From d0053c7b45767e294e5746d1c5c601704075dee2 Mon Sep 17 00:00:00 2001 From: Nicolas Martinelli Date: Wed, 7 Oct 2020 16:22:58 +0000 Subject: [PATCH] [FIX] stock: routes in multi-company - Create companies A & B - Create a Dropship route for B - Create a product P with route 'Dropship' - Set the website under company A - As a portal user, buy the product P on the website - Do the payment The SO is confirmed but the Dropship route for B is used despite the fact that the website is under company A. This happens because `_search_rule` is called as superuser: therefore, routes from all companies are retrieved. To prevent this, we add the company in the domain. opw-2349094 closes odoo/odoo#60482 X-original-commit: 31a54b5e859ead7972cdccc956518e14038476ba Signed-off-by: Nicolas Martinelli (nim) --- addons/stock/models/stock_rule.py | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/addons/stock/models/stock_rule.py b/addons/stock/models/stock_rule.py index 8202d3e3a0a..00650716e7d 100644 --- a/addons/stock/models/stock_rule.py +++ b/addons/stock/models/stock_rule.py @@ -391,7 +391,7 @@ class ProcurementGroup(models.Model): actions_to_run = defaultdict(list) procurement_errors = [] for procurement in procurements: - procurement.values.setdefault('company_id', self.env.company) + procurement.values.setdefault('company_id', procurement.location_id.company_id) procurement.values.setdefault('priority', '0') procurement.values.setdefault('date_planned', fields.Datetime.now()) if ( @@ -461,7 +461,14 @@ class ProcurementGroup(models.Model): @api.model def _get_rule_domain(self, location, values): - return [('location_id', '=', location.id), ('action', '!=', 'push')] + domain = ['&', ('location_id', '=', location.id), ('action', '!=', 'push')] + # In case the method is called by the superuser, we need to restrict the rules to the + # ones of the company. This is not useful as a regular user since there is a record + # rule to filter out the rules based on the company. + if self.env.su and values.get('company_id'): + domain_company = ['|', ('company_id', '=', False), ('company_id', 'child_of', values['company_id'].ids)] + domain = expression.AND([domain, domain_company]) + return domain def _merge_domain(self, values, rule, group_id): return [