Files
odoo_source/addons/mail/controllers/message_reaction.py
T
Sébastien Theys 005b76462a [IMP] mail, im_livechat, *: simplify channel ACL
* = bus, crm_livechat, hr, mail_bot, test_discuss_full, test_mail,
    website_livechat

Now that livechat uses guest, we can write proper ACL for channel and
channel member to check if the current user/guest is a member.

This allows removing most sudo in code and to simplify search domains.
Remaining sudo in discuss folder have been reviewed and commented.

task-3394829

closes odoo/odoo#138330

Related: odoo/upgrade#5295
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-10-24 12:38:21 +00:00

18 lines
718 B
Python

# Part of Odoo. See LICENSE file for full copyright and licensing details.
from werkzeug.exceptions import NotFound
from odoo import http
from odoo.http import request
from odoo.addons.mail.models.discuss.mail_guest import add_guest_to_context
class MessageReactionController(http.Controller):
@http.route("/mail/message/reaction", methods=["POST"], type="json", auth="public")
@add_guest_to_context
def mail_message_add_reaction(self, message_id, content, action):
message = request.env["mail.message"].browse(int(message_id)).exists()
if not message._validate_access_for_current_persona("write"):
raise NotFound()
message.sudo()._message_reaction(content, action)