This fixes an issue where access rules are checked on a new record: the
rule domains are evaluated with method filtered_domain(), and one rule
uses the operator 'child_of', which is implemented with a call to
search(). When used with a new record, filtered_domain() returns an
empty recordset instead of the record itself.
By design, the ORM doesn't check security on new records. A base
automation of type 'onchange' will run some server action on a new
record. The server action may still check access rights on the model,
but should not check access rules.
closesodoo/odoo#158309
Signed-off-by: Rémy Voet (ryv) <ryv@odoo.com>