From 8e4a55fb81f40a5d406a0906ee3ffeacdcfffc4e Mon Sep 17 00:00:00 2001 From: Nans Lefebvre Date: Fri, 6 Dec 2019 13:05:48 +0000 Subject: [PATCH] [FIX] ir_translation: correct rights check in _set_ids Suppose you have a record rA of model A, and a record rB of model B which has a related B.v on field A.x, that is stored and translatable. Suppose also that user U can write on A, but not on B because of ACLs. Let U write on rA.x. Then it recomputes the value of rB.v. Since this directly calls the _write, we check the record rules but not the ACLs, so U wrote rA.x and rB.v successfully. Now let U be in another language L. This means that we go trough translations, which calls _set_ids. If the translation already exists, then the update is done in SQL so no access rights are checked. However if translations do not exist, the translations are created via the ORM and thus check both record rules and ACLs. Therefore the operation is forbidden, since by hypothesis U cannot write on B. We can skip the check in this case, since we come from either a create or a write, so the ACLs should already be checked on the original models as intended (in the case of B, not fully). Furthermore it removes the incoherency with the update case. opw 2145738 closes odoo/odoo#41546 X-original-commit: 19d18e81dd9d3dcce1281f662abdaf941c0c357a Signed-off-by: Nans Lefebvre (len) --- odoo/addons/base/models/ir_translation.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/odoo/addons/base/models/ir_translation.py b/odoo/addons/base/models/ir_translation.py index 1ba9237344a..a133758c2c1 100644 --- a/odoo/addons/base/models/ir_translation.py +++ b/odoo/addons/base/models/ir_translation.py @@ -263,7 +263,7 @@ class IrTranslation(models.Model): existing_ids = [row[0] for row in self._cr.fetchall()] # create missing translations - self.create([{ + self.sudo().create([{ 'lang': lang, 'type': tt, 'name': name,