Commit78ac6de52drefactored methods checking alias security on the routing found for a given destination address. Indeed if a routing is found linked to an alias a security check is performed according to the restriction defined on the alias itself. HR module adds the 'employees only' restriction. A bug has been introduced in the mentioned commit concerning employees-based aliases. Indeed a condition on having a recordset has been added (self.ids, changed to record.ids at20d8025036). This condition is actually not necessary as checking the email author is linked to an existing employee has nothing to do with the alias being linked to a record or creating new record. This may causes issues notably using employees-restricted aliases in expense application. Indeed you could use aliases to create new expenses for employees and you could have issues with this condition. This commit is linked to task ID 1829860 and ID 35093. Closes #22960 .
30 lines
1.2 KiB
Python
30 lines
1.2 KiB
Python
# -*- coding: utf-8 -*-
|
|
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
|
|
|
from odoo import fields, models, tools
|
|
|
|
|
|
class Alias(models.Model):
|
|
_inherit = 'mail.alias'
|
|
|
|
alias_contact = fields.Selection(selection_add=[('employees', 'Authenticated Employees')])
|
|
|
|
|
|
class MailAlias(models.AbstractModel):
|
|
_inherit = 'mail.alias.mixin'
|
|
|
|
def _alias_check_contact_on_record(self, record, message, message_dict, alias):
|
|
if alias.alias_contact == 'employees':
|
|
email_from = tools.decode_message_header(message, 'From')
|
|
email_address = tools.email_split(email_from)[0]
|
|
employee = self.env['hr.employee'].search([('work_email', 'ilike', email_address)], limit=1)
|
|
if not employee:
|
|
employee = self.env['hr.employee'].search([('user_id.email', 'ilike', email_address)], limit=1)
|
|
if not employee:
|
|
return {
|
|
'error_message': 'restricted to employees',
|
|
'error_template': self.env.ref('hr.mail_template_data_unknown_employee_email_address').body_html,
|
|
}
|
|
return True
|
|
return super(MailAlias, self)._alias_check_contact_on_record(record, message, message_dict, alias)
|