From b4e9cda4bf2e52f27f110bfe7b5156da46ac9801 Mon Sep 17 00:00:00 2001 From: "Merlin (megu)" Date: Mon, 2 May 2022 14:03:29 +0000 Subject: [PATCH] [FIX] sale,sale_product_configurator: company access in price_compute There is an access error when using the product configurator in a mutli- company environment Steps to reproduce: 1. Install Sales 2. Go to Settings > General Settings > Companies and create a new company 3. Go to Settings > Sales > Product Catalog and enable Product Configurator 4. Switch to the new company 5. Go to Sales > Products > Products and create a new product 6. Set the product's company to the new company 7. Add the 'Color' variant on the product with at least two values 8. Go to Sales > Orders > Quotations and create a new quotation 9. Add the new product to the quotation, the product configurator shows up 10. Increasing the number of product in the configurator will put the total to 0 and the http request `/sale/get_combination_info` raises an access error Solution: Pass the company in the context of the rpc call Problem: If we are in a secondary company, we try to acces the product of this company from the default company in `price_compute`, which raises the error opw-2826227 closes odoo/odoo#91266 X-original-commit: 5477e1bce1a3791b39d0f6de9d382416fb4b6ebf Signed-off-by: Guillaume Merlin (megu) --- addons/sale/controllers/variant.py | 4 +++- addons/sale_product_configurator/controllers/main.py | 3 --- .../static/src/js/product_configurator_controller.js | 3 ++- .../static/src/js/product_configurator_modal.js | 6 +----- 4 files changed, 6 insertions(+), 10 deletions(-) diff --git a/addons/sale/controllers/variant.py b/addons/sale/controllers/variant.py index 06958dea7e0..c8f1ed9cd0c 100644 --- a/addons/sale/controllers/variant.py +++ b/addons/sale/controllers/variant.py @@ -12,7 +12,9 @@ class VariantController(http.Controller): def get_combination_info(self, product_template_id, product_id, combination, add_qty, pricelist_id, **kw): combination = request.env['product.template.attribute.value'].browse(combination) pricelist = self._get_pricelist(pricelist_id) - ProductTemplate = request.env['product.template'] + cids = request.httprequest.cookies.get('cids', str(request.env.user.company_id.id)) + allowed_company_ids = [int(cid) for cid in cids.split(',')] + ProductTemplate = request.env['product.template'].with_context(allowed_company_ids=allowed_company_ids) if 'context' in kw: ProductTemplate = ProductTemplate.with_context(**kw.get('context')) product_template = ProductTemplate.browse(int(product_template_id)) diff --git a/addons/sale_product_configurator/controllers/main.py b/addons/sale_product_configurator/controllers/main.py index 580d3feeda6..541246ba703 100644 --- a/addons/sale_product_configurator/controllers/main.py +++ b/addons/sale_product_configurator/controllers/main.py @@ -61,9 +61,6 @@ class ProductConfiguratorController(http.Controller): combination = request.env['product.template.attribute.value'].browse(variant_values) add_qty = int(kw.get('add_qty', 1)) - if 'kwargs' in kw and 'context' in kw['kwargs']: - product = product.with_context(**kw['kwargs']['context']) - no_variant_attribute_values = combination.filtered( lambda product_template_attribute_value: product_template_attribute_value.attribute_id.create_variant == 'no_variant' ) diff --git a/addons/sale_product_configurator/static/src/js/product_configurator_controller.js b/addons/sale_product_configurator/static/src/js/product_configurator_controller.js index 18647503c9d..825aebc630f 100644 --- a/addons/sale_product_configurator/static/src/js/product_configurator_controller.js +++ b/addons/sale_product_configurator/static/src/js/product_configurator_controller.js @@ -129,7 +129,8 @@ var ProductConfiguratorFormController = FormController.extend({ ), product_no_variant_attribute_value_ids: changed ? [] : this._getAttributeValueIds( data.product_no_variant_attribute_value_ids - ) + ), + context: this.getSession().user_context, } }).then(function (configurator) { self.renderer.configuratorHtml = configurator; diff --git a/addons/sale_product_configurator/static/src/js/product_configurator_modal.js b/addons/sale_product_configurator/static/src/js/product_configurator_modal.js index 48895db2f05..c2981569043 100644 --- a/addons/sale_product_configurator/static/src/js/product_configurator_modal.js +++ b/addons/sale_product_configurator/static/src/js/product_configurator_modal.js @@ -80,11 +80,7 @@ var OptionalProductsModal = Dialog.extend(ServicesMixin, VariantMixin, { pricelist_id: self.pricelistId || false, add_qty: self.rootProduct.quantity, force_dialog: self.forceDialog, - kwargs: { - context: _.extend({ - 'quantity': self.rootProduct.quantity - }, this.context), - } + context: _.extend({'quantity': self.rootProduct.quantity}, this.context), }) .then(function (modalContent) { if (modalContent) {