[FIX] core: avoid access error in (parent/child)_of_domain

Purpose
=======

Loading a view trying to retrieve the hierarchy of a record using the field
parent_path could lead to an access error if records are mixed up.

Note:
Easily achievable for an end user. It could happen in a multi company
environment (you activate 2 companies at the same time) while configuring
the departments (using _parent_store=True), and you say that you have:

R&D (company=1):
     - R&D Belgium (company=1)
     - R&D India (company=2)
Then you go back to a single-company environment, you click on the form
view of an employee and crack, since there is a multi-company rule on the
departments, and that the search panel is loading the hierarchy for
display purpose.

Use sudo to avoid access rights issues, as the forbidden records will be
filtered automatically by the constructed domain like this:

```py
parent_ids = [
    int(label)
    for rec in left_model.sudo().browse(ids)
    for label in rec.parent_path.split('/')[:-1]
]
domain = [('id', 'in', parent_ids)]
```

This actually makes the search consistent with the case where
_parent_store=False.

closes odoo/odoo#85042

X-original-commit: a7e13b32e6c47a3fdcfad8a6c6337b89580ad70a
Signed-off-by: Raphael Collet <rco@odoo.com>
This commit is contained in:
Yannick Tivisse
2022-02-21 17:01:12 +00:00
committed by Raphael Collet
parent a1350dc414
commit daa9a1911e
+2 -2
View File
@@ -555,7 +555,7 @@ class expression(object):
if left_model._parent_store:
domain = OR([
[('parent_path', '=like', rec.parent_path + '%')]
for rec in left_model.browse(ids)
for rec in left_model.sudo().browse(ids)
])
else:
# recursively retrieve all children nodes with sudo(); the
@@ -581,7 +581,7 @@ class expression(object):
if left_model._parent_store:
parent_ids = [
int(label)
for rec in left_model.browse(ids)
for rec in left_model.sudo().browse(ids)
for label in rec.parent_path.split('/')[:-1]
]
domain = [('id', 'in', parent_ids)]