Files
odoo_source/odoo
Martin TrigauxandXavier Morel 49838338e0 [FIX] *: sanitize action content reading
The open_action_with_context was not using _for_xml_id, producing an
error when reading the action content.

In open_action, the action_name was taken from the context and needs
sanity checks. Ensure only actions from the account module can be
read and only if the user has access to the target model.
This is a limitation of the previous behaviour but, at the moment, all
known calls are made refering to an action from the account module.
Limit the scope of this method while the 14.0 is still early to avoid
having a door open to ready any action, and difficult to close later.

Remove old action fetching from the context in create_move that is no
longer used.

closes odoo/odoo#61602

X-original-commit: a39e94f7e4dc74e850650ac90bbc5f85af130bc8
Related: odoo/enterprise#14695
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Co-authored-by: Xavier Morel <xmo@odoo.com>
2020-11-10 16:04:29 +00:00
..
2020-10-19 07:03:01 +00:00
…
2020-10-19 07:03:01 +00:00