From f25df506af39bcd19fbe107367560ef45c887756 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?R=C3=A9my=20Voet=20=28ryv=29?= Date: Mon, 24 Apr 2023 08:49:27 +0000 Subject: [PATCH] [FIX] calendar: groupby on `calendar.event` triggers 'danger' notification The `read_group` of `calendar.event` sends a danger notification when the user groups by any field in the list view. It is because the security reenforcement done in 2c0b3ab670168a155b3974d5a5b39aa1f1df3452 is too strict. It checks all `fields`, even the ones that are filtered out by the `read_group` (`fields` without aggregation specification nor `group_operator`). closes odoo/odoo#119459 Signed-off-by: Raphael Collet --- addons/calendar/models/calendar_event.py | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/addons/calendar/models/calendar_event.py b/addons/calendar/models/calendar_event.py index 6311101d084..711ccf5d5c1 100644 --- a/addons/calendar/models/calendar_event.py +++ b/addons/calendar/models/calendar_event.py @@ -656,7 +656,11 @@ class Meeting(models.Model): @api.model def read_group(self, domain, fields, groupby, offset=0, limit=None, orderby=False, lazy=True): groupby = [groupby] if isinstance(groupby, str) else groupby - grouped_fields = {group_field.split(':')[0] for group_field in groupby + (fields or list(self._fields))} + fields_aggregates = [ + field_name for field_name in (fields or list(self._fields)) + if ':' in field_name or (field_name in self and self._fields[field_name].group_operator) + ] + grouped_fields = {group_field.split(':')[0] for group_field in groupby + fields_aggregates} private_fields = grouped_fields - self._get_public_fields() if not self.env.su and private_fields: # display public and confidential events