[FIX] ir.actions.server: allow execution by portal/public requesests

When an automated action triggers for an action of a public/portal
user session, the server action is executed with the session
credentials. As of 4a18d5744e
only employees can access model fields, including the model name,
so a temporary sudo() elevation is necessary to find the model name.

The `model` and `record` action context parameters are however still
provided with the credentials of the session, not the super-user.
This commit is contained in:
Olivier Dony
2017-03-06 10:56:23 +01:00
parent d569142ec8
commit 944def6932
+4 -3
View File
@@ -618,12 +618,13 @@ class IrActionsServer(models.Model):
""", (self.env.uid, 'server', self._cr.dbname, __name__, level, message, "action", action.id, action.name))
eval_context = super(IrActionsServer, self)._get_eval_context(action=action)
model = self.env[action.model_id.model]
model_name = action.model_id.sudo().model
model = self.env[model_name]
record = None
records = None
if self._context.get('active_model') == action.model_id.model and self._context.get('active_id'):
if self._context.get('active_model') == model_name and self._context.get('active_id'):
record = model.browse(self._context['active_id'])
if self._context.get('active_model') == action.model_id.model and self._context.get('active_ids'):
if self._context.get('active_model') == model_name and self._context.get('active_ids'):
records = model.browse(self._context['active_ids'])
if self._context.get('onchange_self'):
record = self._context['onchange_self']