[IMP] core: clarify making fields inaccessible
* add a constant to `fields` for that purpose * add a test to ensure that it works as expected * fix the formatter so it handles the pattern correctly
This commit is contained in:
@@ -21,7 +21,7 @@ _logger = logging.getLogger(__name__)
|
||||
class Users(models.Model):
|
||||
_inherit = 'res.users'
|
||||
|
||||
totp_secret = fields.Char(copy=False, groups=".") # no access
|
||||
totp_secret = fields.Char(copy=False, groups=fields.NO_ACCESS)
|
||||
totp_enabled = fields.Boolean(string="TOTP enabled", compute='_compute_totp_enabled')
|
||||
|
||||
def __init__(self, pool, cr):
|
||||
|
||||
@@ -1475,7 +1475,7 @@ class CheckIdentity(models.TransientModel):
|
||||
_name = 'res.users.identitycheck'
|
||||
_description = "Password Check Wizard"
|
||||
|
||||
request = fields.Char(readonly=True, groups='.') # no access
|
||||
request = fields.Char(readonly=True, groups=fields.NO_ACCESS)
|
||||
password = fields.Char()
|
||||
|
||||
def run_check(self):
|
||||
|
||||
@@ -15,6 +15,7 @@ class SomeObj(models.Model):
|
||||
default=5
|
||||
)
|
||||
forbidden2 = fields.Integer(groups='test_access_rights.test_group')
|
||||
forbidden3 = fields.Integer(groups=fields.NO_ACCESS)
|
||||
|
||||
class Container(models.Model):
|
||||
_name = 'test_access_right.container'
|
||||
@@ -65,4 +66,4 @@ class ResPartner(models.Model):
|
||||
|
||||
def _get_company_currency(self):
|
||||
for partner in self:
|
||||
partner.currency_id = partner.sudo().company_id.currency_id
|
||||
partner.currency_id = partner.sudo().company_id.currency_id
|
||||
|
||||
@@ -390,6 +390,20 @@ Fields:
|
||||
% self.user.id
|
||||
)
|
||||
|
||||
with self.assertRaises(AccessError) as ctx:
|
||||
_ = self.record.forbidden3
|
||||
|
||||
self.assertEqual(
|
||||
ctx.exception.args[0],
|
||||
"""The requested operation can not be completed due to security restrictions.
|
||||
|
||||
Document type: Object For Test Access Right (test_access_right.some_obj)
|
||||
Operation: read
|
||||
User: %s
|
||||
Fields:
|
||||
- forbidden3 (always forbidden)""" % self.user.id
|
||||
)
|
||||
|
||||
def test_write(self):
|
||||
self.env.ref('base.group_no_one').write(
|
||||
{'users': [(4, self.user.id)]})
|
||||
|
||||
@@ -29,6 +29,9 @@ from odoo.exceptions import CacheMiss
|
||||
DATE_LENGTH = len(date.today().strftime(DATE_FORMAT))
|
||||
DATETIME_LENGTH = len(datetime.now().strftime(DATETIME_FORMAT))
|
||||
|
||||
# hacky-ish way to prevent access to a field through the ORM (except for sudo mode)
|
||||
NO_ACCESS='.'
|
||||
|
||||
IR_MODELS = (
|
||||
'ir.model', 'ir.model.data', 'ir.model.fields', 'ir.model.fields.selection',
|
||||
'ir.model.relation', 'ir.model.constraint', 'ir.module.module',
|
||||
|
||||
@@ -2888,6 +2888,9 @@ class BaseModel(MetaModel('DummyModel', (object,), {'_register': False})):
|
||||
})
|
||||
|
||||
def format_groups(field):
|
||||
if field.groups == '.':
|
||||
return _("always forbidden")
|
||||
|
||||
anyof = self.env['res.groups']
|
||||
noneof = self.env['res.groups']
|
||||
for g in field.groups.split(','):
|
||||
|
||||
Reference in New Issue
Block a user