[FIX] hr: Allow user to see fields in profile

Currently, a simple user no longer see fields protected
by groups in his profile.

When retreiving the view arch, `sudo()` is used to bypass
the group protection.
But since commit 1e6c3be, `.sudo()` no longer changes the user.
Hence, groups are still checked for the simple user.

To fix the problem, the view arch should be retrieved with
a user with all groups (SUPERUSER). This assumes that
SUPERUSER has effectively all groups.

closes odoo/odoo#35486

Signed-off-by: Romain Libert (rli) <rli@odoo.com>
This commit is contained in:
Lucas Lefèvre
2019-08-07 12:40:41 +00:00
parent 9419d171a8
commit 86dfe52eab
2 changed files with 28 additions and 2 deletions
+2 -2
View File
@@ -1,7 +1,7 @@
# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
from odoo import api, models, fields, _
from odoo import api, models, fields, _, SUPERUSER_ID
from odoo.exceptions import AccessError
@@ -136,7 +136,7 @@ class User(models.Model):
# avoid breaking `groups` mecanism on res.users form view.
profile_view = self.env.ref("hr.res_users_view_form_profile")
if profile_view and view_id == profile_view.id:
self = self.sudo()
self = self.with_user(SUPERUSER_ID)
return super(User, self).fields_view_get(view_id=view_id, view_type=view_type, toolbar=toolbar, submenu=submenu)
def write(self, vals):
+26
View File
@@ -2,6 +2,7 @@
# Part of Odoo. See LICENSE file for full copyright and licensing details.
from collections import OrderedDict
from itertools import chain
from odoo.addons.hr.tests.common import TestHrCommon
from odoo.tests import new_test_user, tagged
@@ -23,6 +24,31 @@ class TestSelfAccessProfile(TestHrCommon):
fields = view_infos['fields'].keys()
james.read(fields)
def test_profile_view_fields(self):
""" A simple user should see all fields in profile view, even if they are protected by groups """
view = self.env.ref('hr.res_users_view_form_profile')
# For reference, check the view with user with every groups protecting user fields
all_groups_xml_ids = chain(*[
field.groups.split(',')
for field in self.env['res.users']._fields.values()
if field.groups
])
all_groups = self.env['res.groups']
for xml_id in all_groups_xml_ids:
all_groups |= self.env.ref(xml_id.strip())
user_all_groups = new_test_user(self.env, groups='base.group_user', login='hel', name='God')
user_all_groups.write({'groups_id': [(4, group.id, False) for group in all_groups]})
view_infos = self.env['res.users'].with_user(user_all_groups).fields_view_get(view_id=view.id)
full_fields = view_infos['fields']
# Now check the view for a simple user
user = new_test_user(self.env, login='gro', name='Grouillot')
view_infos = self.env['res.users'].with_user(user).fields_view_get(view_id=view.id)
fields = view_infos['fields']
# Compare both
self.assertEqual(full_fields.keys(), fields.keys(), "View fields should not depend on user's groups")
class TestSelfAccessRights(TestHrCommon):