From be42e8178d0f9088ddefaf8b58332f70f9cdde44 Mon Sep 17 00:00:00 2001 From: Victor Feyens Date: Tue, 21 Feb 2023 09:39:47 +0000 Subject: [PATCH] [IMP] product,*: privatize price_compute method This method is not used by rpc calls and wrongly allowed users to read the standard_price field by calling the method through rpc. Make it private to reduce its uses and avoid this potential leak of information. closes odoo/odoo#113234 Signed-off-by: Victor Feyens (vfe) --- addons/account/models/account_analytic_line.py | 2 +- addons/hr_expense/models/hr_expense.py | 2 +- addons/hr_expense/wizard/hr_expense_split.py | 4 ++-- addons/membership/wizard/membership_invoice.py | 2 +- addons/product/models/product_pricelist_item.py | 4 ++-- addons/product/models/product_product.py | 2 +- addons/product/models/product_template.py | 2 +- addons/sale/models/product_template.py | 2 +- addons/website_sale/models/product_template.py | 2 +- 9 files changed, 11 insertions(+), 11 deletions(-) diff --git a/addons/account/models/account_analytic_line.py b/addons/account/models/account_analytic_line.py index 1020ca41bff..fd504a55cc7 100644 --- a/addons/account/models/account_analytic_line.py +++ b/addons/account/models/account_analytic_line.py @@ -71,7 +71,7 @@ class AccountAnalyticLine(models.Model): unit = self.product_id.uom_po_id # Compute based on pricetype - amount_unit = self.product_id.price_compute('standard_price', uom=unit)[self.product_id.id] + amount_unit = self.product_id._price_compute('standard_price', uom=unit)[self.product_id.id] amount = amount_unit * self.unit_amount or 0.0 result = (self.currency_id.round(amount) if self.currency_id else round(amount, 2)) * -1 self.amount = result diff --git a/addons/hr_expense/models/hr_expense.py b/addons/hr_expense/models/hr_expense.py index 387947c9e1d..058ecd25ca7 100644 --- a/addons/hr_expense/models/hr_expense.py +++ b/addons/hr_expense/models/hr_expense.py @@ -264,7 +264,7 @@ class HrExpense(models.Model): continue # Only change unit_amount if the product has no cost defined on it if not expense.attachment_number or (expense.attachment_number and not expense.unit_amount): - expense.unit_amount = expense.product_id.price_compute('standard_price', currency=expense.currency_id)[expense.product_id.id] + expense.unit_amount = expense.product_id._price_compute('standard_price', currency=expense.currency_id)[expense.product_id.id] expense = expense.with_company(expense.company_id) expense.name = expense.name or expense.product_id.display_name expense.product_uom_id = expense.product_id.uom_id diff --git a/addons/hr_expense/wizard/hr_expense_split.py b/addons/hr_expense/wizard/hr_expense_split.py index c256f043982..c57f65d22dc 100644 --- a/addons/hr_expense/wizard/hr_expense_split.py +++ b/addons/hr_expense/wizard/hr_expense_split.py @@ -49,7 +49,7 @@ class HrExpenseSplit(models.TransientModel): for split in self: split.product_has_cost = split.product_id and (float_compare(split.product_id.standard_price, 0.0, precision_digits=2) != 0) if split.product_has_cost: - split.total_amount = split.product_id.price_compute('standard_price', currency=split.currency_id)[split.product_id.id] + split.total_amount = split.product_id._price_compute('standard_price', currency=split.currency_id)[split.product_id.id] @api.onchange('product_id') def _onchange_product_id(self): @@ -74,7 +74,7 @@ class HrExpenseSplit(models.TransientModel): 'analytic_distribution': self.analytic_distribution, 'employee_id': self.employee_id.id, 'product_uom_id': self.product_id.uom_id.id, - 'unit_amount': self.product_id.price_compute('standard_price', currency=self.currency_id)[self.product_id.id] + 'unit_amount': self.product_id._price_compute('standard_price', currency=self.currency_id)[self.product_id.id] } account = self.product_id.product_tmpl_id._get_product_accounts()['expense'] diff --git a/addons/membership/wizard/membership_invoice.py b/addons/membership/wizard/membership_invoice.py index d53fbd99654..b6d360c1de8 100644 --- a/addons/membership/wizard/membership_invoice.py +++ b/addons/membership/wizard/membership_invoice.py @@ -15,7 +15,7 @@ class MembershipInvoice(models.TransientModel): def onchange_product(self): """This function returns value of product's member price based on product id. """ - price_dict = self.product_id.price_compute('list_price') + price_dict = self.product_id._price_compute('list_price') self.member_price = price_dict.get(self.product_id.id) or False def membership_invoice(self): diff --git a/addons/product/models/product_pricelist_item.py b/addons/product/models/product_pricelist_item.py index de656a57cea..c17a2a6dbba 100644 --- a/addons/product/models/product_pricelist_item.py +++ b/addons/product/models/product_pricelist_item.py @@ -420,10 +420,10 @@ class PricelistItem(models.Model): src_currency = self.base_pricelist_id.currency_id elif rule_base == "standard_price": src_currency = product.cost_currency_id - price = product.price_compute(rule_base, uom=uom, date=date)[product.id] + price = product._price_compute(rule_base, uom=uom, date=date)[product.id] else: # list_price src_currency = product.currency_id - price = product.price_compute(rule_base, uom=uom, date=date)[product.id] + price = product._price_compute(rule_base, uom=uom, date=date)[product.id] if src_currency != target_currency: price = src_currency._convert(price, target_currency, self.env.company, date, round=False) diff --git a/addons/product/models/product_product.py b/addons/product/models/product_product.py index 97fe4b390f7..49b9cee8dc7 100644 --- a/addons/product/models/product_product.py +++ b/addons/product/models/product_product.py @@ -645,7 +645,7 @@ class ProductProduct(models.Model): return self.price_extra + sum( self.env.context.get('no_variant_attributes_price_extra', [])) - def price_compute(self, price_type, uom=None, currency=None, company=None, date=False): + def _price_compute(self, price_type, uom=None, currency=None, company=None, date=False): company = company or self.env.company date = date or fields.Date.context_today(self) diff --git a/addons/product/models/product_template.py b/addons/product/models/product_template.py index b7560de97b5..20ccd729184 100644 --- a/addons/product/models/product_template.py +++ b/addons/product/models/product_template.py @@ -583,7 +583,7 @@ class ProductTemplate(models.Model): return sum(self.env.context.get('current_attributes_price_extra', [])) - def price_compute(self, price_type, uom=None, currency=None, company=None, date=False): + def _price_compute(self, price_type, uom=None, currency=None, company=None, date=False): company = company or self.env.company date = date or fields.Date.context_today(self) diff --git a/addons/sale/models/product_template.py b/addons/sale/models/product_template.py index cc6cc088446..359f046e15c 100644 --- a/addons/sale/models/product_template.py +++ b/addons/sale/models/product_template.py @@ -243,7 +243,7 @@ class ProductTemplate(models.Model): price_context = product_or_template._get_product_price_context(combination) product_or_template = product_or_template.with_context(**price_context) - list_price = product_or_template.price_compute('list_price')[product_or_template.id] + list_price = product_or_template._price_compute('list_price')[product_or_template.id] price_extra = product_or_template._get_attributes_extra_price() price = pricelist._get_product_price(product_or_template, quantity) diff --git a/addons/website_sale/models/product_template.py b/addons/website_sale/models/product_template.py index 82920a4b665..7d9946a28b0 100644 --- a/addons/website_sale/models/product_template.py +++ b/addons/website_sale/models/product_template.py @@ -177,7 +177,7 @@ class ProductTemplate(models.Model): sales_prices = pricelist._get_products_price(self, 1.0) show_discount = pricelist and pricelist.discount_policy == 'without_discount' - base_sales_prices = self.price_compute('list_price', currency=currency) + base_sales_prices = self._price_compute('list_price', currency=currency) res = {} for template in self: