[FIX] crm: don't bypass access right to find partner:

Problem
-------

Sales people can have restriction on partner they can see
Private addresses, multi company, ....

When they convert a lead to opportunity, it's currently possible
that the wizard will find and link a partner that the current user
cannot see.

Solution
--------
Field that are now computed store field, that were previously
normal field with onchange, should not be computed as sudo
to respect the record rule

closes odoo/odoo#59957

X-original-commit: 182fa38d7f28a92e7171c4ee3a42c8f73217b765
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
This commit is contained in:
Thibault Francois
2020-10-14 09:47:12 +00:00
committed by Thibault Delavallée
parent af2eaae941
commit 6ce289606f
3 changed files with 33 additions and 7 deletions
+26
View File
@@ -1,6 +1,7 @@
# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
from odoo import SUPERUSER_ID
from odoo.addons.crm.tests import common as crm_common
from odoo.fields import Datetime
from odoo.tests.common import tagged, users
@@ -206,6 +207,31 @@ class TestLeadConvert(crm_common.TestLeadConvertCommon):
self.assertEqual(self.lead_1.stage_id, self.stage_team1_1)
self.assertEqual(self.lead_1.partner_id, self.env['res.partner'])
@users('user_sales_manager')
def test_lead_convert_contact_mutlicompany(self):
""" Check the wizard convert to opp don't find contact
You are not able to see because they belong to another company """
# Use superuser_id because creating a company with a user add directly
# the company in company_ids of the user.
company_2 = self.env['res.company'].with_user(SUPERUSER_ID).create({'name': 'Company 2'})
partner_company_2 = self.env['res.partner'].with_user(SUPERUSER_ID).create({
'name': 'Contact in other company',
'email': 'test@company2.com',
'company_id': company_2.id,
})
lead = self.env['crm.lead'].create({
'name': 'LEAD',
'type': 'lead',
'email_from': 'test@company2.com',
})
convert = self.env['crm.lead2opportunity.partner'].with_context({
'active_model': 'crm.lead',
'active_id': lead.id,
'active_ids': lead.ids,
}).create({'name': 'convert', 'action': 'exist'})
self.assertNotEqual(convert.partner_id, partner_company_2,
"Conversion wizard should not be able to find the partner from another company")
@users('user_sales_manager')
def test_lead_convert_same_partner(self):
""" Check that we don't erase lead information
@@ -166,7 +166,7 @@ class TestLeadConvertMass(crm_common.TestLeadConvertMassCommon):
test_leads = self._create_leads_batch(count=50, user_ids=[False])
user_ids = self.assign_users.ids
with self.assertQueryCount(user_sales_manager=1347): # crm only: 1336
with self.assertQueryCount(user_sales_manager=1363): # crm only: 1352
mass_convert = self.env['crm.lead2opportunity.partner.mass'].with_context({
'active_model': 'crm.lead',
'active_ids': test_leads.ids,
+6 -6
View File
@@ -24,25 +24,25 @@ class Lead2OpportunityPartner(models.TransientModel):
name = fields.Selection([
('convert', 'Convert to opportunity'),
('merge', 'Merge with existing opportunities')
], 'Conversion Action', compute='_compute_name', readonly=False, store=True)
], 'Conversion Action', compute='_compute_name', readonly=False, store=True, compute_sudo=False)
action = fields.Selection([
('create', 'Create a new customer'),
('exist', 'Link to an existing customer'),
('nothing', 'Do not link to a customer')
], string='Related Customer', compute='_compute_action', readonly=False, store=True)
], string='Related Customer', compute='_compute_action', readonly=False, store=True, compute_sudo=False)
lead_id = fields.Many2one('crm.lead', 'Associated Lead', required=True)
duplicated_lead_ids = fields.Many2many(
'crm.lead', string='Opportunities', context={'active_test': False},
compute='_compute_duplicated_lead_ids', readonly=False, store=True)
compute='_compute_duplicated_lead_ids', readonly=False, store=True, compute_sudo=False)
partner_id = fields.Many2one(
'res.partner', 'Customer',
compute='_compute_partner_id', readonly=False, store=True)
compute='_compute_partner_id', readonly=False, store=True, compute_sudo=False)
user_id = fields.Many2one(
'res.users', 'Salesperson',
compute='_compute_user_id', readonly=False, store=True)
compute='_compute_user_id', readonly=False, store=True, compute_sudo=False)
team_id = fields.Many2one(
'crm.team', 'Sales Team',
compute='_compute_team_id', readonly=False, store=True)
compute='_compute_team_id', readonly=False, store=True, compute_sudo=False)
force_assignment = fields.Boolean(
'Force assignment', default=True,
help='If checked, forces salesman to be updated on updated opportunities even if already set.')