[FIX] account: restrict invoice sending to customer and added recipients

Summary
-------
Currently, when you send an invoice, every recipient receives the link
including the access token. Only the invoice's customer and manually
added recipients should receive the token.

Steps to reproduce
------------------
* Create and validate an invoice
* Add a follower `F `to the invoice
* Click on the Send & Print button, then add a recipient `R` who is not
  the customer associated with the invoice
* Proceed to send the invoice.
* Access the emails that were sent
* Using an incognito or private browsing window, open the `View Invoice`
  link for each of the 3 recipients.

You should see that all the links give access to the invoice.
What should happen is that only partner `R` and the invoice's customer
should haveaccess to the invoice.
`F` should be asked to login.

Cause
-----
Issue was introduced by 95c585f

Fix
---
Add a new notification group for partners that were manually added as
recipients, and give that group access to the invoice.

opw-3385302

closes odoo/odoo#146575

X-original-commit: 755814ea170adbade23692767fcb17b5422863e7
Signed-off-by: Brice Bartoletti (bib) <bib@odoo.com>
Signed-off-by: Séna Serge Nshimiyimana (sesn) <sesn@odoo.com>
This commit is contained in:
sesn-odoo
2023-12-18 14:34:21 +00:00
parent 7e58f703f4
commit ff51570aed
2 changed files with 32 additions and 14 deletions
+19 -14
View File
@@ -4067,21 +4067,26 @@ class AccountMove(models.Model):
)
def _notify_get_recipients_groups(self, message, model_description, msg_vals=None):
groups = super()._notify_get_recipients_groups(
message, model_description, msg_vals=msg_vals)
local_msg_vals = dict(msg_vals or {})
groups = super()._notify_get_recipients_groups(message, model_description, msg_vals=msg_vals)
self.ensure_one()
if self.move_type != 'entry':
# This allows partners added to the email list in the sending wizard to access this document.
for group_name, _group_method, group_data in groups:
if group_name == 'customer' and self._portal_ensure_token():
access_link = self._notify_get_action_link(
'view', **local_msg_vals, access_token=self.access_token)
group_data.update({
'has_button_access': True,
'button_access': {
'url': access_link,
},
})
local_msg_vals = dict(msg_vals or {})
self._portal_ensure_token()
access_link = self._notify_get_action_link('view', **local_msg_vals, access_token=self.access_token)
# Create a new group for partners that have been manually added as recipients.
# Those partners should have access to the invoice.
button_access = {'url': access_link} if access_link else {}
recipient_group = (
'additional_intended_recipient',
lambda pdata: pdata['id'] in local_msg_vals.get('partner_ids', []) and pdata['id'] != self.partner_id.id,
{
'has_button_access': True,
'button_access': button_access,
}
)
groups.insert(0, recipient_group)
return groups
@@ -404,6 +404,10 @@ class TestAccountComposerPerformance(AccountTestInvoicingCommon, MailCommon):
test_move = self.test_account_moves[1].with_env(self.env)
move_template = self.move_template.with_env(self.env)
# add a follower to the invoice
self.partner_b.email = 'partner_b@example.com'
test_move.message_subscribe(self.partner_b.ids)
additional_partner = self.env['res.partner'].create({
'name': "Additional Partner",
'email': "additional@example.com",
@@ -429,6 +433,15 @@ class TestAccountComposerPerformance(AccountTestInvoicingCommon, MailCommon):
content='access_token='
)
follower_mail = self.assertMailMail(
self.partner_b,
'sent',
author=self.user_account_other.partner_id,
)
self.assertNotIn('access_token=', follower_mail.body_html,
"The followers should not bet sent the access token by default")
@tagged('post_install_l10n', 'post_install', '-at_install')
class TestAccountMoveSendCommon(AccountTestInvoicingCommon):