diff --git a/addons/mail/models/mail_message.py b/addons/mail/models/mail_message.py index ddf2198ed72..7b26de57423 100644 --- a/addons/mail/models/mail_message.py +++ b/addons/mail/models/mail_message.py @@ -954,7 +954,8 @@ class Message(models.Model): # we replace every space by a % to avoid hard spacing matching search_term = search_term.replace(" ", "%") domain = expression.AND([domain, expression.OR([ - [("attachment_ids.name", "ilike", search_term)], + # sudo: access to attachment is allowed if you have access to the parent model + [("attachment_ids", "in", self.env["ir.attachment"].sudo()._search([("name", "ilike", search_term)]))], [("body", "ilike", search_term)], [("subject", "ilike", search_term)], [("subtype_id.description", "ilike", search_term)], diff --git a/addons/mail/static/tests/tours/discuss_channel_public_tour.js b/addons/mail/static/tests/tours/discuss_channel_public_tour.js index 91697d43c27..bff9c9ef392 100644 --- a/addons/mail/static/tests/tours/discuss_channel_public_tour.js +++ b/addons/mail/static/tests/tours/discuss_channel_public_tour.js @@ -130,5 +130,24 @@ registry.category("web_tour.tours").add("discuss_channel_public_tour.js", { await contains(".o-mail-AttachmentCard", { text: "extra.txt", count: 0 }); }, }, + { + content: "Open search panel", + trigger: "button[title='Search Messages']", + }, + { + content: "Search for the attachment name", + trigger: ".o_searchview_input", + run: "text text.txt", + }, + { + content: "Trigger the search", + trigger: "button[aria-label='Search button']", + }, + { + content: "Check that searched message contains the attachment", + trigger: + '.o-mail-SearchMessagesPanel .o-mail-Message .o-mail-AttachmentCard:contains("text.txt")', + run() {}, + }, ], });