[FIX] website_profile: always give access to user to his own profile
The main condition to be able to see a profile is that the user we want to see the profile is website_published. But if a new user sign up and wants to access his own profile, he must get access to his own profile, even if he is (not yet) website_published. Commit linked to task ID 1941250 and PR #31279.
This commit is contained in:
committed by
Aurélien Warnon
parent
b612766575
commit
9f969fbcb0
@@ -36,7 +36,6 @@ class WebsiteProfile(http.Controller):
|
||||
content = base64.b64encode(image)
|
||||
dictheaders = dict(headers) if headers else {}
|
||||
dictheaders['Content-Type'] = 'image/png'
|
||||
headers = list(dictheaders.items())
|
||||
if not (width or height):
|
||||
suffix = field.split('_')[-1] if '_' in field else 'large'
|
||||
if suffix in ('small', 'medium', 'large', 'big'):
|
||||
@@ -45,6 +44,9 @@ class WebsiteProfile(http.Controller):
|
||||
|
||||
def _check_user_profile_access(self, user_id):
|
||||
user_sudo = request.env['res.users'].sudo().browse(user_id)
|
||||
# User can access - no matter what - his own profile
|
||||
if user_sudo.id == request.env.user.id:
|
||||
return user_sudo
|
||||
if user_sudo.karma == 0 or not user_sudo.website_published or \
|
||||
(user_sudo.id != request.session.uid and request.env.user.karma < request.website.karma_profile_min):
|
||||
return False
|
||||
|
||||
Reference in New Issue
Block a user