Files
odoo_source/odoo/addons/test_access_rights/ir.model.access.csv
T
Rémy Voet (ryv) 160acc0200 [FIX] core: fix inconsistencies between _apply_ir_rule and check_access_rule
Issues
======
- `_apply_ir_rule` applies `ir.rule` of the current model and also
`ir.rule` from the inherited model (via inherits). But
`check_access_rule` doesn't check the later one.
- `_flush_search` doesn't flush fields coming from the `ir.rule` of
the inherited model (via inherits). Then the filtering done by
`_apply_ir_rule` may be inconsistent with cached values.

Changes
=======
Because of https://github.com/odoo/odoo/blob/6ddcb448612f5d784c8e9ebb90f19077e65be3e1/odoo/osv/expression.py#L1073-L1073,
and https://github.com/odoo/odoo/blob/00e86b1552d1e5541a8dbf9411de5cfdb8990cc4/odoo/fields.py#L2895
leaf like `('<many2one_delegate>', 'any', [<sub-domain>])`,
will be translated in the same way as `_inherits_join_add` does.
We can remove `_inherits_join_add` and its usage in `_apply_ir_rule`
and change `ir.rule._compute_domain` to also return the inherited
(via inherits) `ir.rule` domain (with the new 'any' operator).
Since `_compute_domain` is used by `_apply_ir_rule` and
`_filter_access_rules_python`, everything is consistent.

Also fix `BaseModel._flush_search` to take in account 'any'/'not any'
operators (compulsory in order to flush correctly new domain
from `ir.rule._compute_domain` generated).

Part-of: odoo/odoo#125916
2023-08-21 19:56:55 +02:00

1.4 KiB

1idnamemodel_id:idgroup_id:idperm_readperm_writeperm_createperm_unlink
2access_test_access_right_some_obj_employeeaccess_test_access_right_some_objmodel_test_access_right_some_objbase.group_user1111
3access_test_access_right_some_obj_publicaccess_test_access_right_some_objmodel_test_access_right_some_objbase.group_public1111
4access_test_access_right_container_employeeaccess_test_access_right_containermodel_test_access_right_containerbase.group_user1111
5access_test_access_right_container_publicaccess_test_access_right_containermodel_test_access_right_containerbase.group_public1111
6access_test_access_right_inherits_publicaccess_test_access_right_inheritsmodel_test_access_right_inheritsbase.group_public1111
7access_test_access_right_inherits_employeeaccess_test_access_right_inheritsmodel_test_access_right_inheritsbase.group_user1111
8access_test_access_right_child_publicaccess_test_access_right_childmodel_test_access_right_childbase.group_public1111
9access_test_access_right_child_employeeaccess_test_access_right_childmodel_test_access_right_childbase.group_user1111
10access_test_access_right_obj_categaccess_test_access_right_obj_categmodel_test_access_right_obj_categbase.group_user1111
11access_test_ticket_portalaccess_test_ticket_portalmodel_test_access_right_ticketbase.group_portal1000
12access_test_ticket_useraccess_test_ticket_usermodel_test_access_right_ticketbase.group_user1111