[FIX] portal: no note in frontend chatter w/ token
When a chatter is displayed and the document is accessed with a valid
access_token, the message related to the document are searched in sudo.
This bypass valid filtering we may down the line.
This change apply the filtering so note type messages are not displayed
for user who are not employees.
note: before 11.0 this logic was in 1b5c2ced. In future version it would
probably be better to have a method eg. _get_domain_based_on_user
that would be called before sudo and if not sudo.
opw-1819702
closes #23544
This commit is contained in:
@@ -5,6 +5,7 @@ from werkzeug.exceptions import NotFound, Forbidden
|
||||
|
||||
from odoo import http
|
||||
from odoo.http import request
|
||||
from odoo.osv import expression
|
||||
from odoo.tools import consteq
|
||||
|
||||
|
||||
@@ -95,6 +96,9 @@ class PortalChatter(http.Controller):
|
||||
access_as_sudo = _has_token_access(res_model, res_id, token=kw.get('token'))
|
||||
if not access_as_sudo: # if token is not correct, raise Forbidden
|
||||
raise Forbidden()
|
||||
# Non-employee see only messages with not internal subtype (aka, no internal logs)
|
||||
if not request.env['res.users'].has_group('base.group_user'):
|
||||
domain = expression.AND([['&', '&', ('subtype_id', '!=', False), ('subtype_id.internal', '=', False)], domain])
|
||||
Message = request.env['mail.message'].sudo()
|
||||
return {
|
||||
'messages': Message.search(domain, limit=limit, offset=offset).portal_message_format(),
|
||||
|
||||
Reference in New Issue
Block a user