Files
odoo_source/addons/website/models
Simon Lejeune 19ac9fba0d [FIX] base: strengthen ir.attachment access rights
An ir.attachment record can be served as a request's reponse if:
  - a request triggers a 404
  - the ir.attachment record has its url field matching the url of
    the failed and is of binary type

Following rev[1], portal users have the right to create these kind of
records, and it is a security concern.

This patch restrict the ability to create and write on the ir.attachment
records that may be served through the dispatch's exception mechanism to
settings users.

As the asset bundles files are served through the use of these special
ir.attachment, we make sure to retrieve only ir.attachment records
created by the superuser in the `get_attachment` method.

As website administrators often need to play with these special
ir.attachment, we also let to this group the permission to manage them.

[1] 61065b6d04
2018-07-29 14:10:42 +01:00
..