Files
odoo_source/addons/payment/models
Adrien Widart fa68c23276 [FIX] account: read invoice of archived partner
If a user has the portal access, when going to his documents, if one of
them belongs to an archived partner, it will raise a 403 error.

To reproduce the error:
1. Go to Settings > Invoicing > Customer Payments
2. Enable "Invoice Online Payment"
3. Create a customer C
	- Set a name
	- In Contacts & Addresses, add two contacts C_01 and C_02
		- Both are "Invoice Address"
		- Add a valid email for C_01
4. Go to Customers > C_01, Action, Grand portal acess
	- Check "In Portal", Apply
5. Go to Settings > Users & Companies > Users
6. Remove the search filter, Select C_01, Add a password
7. Create an invoice INV
	- Customer: C_02
8. Connect to C_01's account
9. Click on "Invoices & Bills"
	- The invoice INV is listed
10. Connect to admin's account
11. Go to Customers, Archive C_02
12. Repeat steps 8-9

=> A 403-Forbidden page is displayed with a traceback.

For a user to have access to the "Invoices & Bills", one of the
followers of each invoice must be part of the same commercial partner:
`('message_partner_ids','child_of',[user.commercial_partner_id.id])`.
Here is the issue: if archived, the partner will not be in the
`message_partner_ids` list. This is the reason why, in our case, C_01
can no longer access the documents.

This commit allows the archived partners to be listed when getting the
portal transactions.

OPW-2417275

closes odoo/odoo#63790

X-original-commit: ad36feae0a1ee6fe0bdfbb622685a6b143ea4f2a
Signed-off-by: Adrien Widart <adwid@users.noreply.github.com>
2020-12-24 16:25:09 +00:00
..