[IMP] product,*: privatize price_compute method

This method is not used by rpc calls and wrongly allowed users to read the standard_price
field by calling the method through rpc.

Make it private to reduce its uses and avoid this potential leak of information.

closes odoo/odoo#113234

Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
This commit is contained in:
Victor Feyens
2023-02-21 21:07:34 +01:00
parent 35e84e096b
commit be42e8178d
9 changed files with 11 additions and 11 deletions
@@ -71,7 +71,7 @@ class AccountAnalyticLine(models.Model):
unit = self.product_id.uom_po_id
# Compute based on pricetype
amount_unit = self.product_id.price_compute('standard_price', uom=unit)[self.product_id.id]
amount_unit = self.product_id._price_compute('standard_price', uom=unit)[self.product_id.id]
amount = amount_unit * self.unit_amount or 0.0
result = (self.currency_id.round(amount) if self.currency_id else round(amount, 2)) * -1
self.amount = result
+1 -1
View File
@@ -264,7 +264,7 @@ class HrExpense(models.Model):
continue
# Only change unit_amount if the product has no cost defined on it
if not expense.attachment_number or (expense.attachment_number and not expense.unit_amount):
expense.unit_amount = expense.product_id.price_compute('standard_price', currency=expense.currency_id)[expense.product_id.id]
expense.unit_amount = expense.product_id._price_compute('standard_price', currency=expense.currency_id)[expense.product_id.id]
expense = expense.with_company(expense.company_id)
expense.name = expense.name or expense.product_id.display_name
expense.product_uom_id = expense.product_id.uom_id
+2 -2
View File
@@ -49,7 +49,7 @@ class HrExpenseSplit(models.TransientModel):
for split in self:
split.product_has_cost = split.product_id and (float_compare(split.product_id.standard_price, 0.0, precision_digits=2) != 0)
if split.product_has_cost:
split.total_amount = split.product_id.price_compute('standard_price', currency=split.currency_id)[split.product_id.id]
split.total_amount = split.product_id._price_compute('standard_price', currency=split.currency_id)[split.product_id.id]
@api.onchange('product_id')
def _onchange_product_id(self):
@@ -74,7 +74,7 @@ class HrExpenseSplit(models.TransientModel):
'analytic_distribution': self.analytic_distribution,
'employee_id': self.employee_id.id,
'product_uom_id': self.product_id.uom_id.id,
'unit_amount': self.product_id.price_compute('standard_price', currency=self.currency_id)[self.product_id.id]
'unit_amount': self.product_id._price_compute('standard_price', currency=self.currency_id)[self.product_id.id]
}
account = self.product_id.product_tmpl_id._get_product_accounts()['expense']
@@ -15,7 +15,7 @@ class MembershipInvoice(models.TransientModel):
def onchange_product(self):
"""This function returns value of product's member price based on product id.
"""
price_dict = self.product_id.price_compute('list_price')
price_dict = self.product_id._price_compute('list_price')
self.member_price = price_dict.get(self.product_id.id) or False
def membership_invoice(self):
@@ -420,10 +420,10 @@ class PricelistItem(models.Model):
src_currency = self.base_pricelist_id.currency_id
elif rule_base == "standard_price":
src_currency = product.cost_currency_id
price = product.price_compute(rule_base, uom=uom, date=date)[product.id]
price = product._price_compute(rule_base, uom=uom, date=date)[product.id]
else: # list_price
src_currency = product.currency_id
price = product.price_compute(rule_base, uom=uom, date=date)[product.id]
price = product._price_compute(rule_base, uom=uom, date=date)[product.id]
if src_currency != target_currency:
price = src_currency._convert(price, target_currency, self.env.company, date, round=False)
+1 -1
View File
@@ -645,7 +645,7 @@ class ProductProduct(models.Model):
return self.price_extra + sum(
self.env.context.get('no_variant_attributes_price_extra', []))
def price_compute(self, price_type, uom=None, currency=None, company=None, date=False):
def _price_compute(self, price_type, uom=None, currency=None, company=None, date=False):
company = company or self.env.company
date = date or fields.Date.context_today(self)
+1 -1
View File
@@ -583,7 +583,7 @@ class ProductTemplate(models.Model):
return sum(self.env.context.get('current_attributes_price_extra', []))
def price_compute(self, price_type, uom=None, currency=None, company=None, date=False):
def _price_compute(self, price_type, uom=None, currency=None, company=None, date=False):
company = company or self.env.company
date = date or fields.Date.context_today(self)
+1 -1
View File
@@ -243,7 +243,7 @@ class ProductTemplate(models.Model):
price_context = product_or_template._get_product_price_context(combination)
product_or_template = product_or_template.with_context(**price_context)
list_price = product_or_template.price_compute('list_price')[product_or_template.id]
list_price = product_or_template._price_compute('list_price')[product_or_template.id]
price_extra = product_or_template._get_attributes_extra_price()
price = pricelist._get_product_price(product_or_template, quantity)
@@ -177,7 +177,7 @@ class ProductTemplate(models.Model):
sales_prices = pricelist._get_products_price(self, 1.0)
show_discount = pricelist and pricelist.discount_policy == 'without_discount'
base_sales_prices = self.price_compute('list_price', currency=currency)
base_sales_prices = self._price_compute('list_price', currency=currency)
res = {}
for template in self: