[FIX] mail, website_(blog/forum/slides): correctly redirect users on backend/frontend

/mail/view controller is a generic controller that redirects to a view
on a document either on backend or frontend depending on the module,
user and some model specific conditions.

However currently url computation is not always correct as you may end
up on frontend view even when you are a regular user that should land
on backend views.

In this stable version we introduced a key in the returned action that
indicates the action is a pure front-end (public) action or not. This
way people are correctly redirected to the backend or the frontend
when going through the controller.
This commit is contained in:
Thibault Delavallée
2017-08-16 11:13:11 +02:00
parent 3207c7226f
commit aab6bdd54a
4 changed files with 13 additions and 2 deletions
+10 -2
View File
@@ -119,10 +119,15 @@ class MailController(http.Controller):
# record does not seem to exist -> redirect to login
return self._redirect_to_messaging()
record_action = record_sudo.get_access_action()
record_target_type = record_action.pop('target_type', 'dummy')
# the record has an URL redirection: use it directly
# the record has a public URL redirection: use it directly
if record_action['type'] == 'ir.actions.act_url':
return werkzeug.utils.redirect(record_action['url'])
if record_target_type == 'public' and not uid:
return werkzeug.utils.redirect(record_action['url'])
else:
# user connected or non-public URL, handled below
pass
# other choice: act_window (no support of anything else currently)
elif not record_action['type'] == 'ir.actions.act_window':
return self._redirect_to_messaging()
@@ -135,6 +140,9 @@ class MailController(http.Controller):
except AccessError:
return self._redirect_to_messaging()
if record_action['type'] == 'ir.actions.act_url':
return werkzeug.utils.redirect(record_action['url'])
query = {}
url_params = {
'view_type': record_action['view_type'],
@@ -249,6 +249,7 @@ class BlogPost(osv.Model):
'type': 'ir.actions.act_url',
'url': '/blog/%s/post/%s' % (post.blog_id.id, post.id),
'target': 'self',
'target_type': 'public',
'res_id': post.id,
}
+1
View File
@@ -763,6 +763,7 @@ class Post(models.Model):
'type': 'ir.actions.act_url',
'url': '/forum/%s/question/%s' % (self.forum_id.id, self.id),
'target': 'self',
'target_type': 'public',
'res_id': self.id,
}
+1
View File
@@ -421,6 +421,7 @@ class Slide(models.Model):
'type': 'ir.actions.act_url',
'url': '%s' % self.website_url,
'target': 'self',
'target_type': 'public',
'res_id': self.id,
}
return super(Slide, self).get_access_action()