[FIX] bus: authenticate on the correct env

`_authenticate` is updating the `env`, but it updated the `env` of
`ir_websocket` instead of `self`. There was then a mismatch between
the `update_context` and the current user.

This was highlighted in another PR that removed sudo from these methods
with the hope on relying on ACL, which depends on current user and other
context values at the same time.

closes odoo/odoo#139436

Signed-off-by: Matthieu Stockbauer (tsm) <tsm@odoo.com>
This commit is contained in:
Sébastien Theys
2023-10-23 13:11:27 +00:00
parent fc573a8d8b
commit d15e88abef
+3 -4
View File
@@ -782,14 +782,13 @@ class WebsocketRequest:
appropriate ir.websocket method since only two events are
tolerated: `subscribe` and `update_presence`.
"""
ir_websocket = self.env['ir.websocket']
ir_websocket._authenticate()
self.env['ir.websocket']._authenticate()
if context:
self.update_context(**context)
if event_name == 'subscribe':
ir_websocket._subscribe(data)
self.env['ir.websocket']._subscribe(data)
if event_name == 'update_presence':
ir_websocket._update_bus_presence(**data)
self.env['ir.websocket']._update_bus_presence(**data)
def _get_session(self):
session = root.session_store.get(self.ws._session.sid)