From 944def6932ac73a05e7db33dbefc92a885bc9744 Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Mon, 6 Mar 2017 10:33:58 +0100 Subject: [PATCH] [FIX] ir.actions.server: allow execution by portal/public requesests When an automated action triggers for an action of a public/portal user session, the server action is executed with the session credentials. As of 4a18d5744e0a36cb2f120bfad00b52ad22f4d01d only employees can access model fields, including the model name, so a temporary sudo() elevation is necessary to find the model name. The `model` and `record` action context parameters are however still provided with the credentials of the session, not the super-user. --- odoo/addons/base/ir/ir_actions.py | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/odoo/addons/base/ir/ir_actions.py b/odoo/addons/base/ir/ir_actions.py index 1b2cbad555d..26e209f3f07 100644 --- a/odoo/addons/base/ir/ir_actions.py +++ b/odoo/addons/base/ir/ir_actions.py @@ -618,12 +618,13 @@ class IrActionsServer(models.Model): """, (self.env.uid, 'server', self._cr.dbname, __name__, level, message, "action", action.id, action.name)) eval_context = super(IrActionsServer, self)._get_eval_context(action=action) - model = self.env[action.model_id.model] + model_name = action.model_id.sudo().model + model = self.env[model_name] record = None records = None - if self._context.get('active_model') == action.model_id.model and self._context.get('active_id'): + if self._context.get('active_model') == model_name and self._context.get('active_id'): record = model.browse(self._context['active_id']) - if self._context.get('active_model') == action.model_id.model and self._context.get('active_ids'): + if self._context.get('active_model') == model_name and self._context.get('active_ids'): records = model.browse(self._context['active_ids']) if self._context.get('onchange_self'): record = self._context['onchange_self']