[FIX] website_portal_sale: ACL are too wide for employees

In revision 15b8f35, we decided to 'let ACL and ir_rules
do their job', which is an excellent idea for portal
users but a catastrophe for employee users (since, with
ACLs and rules, they have access to an giganormous amount
of SO, invoices, etc.), which made the server timeout for
big databases.

This commits reintroduces a limitation of the search that
matches ir_rules for portal users but which should limit
the number of elements visible to employees.
This commit is contained in:
Damien Bouvy
2016-03-24 14:34:23 +01:00
parent 5e84021cbb
commit a2c5fe4a64
@@ -17,12 +17,15 @@ class website_account(website_account):
res_sale_order = request.env['sale.order']
res_invoices = request.env['account.invoice']
quotations = res_sale_order.search([
('message_partner_ids', 'child_of', [partner.commercial_partner_id.id]),
('state', 'in', ['sent', 'cancel'])
])
orders = res_sale_order.search([
('message_partner_ids', 'child_of', [partner.commercial_partner_id.id]),
('state', 'in', ['sale', 'done'])
])
invoices = res_invoices.search([
('message_partner_ids', 'child_of', [partner.commercial_partner_id.id]),
('state', 'in', ['open', 'paid', 'cancelled'])
])