From aab6bdd54a11cb8bdb19746a9861776d3be622a6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thibault=20Delavall=C3=A9e?= Date: Thu, 27 Jul 2017 13:14:26 +0200 Subject: [PATCH] [FIX] mail, website_(blog/forum/slides): correctly redirect users on backend/frontend /mail/view controller is a generic controller that redirects to a view on a document either on backend or frontend depending on the module, user and some model specific conditions. However currently url computation is not always correct as you may end up on frontend view even when you are a regular user that should land on backend views. In this stable version we introduced a key in the returned action that indicates the action is a pure front-end (public) action or not. This way people are correctly redirected to the backend or the frontend when going through the controller. --- addons/mail/controllers/main.py | 12 ++++++++++-- addons/website_blog/models/website_blog.py | 1 + addons/website_forum/models/forum.py | 1 + addons/website_slides/models/slides.py | 1 + 4 files changed, 13 insertions(+), 2 deletions(-) diff --git a/addons/mail/controllers/main.py b/addons/mail/controllers/main.py index 320020d2c6f..b07ef4167c3 100644 --- a/addons/mail/controllers/main.py +++ b/addons/mail/controllers/main.py @@ -119,10 +119,15 @@ class MailController(http.Controller): # record does not seem to exist -> redirect to login return self._redirect_to_messaging() record_action = record_sudo.get_access_action() + record_target_type = record_action.pop('target_type', 'dummy') - # the record has an URL redirection: use it directly + # the record has a public URL redirection: use it directly if record_action['type'] == 'ir.actions.act_url': - return werkzeug.utils.redirect(record_action['url']) + if record_target_type == 'public' and not uid: + return werkzeug.utils.redirect(record_action['url']) + else: + # user connected or non-public URL, handled below + pass # other choice: act_window (no support of anything else currently) elif not record_action['type'] == 'ir.actions.act_window': return self._redirect_to_messaging() @@ -135,6 +140,9 @@ class MailController(http.Controller): except AccessError: return self._redirect_to_messaging() + if record_action['type'] == 'ir.actions.act_url': + return werkzeug.utils.redirect(record_action['url']) + query = {} url_params = { 'view_type': record_action['view_type'], diff --git a/addons/website_blog/models/website_blog.py b/addons/website_blog/models/website_blog.py index 3fe593064f5..9af46ca2586 100644 --- a/addons/website_blog/models/website_blog.py +++ b/addons/website_blog/models/website_blog.py @@ -249,6 +249,7 @@ class BlogPost(osv.Model): 'type': 'ir.actions.act_url', 'url': '/blog/%s/post/%s' % (post.blog_id.id, post.id), 'target': 'self', + 'target_type': 'public', 'res_id': post.id, } diff --git a/addons/website_forum/models/forum.py b/addons/website_forum/models/forum.py index fa23f56478d..6adf01323b4 100644 --- a/addons/website_forum/models/forum.py +++ b/addons/website_forum/models/forum.py @@ -763,6 +763,7 @@ class Post(models.Model): 'type': 'ir.actions.act_url', 'url': '/forum/%s/question/%s' % (self.forum_id.id, self.id), 'target': 'self', + 'target_type': 'public', 'res_id': self.id, } diff --git a/addons/website_slides/models/slides.py b/addons/website_slides/models/slides.py index e7455ca138a..8649b59660c 100644 --- a/addons/website_slides/models/slides.py +++ b/addons/website_slides/models/slides.py @@ -421,6 +421,7 @@ class Slide(models.Model): 'type': 'ir.actions.act_url', 'url': '%s' % self.website_url, 'target': 'self', + 'target_type': 'public', 'res_id': self.id, } return super(Slide, self).get_access_action()