Issues ====== - `_apply_ir_rule` applies `ir.rule` of the current model and also `ir.rule` from the inherited model (via inherits). But `check_access_rule` doesn't check the later one. - `_flush_search` doesn't flush fields coming from the `ir.rule` of the inherited model (via inherits). Then the filtering done by `_apply_ir_rule` may be inconsistent with cached values. Changes ======= Because of https://github.com/odoo/odoo/blob/6ddcb448612f5d784c8e9ebb90f19077e65be3e1/odoo/osv/expression.py#L1073-L1073, and https://github.com/odoo/odoo/blob/00e86b1552d1e5541a8dbf9411de5cfdb8990cc4/odoo/fields.py#L2895 leaf like `('<many2one_delegate>', 'any', [<sub-domain>])`, will be translated in the same way as `_inherits_join_add` does. We can remove `_inherits_join_add` and its usage in `_apply_ir_rule` and change `ir.rule._compute_domain` to also return the inherited (via inherits) `ir.rule` domain (with the new 'any' operator). Since `_compute_domain` is used by `_apply_ir_rule` and `_filter_access_rules_python`, everything is consistent. Also fix `BaseModel._flush_search` to take in account 'any'/'not any' operators (compulsory in order to flush correctly new domain from `ir.rule._compute_domain` generated). Part-of: odoo/odoo#125916
1.4 KiB
1.4 KiB
| 1 | id | name | model_id:id | group_id:id | perm_read | perm_write | perm_create | perm_unlink |
|---|---|---|---|---|---|---|---|---|
| 2 | access_test_access_right_some_obj_employee | access_test_access_right_some_obj | model_test_access_right_some_obj | base.group_user | 1 | 1 | 1 | 1 |
| 3 | access_test_access_right_some_obj_public | access_test_access_right_some_obj | model_test_access_right_some_obj | base.group_public | 1 | 1 | 1 | 1 |
| 4 | access_test_access_right_container_employee | access_test_access_right_container | model_test_access_right_container | base.group_user | 1 | 1 | 1 | 1 |
| 5 | access_test_access_right_container_public | access_test_access_right_container | model_test_access_right_container | base.group_public | 1 | 1 | 1 | 1 |
| 6 | access_test_access_right_inherits_public | access_test_access_right_inherits | model_test_access_right_inherits | base.group_public | 1 | 1 | 1 | 1 |
| 7 | access_test_access_right_inherits_employee | access_test_access_right_inherits | model_test_access_right_inherits | base.group_user | 1 | 1 | 1 | 1 |
| 8 | access_test_access_right_child_public | access_test_access_right_child | model_test_access_right_child | base.group_public | 1 | 1 | 1 | 1 |
| 9 | access_test_access_right_child_employee | access_test_access_right_child | model_test_access_right_child | base.group_user | 1 | 1 | 1 | 1 |
| 10 | access_test_access_right_obj_categ | access_test_access_right_obj_categ | model_test_access_right_obj_categ | base.group_user | 1 | 1 | 1 | 1 |
| 11 | access_test_ticket_portal | access_test_ticket_portal | model_test_access_right_ticket | base.group_portal | 1 | 0 | 0 | 0 |
| 12 | access_test_ticket_user | access_test_ticket_user | model_test_access_right_ticket | base.group_user | 1 | 1 | 1 | 1 |