[FIX] account_edi: allow to read edi attachment

When you have a journal configure to create add e-fff xml file to
integrate into the invoice, you get an access error when the user that
prints the invoice is not the same as the user that has posted the
invoice.

To avoid this issue, we are calling the '_prepare_invoice_report' with
an edi_document in sudo. The issue comes from that the attachment_id on
the account.edi.document has no res_id and res_model (to be hidden in
the chatter of the invoice). So to get access to such attachment, you
need to have the same 'create_uid' or being a 'Setting' user.

The issue was not present in saas-15.3 because the reports were executed
in sudo, so everything was accessible.

To easily reproduce:

- create a company in belgium
- activate E-FFF edi on the sales journal
- create and post an invoice with the user A
- print it with the user B (that is not an administrator

closes odoo/odoo#109702

X-original-commit: 87716488670b0ba4619d7e8c49e99dfd61ff88d7
Signed-off-by: William André (wan) <wan@odoo.com>
This commit is contained in:
Pierre Masereel
2023-01-11 22:43:27 +01:00
parent b11c274800
commit 75c98684fe
@@ -33,7 +33,10 @@ class IrActionsReport(models.Model):
writer = OdooPdfFileWriter()
writer.cloneReaderDocumentRoot(reader)
for edi_document in to_embed:
edi_document.edi_format_id._prepare_invoice_report(writer, edi_document)
# The attachements on the edi documents are only system readable
# because they don't have res_id and res_model, here we are sure that
# the user has access to the invoice and edi document
edi_document.edi_format_id._prepare_invoice_report(writer, edi_document.sudo())
# Replace the current content.
pdf_stream.close()