Currently if public user has country_id, following traceback is raise
when /shop URL is opened:
Traceback (most recent call last):
File "/.repo_requirements/odoo/odoo/addons/base/models/qweb.py", line 331, in _compiled_fn
return compiled(self, append, new, options, log)
File "<template>", line 1, in template_website_sale_products_item_306
File "/.repo_requirements/odoo/addons/website_sale/models/product.py", line 294, in _get_combination_info
fpos = self.env['account.fiscal.position'].get_fiscal_position(partner.id).sudo()
File "/.repo_requirements/odoo/addons/account/models/partner.py", line 184, in get_fiscal_position
fp = self._get_fpos_by_region(delivery.country_id.id, delivery.state_id.id, delivery.zip, vat_required)
File "/.repo_requirements/odoo/addons/account/models/partner.py", line 141, in _get_fpos_by_region
fpos = self.search(domain_country + state_domain + zip_domain, limit=1)
File "/.repo_requirements/odoo/odoo/models.py", line 1708, in search
res = self._search(args, offset=offset, limit=limit, order=order, count=count)
File "/.repo_requirements/odoo/odoo/models.py", line 4485, in _search
model.check_access_rights('read')
File "/.repo_requirements/odoo/odoo/models.py", line 3331, in check_access_rights
return self.env['ir.model.access'].check(self._name, operation, raise_exception)
File "<decorator-gen-33>", line 2, in check
File "/.repo_requirements/odoo/odoo/tools/cache.py", line 90, in lookup
value = d[key] = self.method(*args, **kwargs)
File "/.repo_requirements/odoo/odoo/addons/base/models/ir_model.py", line 1792, in check
raise AccessError(msg)
odoo.exceptions.AccessError: You are not allowed to access 'Fiscal Position' (account.fiscal.position) records.
This operation is allowed for the following groups:
- Accounting/Advisor
- User types/Internal User
- User types/Portal
Contact your administrator to request access if necessary.
Error to render compiling AST
AccessError: You are not allowed to access 'Fiscal Position' (account.fiscal.position) records.
This operation is allowed for the following groups:
- Accounting/Advisor
- User types/Internal User
- User types/Portal
Contact your administrator to request access if necessary.
Template: website_sale.products_item
Path: /t/t[2]
Node: <t t-set="combination_info" t-value="product._get_combination_info(only_template=True, add_qty=add_qty or 1, pricelist=pricelist)"/>
Above was tested and reproduced in an instance of odoo runbot v14.0:
https://youtu.be/GgUnyna_EX8
That is due to public user has not permission to read model
account.fiscal.position and in fact in ACL, permission contains
'public' but is setting group_portal.
closesodoo/odoo#73117
X-original-commit: 53dc9f62b6d4c362292bf48df54b11c4852f6006
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
In order to ensure consistent results of all error conditions returned
by the LDAP server, the _authenticate() method should return `False`
for every kind of exception, not just for INVALID_CREDENTIALS.
This is not actually relevant in 12.0 as the result is exactly the
same, due to the way the `entry` variable is being initialized, but it
will make the code path "visibly consistent" across all supported
versions
closesodoo/odoo#72484
X-original-commit: 24a3f669e5199c35849dabbf7b0d37f43b684538
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
This method only expects to be called as POST and should not be called
with GET.
This commit enforces that.
[CLA] Signature for sushiwushi
closesodoo/odoo#71575
X-original-commit: 00f2eeee7aa514599b40e049be46eacdcc8332fa
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
When Odoo routes incoming emails it is looking for existing messages in
database using Message Ids which are coming from e-mail header
References.
In Odoo the message id looks pretty long like
743570479975566.1584086032.522504091262817-openerp-message-notify@ip-172-31-45-160
As it declared in [RFC2822] long header bodies can be "folded" using
CRLF+WSP. And some mail clients do that very thing. They split
References header body which contains Message Ids by "\n ". The example
of mail client where it can be reproduced is apps.rackspace.com We
created Sales Order in Odoo, sent this quotation to the client email. He
replied with e-mail, and this email can't be matched with any existing
message id and as result it's not attached to the Sales Order.
RFC2882: https://tools.ietf.org/html/rfc2822#section-2.2.3closesodoo/odoo#68077
X-original-commit: 559f6cf62711ad45557eddec3af7c66616724eb5
Signed-off-by: Julien Castiaux <Julien00859@users.noreply.github.com>