Steps to reproduce:
- take a project;
- change the visibility to allow sharing;
- click on "SHARE EDITABLE";
- share the project with a portal user;
- login as portal;
- try to open a project task.
Remark: the problem does not occur for all tasks.
Issue:
A traceback appears.
Cause:
Error occurs because: `return (token and record and consteq(record[token_field], token))`
compare two values with different type.
- `token` is equal to `'null'`
- `record[token_field]` is equal to `False`
In the code: `consteq = hmac_lib.compare_digest`
> `hmac.compare_digest(a, b)`
Return `a == b`.
This function uses an approach designed to prevent timing analysis
by avoiding content-based short circuiting behaviour, making it appropriate for cryptography.
a and b must both be of the same type:
either str (ASCII only, as e.g. returned by HMAC.hexdigest()), or a bytes-like object.
[source](https://docs.python.org/3/library/hmac.html#hmac.compare_digest)
The source of the problem is upstream to this comparison.
Indeed, we first test if we have a token.
As the value of the token is `'null'`, we pass the condition.
Solution:
It is necessary to have a token equal to `False` if the task has not token.
Therefore, whatever the value of the token (token value or `False`), we have to update the token.
opw-3217490
closesodoo/odoo#115947
X-original-commit: dd3a59fa28c5644be93cc2778e0c6854a4481d51
Signed-off-by: Xavier Bol (xbo) <xbo@odoo.com>
Before this commit, when the internal user is not follower of the
project and enter in the project sharing feature. If he wants to see the
form view of a task, he cannot and have a Session expired error.
This issue arrives because in the chatter we check is the user is a
follower of the project shared.
This commit fixes this issue by just using the _document_check_access
method to check if the user can access to the document. Indeed, we don't
need to check if user is a follower because the _document_check_access
does it with the `ir.rules`.
Related PR: #73341
Part of task-2633229
closes#76098
This reverts commit fc7778f8c512202dc3361d6b87be8c28b299c3c8 because of
a change in the spec.
The access mode are removed and replaced by this access mode for portal
user:
- read: the user goes to the classic portal view
- edit: the user is added as collaborator of the shared project and can
access to project sharing views.
To do this, the portal share is inherited by the project share wizard.
This new wizard can be open to share in readonly and open to share in
edit mode via 2 buttons in the form view of the shared project.
A new stat button is added to form view of project to see the
collaborators of this project. That is, the ones can access to the
project sharing views. The project manager will can remove or also add
new collaborators via the views in this stat button.
task-2379518
closes#73341
Before this commit, when we change the access right to the portal user
and this user is in task form view with chatter. He can send message
even we remove the access right.
This commit checks if the user has the access before sending the
message.
task-2379518
Before this commit, if the portal user is a follower of the project he
can use the chatter of new tasks in the project sharing feature since
the follower of the project is automatically the follower of new tasks.
But if he is not a follower of the task (for instance, old task in the
project) then we have to check if the
access token is the one of the shared project to give the access to
the chatter.
This commit checks the `access_token` of the project when we are in the
project sharing form view to allow the portal user to use the chatter.
task-2379518
closes#73341
Co-authored: Yannick Tivisse (yti) <yti@odoo.com>