From 66644e856c5075925fe253699afba89869f12a26 Mon Sep 17 00:00:00 2001 From: Damien Bouvy Date: Tue, 6 Jan 2015 17:28:27 +0100 Subject: [PATCH] [FIX] ir_attachment: Unlinking and creating attachments shoud be considered as a write to the related resource. Read and write access should be identical to the rights on the related resource. --- openerp/addons/base/ir/ir_attachment.py | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/openerp/addons/base/ir/ir_attachment.py b/openerp/addons/base/ir/ir_attachment.py index cd245aaaf72..cb9429dcda0 100644 --- a/openerp/addons/base/ir/ir_attachment.py +++ b/openerp/addons/base/ir/ir_attachment.py @@ -354,9 +354,12 @@ class ir_attachment(osv.osv): existing_ids = self.pool[model].exists(cr, uid, mids) if len(existing_ids) != len(mids): require_employee = True - # For related models, check if we can write to the model, as linking - # or unlinking attachments can be seen as an update to the model - ima.check(cr, uid, model, 'write') + # For related models, check if we can write to the model, as unlinking + # and creating attachments can be seen as an update to the model + if (mode in ['unlink','create']): + ima.check(cr, uid, model, 'write') + else: + ima.check(cr, uid, model, mode) self.pool[model].check_access_rule(cr, uid, existing_ids, mode, context=context) if require_employee: if not self.pool['res.users'].has_group(cr, uid, 'base.group_user'):