[FIX] website_profile: fix edit profile issue
PURPOSE Before this commit when an administrator edit another user's profile it was his own data that displayed for the changes. This commit fixes this issue. SPECIFICATION Add a test in both controller route when displaying the edit view and when submitting the changes that check if the edited user is the same as the actual user. LINKS Task ID : 2222043 PR : #48262 closes odoo/odoo#48575 X-original-commit: 4ab4de5b57a17002d8b14584c7d39a29e8bca357 Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
This commit is contained in:
committed by
Thibault Delavallée
parent
a8b803c26b
commit
e711dc08d4
@@ -120,8 +120,13 @@ class WebsiteProfile(http.Controller):
|
||||
# ---------------------------------------------------
|
||||
@http.route('/profile/edit', type='http', auth="user", website=True)
|
||||
def view_user_profile_edition(self, **kwargs):
|
||||
user_id = int(kwargs.get('user_id'))
|
||||
countries = request.env['res.country'].search([])
|
||||
values = self._prepare_user_values(searches=kwargs)
|
||||
if user_id and request.env.user.id != user_id and request.env.user._is_admin():
|
||||
user = request.env['res.users'].browse(user_id)
|
||||
values = self._prepare_user_values(searches=kwargs, user=user, is_public_user=False)
|
||||
else:
|
||||
values = self._prepare_user_values(searches=kwargs)
|
||||
values.update({
|
||||
'email_required': kwargs.get('email_required'),
|
||||
'countries': countries,
|
||||
@@ -151,7 +156,11 @@ class WebsiteProfile(http.Controller):
|
||||
|
||||
@http.route('/profile/user/save', type='http', auth="user", methods=['POST'], website=True)
|
||||
def save_edited_profile(self, **kwargs):
|
||||
user = request.env.user
|
||||
user_id = int(kwargs.get('user_id'))
|
||||
if user_id and request.env.user.id != user_id and request.env.user._is_admin():
|
||||
user = request.env['res.users'].browse(user_id)
|
||||
else:
|
||||
user = request.env.user
|
||||
values = self._profile_edition_preprocess_values(user, **kwargs)
|
||||
whitelisted_values = {key: values[key] for key in type(user).SELF_WRITEABLE_FIELDS if key in values}
|
||||
user.write(whitelisted_values)
|
||||
|
||||
@@ -204,7 +204,9 @@
|
||||
<div class="col-12 col-md-4 col-lg-3">
|
||||
<div t-attf-class="d-flex align-items-start h-100 #{'justify-content-between' if (request.env.user == user) else 'justify-content-around' }">
|
||||
<div class="o_wprofile_pict d-inline-block mb-3 mb-md-0" t-attf-style="background-image: url(#{website.image_url(user, 'image_1024')});"/>
|
||||
<a class="btn btn-primary d-inline-block d-md-none" t-if="request.env.user == user and user.karma != 0" t-attf-href="/profile/edit?url_param=#{edit_button_url_param}">
|
||||
<a class="btn btn-primary d-inline-block d-md-none"
|
||||
t-if="request.env.user == user and user.karma != 0"
|
||||
t-attf-href="/profile/edit?url_param=#{edit_button_url_param}&user_id=#{user.id}">
|
||||
<i class="fa fa-pencil mr-1"/>EDIT
|
||||
</a>
|
||||
</div>
|
||||
@@ -216,7 +218,7 @@
|
||||
<h1 class="o_card_people_name">
|
||||
<span t-field="user.name"/><small t-if="user.karma == 0"> (not verified)</small>
|
||||
</h1>
|
||||
<a class="btn btn-primary d-none d-md-inline-block" t-if="request.env.user == user and user.karma != 0 or request.env.user._is_admin()" t-attf-href="/profile/edit?url_param=#{edit_button_url_param}">
|
||||
<a class="btn btn-primary d-none d-md-inline-block" t-if="request.env.user == user and user.karma != 0 or request.env.user._is_admin()" t-attf-href="/profile/edit?url_param=#{edit_button_url_param}&user_id=#{user.id}">
|
||||
<i class="fa fa-pencil mr-2"/>EDIT PROFILE
|
||||
</a>
|
||||
</div>
|
||||
|
||||
Reference in New Issue
Block a user