[FIX] website_profile: always give access to user to his own profile

The main condition to be able to see a profile is that the user we want to
see the profile is website_published.
But if a new user sign up and wants to access his own profile, he must
get access to his own profile, even if he is (not yet) website_published.

Commit linked to task ID 1941250 and PR #31279.
This commit is contained in:
David Beguin
2019-02-21 06:57:05 +00:00
committed by Aurélien Warnon
parent b612766575
commit 9f969fbcb0
+3 -1
View File
@@ -36,7 +36,6 @@ class WebsiteProfile(http.Controller):
content = base64.b64encode(image)
dictheaders = dict(headers) if headers else {}
dictheaders['Content-Type'] = 'image/png'
headers = list(dictheaders.items())
if not (width or height):
suffix = field.split('_')[-1] if '_' in field else 'large'
if suffix in ('small', 'medium', 'large', 'big'):
@@ -45,6 +44,9 @@ class WebsiteProfile(http.Controller):
def _check_user_profile_access(self, user_id):
user_sudo = request.env['res.users'].sudo().browse(user_id)
# User can access - no matter what - his own profile
if user_sudo.id == request.env.user.id:
return user_sudo
if user_sudo.karma == 0 or not user_sudo.website_published or \
(user_sudo.id != request.session.uid and request.env.user.karma < request.website.karma_profile_min):
return False