[FIX] base: do not depend on active_test to evaluate parent_of
Let's assume that
* Company S is a sub company of it's parent company P
* Company S has access to all the accounts and taxes of company P
* Some taxes are archived, but used
Because of the needed access rules, there will be a `parent_of` on the
record rules of accounts and taxes.
If we consider that we should consider the context key `active_test` to
add a implicit `('active', '=', True)` clause in the domain when
evaluating `parent_of` and `child_of` clauses, an access error will be
raised instead of hiding the archived records, even when simply trying
to read an archived record.
The archive feature and the security rules should be independent; if a
security rules needs to depend on the fact that a record is archived, it
should be explicit in the domain and not rely on side effects of the
implementation of `parent_of`/`child_of`
Part-of: odoo/odoo#125642
This commit is contained in:
@@ -868,6 +868,7 @@ class expression(object):
|
||||
(when available), or as an expanded [(left,in,child_ids)] """
|
||||
if not ids:
|
||||
return [FALSE_LEAF]
|
||||
left_model = left_model.with_context(active_test=False)
|
||||
if left_model._parent_store:
|
||||
domain = OR([
|
||||
[('parent_path', '=like', rec.parent_path + '%')]
|
||||
@@ -896,6 +897,7 @@ class expression(object):
|
||||
(when available), or as an expanded [(left,in,parent_ids)] """
|
||||
if not ids:
|
||||
return [FALSE_LEAF]
|
||||
left_model = left_model.with_context(active_test=False)
|
||||
if left_model._parent_store:
|
||||
parent_ids = [
|
||||
int(label)
|
||||
|
||||
Reference in New Issue
Block a user