Files
odoo_source/addons/mail/controllers/webclient.py
T
Sébastien Theys 005b76462a [IMP] mail, im_livechat, *: simplify channel ACL
* = bus, crm_livechat, hr, mail_bot, test_discuss_full, test_mail,
    website_livechat

Now that livechat uses guest, we can write proper ACL for channel and
channel member to check if the current user/guest is a member.

This allows removing most sudo in code and to simplify search domains.
Remaining sudo in discuss folder have been reviewed and commented.

task-3394829

closes odoo/odoo#138330

Related: odoo/upgrade#5295
Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
2023-10-24 12:38:21 +00:00

24 lines
918 B
Python

# Part of Odoo. See LICENSE file for full copyright and licensing details.
from werkzeug.exceptions import NotFound
from odoo import http
from odoo.http import request
from odoo.addons.mail.models.discuss.mail_guest import add_guest_to_context
class WebclientController(http.Controller):
@http.route("/mail/init_messaging", methods=["POST"], type="json", auth="public")
@add_guest_to_context
def mail_init_messaging(self):
if not request.env.user._is_public():
return request.env.user.sudo(False)._init_messaging()
guest = request.env["mail.guest"]._get_guest_from_context()
if guest:
return guest._init_messaging()
raise NotFound()
@http.route("/mail/load_message_failures", methods=["POST"], type="json", auth="user")
def mail_load_message_failures(self):
return request.env.user.sudo(False).partner_id._message_fetch_failed()