From aac2f49acfe1ec1146a13eede209b7bb3bf9e25c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Nguy=E1=BB=85n=20=C4=90=E1=BA=A1i=20D=C6=B0=C6=A1ng?= Date: Mon, 8 Apr 2024 11:12:08 +0700 Subject: [PATCH] [FIX] http_routing: can't redirect the user to friendly access error MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit -Step to reproduce: create a custom module and try to extend method in website_slides controller like this: @http.route(sitemap=sitemap_slide_view) def slide_view(self, slide, **kwargs): return super(WebsiteSlidesSeo, self).slide_view(slide, **kwargs) From there, 'rule.endpoint.original_routing' will take the value from the extend method not the original one therefore user will one again go to the the forbidden error page which is'n friendly. We shouldn't access original_routing because that's the "function's specific @http.route" closes odoo/odoo#160864 -solution: we only need rule.endpoint.routing because it is the one holding the "merged @http.route accross inherited controllers". Signed-off-by: Stéphane Debauche (std) --- odoo/addons/base/models/ir_http.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/odoo/addons/base/models/ir_http.py b/odoo/addons/base/models/ir_http.py index d63ec1400a6..058965d152b 100644 --- a/odoo/addons/base/models/ir_http.py +++ b/odoo/addons/base/models/ir_http.py @@ -210,7 +210,7 @@ class IrHttp(models.AbstractModel): args[key].check_access_rule('read') except (odoo.exceptions.AccessError, odoo.exceptions.MissingError) as e: # custom behavior in case a record is not accessible / has been removed - if handle_error := rule.endpoint.original_routing.get('handle_params_access_error'): + if handle_error := rule.endpoint.routing.get('handle_params_access_error'): if response := handle_error(e): werkzeug.exceptions.abort(response) if isinstance(e, odoo.exceptions.MissingError):