From c1f3596bd32efcbec40e66c29930ccdc29072f92 Mon Sep 17 00:00:00 2001 From: svs-odoo Date: Wed, 25 Mar 2020 15:55:52 +0000 Subject: [PATCH] [FIX] mrp: create mrp.document through mrp.eco How to reproduce: - Open PLM app, open an Engineering Change Order; - Click on "Update Documents"; - Try to upload a document -> Traceback. As we did not cast res_id as integer, the check method of ir.attachment crashes when accessing company_id on a malformed recordset of ECO because the domain generated by _filter_access_rules_python is: `['|', ('company_id', '=', False), ('company_id', 'in', [2, 1])]` This route is also used when adding attachment to a `product.product`. In this case the check didn't work either but somehow passed because no domain is generated by `_filter_access_rules_python`. The following snippet shows that if there was one, it would also crash: ``` In [16]: records Out[16]: product.product('25',) In [17]: records.stock_move_ids Out[17]: stock.move() In [18]: self.env['product.product'].browse(25) Out[18]: product.product(25,) In [19]: self.env['product.product'].browse(25).stock_move_ids Out[19]: stock.move(41, 13) ``` task-2223153 closes odoo/odoo#48515 Signed-off-by: Simon Lejeune (sle) --- addons/mrp/controller/main.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/mrp/controller/main.py b/addons/mrp/controller/main.py index 0c8b40f0621..e916cc7ea96 100644 --- a/addons/mrp/controller/main.py +++ b/addons/mrp/controller/main.py @@ -25,7 +25,7 @@ class MrpDocumentRoute(http.Controller): request.env['mrp.document'].create({ 'name': ufile.filename, 'res_model': kwargs.get('res_model'), - 'res_id': kwargs.get('res_id'), + 'res_id': int(kwargs.get('res_id')), 'mimetype': mimetype, 'datas': base64.encodebytes(ufile.read()), })