5edb04d4914560796b5f3cd158dbbfd24ae17a74
Purpose of this commit is to add tests to post in record user cannot access
especially in multi company environment.
Main observations
* ACLs are checked when fetching record_name, then when fetching reply_to
information, adding a bit of ACLs noise in the process;
* check_access_rule of mail.message is called when creating the message
(which is the real protection);
* posting on a document user cannot see is possible when they have been
notified of a parent message. Use case is: answer a ping, even on a
document non readable, should always be doable. However it currently
crashes notably due to attachments check, who always require the read
access on the related document even if the message is authorized;
In this commit we also move other tests about multi_company in the right
file (and add a test flag) in order to have all of them in the same place
easing debug and testing.
Task-3213982 (Mail: fix 'multi-company' post support)
X-original-commit: odoo/odoo@5656f4d20d
Part-of: odoo/odoo#114511
…
Odoo
Odoo is a suite of web based open source business apps.
The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...
Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.
Getting started with Odoo
For a standard installation please follow the Setup instructions from the documentation.
To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials
Languages
Python
49.6%
JavaScript
47.8%
SCSS
2%
CSS
0.3%
HTML
0.2%