[FIX] stock: inventory security with translation

Usecase to reproduce:
- Enable multiple languages and companies
- Set one language on the admin and another on the demo user.
- Create a product and a translation for its name (both languages)
- Create an inventory adjustement in a company A for this product
- Switch on demo user (inventory manager rights but in company B only)
- Create another inventory adjustement for company B
- Add the invenory line with the product and save

The Inventory Line multi-company rule raise an access error
because the system set product_name on the inventory_line that is
a related field. Since it changes the product name with its translation
it will update it on other inventory line that have this product. The
other inventory line is in company A and the user don't have access to
it thus the access error is raise.

This adds readonly on the product_name since it should not be update
with an inventory line.

opw-1855137
This commit is contained in:
Arnold Moyaux
2018-06-20 14:06:25 +02:00
committed by Nicolas Martinelli
parent b81b9f9ca1
commit 91714d4c46
+1 -1
View File
@@ -341,7 +341,7 @@ class InventoryLine(models.Model):
# TDE FIXME: necessary ? -> replace by location_id
prodlot_name = fields.Char(
'Serial Number Name',
related='prod_lot_id.name', store=True)
related='prod_lot_id.name', store=True, readonly=True)
company_id = fields.Many2one(
'res.company', 'Company', related='inventory_id.company_id',
index=True, readonly=True, store=True)