From 9ea17019f6891a8036aac9e87b6f636f921e486c Mon Sep 17 00:00:00 2001 From: Victor Feyens Date: Thu, 14 Dec 2023 15:06:18 +0100 Subject: [PATCH] [FIX] core: default multi-company domain of check_company=True fields. Suppose two models class A: company_id = fields.M2O() # not required class B: _check_company_auto = True company_id = fields.M2O() # not required a_id = fields.M20(check_company=True) and the following code: a = A.create({'company_id': 1}) b = B.create({'a_id': a.id, 'company_id': False}) The creation of B will fail because of the multi-company checks, which is expected. Nevertheless, since 0d30cc2bc9b9cc2b805d6c2d0a440f185c648da0, the domain of the field a_id would be: (company_id and ['|', ('company_id', '=', False), ('company_id', 'in', [company_id])] or []) + ([]) which means that through the interface, if you create a record b following the example above (no company_id on b), the evaluated domain would be empty, allowing to select records of class A, even if they belong to another company. Of course, this would lead to a multi-company error when trying to save the record. This commit makes sure that the right domain is applied on check_company=True fields, even if the current record has no value in its `company_id` field. opw-3629374 closes odoo/odoo#151341 X-original-commit: aaddedc3bab4f16747fb0f71ae626d94f3975ee3 Signed-off-by: Victor Feyens (vfe) --- odoo/addons/base/models/res_users.py | 6 ++++-- odoo/fields.py | 3 ++- odoo/models.py | 2 ++ 3 files changed, 8 insertions(+), 3 deletions(-) diff --git a/odoo/addons/base/models/res_users.py b/odoo/addons/base/models/res_users.py index 9e7e65cec9d..9308aaf71f7 100644 --- a/odoo/addons/base/models/res_users.py +++ b/odoo/addons/base/models/res_users.py @@ -280,8 +280,10 @@ class Users(models.Model): _order = 'name, login' _allow_sudo_commands = False - def _check_company_domain(self, companies=None): - return [('company_ids', 'in', models.to_company_ids(companies))] if companies else [] + def _check_company_domain(self, companies): + if not companies: + return [] + return [('company_ids', 'in', models.to_company_ids(companies))] @property def SELF_READABLE_FIELDS(self): diff --git a/odoo/fields.py b/odoo/fields.py index 4baede645ad..04083a0cfe4 100644 --- a/odoo/fields.py +++ b/odoo/fields.py @@ -2925,7 +2925,8 @@ class _Relational(Field): else: cid = "id" if self.model_name == "res.company" else "company_id" company_domain = env[self.comodel_name]._check_company_domain(companies=unquote(cid)) - return f"({cid} and {company_domain} or []) + ({domain or []})" + no_company_domain = env[self.comodel_name]._check_company_domain(companies='') + return f"({cid} and {company_domain} or {no_company_domain}) + ({domain or []})" return domain diff --git a/odoo/models.py b/odoo/models.py index 79eb7f9d35a..1a77dd270e2 100644 --- a/odoo/models.py +++ b/odoo/models.py @@ -4000,6 +4000,8 @@ class BaseModel(metaclass=MetaModel): :param companies: the allowed companies for the related record :type companies: BaseModel or list or tuple or int or unquote """ + if not companies: + return [('company_id', '=', False)] return ['|', ('company_id', '=', False), ('company_id', 'in', to_company_ids(companies))] def _check_company(self, fnames=None):