[FIX] sale,sale_product_configurator: company access in price_compute

There is an access error when using the product configurator in a mutli-
company environment

Steps to reproduce:
1. Install Sales
2. Go to Settings > General Settings > Companies and create a new
company
3. Go to Settings > Sales > Product Catalog and enable Product
Configurator
4. Switch to the new company
5. Go to Sales > Products > Products and create a new product
6. Set the product's company to the new company
7. Add the 'Color' variant on the product with at least two values
8. Go to Sales > Orders > Quotations and create a new quotation
9. Add the new product to the quotation, the product configurator shows
up
10. Increasing the number of product in the configurator will put the
total to 0 and the http request `/sale/get_combination_info` raises an
access error

Solution:
Pass the company in the context of the rpc call

Problem:
If we are in a secondary company, we try to acces the product of this
company from the default company in `price_compute`, which raises the
error

opw-2826227

closes odoo/odoo#91266

X-original-commit: 5477e1bce1a3791b39d0f6de9d382416fb4b6ebf
Signed-off-by: Guillaume Merlin (megu) <megu@odoo.com>
This commit is contained in:
Merlin (megu)
2022-05-13 12:00:07 +02:00
parent 0e0047a533
commit b4e9cda4bf
4 changed files with 6 additions and 10 deletions
+3 -1
View File
@@ -12,7 +12,9 @@ class VariantController(http.Controller):
def get_combination_info(self, product_template_id, product_id, combination, add_qty, pricelist_id, **kw):
combination = request.env['product.template.attribute.value'].browse(combination)
pricelist = self._get_pricelist(pricelist_id)
ProductTemplate = request.env['product.template']
cids = request.httprequest.cookies.get('cids', str(request.env.user.company_id.id))
allowed_company_ids = [int(cid) for cid in cids.split(',')]
ProductTemplate = request.env['product.template'].with_context(allowed_company_ids=allowed_company_ids)
if 'context' in kw:
ProductTemplate = ProductTemplate.with_context(**kw.get('context'))
product_template = ProductTemplate.browse(int(product_template_id))
@@ -61,9 +61,6 @@ class ProductConfiguratorController(http.Controller):
combination = request.env['product.template.attribute.value'].browse(variant_values)
add_qty = int(kw.get('add_qty', 1))
if 'kwargs' in kw and 'context' in kw['kwargs']:
product = product.with_context(**kw['kwargs']['context'])
no_variant_attribute_values = combination.filtered(
lambda product_template_attribute_value: product_template_attribute_value.attribute_id.create_variant == 'no_variant'
)
@@ -129,7 +129,8 @@ var ProductConfiguratorFormController = FormController.extend({
),
product_no_variant_attribute_value_ids: changed ? [] : this._getAttributeValueIds(
data.product_no_variant_attribute_value_ids
)
),
context: this.getSession().user_context,
}
}).then(function (configurator) {
self.renderer.configuratorHtml = configurator;
@@ -80,11 +80,7 @@ var OptionalProductsModal = Dialog.extend(ServicesMixin, VariantMixin, {
pricelist_id: self.pricelistId || false,
add_qty: self.rootProduct.quantity,
force_dialog: self.forceDialog,
kwargs: {
context: _.extend({
'quantity': self.rootProduct.quantity
}, this.context),
}
context: _.extend({'quantity': self.rootProduct.quantity}, this.context),
})
.then(function (modalContent) {
if (modalContent) {