[FIX] base: access rights on transient models

This commit is contained in:
Raphael Collet
2018-07-23 16:21:07 +02:00
parent a1b92ad2b8
commit 67bf250ea5
+9 -4
View File
@@ -4615,6 +4615,15 @@ class BaseModel(object):
return True
return False
if self.is_transient():
# One single implicit access rule for transient models: owner only!
# This is ok because we assert that TransientModels always have
# log_access enabled, so that 'create_uid' is always there.
domain = [('create_uid', '=', uid)]
tquery = self._where_calc(cr, uid, domain, active_test=False)
apply_rule(tquery.where_clause, tquery.where_clause_params, tquery.tables)
return
# apply main rules on the object
rule_obj = self.pool.get('ir.rule')
rule_where_clause, rule_where_clause_params, rule_tables = rule_obj.domain_get(cr, uid, self._name, mode, context=context)
@@ -4787,10 +4796,6 @@ class BaseModel(object):
context = {}
self.check_access_rights(cr, access_rights_uid or user, 'read')
# For transient models, restrict access to the current user, except for the super-user
if self.is_transient() and self._log_access and user != SUPERUSER_ID:
args = expression.AND(([('create_uid', '=', user)], args or []))
query = self._where_calc(cr, user, args, context=context)
self._apply_ir_rules(cr, user, query, 'read', context=context)
order_by = self._generate_order_by(cr, user, order, query, context=context)