[FIX] account: restrict invoice sending to customer and added recipients
Summary ------- Currently, when you send an invoice, every recipient receives the link including the access token. Only the invoice's customer and manually added recipients should receive the token. Steps to reproduce ------------------ * Create and validate an invoice * Add a follower `F `to the invoice * Click on the Send & Print button, then add a recipient `R` who is not the customer associated with the invoice * Proceed to send the invoice. * Access the emails that were sent * Using an incognito or private browsing window, open the `View Invoice` link for each of the 3 recipients. You should see that all the links give access to the invoice. What should happen is that only partner `R` and the invoice's customer should haveaccess to the invoice. `F` should be asked to login. Cause ----- Issue was introduced by 95c585f Fix --- Add a new notification group for partners that were manually added as recipients, and give that group access to the invoice. opw-3385302 closes odoo/odoo#146575 X-original-commit: 755814ea170adbade23692767fcb17b5422863e7 Signed-off-by: Brice Bartoletti (bib) <bib@odoo.com> Signed-off-by: Séna Serge Nshimiyimana (sesn) <sesn@odoo.com>
This commit is contained in:
@@ -4067,21 +4067,26 @@ class AccountMove(models.Model):
|
||||
)
|
||||
|
||||
def _notify_get_recipients_groups(self, message, model_description, msg_vals=None):
|
||||
groups = super()._notify_get_recipients_groups(
|
||||
message, model_description, msg_vals=msg_vals)
|
||||
local_msg_vals = dict(msg_vals or {})
|
||||
groups = super()._notify_get_recipients_groups(message, model_description, msg_vals=msg_vals)
|
||||
self.ensure_one()
|
||||
|
||||
if self.move_type != 'entry':
|
||||
# This allows partners added to the email list in the sending wizard to access this document.
|
||||
for group_name, _group_method, group_data in groups:
|
||||
if group_name == 'customer' and self._portal_ensure_token():
|
||||
access_link = self._notify_get_action_link(
|
||||
'view', **local_msg_vals, access_token=self.access_token)
|
||||
group_data.update({
|
||||
'has_button_access': True,
|
||||
'button_access': {
|
||||
'url': access_link,
|
||||
},
|
||||
})
|
||||
local_msg_vals = dict(msg_vals or {})
|
||||
self._portal_ensure_token()
|
||||
access_link = self._notify_get_action_link('view', **local_msg_vals, access_token=self.access_token)
|
||||
|
||||
# Create a new group for partners that have been manually added as recipients.
|
||||
# Those partners should have access to the invoice.
|
||||
button_access = {'url': access_link} if access_link else {}
|
||||
recipient_group = (
|
||||
'additional_intended_recipient',
|
||||
lambda pdata: pdata['id'] in local_msg_vals.get('partner_ids', []) and pdata['id'] != self.partner_id.id,
|
||||
{
|
||||
'has_button_access': True,
|
||||
'button_access': button_access,
|
||||
}
|
||||
)
|
||||
groups.insert(0, recipient_group)
|
||||
|
||||
return groups
|
||||
|
||||
|
||||
@@ -404,6 +404,10 @@ class TestAccountComposerPerformance(AccountTestInvoicingCommon, MailCommon):
|
||||
test_move = self.test_account_moves[1].with_env(self.env)
|
||||
move_template = self.move_template.with_env(self.env)
|
||||
|
||||
# add a follower to the invoice
|
||||
self.partner_b.email = 'partner_b@example.com'
|
||||
test_move.message_subscribe(self.partner_b.ids)
|
||||
|
||||
additional_partner = self.env['res.partner'].create({
|
||||
'name': "Additional Partner",
|
||||
'email': "additional@example.com",
|
||||
@@ -429,6 +433,15 @@ class TestAccountComposerPerformance(AccountTestInvoicingCommon, MailCommon):
|
||||
content='access_token='
|
||||
)
|
||||
|
||||
follower_mail = self.assertMailMail(
|
||||
self.partner_b,
|
||||
'sent',
|
||||
author=self.user_account_other.partner_id,
|
||||
)
|
||||
|
||||
self.assertNotIn('access_token=', follower_mail.body_html,
|
||||
"The followers should not bet sent the access token by default")
|
||||
|
||||
@tagged('post_install_l10n', 'post_install', '-at_install')
|
||||
class TestAccountMoveSendCommon(AccountTestInvoicingCommon):
|
||||
|
||||
|
||||
Reference in New Issue
Block a user