From bd4f09fa72fd12a8c4347c2080b5236ae1023d52 Mon Sep 17 00:00:00 2001 From: Nicolas Lempereur Date: Thu, 8 Mar 2018 10:55:34 +0100 Subject: [PATCH] [FIX] portal: no note in frontend chatter w/ token When a chatter is displayed and the document is accessed with a valid access_token, the message related to the document are searched in sudo. This bypass valid filtering we may down the line. This change apply the filtering so note type messages are not displayed for user who are not employees. note: before 11.0 this logic was in 1b5c2ced. In future version it would probably be better to have a method eg. _get_domain_based_on_user that would be called before sudo and if not sudo. opw-1819702 closes #23544 --- addons/portal/controllers/mail.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/addons/portal/controllers/mail.py b/addons/portal/controllers/mail.py index 3a59ecd70b3..b8ff6f8f2fd 100644 --- a/addons/portal/controllers/mail.py +++ b/addons/portal/controllers/mail.py @@ -5,6 +5,7 @@ from werkzeug.exceptions import NotFound, Forbidden from odoo import http from odoo.http import request +from odoo.osv import expression from odoo.tools import consteq @@ -95,6 +96,9 @@ class PortalChatter(http.Controller): access_as_sudo = _has_token_access(res_model, res_id, token=kw.get('token')) if not access_as_sudo: # if token is not correct, raise Forbidden raise Forbidden() + # Non-employee see only messages with not internal subtype (aka, no internal logs) + if not request.env['res.users'].has_group('base.group_user'): + domain = expression.AND([['&', '&', ('subtype_id', '!=', False), ('subtype_id.internal', '=', False)], domain]) Message = request.env['mail.message'].sudo() return { 'messages': Message.search(domain, limit=limit, offset=offset).portal_message_format(),