From daa9a1911e323cf046c2f16f13b5c9f15e32a262 Mon Sep 17 00:00:00 2001 From: Yannick Tivisse Date: Tue, 15 Feb 2022 09:51:04 +0000 Subject: [PATCH] [FIX] core: avoid access error in (parent/child)_of_domain Purpose ======= Loading a view trying to retrieve the hierarchy of a record using the field parent_path could lead to an access error if records are mixed up. Note: Easily achievable for an end user. It could happen in a multi company environment (you activate 2 companies at the same time) while configuring the departments (using _parent_store=True), and you say that you have: R&D (company=1): - R&D Belgium (company=1) - R&D India (company=2) Then you go back to a single-company environment, you click on the form view of an employee and crack, since there is a multi-company rule on the departments, and that the search panel is loading the hierarchy for display purpose. Use sudo to avoid access rights issues, as the forbidden records will be filtered automatically by the constructed domain like this: ```py parent_ids = [ int(label) for rec in left_model.sudo().browse(ids) for label in rec.parent_path.split('/')[:-1] ] domain = [('id', 'in', parent_ids)] ``` This actually makes the search consistent with the case where _parent_store=False. closes odoo/odoo#85042 X-original-commit: a7e13b32e6c47a3fdcfad8a6c6337b89580ad70a Signed-off-by: Raphael Collet --- odoo/osv/expression.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/odoo/osv/expression.py b/odoo/osv/expression.py index e96e550918b..5bf4c606a34 100644 --- a/odoo/osv/expression.py +++ b/odoo/osv/expression.py @@ -555,7 +555,7 @@ class expression(object): if left_model._parent_store: domain = OR([ [('parent_path', '=like', rec.parent_path + '%')] - for rec in left_model.browse(ids) + for rec in left_model.sudo().browse(ids) ]) else: # recursively retrieve all children nodes with sudo(); the @@ -581,7 +581,7 @@ class expression(object): if left_model._parent_store: parent_ids = [ int(label) - for rec in left_model.browse(ids) + for rec in left_model.sudo().browse(ids) for label in rec.parent_path.split('/')[:-1] ] domain = [('id', 'in', parent_ids)]