From 90853ef0abcb01fda9cacf99bc09f0ff99b496d8 Mon Sep 17 00:00:00 2001 From: "Thomas Lefebvre (thle)" Date: Fri, 2 Feb 2024 11:00:02 +0100 Subject: [PATCH] [FIX] im_livechat: add self writable fields for user MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Issue: ------ Since this commit[^1], a user who is not in the `Administration/Access Rights` group cannot modify certain fields available to him on his user profile (`livechat_username` and `livechat_lang_ids`). Solution: --------- As it is possible for a user to write to these fields, it is necessary to put them in `SELF_READABLE_FIELDS` in order to obtain sudo rights when writing if the environment user corresponds to the user to whom we want to write the new values. opw-3717266 [^1]: 78f6b83b348326ac0848692ca228a4650057f95c closes odoo/odoo#152425 Signed-off-by: Sébastien Theys (seb) --- addons/im_livechat/models/res_users.py | 4 ++++ addons/im_livechat/tests/test_message.py | 14 ++++++++++++++ odoo/addons/base/models/res_lang.py | 1 + 3 files changed, 19 insertions(+) diff --git a/addons/im_livechat/models/res_users.py b/addons/im_livechat/models/res_users.py index 96ca99ee741..9de83ef8928 100644 --- a/addons/im_livechat/models/res_users.py +++ b/addons/im_livechat/models/res_users.py @@ -18,6 +18,10 @@ class Users(models.Model): def SELF_READABLE_FIELDS(self): return super().SELF_READABLE_FIELDS + ['livechat_username', 'livechat_lang_ids', 'has_access_livechat'] + @property + def SELF_WRITEABLE_FIELDS(self): + return super().SELF_WRITEABLE_FIELDS + ['livechat_username', 'livechat_lang_ids'] + @api.depends('res_users_settings_id.livechat_username') def _compute_livechat_username(self): for user in self: diff --git a/addons/im_livechat/tests/test_message.py b/addons/im_livechat/tests/test_message.py index daef9d8e33d..f9c1e937859 100644 --- a/addons/im_livechat/tests/test_message.py +++ b/addons/im_livechat/tests/test_message.py @@ -4,6 +4,7 @@ from markupsafe import Markup from odoo import Command +from odoo.exceptions import AccessError from odoo.tests.common import users, tagged, HttpCase @@ -25,6 +26,19 @@ class TestImLivechatMessage(HttpCase): {'name': 'test1', 'login': 'test1', 'password': self.password, 'email': 'test1@example.com', 'livechat_username': 'chuck'}, ]) + def test_update_username(self): + user = self.env['res.users'].create({ + 'name': 'User', + 'login': 'User', + 'password': self.password, + 'email': 'user@example.com', + 'livechat_username': 'edit me' + }) + with self.assertRaises(AccessError): + self.env['res.users'].with_user(user).check_access_rights('write') + user.with_user(user).livechat_username = 'New username' + self.assertEqual(user.livechat_username, 'New username') + @users('emp') def test_message_format(self): im_livechat_channel = self.env['im_livechat.channel'].sudo().create({'name': 'support', 'user_ids': [Command.link(self.users[0].id)]}) diff --git a/odoo/addons/base/models/res_lang.py b/odoo/addons/base/models/res_lang.py index 0ebfd61f430..87b84c043da 100644 --- a/odoo/addons/base/models/res_lang.py +++ b/odoo/addons/base/models/res_lang.py @@ -21,6 +21,7 @@ class Lang(models.Model): _name = "res.lang" _description = "Languages" _order = "active desc,name" + _allow_sudo_commands = False _disallowed_datetime_patterns = list(tools.DATETIME_FORMATS_MAP) _disallowed_datetime_patterns.remove('%y') # this one is in fact allowed, just not good practice