[FIX] website_slides: user can not access his own attachment in the PortalComposer
Bug === 1. login as demo user 2. add a review on a course and upload an attachment 3. click on the attachment link => You get a 404 error For some reason, we do not return the access token if the user is internal. The generation is not a heavy process, and might be needed depending on the <ir.rule>. Task-3693072 closes odoo/odoo#159126 X-original-commit: 74b0f88c6b15feb8d3453edf20acda81b37df66c Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com> Signed-off-by: Stéphane Debauche (std) <std@odoo.com>
This commit is contained in:
@@ -330,13 +330,11 @@ class CustomerPortal(Controller):
|
||||
raise UserError(_("The document does not exist or you do not have the rights to access it."))
|
||||
|
||||
IrAttachment = request.env['ir.attachment']
|
||||
access_token = False
|
||||
|
||||
# Avoid using sudo or creating access_token when not necessary: internal
|
||||
# users can create attachments, as opposed to public and portal users.
|
||||
# Avoid using sudo when not necessary: internal users can create attachments,
|
||||
# as opposed to public and portal users.
|
||||
if not request.env.user._is_internal():
|
||||
IrAttachment = IrAttachment.sudo()
|
||||
access_token = IrAttachment._generate_access_token()
|
||||
|
||||
# At this point the related message does not exist yet, so we assign
|
||||
# those specific res_model and res_is. They will be correctly set
|
||||
@@ -347,7 +345,7 @@ class CustomerPortal(Controller):
|
||||
'datas': base64.b64encode(file.read()),
|
||||
'res_model': 'mail.compose.message',
|
||||
'res_id': 0,
|
||||
'access_token': access_token,
|
||||
'access_token': IrAttachment._generate_access_token(),
|
||||
})
|
||||
return request.make_response(
|
||||
data=json.dumps(attachment.read(['id', 'name', 'mimetype', 'file_size', 'access_token'])[0]),
|
||||
|
||||
@@ -4,7 +4,7 @@ import base64
|
||||
|
||||
from dateutil.relativedelta import relativedelta
|
||||
|
||||
from odoo import tests
|
||||
from odoo import http, tests
|
||||
from odoo.addons.base.tests.common import HttpCaseWithUserPortal
|
||||
from odoo.addons.gamification.tests.common import HttpCaseGamification
|
||||
from odoo.fields import Command, Datetime
|
||||
@@ -269,3 +269,18 @@ class TestUiPublisherYoutube(HttpCaseGamification):
|
||||
})
|
||||
|
||||
self.start_tour(self.env['website'].get_client_action_url('/slides'), 'course_publisher', login=user_demo.login)
|
||||
|
||||
|
||||
@tests.common.tagged('external', 'post_install', '-standard', '-at_install')
|
||||
class TestPortalComposer(TestUICommon):
|
||||
def test_portal_composer_attachment(self):
|
||||
"""Check that the access token is returned when we upload an attachment."""
|
||||
self.authenticate('demo', 'demo')
|
||||
response = self.url_open('/portal/attachment/add', data={
|
||||
'name': 'image.png',
|
||||
'res_id': self.channel.id,
|
||||
'res_model': 'slide.channel',
|
||||
'csrf_token': http.WebRequest.csrf_token(self),
|
||||
}, files={'file': ('image.png', '', 'image/png')})
|
||||
self.assertTrue(response.ok)
|
||||
self.assertTrue(response.json().get('access_token'))
|
||||
|
||||
Reference in New Issue
Block a user