[FIX] website_slides: user can not access his own attachment in the PortalComposer

Bug
===
1. login as demo user
2. add a review on a course and upload an attachment
3. click on the attachment link
=> You get a 404 error

For some reason, we do not return the access token if the user is
internal. The generation is not a heavy process, and might be needed
depending on the <ir.rule>.

Task-3693072

closes odoo/odoo#159126

X-original-commit: 74b0f88c6b15feb8d3453edf20acda81b37df66c
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
Signed-off-by: Stéphane Debauche (std) <std@odoo.com>
This commit is contained in:
std-odoo
2024-03-26 08:20:23 +00:00
parent 48e4737534
commit d90ed9d359
2 changed files with 19 additions and 6 deletions
+3 -5
View File
@@ -330,13 +330,11 @@ class CustomerPortal(Controller):
raise UserError(_("The document does not exist or you do not have the rights to access it."))
IrAttachment = request.env['ir.attachment']
access_token = False
# Avoid using sudo or creating access_token when not necessary: internal
# users can create attachments, as opposed to public and portal users.
# Avoid using sudo when not necessary: internal users can create attachments,
# as opposed to public and portal users.
if not request.env.user._is_internal():
IrAttachment = IrAttachment.sudo()
access_token = IrAttachment._generate_access_token()
# At this point the related message does not exist yet, so we assign
# those specific res_model and res_is. They will be correctly set
@@ -347,7 +345,7 @@ class CustomerPortal(Controller):
'datas': base64.b64encode(file.read()),
'res_model': 'mail.compose.message',
'res_id': 0,
'access_token': access_token,
'access_token': IrAttachment._generate_access_token(),
})
return request.make_response(
data=json.dumps(attachment.read(['id', 'name', 'mimetype', 'file_size', 'access_token'])[0]),
+16 -1
View File
@@ -4,7 +4,7 @@ import base64
from dateutil.relativedelta import relativedelta
from odoo import tests
from odoo import http, tests
from odoo.addons.base.tests.common import HttpCaseWithUserPortal
from odoo.addons.gamification.tests.common import HttpCaseGamification
from odoo.fields import Command, Datetime
@@ -269,3 +269,18 @@ class TestUiPublisherYoutube(HttpCaseGamification):
})
self.start_tour(self.env['website'].get_client_action_url('/slides'), 'course_publisher', login=user_demo.login)
@tests.common.tagged('external', 'post_install', '-standard', '-at_install')
class TestPortalComposer(TestUICommon):
def test_portal_composer_attachment(self):
"""Check that the access token is returned when we upload an attachment."""
self.authenticate('demo', 'demo')
response = self.url_open('/portal/attachment/add', data={
'name': 'image.png',
'res_id': self.channel.id,
'res_model': 'slide.channel',
'csrf_token': http.WebRequest.csrf_token(self),
}, files={'file': ('image.png', '', 'image/png')})
self.assertTrue(response.ok)
self.assertTrue(response.json().get('access_token'))