[FIX] calendar: groupby on calendar.event triggers 'danger' notification

The `read_group` of `calendar.event` sends a danger notification when
the user groups by any field in the list view. It is because the
security reenforcement done in 2c0b3ab670168a155b3974d5a5b39aa1f1df3452
is too strict. It checks all `fields`, even the ones that are filtered
out by the `read_group` (`fields` without aggregation specification
nor `group_operator`).

closes odoo/odoo#119459

Signed-off-by: Raphael Collet <rco@odoo.com>
This commit is contained in:
Rémy Voet (ryv)
2023-04-24 23:48:53 +02:00
parent 0c9e591965
commit f25df506af
+5 -1
View File
@@ -656,7 +656,11 @@ class Meeting(models.Model):
@api.model
def read_group(self, domain, fields, groupby, offset=0, limit=None, orderby=False, lazy=True):
groupby = [groupby] if isinstance(groupby, str) else groupby
grouped_fields = {group_field.split(':')[0] for group_field in groupby + (fields or list(self._fields))}
fields_aggregates = [
field_name for field_name in (fields or list(self._fields))
if ':' in field_name or (field_name in self and self._fields[field_name].group_operator)
]
grouped_fields = {group_field.split(':')[0] for group_field in groupby + fields_aggregates}
private_fields = grouped_fields - self._get_public_fields()
if not self.env.su and private_fields:
# display public and confidential events