From 9aa1b7ba1208cd4afd507320ce00a3037f8f286b Mon Sep 17 00:00:00 2001 From: Toufik Benjaa Date: Wed, 21 Mar 2018 11:27:10 +0100 Subject: [PATCH] [FIX] web: Access issue for non qweb reports - With the removal of the password field on the sessions (https://github.com/odoo/odoo/commit/da1f153d61d747d9357694382fe04f96c0ca886a) the non qweb reports going through the route '/web/report' were not able to be generated. We address this issue by avoiding to call dispatch_rpc and by using the functions to generate the report directly. This doesn't cause any security issue because the route '/web/report' is callable only by logged in user. Meaning that the session is already validated. --- addons/web/controllers/main.py | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/addons/web/controllers/main.py b/addons/web/controllers/main.py index 438295e6233..d99395c6032 100644 --- a/addons/web/controllers/main.py +++ b/addons/web/controllers/main.py @@ -39,6 +39,7 @@ from odoo.http import content_disposition, dispatch_rpc, request, \ from odoo.exceptions import AccessError, UserError from odoo.models import check_method_name from odoo.service import db +from odoo.service.report import exp_report, exp_report_get _logger = logging.getLogger(__name__) @@ -1475,14 +1476,11 @@ class Reports(http.Controller): report_ids = action['datas'].pop('ids') report_data.update(action['datas']) - report_id = dispatch_rpc('report', 'report', [ - request.session.db, request.session.uid, request.session.password, - action["report_name"], report_ids, report_data, context]) + report_id = exp_report(request.session.db, request.session.uid, action["report_name"], report_ids, report_data, context) report_struct = None while True: - report_struct = dispatch_rpc('report', 'report_get', [ - request.session.db, request.session.uid, request.session.password, report_id]) + report_struct = exp_report_get(request.session.db, request.session.uid, report_id) if report_struct["state"]: break