From 91714d4c46f3b45bc76649dbcb7acd3a741bc2da Mon Sep 17 00:00:00 2001 From: Arnold Moyaux Date: Mon, 18 Jun 2018 14:48:03 +0200 Subject: [PATCH] [FIX] stock: inventory security with translation Usecase to reproduce: - Enable multiple languages and companies - Set one language on the admin and another on the demo user. - Create a product and a translation for its name (both languages) - Create an inventory adjustement in a company A for this product - Switch on demo user (inventory manager rights but in company B only) - Create another inventory adjustement for company B - Add the invenory line with the product and save The Inventory Line multi-company rule raise an access error because the system set product_name on the inventory_line that is a related field. Since it changes the product name with its translation it will update it on other inventory line that have this product. The other inventory line is in company A and the user don't have access to it thus the access error is raise. This adds readonly on the product_name since it should not be update with an inventory line. opw-1855137 --- addons/stock/models/stock_inventory.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/stock/models/stock_inventory.py b/addons/stock/models/stock_inventory.py index 2f1b757960a..ed3d354b295 100644 --- a/addons/stock/models/stock_inventory.py +++ b/addons/stock/models/stock_inventory.py @@ -341,7 +341,7 @@ class InventoryLine(models.Model): # TDE FIXME: necessary ? -> replace by location_id prodlot_name = fields.Char( 'Serial Number Name', - related='prod_lot_id.name', store=True) + related='prod_lot_id.name', store=True, readonly=True) company_id = fields.Many2one( 'res.company', 'Company', related='inventory_id.company_id', index=True, readonly=True, store=True)