diff --git a/addons/mail/static/src/js/client_action.js b/addons/mail/static/src/js/client_action.js
index bd7638ab9e2..165dda719c2 100644
--- a/addons/mail/static/src/js/client_action.js
+++ b/addons/mail/static/src/js/client_action.js
@@ -249,6 +249,9 @@ var ChatAction = Widget.extend(ControlPanelMixin, {
var def3 = this.extended_composer.appendTo(this.$('.o_mail_chat_content'));
var def4 = this.searchview.appendTo($("
")).then(function () {
self.$searchview_buttons = self.searchview.$buttons.contents();
+ // manually call do_search to generate the initial domain and filter
+ // the messages in the default channel
+ self.searchview.do_search();
});
this.render_sidebar();
@@ -565,7 +568,12 @@ var ChatAction = Widget.extend(ControlPanelMixin, {
});
this.domain = result.domain;
- this.fetch_and_render_thread();
+ if (this.channel) {
+ // initially (when do_search is called manually), there is no
+ // channel set yet, so don't try to fetch and render the thread as
+ // this will be done as soon as the default channel is set
+ this.fetch_and_render_thread();
+ }
},
on_post_message: function (message) {
diff --git a/addons/website_forum/models/forum.py b/addons/website_forum/models/forum.py
index 478c211634a..59b22290fee 100644
--- a/addons/website_forum/models/forum.py
+++ b/addons/website_forum/models/forum.py
@@ -442,7 +442,7 @@ class Post(models.Model):
elif post.parent_id and not post.can_answer:
raise KarmaError('Not enough karma to answer to a question')
if not post.parent_id and not post.can_post:
- post.state = 'pending'
+ post.sudo().state = 'pending'
# add karma for posting new questions
if not post.parent_id and post.state == 'active':
@@ -471,11 +471,18 @@ class Post(models.Model):
@api.multi
def write(self, vals):
+ trusted_keys = ['active', 'is_correct', 'tag_ids'] # fields where security is checked manually
if 'content' in vals:
vals['content'] = self._update_content(vals['content'], self.forum_id.id)
if 'state' in vals:
- if vals['state'] in ['active', 'close'] and any(not post.can_close for post in self):
- raise KarmaError('Not enough karma to close or reopen a post.')
+ if vals['state'] in ['active', 'close']:
+ if any(not post.can_close for post in self):
+ raise KarmaError('Not enough karma to close or reopen a post.')
+ trusted_keys += ['state', 'closed_uid', 'closed_date', 'closed_reason_id']
+ elif vals['state'] == 'flagged':
+ if any(not post.can_flag for post in self):
+ raise KarmaError('Not enough karma to flag a post.')
+ trusted_keys += ['state', 'flag_user_id']
if 'active' in vals:
if any(not post.can_unlink for post in self):
raise KarmaError('Not enough karma to delete or reactivate a post')
@@ -492,7 +499,7 @@ class Post(models.Model):
tag_ids = set(tag.get('id') for tag in self.resolve_2many_commands('tag_ids', vals['tag_ids']))
if any(set(post.tag_ids) != tag_ids for post in self) and any(self.env.user.karma < post.forum_id.karma_edit_retag for post in self):
raise KarmaError(_('Not enough karma to retag.'))
- if any(key not in ['state', 'active', 'is_correct', 'closed_uid', 'closed_date', 'closed_reason_id', 'tag_ids'] for key in vals.keys()) and any(not post.can_edit for post in self):
+ if any(key not in trusted_keys for key in vals) and any(not post.can_edit for post in self):
raise KarmaError('Not enough karma to edit a post.')
res = super(Post, self).write(vals)
diff --git a/addons/website_forum/views/ir_qweb.xml b/addons/website_forum/views/ir_qweb.xml
index 671ae21944d..f823262d91b 100644
--- a/addons/website_forum/views/ir_qweb.xml
+++ b/addons/website_forum/views/ir_qweb.xml
@@ -5,9 +5,9 @@