[IMP] product,*: privatize price_compute method
This method is not used by rpc calls and wrongly allowed users to read the standard_price field by calling the method through rpc. Make it private to reduce its uses and avoid this potential leak of information. closes odoo/odoo#113234 Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
This commit is contained in:
@@ -71,7 +71,7 @@ class AccountAnalyticLine(models.Model):
|
||||
unit = self.product_id.uom_po_id
|
||||
|
||||
# Compute based on pricetype
|
||||
amount_unit = self.product_id.price_compute('standard_price', uom=unit)[self.product_id.id]
|
||||
amount_unit = self.product_id._price_compute('standard_price', uom=unit)[self.product_id.id]
|
||||
amount = amount_unit * self.unit_amount or 0.0
|
||||
result = (self.currency_id.round(amount) if self.currency_id else round(amount, 2)) * -1
|
||||
self.amount = result
|
||||
|
||||
@@ -264,7 +264,7 @@ class HrExpense(models.Model):
|
||||
continue
|
||||
# Only change unit_amount if the product has no cost defined on it
|
||||
if not expense.attachment_number or (expense.attachment_number and not expense.unit_amount):
|
||||
expense.unit_amount = expense.product_id.price_compute('standard_price', currency=expense.currency_id)[expense.product_id.id]
|
||||
expense.unit_amount = expense.product_id._price_compute('standard_price', currency=expense.currency_id)[expense.product_id.id]
|
||||
expense = expense.with_company(expense.company_id)
|
||||
expense.name = expense.name or expense.product_id.display_name
|
||||
expense.product_uom_id = expense.product_id.uom_id
|
||||
|
||||
@@ -49,7 +49,7 @@ class HrExpenseSplit(models.TransientModel):
|
||||
for split in self:
|
||||
split.product_has_cost = split.product_id and (float_compare(split.product_id.standard_price, 0.0, precision_digits=2) != 0)
|
||||
if split.product_has_cost:
|
||||
split.total_amount = split.product_id.price_compute('standard_price', currency=split.currency_id)[split.product_id.id]
|
||||
split.total_amount = split.product_id._price_compute('standard_price', currency=split.currency_id)[split.product_id.id]
|
||||
|
||||
@api.onchange('product_id')
|
||||
def _onchange_product_id(self):
|
||||
@@ -74,7 +74,7 @@ class HrExpenseSplit(models.TransientModel):
|
||||
'analytic_distribution': self.analytic_distribution,
|
||||
'employee_id': self.employee_id.id,
|
||||
'product_uom_id': self.product_id.uom_id.id,
|
||||
'unit_amount': self.product_id.price_compute('standard_price', currency=self.currency_id)[self.product_id.id]
|
||||
'unit_amount': self.product_id._price_compute('standard_price', currency=self.currency_id)[self.product_id.id]
|
||||
}
|
||||
|
||||
account = self.product_id.product_tmpl_id._get_product_accounts()['expense']
|
||||
|
||||
@@ -15,7 +15,7 @@ class MembershipInvoice(models.TransientModel):
|
||||
def onchange_product(self):
|
||||
"""This function returns value of product's member price based on product id.
|
||||
"""
|
||||
price_dict = self.product_id.price_compute('list_price')
|
||||
price_dict = self.product_id._price_compute('list_price')
|
||||
self.member_price = price_dict.get(self.product_id.id) or False
|
||||
|
||||
def membership_invoice(self):
|
||||
|
||||
@@ -420,10 +420,10 @@ class PricelistItem(models.Model):
|
||||
src_currency = self.base_pricelist_id.currency_id
|
||||
elif rule_base == "standard_price":
|
||||
src_currency = product.cost_currency_id
|
||||
price = product.price_compute(rule_base, uom=uom, date=date)[product.id]
|
||||
price = product._price_compute(rule_base, uom=uom, date=date)[product.id]
|
||||
else: # list_price
|
||||
src_currency = product.currency_id
|
||||
price = product.price_compute(rule_base, uom=uom, date=date)[product.id]
|
||||
price = product._price_compute(rule_base, uom=uom, date=date)[product.id]
|
||||
|
||||
if src_currency != target_currency:
|
||||
price = src_currency._convert(price, target_currency, self.env.company, date, round=False)
|
||||
|
||||
@@ -645,7 +645,7 @@ class ProductProduct(models.Model):
|
||||
return self.price_extra + sum(
|
||||
self.env.context.get('no_variant_attributes_price_extra', []))
|
||||
|
||||
def price_compute(self, price_type, uom=None, currency=None, company=None, date=False):
|
||||
def _price_compute(self, price_type, uom=None, currency=None, company=None, date=False):
|
||||
company = company or self.env.company
|
||||
date = date or fields.Date.context_today(self)
|
||||
|
||||
|
||||
@@ -583,7 +583,7 @@ class ProductTemplate(models.Model):
|
||||
|
||||
return sum(self.env.context.get('current_attributes_price_extra', []))
|
||||
|
||||
def price_compute(self, price_type, uom=None, currency=None, company=None, date=False):
|
||||
def _price_compute(self, price_type, uom=None, currency=None, company=None, date=False):
|
||||
company = company or self.env.company
|
||||
date = date or fields.Date.context_today(self)
|
||||
|
||||
|
||||
@@ -243,7 +243,7 @@ class ProductTemplate(models.Model):
|
||||
price_context = product_or_template._get_product_price_context(combination)
|
||||
product_or_template = product_or_template.with_context(**price_context)
|
||||
|
||||
list_price = product_or_template.price_compute('list_price')[product_or_template.id]
|
||||
list_price = product_or_template._price_compute('list_price')[product_or_template.id]
|
||||
price_extra = product_or_template._get_attributes_extra_price()
|
||||
price = pricelist._get_product_price(product_or_template, quantity)
|
||||
|
||||
|
||||
@@ -177,7 +177,7 @@ class ProductTemplate(models.Model):
|
||||
sales_prices = pricelist._get_products_price(self, 1.0)
|
||||
show_discount = pricelist and pricelist.discount_policy == 'without_discount'
|
||||
|
||||
base_sales_prices = self.price_compute('list_price', currency=currency)
|
||||
base_sales_prices = self._price_compute('list_price', currency=currency)
|
||||
|
||||
res = {}
|
||||
for template in self:
|
||||
|
||||
Reference in New Issue
Block a user