From a94914d775b85605d636cd820b09abc2dc7f91c8 Mon Sep 17 00:00:00 2001 From: Julien Mougenot Date: Mon, 13 Sep 2021 09:31:36 +0000 Subject: [PATCH] [FIX] web_tour: Give correct access when reading modules MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Tours are automatically disabled when the demo data are enabled on at least one module. To ensure that, when giving the session_info object, we read on the `ir.module.module` model to check whether some of them have demo data. Before this commit, this check only relied on the user's `is_admin` flag, which does not give read access on the `ir.module.module` model. Now, a `sudo` ensures that any admin user can read on the model. closes odoo/odoo#76864 X-original-commit: 3a8d30d51a392f42d83d24b5f865f77b05205b50 Signed-off-by: Rémi Rahir (rar) --- addons/web_tour/models/ir_http.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/web_tour/models/ir_http.py b/addons/web_tour/models/ir_http.py index 1e86babb6ad..bb44df13982 100644 --- a/addons/web_tour/models/ir_http.py +++ b/addons/web_tour/models/ir_http.py @@ -11,7 +11,7 @@ class Http(models.AbstractModel): def session_info(self): result = super().session_info() if result['is_admin']: - demo_modules_count = self.env['ir.module.module'].search_count([('demo', '=', True)]) + demo_modules_count = self.env['ir.module.module'].sudo().search_count([('demo', '=', True)]) result['web_tours'] = request.env['web_tour.tour'].get_consumed_tours() result['tour_disable'] = demo_modules_count > 0 return result