[IMP] core: clarify making fields inaccessible

* add a constant to `fields` for that purpose
* add a test to ensure that it works as expected
* fix the formatter so it handles the pattern correctly
This commit is contained in:
Xavier Morel
2020-08-17 09:30:53 +00:00
parent bfcc7dee8f
commit bfa00919cd
6 changed files with 24 additions and 3 deletions
+1 -1
View File
@@ -21,7 +21,7 @@ _logger = logging.getLogger(__name__)
class Users(models.Model):
_inherit = 'res.users'
totp_secret = fields.Char(copy=False, groups=".") # no access
totp_secret = fields.Char(copy=False, groups=fields.NO_ACCESS)
totp_enabled = fields.Boolean(string="TOTP enabled", compute='_compute_totp_enabled')
def __init__(self, pool, cr):
+1 -1
View File
@@ -1475,7 +1475,7 @@ class CheckIdentity(models.TransientModel):
_name = 'res.users.identitycheck'
_description = "Password Check Wizard"
request = fields.Char(readonly=True, groups='.') # no access
request = fields.Char(readonly=True, groups=fields.NO_ACCESS)
password = fields.Char()
def run_check(self):
+2 -1
View File
@@ -15,6 +15,7 @@ class SomeObj(models.Model):
default=5
)
forbidden2 = fields.Integer(groups='test_access_rights.test_group')
forbidden3 = fields.Integer(groups=fields.NO_ACCESS)
class Container(models.Model):
_name = 'test_access_right.container'
@@ -65,4 +66,4 @@ class ResPartner(models.Model):
def _get_company_currency(self):
for partner in self:
partner.currency_id = partner.sudo().company_id.currency_id
partner.currency_id = partner.sudo().company_id.currency_id
@@ -390,6 +390,20 @@ Fields:
% self.user.id
)
with self.assertRaises(AccessError) as ctx:
_ = self.record.forbidden3
self.assertEqual(
ctx.exception.args[0],
"""The requested operation can not be completed due to security restrictions.
Document type: Object For Test Access Right (test_access_right.some_obj)
Operation: read
User: %s
Fields:
- forbidden3 (always forbidden)""" % self.user.id
)
def test_write(self):
self.env.ref('base.group_no_one').write(
{'users': [(4, self.user.id)]})
+3
View File
@@ -29,6 +29,9 @@ from odoo.exceptions import CacheMiss
DATE_LENGTH = len(date.today().strftime(DATE_FORMAT))
DATETIME_LENGTH = len(datetime.now().strftime(DATETIME_FORMAT))
# hacky-ish way to prevent access to a field through the ORM (except for sudo mode)
NO_ACCESS='.'
IR_MODELS = (
'ir.model', 'ir.model.data', 'ir.model.fields', 'ir.model.fields.selection',
'ir.model.relation', 'ir.model.constraint', 'ir.module.module',
+3
View File
@@ -2888,6 +2888,9 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
})
def format_groups(field):
if field.groups == '.':
return _("always forbidden")
anyof = self.env['res.groups']
noneof = self.env['res.groups']
for g in field.groups.split(','):