Files
odoo_source/addons/project_sms
lase@odoo.com 1ecd0b2160 [FIX] project_sms: Allow transition of task to state with SMS template
Steps to reproduce:

Be sure to have the `sale_sms` module installed.

- Connect as Marc Demo. Note: Marc has the administrator access rights
  in every service application including projects,...
- Go to the field service app create a new task and change its state to
  `planned`.

> Access error: you are not allowed to access 'SMS Templates'

Expected behavior:

Since the newly created user has the rights to modify the state of the
task and since he does not try to access the content of any sms.template
he should not raise this access error.

Cause of the issue:

The stage `planned` is associated with an SMS template. As such, when a
task is moved to this stage, an sms will be sent using the template.
This action is done during the `write` override of the `project_sms`
module:
https://github.com/odoo/odoo/blob/5f1a3bdcaa63492cf169f6f5f3eb2e2281ad5ab5/addons/project_sms/models/project_task.py#L24-L32
However, this `_send_sms` method will need to 'read' the sms.template to
generate the sms:
https://github.com/odoo/odoo/blob/e6be732450d9ef662a48ba074e1ca1ad32e35c04/addons/sms/models/mail_thread.py#L191-L192
Since the user does not have the acess rights to 'read' this template
because of the `ir_rule_sms_template_so_sale_manager` access rule
defined in the `sale_sms` module, the access error will be raised.

Fix:

Since the `_send_sms` method will only read records in order to generate
the sms that will be send, we should bypass access rigths checks during
the call of this method.

Note: this was already the solution used for portal users.

opw-3789197

closes odoo/odoo#163525

X-original-commit: b5b63509a6bc4467cf84cd15ebdf3b4b0601aeb0
Signed-off-by: Lancelot Semal (lase) <lase@odoo.com>
Signed-off-by: Xavier Bol (xbo) <xbo@odoo.com>
2024-04-29 08:07:28 +00:00
..