From dd998b5717c9f162f9d03904fbcfe6e5f37a6b1a Mon Sep 17 00:00:00 2001 From: Dossogne Bertrand Date: Wed, 28 Feb 2024 13:39:05 +0000 Subject: [PATCH] [FIX] hr: override get_views for dashboard employee filters Purpose of this commit: Currently, people having access to different dashboards without any access rights would end up with a traceback when trying to search more employees. Steps to reproduce this issue: - have a user with timesheet officer rights and no hr rights - log in with that user account - go on the dashboard app and select "Timesheets" - go on employee filter and click on "search more" Current behaviour: A traceback is displayed because the user has no access to the view Expected behaviour: The public employee search view should be displayed How the issue was fixed: The method called `_get_views` has been overriden in the `hr.employee` model to return the `hr.employee.public` views instead. As there was no way through the dashboard to define a relation, the method explicitely takes the result for the public employee and sets it as result of the private one as well. closes odoo/odoo#158380 X-original-commit: 6e304037023545eb7eb453d5656f7e1769615d38 Signed-off-by: Sofie Gvaladze (sgv) Signed-off-by: Xavier Bol (xbo) Signed-off-by: Bertrand Dossogne (bedo) --- addons/hr/models/hr_employee.py | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/addons/hr/models/hr_employee.py b/addons/hr/models/hr_employee.py index a001fdab00a..2f531f75ebf 100644 --- a/addons/hr/models/hr_employee.py +++ b/addons/hr/models/hr_employee.py @@ -284,6 +284,14 @@ class HrEmployeePrivate(models.Model): return super().get_view(view_id, view_type, **options) return self.env['hr.employee.public'].get_view(view_id, view_type, **options) + @api.model + def get_views(self, views, options=None): + if self.check_access_rights('read', raise_exception=False): + return super().get_views(views, options) + res = self.env['hr.employee.public'].get_views(views, options) + res['models'].update({'hr.employee': res['models']['hr.employee.public']}) + return res + @api.model def _search(self, domain, offset=0, limit=None, order=None, access_rights_uid=None): """