44d336128dfe945a40db32e8df2810cbcf323b35
This is about the overrides of _search() on models mail.activity and mail.message, which both make extra queries to implement their specific access rights. We combine both queries made in _search() to retrieve accessible records. This simply uses the API of the Query object to retrieve the data that is necessary to restrict access to messages. Move security check outside of _message_format() for performance. The call to check_access_rule() inside _message_format() was redundant in many cases and generated more SQL queries than necessary. Also for performance, accessing fields from records should not actually check permission. That's a bit freaky, but this reproduces the former behavior of mail.message. And finally, make method check_access_rule() on mail.message check ir.rules, in order to make it consistent with method _search(). Part-of: odoo/odoo#112126
…
…
…
Odoo
Odoo is a suite of web based open source business apps.
The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...
Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.
Getting started with Odoo
For a standard installation please follow the Setup instructions from the documentation.
To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials
Languages
Python
49.6%
JavaScript
47.8%
SCSS
2%
CSS
0.3%
HTML
0.2%