From 86dfe52eab579bb7fa2ec12e0bb628e1bd93d8c1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Lucas=20Lef=C3=A8vre?= Date: Wed, 7 Aug 2019 08:51:19 +0000 Subject: [PATCH] [FIX] hr: Allow user to see fields in profile Currently, a simple user no longer see fields protected by groups in his profile. When retreiving the view arch, `sudo()` is used to bypass the group protection. But since commit 1e6c3be, `.sudo()` no longer changes the user. Hence, groups are still checked for the simple user. To fix the problem, the view arch should be retrieved with a user with all groups (SUPERUSER). This assumes that SUPERUSER has effectively all groups. closes odoo/odoo#35486 Signed-off-by: Romain Libert (rli) --- addons/hr/models/res_users.py | 4 ++-- addons/hr/tests/test_self_user_access.py | 26 ++++++++++++++++++++++++ 2 files changed, 28 insertions(+), 2 deletions(-) diff --git a/addons/hr/models/res_users.py b/addons/hr/models/res_users.py index 1c3fed840db..b189325a73a 100644 --- a/addons/hr/models/res_users.py +++ b/addons/hr/models/res_users.py @@ -1,7 +1,7 @@ # -*- coding: utf-8 -*- # Part of Odoo. See LICENSE file for full copyright and licensing details. -from odoo import api, models, fields, _ +from odoo import api, models, fields, _, SUPERUSER_ID from odoo.exceptions import AccessError @@ -136,7 +136,7 @@ class User(models.Model): # avoid breaking `groups` mecanism on res.users form view. profile_view = self.env.ref("hr.res_users_view_form_profile") if profile_view and view_id == profile_view.id: - self = self.sudo() + self = self.with_user(SUPERUSER_ID) return super(User, self).fields_view_get(view_id=view_id, view_type=view_type, toolbar=toolbar, submenu=submenu) def write(self, vals): diff --git a/addons/hr/tests/test_self_user_access.py b/addons/hr/tests/test_self_user_access.py index b076acb83b5..d23b420d854 100644 --- a/addons/hr/tests/test_self_user_access.py +++ b/addons/hr/tests/test_self_user_access.py @@ -2,6 +2,7 @@ # Part of Odoo. See LICENSE file for full copyright and licensing details. from collections import OrderedDict +from itertools import chain from odoo.addons.hr.tests.common import TestHrCommon from odoo.tests import new_test_user, tagged @@ -23,6 +24,31 @@ class TestSelfAccessProfile(TestHrCommon): fields = view_infos['fields'].keys() james.read(fields) + def test_profile_view_fields(self): + """ A simple user should see all fields in profile view, even if they are protected by groups """ + view = self.env.ref('hr.res_users_view_form_profile') + + # For reference, check the view with user with every groups protecting user fields + all_groups_xml_ids = chain(*[ + field.groups.split(',') + for field in self.env['res.users']._fields.values() + if field.groups + ]) + all_groups = self.env['res.groups'] + for xml_id in all_groups_xml_ids: + all_groups |= self.env.ref(xml_id.strip()) + user_all_groups = new_test_user(self.env, groups='base.group_user', login='hel', name='God') + user_all_groups.write({'groups_id': [(4, group.id, False) for group in all_groups]}) + view_infos = self.env['res.users'].with_user(user_all_groups).fields_view_get(view_id=view.id) + full_fields = view_infos['fields'] + + # Now check the view for a simple user + user = new_test_user(self.env, login='gro', name='Grouillot') + view_infos = self.env['res.users'].with_user(user).fields_view_get(view_id=view.id) + fields = view_infos['fields'] + + # Compare both + self.assertEqual(full_fields.keys(), fields.keys(), "View fields should not depend on user's groups") class TestSelfAccessRights(TestHrCommon):