[FIX] event_sale: prevent useless write on the product

`event_sale` adds an onchange on the `product_id` of the
sale order lines, which returns values for the fields
`event_type_id` & `event_ok`, which are used for an attrs
domain on the fields `event_id` & `event_ticket_id` in
the sale order line form (dialog). `event_type_id`
& `event_ok` are related to `product.product` fields,
in addition.

Changing the partner of the sale order triggers
the onchange on the lines, which triggers
the onchange of the `product_id`.

As these two fields `event_type_id` & `event_ok` were
not in the sale order lines tree view, as readonly,
they were passed to the write operation when
saving the SO, therefore writing on the product (the
same value than before, in addition).

Indeed, if an onchange returns values for fields
that are reandonly in the view, these are ignored
when saving/writing. However, if the onchange
returns values for fields that are not in the view,
these values are nevertheless passed to the write operation,
even if there was actually no change.

This behavior should probably change, that if an onchange
returns values for fields that are not in the view, these
are ignored, either when saving the record, either when
returning the result of the onchange.

Either way, these are risky changes, that we prefer to avoid
in a stable release such as 9.0. As a workaround,
we therefore add these fields in the sale order line tree view,
as readonly, so they are properly ignored when saving
the record.

This is important to avoid this write on `product.product`, as
users can have the write access to the `sale.order` without
having access to the `product.product`
(e.g. `Sales > See own leads` group)

opw-660716
This commit is contained in:
Denis Ledoux
2016-01-05 16:21:06 +01:00
parent 6c9a874635
commit c043025e5d
2 changed files with 7 additions and 3 deletions
+2 -2
View File
@@ -30,8 +30,8 @@ class sale_order_line(osv.osv):
help="Choose an event ticket and it will automatically create a registration for this event ticket."),
# those 2 fields are used for dynamic domains and filled by onchange
# TDE: really necessary ? ...
'event_type_id': fields.related('product_id', 'event_type_id', type='many2one', relation="event.type", string="Event Type"),
'event_ok': fields.related('product_id', 'event_ok', string='event_ok', type='boolean'),
'event_type_id': fields.related('product_id', 'event_type_id', type='many2one', relation="event.type", string="Event Type", readonly=True),
'event_ok': fields.related('product_id', 'event_ok', string='event_ok', type='boolean', readonly=True),
}
def _prepare_order_line_invoice_line(self, cr, uid, line, account_id=False, context=None):
+5 -1
View File
@@ -6,13 +6,17 @@
<field name="model">sale.order</field>
<field name="inherit_id" ref="sale.view_order_form" />
<field name="arch" type="xml">
<xpath expr="//field[@name='product_id']" position="after">
<xpath expr="//field[@name='order_line']//form//field[@name='product_id']" position="after">
<field name="event_id" domain="['|', ('event_type_id','=', False),('event_type_id', '=', event_type_id),('date_end','&gt;=',time.strftime('%Y-%m-%d 00:00:00'))]" attrs="{'invisible': [('event_ok', '=', False)],'required': [('event_ok', '!=', False)]}"/>
<field name="event_ticket_id" domain="[('event_id', '=', event_id), ('seats_available', '>', 0)]" attrs="{'invisible': [('event_id', '=', False)], 'required': [('event_id', '!=', False)]}"
on_change="onchange_event_ticket_id(event_ticket_id, context)"/>
<field name="event_type_id" invisible="1"/>
<field name="event_ok" invisible="1"/>
</xpath>
<xpath expr="//field[@name='order_line']//tree//field[@name='product_id']" position="after">
<field name="event_type_id" invisible="1"/>
<field name="event_ok" invisible="1"/>
</xpath>
</field>
</record>