From a2c5fe4a64bcceb56fc7df16391c2acbfec6b178 Mon Sep 17 00:00:00 2001 From: Damien Bouvy Date: Thu, 24 Mar 2016 14:27:19 +0100 Subject: [PATCH] [FIX] website_portal_sale: ACL are too wide for employees In revision 15b8f35, we decided to 'let ACL and ir_rules do their job', which is an excellent idea for portal users but a catastrophe for employee users (since, with ACLs and rules, they have access to an giganormous amount of SO, invoices, etc.), which made the server timeout for big databases. This commits reintroduces a limitation of the search that matches ir_rules for portal users but which should limit the number of elements visible to employees. --- addons/website_portal_sale/controllers/main.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/addons/website_portal_sale/controllers/main.py b/addons/website_portal_sale/controllers/main.py index 79512a90c67..fc169bccd06 100644 --- a/addons/website_portal_sale/controllers/main.py +++ b/addons/website_portal_sale/controllers/main.py @@ -17,12 +17,15 @@ class website_account(website_account): res_sale_order = request.env['sale.order'] res_invoices = request.env['account.invoice'] quotations = res_sale_order.search([ + ('message_partner_ids', 'child_of', [partner.commercial_partner_id.id]), ('state', 'in', ['sent', 'cancel']) ]) orders = res_sale_order.search([ + ('message_partner_ids', 'child_of', [partner.commercial_partner_id.id]), ('state', 'in', ['sale', 'done']) ]) invoices = res_invoices.search([ + ('message_partner_ids', 'child_of', [partner.commercial_partner_id.id]), ('state', 'in', ['open', 'paid', 'cancelled']) ])