From e3a7aa5bd01a56db814f07ebd2d8af4a959356a9 Mon Sep 17 00:00:00 2001 From: Martin Trigaux Date: Mon, 22 Nov 2021 12:46:58 +0000 Subject: [PATCH] [IMP] test_mail: add test for ce342f42f21cad3 Without ce342f42f21cad3 the new test fails because copying an attachment requires write access to mail.template closes odoo/odoo#85271 X-original-commit: d5ceaa13a36e86e97f14e870ade477f62234b304 Signed-off-by: Raphael Collet Signed-off-by: Martin Trigaux (mat) --- addons/test_mail/tests/test_mail_composer.py | 48 ++++++++++++++++++++ 1 file changed, 48 insertions(+) diff --git a/addons/test_mail/tests/test_mail_composer.py b/addons/test_mail/tests/test_mail_composer.py index ffcc01eeeca..01c6587ae17 100644 --- a/addons/test_mail/tests/test_mail_composer.py +++ b/addons/test_mail/tests/test_mail_composer.py @@ -6,6 +6,7 @@ from unittest.mock import patch from odoo.addons.mail.tests.common import mail_new_test_user from odoo.addons.test_mail.models.test_mail_models import MailTestTicket from odoo.addons.test_mail.tests.common import TestMailCommon, TestRecipients +from odoo.exceptions import AccessError from odoo.tests import tagged from odoo.tests.common import users, Form from odoo.tools import mute_logger @@ -30,6 +31,17 @@ class TestMailComposer(TestMailCommon, TestRecipients): name='Eglantine Employee', signature='--\nEglantine') cls.partner_employee_2 = cls.user_employee_2.partner_id + # User without the group "mail.group_mail_template_editor" + cls.user_rendering_restricted = mail_new_test_user( + cls.env, login='user_rendering_restricted', + groups='base.group_user', + company_id=cls.company_admin.id, + name='Code Template Restricted User', + notification_type='inbox', + signature='--\nErnest' + ) + cls.env.ref('mail.group_mail_template_editor').users -= cls.user_rendering_restricted + cls.test_record = cls.env['mail.test.ticket'].with_context(cls._test_context).create({ 'name': 'TestRecord', 'customer_id': cls.partner_1.id, @@ -389,6 +401,42 @@ class TestComposerInternals(TestMailComposer): self.assertEqual(composer.body, '

Test Body

') self.assertEqual(composer.partner_ids, self.partner_1 + self.partner_2) + @users('user_rendering_restricted') + def test_mail_composer_rights_attachments(self): + """ Ensure a user without write access to a template can send an email""" + template_1 = self.template.copy({ + 'report_name': 'TestReport for {{ object.name }} (thanks TDE).html', # test cursor forces html + 'report_template': self.test_report.id, + }) + attachment_data = self._generate_attachments_data(2) + template_1.write({ + 'attachment_ids': [(0, 0, dict(a, res_model="mail.template", res_id=template_1.id)) for a in attachment_data] + }) + with self.assertRaises(AccessError): + # ensure user_rendering_restricted has no write access + template_1.with_user(self.env.user).write({'name': 'New Name'}) + + template_1_attachments = template_1.attachment_ids + self.assertEqual(len(template_1_attachments), 2) + template_1_attachment_name = list(template_1_attachments.mapped('name')) + ["TestReport for TestRecord (thanks TDE).html"] + + composer = self.env['mail.compose.message'].with_context( + self._get_web_context(self.test_record) + ).create({ + 'subject': 'Template Subject', + 'body': '

Template Body

', + 'template_id': template_1.id, + 'attachment_ids': template_1_attachments.ids, + 'partner_ids': [self.partner_employee_2.id], + }) + composer._onchange_template_id_wrapper() + composer._action_send_mail() + + self.assertEqual(self.test_record.message_ids[0].subject, 'TemplateSubject TestRecord') + self.assertEqual( + sorted(self.test_record.message_ids[0].attachment_ids.mapped('name')), + sorted(template_1_attachment_name)) + def test_mail_composer_rights_portal(self): portal_user = self._create_portal_user()