* = bus, crm_livechat, hr, mail_bot, test_discuss_full, test_mail,
website_livechat
Now that livechat uses guest, we can write proper ACL for channel and
channel member to check if the current user/guest is a member.
This allows removing most sudo in code and to simplify search domains.
Remaining sudo in discuss folder have been reviewed and commented.
task-3394829
closes odoo/odoo#138330
Related: odoo/upgrade#5295
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
18 lines
718 B
Python
18 lines
718 B
Python
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
|
|
|
from werkzeug.exceptions import NotFound
|
|
|
|
from odoo import http
|
|
from odoo.http import request
|
|
from odoo.addons.mail.models.discuss.mail_guest import add_guest_to_context
|
|
|
|
|
|
class MessageReactionController(http.Controller):
|
|
@http.route("/mail/message/reaction", methods=["POST"], type="json", auth="public")
|
|
@add_guest_to_context
|
|
def mail_message_add_reaction(self, message_id, content, action):
|
|
message = request.env["mail.message"].browse(int(message_id)).exists()
|
|
if not message._validate_access_for_current_persona("write"):
|
|
raise NotFound()
|
|
message.sudo()._message_reaction(content, action)
|