[FIX] fields: read/write company-dependent fields without ir.property access
This is the first step to a more comprehensive handling of company-dependent fields which are ir_properties. With model-specific access rights, users should be able to read/update a company-dependent field no matter their access rights on ir_property. Before this commit, a user having access to res.partner, but not to ir.property couldn't write on property_account_receivable/payable just because he couldn't write the corresponding ir.property. After this commit, he can. OPW 1923345
This commit is contained in:
committed by
Raphael Collet
parent
44b791f5d7
commit
cbdc8d864b
@@ -669,6 +669,10 @@ class TestFields(common.TransactionCase):
|
||||
self.env['ir.property'].create({'name': 'foo', 'fields_id': field_tag_id.id,
|
||||
'value': tag0, 'type': 'many2one'})
|
||||
|
||||
# assumption: users don't have access to 'ir.property'
|
||||
accesses = self.env['ir.model.access'].search([('model_id.model', '=', 'ir.property')])
|
||||
accesses.write(dict.fromkeys(['perm_read', 'perm_write', 'perm_create', 'perm_unlink'], False))
|
||||
|
||||
# create/modify a record, and check the value for each user
|
||||
record = self.env['test_new_api.company'].create({
|
||||
'foo': 'main',
|
||||
@@ -722,6 +726,13 @@ class TestFields(common.TransactionCase):
|
||||
self.assertEqual(record.sudo(user1).foo, False)
|
||||
self.assertEqual(record.sudo(user2).foo, 'default')
|
||||
|
||||
# set field with 'force_company' in context
|
||||
record.sudo(user0).with_context(force_company=company1.id).foo = 'beta'
|
||||
record.invalidate_cache()
|
||||
self.assertEqual(record.sudo(user0).foo, 'main')
|
||||
self.assertEqual(record.sudo(user1).foo, 'beta')
|
||||
self.assertEqual(record.sudo(user2).foo, 'default')
|
||||
|
||||
# create company record and attribute
|
||||
company_record = self.env['test_new_api.company'].create({'foo': 'ABC'})
|
||||
attribute_record = self.env['test_new_api.company.attr'].create({
|
||||
|
||||
+14
-2
@@ -636,13 +636,25 @@ class Field(MetaField('DummyField', (object,), {})):
|
||||
return model.env['ir.property'].get(self.name, self.model_name)
|
||||
|
||||
def _compute_company_dependent(self, records):
|
||||
Property = records.env['ir.property']
|
||||
# read property as superuser, as the current user may not have access
|
||||
context = records.env.context
|
||||
if 'force_company' not in context:
|
||||
field_id = records.env['ir.model.fields']._get_id(self.model_name, self.name)
|
||||
company = records.env['res.company']._company_default_get(self.model_name, field_id)
|
||||
context = dict(context, force_company=company.id)
|
||||
Property = records.env(user=SUPERUSER_ID, context=context)['ir.property']
|
||||
values = Property.get_multi(self.name, self.model_name, records.ids)
|
||||
for record in records:
|
||||
record[self.name] = values.get(record.id)
|
||||
|
||||
def _inverse_company_dependent(self, records):
|
||||
Property = records.env['ir.property']
|
||||
# update property as superuser, as the current user may not have access
|
||||
context = records.env.context
|
||||
if 'force_company' not in context:
|
||||
field_id = records.env['ir.model.fields']._get_id(self.model_name, self.name)
|
||||
company = records.env['res.company']._company_default_get(self.model_name, field_id)
|
||||
context = dict(context, force_company=company.id)
|
||||
Property = records.env(user=SUPERUSER_ID, context=context)['ir.property']
|
||||
values = {
|
||||
record.id: self.convert_to_write(record[self.name], record)
|
||||
for record in records
|
||||
|
||||
Reference in New Issue
Block a user