Files
odoo_source/odoo
Denis Ledoux aee3af0abe [FIX] core: access to ir.attachment without res_model/res_id
This revision restores the behavior of 16.0 regarding
the access to attachments with no `res_model`/`res_id`
set.

It was changed unexpectedly during the refactoring
of `read`/`fetch`.

Basically, the below used to raise an AccessError in 16.0:

Create an attachment without res_model/res_id and access it
as another user
```py
attachment = self.env['ir.attachment'].create({'name': 'foo'})
attachment.invalidate_recordset()
attachment.with_user(self.env.ref('base.user_demo')).datas
```

While it no longer raises the AccessError in saas-16.2

The reason is that the override of `_read` calling
`check` has been removed in saas-16.2:
https://github.com/odoo/odoo/commit/e962860c6f0d8ec9e50bb376e1faab5c7bc69374#diff-ab3dadc37163820f8e863edb1dd216f8b0e7ccf19cf4e2052577a7bae7ddd7e8L606-L608

in favor to do the check in `_search`:

https://github.com/odoo/odoo/commit/ae31aebf095392d8c91f49ac279e1949997dc245

But there is a difference of behavior between the checks in `check` and `_search`
regarding attachments without `res_model`/`res_id`:

https://github.com/odoo/odoo-security/blob/bc538f6944461a642bac0f757ec96d7f8cc14c9a/odoo/addons/base/models/ir_attachment.py#L454-L465

https://github.com/odoo/odoo-security/blob/bc538f6944461a642bac0f757ec96d7f8cc14c9a/odoo/addons/base/models/ir_attachment.py#L566-L573

The goal of this revision is to have an unified behavior regarding the treatment
of attachments without `res_model`/`res_id` in both `check` and `_search`.

closes odoo/odoo#119768

X-original-commit: 82c36285b897b72a956da0585ebd62f4c2d33784
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
2023-04-26 07:53:03 +02:00
..
…
2023-04-20 15:22:04 +02:00
2023-03-14 15:52:10 +01:00
2022-10-19 15:12:44 +02:00
2023-03-14 15:52:10 +01:00