[FIX] website_profile: fix edit profile issue

PURPOSE

Before this commit when an administrator edit another user's profile it
was his own data that displayed for the changes.
This commit fixes this issue.

SPECIFICATION

Add a test in both controller route when displaying the edit view and
when submitting the changes that check if the edited user is the same
as the actual user.

LINKS

Task ID : 2222043
PR : #48262

closes odoo/odoo#48575

X-original-commit: 4ab4de5b57a17002d8b14584c7d39a29e8bca357
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
This commit is contained in:
Patrick Hoste
2020-03-30 09:24:14 +00:00
committed by Thibault Delavallée
parent a8b803c26b
commit e711dc08d4
2 changed files with 15 additions and 4 deletions
+11 -2
View File
@@ -120,8 +120,13 @@ class WebsiteProfile(http.Controller):
# ---------------------------------------------------
@http.route('/profile/edit', type='http', auth="user", website=True)
def view_user_profile_edition(self, **kwargs):
user_id = int(kwargs.get('user_id'))
countries = request.env['res.country'].search([])
values = self._prepare_user_values(searches=kwargs)
if user_id and request.env.user.id != user_id and request.env.user._is_admin():
user = request.env['res.users'].browse(user_id)
values = self._prepare_user_values(searches=kwargs, user=user, is_public_user=False)
else:
values = self._prepare_user_values(searches=kwargs)
values.update({
'email_required': kwargs.get('email_required'),
'countries': countries,
@@ -151,7 +156,11 @@ class WebsiteProfile(http.Controller):
@http.route('/profile/user/save', type='http', auth="user", methods=['POST'], website=True)
def save_edited_profile(self, **kwargs):
user = request.env.user
user_id = int(kwargs.get('user_id'))
if user_id and request.env.user.id != user_id and request.env.user._is_admin():
user = request.env['res.users'].browse(user_id)
else:
user = request.env.user
values = self._profile_edition_preprocess_values(user, **kwargs)
whitelisted_values = {key: values[key] for key in type(user).SELF_WRITEABLE_FIELDS if key in values}
user.write(whitelisted_values)
@@ -204,7 +204,9 @@
<div class="col-12 col-md-4 col-lg-3">
<div t-attf-class="d-flex align-items-start h-100 #{'justify-content-between' if (request.env.user == user) else 'justify-content-around' }">
<div class="o_wprofile_pict d-inline-block mb-3 mb-md-0" t-attf-style="background-image: url(#{website.image_url(user, 'image_1024')});"/>
<a class="btn btn-primary d-inline-block d-md-none" t-if="request.env.user == user and user.karma != 0" t-attf-href="/profile/edit?url_param=#{edit_button_url_param}">
<a class="btn btn-primary d-inline-block d-md-none"
t-if="request.env.user == user and user.karma != 0"
t-attf-href="/profile/edit?url_param=#{edit_button_url_param}&amp;user_id=#{user.id}">
<i class="fa fa-pencil mr-1"/>EDIT
</a>
</div>
@@ -216,7 +218,7 @@
<h1 class="o_card_people_name">
<span t-field="user.name"/><small t-if="user.karma == 0"> (not verified)</small>
</h1>
<a class="btn btn-primary d-none d-md-inline-block" t-if="request.env.user == user and user.karma != 0 or request.env.user._is_admin()" t-attf-href="/profile/edit?url_param=#{edit_button_url_param}">
<a class="btn btn-primary d-none d-md-inline-block" t-if="request.env.user == user and user.karma != 0 or request.env.user._is_admin()" t-attf-href="/profile/edit?url_param=#{edit_button_url_param}&amp;user_id=#{user.id}">
<i class="fa fa-pencil mr-2"/>EDIT PROFILE
</a>
</div>