jem-odoo 3be372cfc4 [FIX] hr: restrict sudoing fields_view_get of res.users
Since d77ce4c2a9, the feature of editing own employee profile was
added. It was complicated with the access rights point of view because the
hr.employee fields are protected (groups="hr.group_hr_user"). To allow editing
its own hr.employee, it was required to `sudo` the field_view_get of res.users
(as the profile form view is a res.users form view, with related field from the
employee).

- Bug
The problem is that calling `fields_view_get` as `sudo` each time breaks the `groups`
mecanism on res.users views (not only form view). For instance, adding a field
on the form view with a group will always make it visible as the `groups`check
is done in sudo mode.

- Solution
This commit tries to fix this matter but reducing the `sudo` usage to
- only form view (we don't want this to applied to every res.users view type)
- only for internal user
- only in the flow of the "self editing profile", by checking the current action
- only for the current user (avoid to get the profile of other res.users by
using the same action)

- Side effect
The `groups` mecanism is still breaking on the "my profile" form view, as the
`sudo` is still applied in that case. We might tolerate this as the view should
only be accessible for the current user.

This is not perfect at all, but cleaning that properly might involve to redevelop
this sensitive feature.

Task-1916925
2019-04-08 07:58:01 +00:00
2019-03-20 14:59:50 +00:00
2019-04-08 10:18:12 +00:00
…
2018-10-09 13:44:38 +00:00
…
…
2019-03-13 15:10:02 +00:00
…
…

Build Status Tech Doc Help Nightly Builds

Odoo

Odoo is a suite of web based open source business apps.

The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, Purchase Management, ...

Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.

Getting started with Odoo

For a standard installation please follow the Setup instructions from the documentation.

Then follow the developer tutorials

S
Description
No description provided
Readme LGPL-3.0
3.4 GiB
Languages
Python 49.6%
JavaScript 47.8%
SCSS 2%
CSS 0.3%
HTML 0.2%