[FIX] portal: no note in frontend chatter w/ token

When a chatter is displayed and the document is accessed with a valid
access_token, the message related to the document are searched in sudo.

This bypass valid filtering we may down the line.

This change apply the filtering so note type messages are not displayed
for user who are not employees.

note: before 11.0 this logic was in 1b5c2ced. In future version it would
      probably be better to have a method eg. _get_domain_based_on_user
      that would be called before sudo and if not sudo.

opw-1819702
closes #23544
This commit is contained in:
Nicolas Lempereur
2018-03-08 13:41:08 +01:00
parent bfe88c50e2
commit bd4f09fa72
+4
View File
@@ -5,6 +5,7 @@ from werkzeug.exceptions import NotFound, Forbidden
from odoo import http
from odoo.http import request
from odoo.osv import expression
from odoo.tools import consteq
@@ -95,6 +96,9 @@ class PortalChatter(http.Controller):
access_as_sudo = _has_token_access(res_model, res_id, token=kw.get('token'))
if not access_as_sudo: # if token is not correct, raise Forbidden
raise Forbidden()
# Non-employee see only messages with not internal subtype (aka, no internal logs)
if not request.env['res.users'].has_group('base.group_user'):
domain = expression.AND([['&', '&', ('subtype_id', '!=', False), ('subtype_id.internal', '=', False)], domain])
Message = request.env['mail.message'].sudo()
return {
'messages': Message.search(domain, limit=limit, offset=offset).portal_message_format(),