From d15e88abefcd6eb2afe29fb7d5b8cbe9ce511164 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A9bastien=20Theys?= Date: Mon, 23 Oct 2023 11:37:58 +0200 Subject: [PATCH] [FIX] bus: authenticate on the correct env `_authenticate` is updating the `env`, but it updated the `env` of `ir_websocket` instead of `self`. There was then a mismatch between the `update_context` and the current user. This was highlighted in another PR that removed sudo from these methods with the hope on relying on ACL, which depends on current user and other context values at the same time. closes odoo/odoo#139436 Signed-off-by: Matthieu Stockbauer (tsm) --- addons/bus/websocket.py | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/addons/bus/websocket.py b/addons/bus/websocket.py index 8b18041ff13..3d4bd77b46c 100644 --- a/addons/bus/websocket.py +++ b/addons/bus/websocket.py @@ -782,14 +782,13 @@ class WebsocketRequest: appropriate ir.websocket method since only two events are tolerated: `subscribe` and `update_presence`. """ - ir_websocket = self.env['ir.websocket'] - ir_websocket._authenticate() + self.env['ir.websocket']._authenticate() if context: self.update_context(**context) if event_name == 'subscribe': - ir_websocket._subscribe(data) + self.env['ir.websocket']._subscribe(data) if event_name == 'update_presence': - ir_websocket._update_bus_presence(**data) + self.env['ir.websocket']._update_bus_presence(**data) def _get_session(self): session = root.session_store.get(self.ws._session.sid)