Earlier PR improved ACLs in Discuss [1]. Route `/mail/load_message_failures` was made in non-sudo as to take ACLs into account, so that we don't get mail failures that we don't have access [2] However, checking ACLs on `mail.message` from `search` on `mail.notification` is very slow [3], to the point where the RPC takes minutes and results in a `memoryerror`. Ideally we should have non-sudo and make checking ACLs more performant. As a quick fix in a stable version, we revert to using `sudo`, which results in same quick results as before. [1]: https://github.com/odoo/odoo/pull/138330 [2]: https://github.com/odoo/odoo/pull/138330/files#diff-6be51f3695e69474a19cf6857370c8bb9b529a15d568952258cec9a0ae519fc4R23 [3]: https://github.com/odoo/odoo/blob/17.0/addons/mail/models/res_partner.py#L251 closes odoo/odoo#146184 Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
26 lines
1.0 KiB
Python
26 lines
1.0 KiB
Python
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
|
|
|
from werkzeug.exceptions import NotFound
|
|
|
|
from odoo import http
|
|
from odoo.http import request
|
|
from odoo.addons.mail.models.discuss.mail_guest import add_guest_to_context
|
|
|
|
|
|
class WebclientController(http.Controller):
|
|
@http.route("/mail/init_messaging", methods=["POST"], type="json", auth="public")
|
|
@add_guest_to_context
|
|
def mail_init_messaging(self):
|
|
if not request.env.user._is_public():
|
|
return request.env.user.sudo(False)._init_messaging()
|
|
guest = request.env["mail.guest"]._get_guest_from_context()
|
|
if guest:
|
|
return guest._init_messaging()
|
|
raise NotFound()
|
|
|
|
@http.route("/mail/load_message_failures", methods=["POST"], type="json", auth="user")
|
|
def mail_load_message_failures(self):
|
|
# sudo as to not check ACL, which is far too costly
|
|
# sudo: res.users - return only failures of current user as author
|
|
return request.env.user.partner_id._message_fetch_failed()
|