
||||
if operation in ('read','unlink'):
|
||||
@@ -3304,7 +3310,13 @@ class BaseModel(object):
|
||||
# errors for non-transactional search/read sequences coming from clients
|
||||
return
|
||||
_logger.info('Failed operation on deleted record(s): %s, uid: %s, model: %s', operation, self._uid, self._name)
|
||||
raise MissingError(_('Missing document(s)') + ':' + _('One of the documents you are trying to access has been deleted, please try again after refreshing.'))
|
||||
raise MissingError(
|
||||
_('Missing document(s)') + ':' + _('One of the documents you are trying to access has been deleted, please try again after refreshing.')
|
||||
+ '\n\n({} {}, {} {}, {} {}, {} {})'.format(
|
||||
_('Document type:'), self._description, _('Operation:'), operation,
|
||||
_('Records:'), missing_ids[:6], _('User:'), self._uid,
|
||||
)
|
||||
)
|
||||
|
||||
@api.model
|
||||
def check_access_rights(self, operation, raise_exception=True):
|
||||
@@ -3645,7 +3657,10 @@ class BaseModel(object):
|
||||
for sub_ids in cr.split_for_in_conditions(set(self.ids)):
|
||||
cr.execute(query, params + (sub_ids,))
|
||||
if cr.rowcount != len(sub_ids):
|
||||
raise MissingError(_('One of the records you are trying to modify has already been deleted (Document type: %s).') % self._description)
|
||||
raise MissingError(
|
||||
_('One of the records you are trying to modify has already been deleted (Document type: %s).') % self._description
|
||||
+ '\n\n({} {}, {} {})'.format(_('Records:'), sub_ids[:6], _('User:'), self._uid)
|
||||
)
|
||||
|
||||
# TODO: optimize
|
||||
for name in direct:
|
||||
@@ -4422,7 +4437,10 @@ class BaseModel(object):
|
||||
existing = self.browse(ids + new_ids)
|
||||
if len(existing) < len(self):
|
||||
# mark missing records in cache with a failed value
|
||||
exc = MissingError(_("Record does not exist or has been deleted."))
|
||||
exc = MissingError(
|
||||
_("Record does not exist or has been deleted.")
|
||||
+ '\n\n({} {}, {} {})'.format(_('Records:'), (self - existing).ids[:6], _('User:'), self._uid)
|
||||
)
|
||||
(self - existing)._cache.update(FailedValue(exc))
|
||||
return existing
|
||||
|
||||
|
||||
Reference in New Issue
Block a user