From 6ce289606ffbaf33f77cc350ea19f0dbf8fa524b Mon Sep 17 00:00:00 2001 From: Thibault Francois Date: Fri, 25 Sep 2020 13:02:48 +0000 Subject: [PATCH] [FIX] crm: don't bypass access right to find partner: Problem ------- Sales people can have restriction on partner they can see Private addresses, multi company, .... When they convert a lead to opportunity, it's currently possible that the wizard will find and link a partner that the current user cannot see. Solution -------- Field that are now computed store field, that were previously normal field with onchange, should not be computed as sudo to respect the record rule closes odoo/odoo#59957 X-original-commit: 182fa38d7f28a92e7171c4ee3a42c8f73217b765 Signed-off-by: Thibault Delavallee (tde) --- addons/crm/tests/test_crm_lead_convert.py | 26 +++++++++++++++++++ .../crm/tests/test_crm_lead_convert_mass.py | 2 +- addons/crm/wizard/crm_lead_to_opportunity.py | 12 ++++----- 3 files changed, 33 insertions(+), 7 deletions(-) diff --git a/addons/crm/tests/test_crm_lead_convert.py b/addons/crm/tests/test_crm_lead_convert.py index 71532306629..c381afdf30a 100644 --- a/addons/crm/tests/test_crm_lead_convert.py +++ b/addons/crm/tests/test_crm_lead_convert.py @@ -1,6 +1,7 @@ # -*- coding: utf-8 -*- # Part of Odoo. See LICENSE file for full copyright and licensing details. +from odoo import SUPERUSER_ID from odoo.addons.crm.tests import common as crm_common from odoo.fields import Datetime from odoo.tests.common import tagged, users @@ -206,6 +207,31 @@ class TestLeadConvert(crm_common.TestLeadConvertCommon): self.assertEqual(self.lead_1.stage_id, self.stage_team1_1) self.assertEqual(self.lead_1.partner_id, self.env['res.partner']) + @users('user_sales_manager') + def test_lead_convert_contact_mutlicompany(self): + """ Check the wizard convert to opp don't find contact + You are not able to see because they belong to another company """ + # Use superuser_id because creating a company with a user add directly + # the company in company_ids of the user. + company_2 = self.env['res.company'].with_user(SUPERUSER_ID).create({'name': 'Company 2'}) + partner_company_2 = self.env['res.partner'].with_user(SUPERUSER_ID).create({ + 'name': 'Contact in other company', + 'email': 'test@company2.com', + 'company_id': company_2.id, + }) + lead = self.env['crm.lead'].create({ + 'name': 'LEAD', + 'type': 'lead', + 'email_from': 'test@company2.com', + }) + convert = self.env['crm.lead2opportunity.partner'].with_context({ + 'active_model': 'crm.lead', + 'active_id': lead.id, + 'active_ids': lead.ids, + }).create({'name': 'convert', 'action': 'exist'}) + self.assertNotEqual(convert.partner_id, partner_company_2, + "Conversion wizard should not be able to find the partner from another company") + @users('user_sales_manager') def test_lead_convert_same_partner(self): """ Check that we don't erase lead information diff --git a/addons/crm/tests/test_crm_lead_convert_mass.py b/addons/crm/tests/test_crm_lead_convert_mass.py index d36878733d6..44d6281cef2 100644 --- a/addons/crm/tests/test_crm_lead_convert_mass.py +++ b/addons/crm/tests/test_crm_lead_convert_mass.py @@ -166,7 +166,7 @@ class TestLeadConvertMass(crm_common.TestLeadConvertMassCommon): test_leads = self._create_leads_batch(count=50, user_ids=[False]) user_ids = self.assign_users.ids - with self.assertQueryCount(user_sales_manager=1347): # crm only: 1336 + with self.assertQueryCount(user_sales_manager=1363): # crm only: 1352 mass_convert = self.env['crm.lead2opportunity.partner.mass'].with_context({ 'active_model': 'crm.lead', 'active_ids': test_leads.ids, diff --git a/addons/crm/wizard/crm_lead_to_opportunity.py b/addons/crm/wizard/crm_lead_to_opportunity.py index a00f76f12da..7f138f2a281 100644 --- a/addons/crm/wizard/crm_lead_to_opportunity.py +++ b/addons/crm/wizard/crm_lead_to_opportunity.py @@ -24,25 +24,25 @@ class Lead2OpportunityPartner(models.TransientModel): name = fields.Selection([ ('convert', 'Convert to opportunity'), ('merge', 'Merge with existing opportunities') - ], 'Conversion Action', compute='_compute_name', readonly=False, store=True) + ], 'Conversion Action', compute='_compute_name', readonly=False, store=True, compute_sudo=False) action = fields.Selection([ ('create', 'Create a new customer'), ('exist', 'Link to an existing customer'), ('nothing', 'Do not link to a customer') - ], string='Related Customer', compute='_compute_action', readonly=False, store=True) + ], string='Related Customer', compute='_compute_action', readonly=False, store=True, compute_sudo=False) lead_id = fields.Many2one('crm.lead', 'Associated Lead', required=True) duplicated_lead_ids = fields.Many2many( 'crm.lead', string='Opportunities', context={'active_test': False}, - compute='_compute_duplicated_lead_ids', readonly=False, store=True) + compute='_compute_duplicated_lead_ids', readonly=False, store=True, compute_sudo=False) partner_id = fields.Many2one( 'res.partner', 'Customer', - compute='_compute_partner_id', readonly=False, store=True) + compute='_compute_partner_id', readonly=False, store=True, compute_sudo=False) user_id = fields.Many2one( 'res.users', 'Salesperson', - compute='_compute_user_id', readonly=False, store=True) + compute='_compute_user_id', readonly=False, store=True, compute_sudo=False) team_id = fields.Many2one( 'crm.team', 'Sales Team', - compute='_compute_team_id', readonly=False, store=True) + compute='_compute_team_id', readonly=False, store=True, compute_sudo=False) force_assignment = fields.Boolean( 'Force assignment', default=True, help='If checked, forces salesman to be updated on updated opportunities even if already set.')