[FIX] base: do not depend on active_test to evaluate parent_of

Let's assume that
* Company S is a sub company of it's parent company P
* Company S has access to all the accounts and taxes of company P
* Some taxes are archived, but used

Because of the needed access rules, there will be a `parent_of` on the
record rules of accounts and taxes.
If we consider that we should consider the context key `active_test` to
add a implicit `('active', '=', True)` clause in the domain when
evaluating `parent_of` and `child_of` clauses, an access error will be
raised instead of hiding the archived records, even when simply trying
to read an archived record.

The archive feature and the security rules should be independent; if a
security rules needs to depend on the fact that a record is archived, it
should be explicit in the domain and not rely on side effects of the
implementation of `parent_of`/`child_of`

Part-of: odoo/odoo#125642
This commit is contained in:
william-andre
2023-07-20 11:49:05 +02:00
committed by qdp-odoo
parent b405bc41fb
commit ba5df07223
4 changed files with 6 additions and 14 deletions
+2
View File
@@ -868,6 +868,7 @@ class expression(object):
(when available), or as an expanded [(left,in,child_ids)] """
if not ids:
return [FALSE_LEAF]
left_model = left_model.with_context(active_test=False)
if left_model._parent_store:
domain = OR([
[('parent_path', '=like', rec.parent_path + '%')]
@@ -896,6 +897,7 @@ class expression(object):
(when available), or as an expanded [(left,in,parent_ids)] """
if not ids:
return [FALSE_LEAF]
left_model = left_model.with_context(active_test=False)
if left_model._parent_store:
parent_ids = [
int(label)