From cffce8a42564eefefe14564cf2021d88236cfb95 Mon Sep 17 00:00:00 2001 From: Cedric Snauwaert Date: Mon, 22 Apr 2013 11:37:58 +0200 Subject: [PATCH 1/2] [FIX]hr_timesheet: fix multi-company problem, when user from company b was trying to create an employee, it was having a read access error due to default value not being on same company bzr revid: csn@openerp.com-20130422093758-2vwa4faf1q485bxq --- addons/hr_timesheet/hr_timesheet.py | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/addons/hr_timesheet/hr_timesheet.py b/addons/hr_timesheet/hr_timesheet.py index 6a538e5d09c..68c158e04e1 100644 --- a/addons/hr_timesheet/hr_timesheet.py +++ b/addons/hr_timesheet/hr_timesheet.py @@ -38,7 +38,13 @@ class hr_employee(osv.osv): md = self.pool.get('ir.model.data') try: result = md.get_object_reference(cr, uid, 'hr_timesheet', 'analytic_journal') - return result[1] + #search on id found in result to check if current user has read access right, if he does, it will return same id, + #otherwise it will return empty list + check_right = self.pool.get('account.analytic.journal').search(cr, uid, [('name', '=', result[1])], context=context) + if check_right: + return result[1] + else: + return False except ValueError: pass return False @@ -47,7 +53,13 @@ class hr_employee(osv.osv): md = self.pool.get('ir.model.data') try: result = md.get_object_reference(cr, uid, 'product', 'product_product_consultant') - return result[1] + #search on id found in result to check if current user has read access right, if he does, it will return same id, + #otherwise it will return empty list + check_right = self.pool.get('product.template').search(cr, uid, [('id', '=', result[1])], context=context) + if check_right: + return result[1] + else: + return False except ValueError: pass return False From b2e2d854f87f7fa73d698093d113a650ff58698f Mon Sep 17 00:00:00 2001 From: Cedric Snauwaert Date: Mon, 22 Apr 2013 13:46:57 +0200 Subject: [PATCH 2/2] [FIX]hr_timesheet: correct mistake in default, should be 'id' instead of 'name' in search bzr revid: csn@openerp.com-20130422114657-ktu1a7z83c0bhv2n --- addons/hr_timesheet/hr_timesheet.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/hr_timesheet/hr_timesheet.py b/addons/hr_timesheet/hr_timesheet.py index 68c158e04e1..bb311778b33 100644 --- a/addons/hr_timesheet/hr_timesheet.py +++ b/addons/hr_timesheet/hr_timesheet.py @@ -40,7 +40,7 @@ class hr_employee(osv.osv): result = md.get_object_reference(cr, uid, 'hr_timesheet', 'analytic_journal') #search on id found in result to check if current user has read access right, if he does, it will return same id, #otherwise it will return empty list - check_right = self.pool.get('account.analytic.journal').search(cr, uid, [('name', '=', result[1])], context=context) + check_right = self.pool.get('account.analytic.journal').search(cr, uid, [('id', '=', result[1])], context=context) if check_right: return result[1] else: