From 9f969fbcb0bd83e07b63799bee5219b7fd84ca4e Mon Sep 17 00:00:00 2001 From: David Beguin Date: Wed, 20 Feb 2019 09:24:23 +0000 Subject: [PATCH] [FIX] website_profile: always give access to user to his own profile The main condition to be able to see a profile is that the user we want to see the profile is website_published. But if a new user sign up and wants to access his own profile, he must get access to his own profile, even if he is (not yet) website_published. Commit linked to task ID 1941250 and PR #31279. --- addons/website_profile/controllers/main.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/addons/website_profile/controllers/main.py b/addons/website_profile/controllers/main.py index ec587f59eca..ea0ccd3f0cb 100644 --- a/addons/website_profile/controllers/main.py +++ b/addons/website_profile/controllers/main.py @@ -36,7 +36,6 @@ class WebsiteProfile(http.Controller): content = base64.b64encode(image) dictheaders = dict(headers) if headers else {} dictheaders['Content-Type'] = 'image/png' - headers = list(dictheaders.items()) if not (width or height): suffix = field.split('_')[-1] if '_' in field else 'large' if suffix in ('small', 'medium', 'large', 'big'): @@ -45,6 +44,9 @@ class WebsiteProfile(http.Controller): def _check_user_profile_access(self, user_id): user_sudo = request.env['res.users'].sudo().browse(user_id) + # User can access - no matter what - his own profile + if user_sudo.id == request.env.user.id: + return user_sudo if user_sudo.karma == 0 or not user_sudo.website_published or \ (user_sudo.id != request.session.uid and request.env.user.karma < request.website.karma_profile_min): return False