[FIX] ir_translation: correct rights check in _set_ids

Suppose you have a record rA of model A, and a record rB of model B
which has a related B.v on field A.x, that is stored and translatable.
Suppose also that user U can write on A, but not on B because of ACLs.

Let U write on rA.x. Then it recomputes the value of rB.v.
Since this directly calls the _write, we check the record rules but not
the ACLs, so U wrote rA.x and rB.v successfully.

Now let U be in another language L.
This means that we go trough translations, which calls _set_ids.
If the translation already exists, then the update is done in SQL so no
access rights are checked.
However if translations do not exist, the translations are created via
the ORM and thus check both record rules and ACLs.
Therefore the operation is forbidden, since by hypothesis U cannot write
on B.

We can skip the check in this case, since we come from either a create
or a write, so the ACLs should already be checked on the original models
as intended (in the case of B, not fully).
Furthermore it removes the incoherency with the update case.

opw 2145738

closes odoo/odoo#41546

X-original-commit: 19d18e81dd9d3dcce1281f662abdaf941c0c357a
Signed-off-by: Nans Lefebvre (len) <len@odoo.com>
This commit is contained in:
Nans Lefebvre
2019-12-09 07:22:07 +00:00
parent 1f218f831c
commit 8e4a55fb81
+1 -1
View File
@@ -263,7 +263,7 @@ class IrTranslation(models.Model):
existing_ids = [row[0] for row in self._cr.fetchall()]
# create missing translations
self.create([{
self.sudo().create([{
'lang': lang,
'type': tt,
'name': name,