[FIX] base: access rights on transient models
This commit is contained in:
+9
-4
@@ -4615,6 +4615,15 @@ class BaseModel(object):
|
||||
return True
|
||||
return False
|
||||
|
||||
if self.is_transient():
|
||||
# One single implicit access rule for transient models: owner only!
|
||||
# This is ok because we assert that TransientModels always have
|
||||
# log_access enabled, so that 'create_uid' is always there.
|
||||
domain = [('create_uid', '=', uid)]
|
||||
tquery = self._where_calc(cr, uid, domain, active_test=False)
|
||||
apply_rule(tquery.where_clause, tquery.where_clause_params, tquery.tables)
|
||||
return
|
||||
|
||||
# apply main rules on the object
|
||||
rule_obj = self.pool.get('ir.rule')
|
||||
rule_where_clause, rule_where_clause_params, rule_tables = rule_obj.domain_get(cr, uid, self._name, mode, context=context)
|
||||
@@ -4787,10 +4796,6 @@ class BaseModel(object):
|
||||
context = {}
|
||||
self.check_access_rights(cr, access_rights_uid or user, 'read')
|
||||
|
||||
# For transient models, restrict access to the current user, except for the super-user
|
||||
if self.is_transient() and self._log_access and user != SUPERUSER_ID:
|
||||
args = expression.AND(([('create_uid', '=', user)], args or []))
|
||||
|
||||
query = self._where_calc(cr, user, args, context=context)
|
||||
self._apply_ir_rules(cr, user, query, 'read', context=context)
|
||||
order_by = self._generate_order_by(cr, user, order, query, context=context)
|
||||
|
||||
Reference in New Issue
Block a user