From d90ed9d359fe2c63266c15e587bf3bbb48b26880 Mon Sep 17 00:00:00 2001 From: std-odoo Date: Wed, 6 Mar 2024 08:04:55 +0000 Subject: [PATCH] [FIX] website_slides: user can not access his own attachment in the PortalComposer MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Bug === 1. login as demo user 2. add a review on a course and upload an attachment 3. click on the attachment link => You get a 404 error For some reason, we do not return the access token if the user is internal. The generation is not a heavy process, and might be needed depending on the . Task-3693072 closes odoo/odoo#159126 X-original-commit: 74b0f88c6b15feb8d3453edf20acda81b37df66c Signed-off-by: Thibault Delavallee (tde) Signed-off-by: Stéphane Debauche (std) --- addons/portal/controllers/portal.py | 8 +++----- addons/website_slides/tests/test_ui_wslides.py | 17 ++++++++++++++++- 2 files changed, 19 insertions(+), 6 deletions(-) diff --git a/addons/portal/controllers/portal.py b/addons/portal/controllers/portal.py index b85cb534360..c30f262109a 100644 --- a/addons/portal/controllers/portal.py +++ b/addons/portal/controllers/portal.py @@ -330,13 +330,11 @@ class CustomerPortal(Controller): raise UserError(_("The document does not exist or you do not have the rights to access it.")) IrAttachment = request.env['ir.attachment'] - access_token = False - # Avoid using sudo or creating access_token when not necessary: internal - # users can create attachments, as opposed to public and portal users. + # Avoid using sudo when not necessary: internal users can create attachments, + # as opposed to public and portal users. if not request.env.user._is_internal(): IrAttachment = IrAttachment.sudo() - access_token = IrAttachment._generate_access_token() # At this point the related message does not exist yet, so we assign # those specific res_model and res_is. They will be correctly set @@ -347,7 +345,7 @@ class CustomerPortal(Controller): 'datas': base64.b64encode(file.read()), 'res_model': 'mail.compose.message', 'res_id': 0, - 'access_token': access_token, + 'access_token': IrAttachment._generate_access_token(), }) return request.make_response( data=json.dumps(attachment.read(['id', 'name', 'mimetype', 'file_size', 'access_token'])[0]), diff --git a/addons/website_slides/tests/test_ui_wslides.py b/addons/website_slides/tests/test_ui_wslides.py index fbd2c79a3b8..5a0b64beceb 100644 --- a/addons/website_slides/tests/test_ui_wslides.py +++ b/addons/website_slides/tests/test_ui_wslides.py @@ -4,7 +4,7 @@ import base64 from dateutil.relativedelta import relativedelta -from odoo import tests +from odoo import http, tests from odoo.addons.base.tests.common import HttpCaseWithUserPortal from odoo.addons.gamification.tests.common import HttpCaseGamification from odoo.fields import Command, Datetime @@ -269,3 +269,18 @@ class TestUiPublisherYoutube(HttpCaseGamification): }) self.start_tour(self.env['website'].get_client_action_url('/slides'), 'course_publisher', login=user_demo.login) + + +@tests.common.tagged('external', 'post_install', '-standard', '-at_install') +class TestPortalComposer(TestUICommon): + def test_portal_composer_attachment(self): + """Check that the access token is returned when we upload an attachment.""" + self.authenticate('demo', 'demo') + response = self.url_open('/portal/attachment/add', data={ + 'name': 'image.png', + 'res_id': self.channel.id, + 'res_model': 'slide.channel', + 'csrf_token': http.WebRequest.csrf_token(self), + }, files={'file': ('image.png', '', 'image/png')}) + self.assertTrue(response.ok) + self.assertTrue(response.json().get('access_token'))