aee3af0abe626b625682d367f45953423a8abaf7
ir.attachment without res_model/res_id
This revision restores the behavior of 16.0 regarding
the access to attachments with no `res_model`/`res_id`
set.
It was changed unexpectedly during the refactoring
of `read`/`fetch`.
Basically, the below used to raise an AccessError in 16.0:
Create an attachment without res_model/res_id and access it
as another user
```py
attachment = self.env['ir.attachment'].create({'name': 'foo'})
attachment.invalidate_recordset()
attachment.with_user(self.env.ref('base.user_demo')).datas
```
While it no longer raises the AccessError in saas-16.2
The reason is that the override of `_read` calling
`check` has been removed in saas-16.2:
https://github.com/odoo/odoo/commit/e962860c6f0d8ec9e50bb376e1faab5c7bc69374#diff-ab3dadc37163820f8e863edb1dd216f8b0e7ccf19cf4e2052577a7bae7ddd7e8L606-L608
in favor to do the check in `_search`:
https://github.com/odoo/odoo/commit/ae31aebf095392d8c91f49ac279e1949997dc245
But there is a difference of behavior between the checks in `check` and `_search`
regarding attachments without `res_model`/`res_id`:
https://github.com/odoo/odoo-security/blob/bc538f6944461a642bac0f757ec96d7f8cc14c9a/odoo/addons/base/models/ir_attachment.py#L454-L465
https://github.com/odoo/odoo-security/blob/bc538f6944461a642bac0f757ec96d7f8cc14c9a/odoo/addons/base/models/ir_attachment.py#L566-L573
The goal of this revision is to have an unified behavior regarding the treatment
of attachments without `res_model`/`res_id` in both `check` and `_search`.
closes odoo/odoo#119768
X-original-commit: 82c36285b897b72a956da0585ebd62f4c2d33784
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
…
…
…
Odoo
Odoo is a suite of web based open source business apps.
The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...
Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.
Getting started with Odoo
For a standard installation please follow the Setup instructions from the documentation.
To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials
Languages
Python
49.6%
JavaScript
47.8%
SCSS
2%
CSS
0.3%
HTML
0.2%