[FIX] web: Access issue for non qweb reports
- With the removal of the password field on the sessions (https://github.com/odoo/odoo/commit/da1f153d61d747d9357694382fe04f96c0ca886a) the non qweb reports going through the route '/web/report' were not able to be generated. We address this issue by avoiding to call dispatch_rpc and by using the functions to generate the report directly. This doesn't cause any security issue because the route '/web/report' is callable only by logged in user. Meaning that the session is already validated.
This commit is contained in:
@@ -39,6 +39,7 @@ from odoo.http import content_disposition, dispatch_rpc, request, \
|
||||
from odoo.exceptions import AccessError, UserError
|
||||
from odoo.models import check_method_name
|
||||
from odoo.service import db
|
||||
from odoo.service.report import exp_report, exp_report_get
|
||||
|
||||
_logger = logging.getLogger(__name__)
|
||||
|
||||
@@ -1475,14 +1476,11 @@ class Reports(http.Controller):
|
||||
report_ids = action['datas'].pop('ids')
|
||||
report_data.update(action['datas'])
|
||||
|
||||
report_id = dispatch_rpc('report', 'report', [
|
||||
request.session.db, request.session.uid, request.session.password,
|
||||
action["report_name"], report_ids, report_data, context])
|
||||
report_id = exp_report(request.session.db, request.session.uid, action["report_name"], report_ids, report_data, context)
|
||||
|
||||
report_struct = None
|
||||
while True:
|
||||
report_struct = dispatch_rpc('report', 'report_get', [
|
||||
request.session.db, request.session.uid, request.session.password, report_id])
|
||||
report_struct = exp_report_get(request.session.db, request.session.uid, report_id)
|
||||
if report_struct["state"]:
|
||||
break
|
||||
|
||||
|
||||
Reference in New Issue
Block a user