From 7a02ea08566da5b45a59b4db0613bc44bc3a6849 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=A9r=C3=A9my=20Hennecart?= Date: Thu, 30 Apr 2020 08:18:17 +0000 Subject: [PATCH] [FIX] sms, various: do not restrict read access on sms.template sms.template model has several record rules to give access to templates linked to models managed by certain groups (like crm.lead for sales managers) These record rules were meant to restrict access to certain model to create, write and unlink, but not read. This is leading to issues when trying to read a template on other models. Indeed people should always be able read sms.template content. Unit test were also added to the sms module to ensure that a member of group_user can always read a sms template. Unit test is added to ensure admin always has full control on sms.templates. Task ID-2191254 COM PR odoo/odoo#68445 ENT PR odoo/enterprise#17340 X-original-commit: 6a00157f79be30a6efd6d039504c57be07c449fd --- addons/calendar_sms/security/sms_security.xml | 3 +- addons/crm_sms/security/sms_security.xml | 3 +- addons/event_sms/security/sms_security.xml | 3 +- addons/hr_presence/security/sms_security.xml | 3 +- addons/sms/tests/__init__.py | 1 + addons/sms/tests/test_sms_template.py | 60 +++++++++++++++++++ addons/stock_sms/security/sms_security.xml | 3 +- 7 files changed, 71 insertions(+), 5 deletions(-) create mode 100644 addons/sms/tests/test_sms_template.py diff --git a/addons/calendar_sms/security/sms_security.xml b/addons/calendar_sms/security/sms_security.xml index 05e82ec8920..4b6d11ccde9 100644 --- a/addons/calendar_sms/security/sms_security.xml +++ b/addons/calendar_sms/security/sms_security.xml @@ -1,9 +1,10 @@ - SMS Template: system administrator CRUD on calendar event templates + SMS Template: system administrator CUD on calendar event templates [('model_id.model', '=', 'calendar.event')] + diff --git a/addons/crm_sms/security/sms_security.xml b/addons/crm_sms/security/sms_security.xml index f5bf0769b15..b29ed067695 100644 --- a/addons/crm_sms/security/sms_security.xml +++ b/addons/crm_sms/security/sms_security.xml @@ -1,9 +1,10 @@ - SMS Template: sale manager CRUD on opportunity / partner templates + SMS Template: sale manager CUD on opportunity / partner templates [('model_id.model', 'in', ('crm.lead', 'res.partner'))] + diff --git a/addons/event_sms/security/sms_security.xml b/addons/event_sms/security/sms_security.xml index 4c7bfa9d80c..87f028ff232 100644 --- a/addons/event_sms/security/sms_security.xml +++ b/addons/event_sms/security/sms_security.xml @@ -1,9 +1,10 @@ - SMS Template: event manager CRUD on event / registrations templates + SMS Template: event manager CUD on event / registrations templates [('model_id.model', 'in', ('event.event', 'event.registration'))] + diff --git a/addons/hr_presence/security/sms_security.xml b/addons/hr_presence/security/sms_security.xml index 024ec0020a8..e70129a8592 100644 --- a/addons/hr_presence/security/sms_security.xml +++ b/addons/hr_presence/security/sms_security.xml @@ -1,9 +1,10 @@ - SMS Template: hr manager CRUD on employee templates + SMS Template: hr manager CUD on employee templates [('model_id.model', '=', 'hr.employee')] + diff --git a/addons/sms/tests/__init__.py b/addons/sms/tests/__init__.py index 511e649c9e2..609586bec6b 100644 --- a/addons/sms/tests/__init__.py +++ b/addons/sms/tests/__init__.py @@ -2,3 +2,4 @@ # Part of Odoo. See LICENSE file for full copyright and licensing details. from . import common +from . import test_sms_template diff --git a/addons/sms/tests/test_sms_template.py b/addons/sms/tests/test_sms_template.py new file mode 100644 index 00000000000..0f9f1513713 --- /dev/null +++ b/addons/sms/tests/test_sms_template.py @@ -0,0 +1,60 @@ +# -*- coding: utf-8 -*- +# Part of Odoo. See LICENSE file for full copyright and licensing details. + +from odoo.tests.common import TransactionCase, users +from odoo.addons.mail.tests.common import mail_new_test_user +from odoo.tests import tagged +from odoo.exceptions import AccessError + + +@tagged('post_install') +class TestSmsTemplateAccessRights(TransactionCase): + + @classmethod + def setUpClass(cls): + super().setUpClass() + cls.user_admin = mail_new_test_user(cls.env, login='user_system', groups='base.group_system') + cls.basic_user = mail_new_test_user(cls.env, login='user_employee', groups='base.group_user') + sms_enabled_models = cls.env['ir.model'].search([('is_mail_thread_sms', '=', True), ('transient', '=', False)]) + vals = [] + for model in sms_enabled_models: + vals.append({ + 'name': 'SMS Template ' + model.name, + 'body': 'Body Test', + 'model_id': model.id, + }) + cls.sms_templates = cls.env['sms.template'].create(vals) + + @users('user_employee') + def test_access_rights_user_sms_template(self): + # Check if a member of group_user can only read on sms.template + for sms_template in self.env['sms.template'].browse(self.sms_templates.ids): + self.assertTrue(bool(sms_template.name)) + with self.assertRaises(AccessError): + sms_template.write({'name': 'Update Template'}) + with self.assertRaises(AccessError): + self.env['sms.template'].create({ + 'name': 'New SMS Template ' + sms_template.model_id.name, + 'body': 'Body Test', + 'model_id': sms_template.model_id.id, + }) + with self.assertRaises(AccessError): + sms_template.unlink() + + @users('user_system') + def test_access_rights_manager_sms_template(self): + admin = self.env.ref('base.user_admin') + for sms_template in self.env['sms.template'].browse(self.sms_templates.ids): + self.assertTrue(bool(sms_template.name)) + sms_template.write({'body': 'New body from admin'}) + self.env['sms.template'].create({ + 'name': 'New SMS Template ' + sms_template.model_id.name, + 'body': 'Body Test', + 'model_id': sms_template.model_id.id, + }) + + # check admin is allowed to read all templates since he can be a member of + # other groups applying restrictions based on the model + self.assertTrue(bool(self.env['sms.template'].with_user(admin).browse(sms_template.ids).name)) + + sms_template.unlink() diff --git a/addons/stock_sms/security/sms_security.xml b/addons/stock_sms/security/sms_security.xml index d6a79e98b7d..5416932e921 100644 --- a/addons/stock_sms/security/sms_security.xml +++ b/addons/stock_sms/security/sms_security.xml @@ -2,10 +2,11 @@ - SMS Template: stock manager CRUD on stock picking templates + SMS Template: stock manager CUD on stock picking templates [('model_id.model', '=', 'stock.picking')] +