Files
odoo_source/odoo
Hugo Carlier (Huca) 9048f585c7 [FIX] models, *: make read_group domains coherent with access rights
* = test_read_group

Currently, a search with the following domain `[('m2m_field', '=',
False)]` will return only the records for which the m2m field is actually
empty and not take access rights into account. This means that, for a
given user and depending on access rules, `record.m2m_field` can give an
empty recordset while a search using the previous domain won't return
this record.

This behavior is problematic when such a domain is returned by the
read_group. Indeed, when using read_group to group on a m2m field,
records for which this m2m field appears empty for the current user will
be counted in the column 'False'. However, the domain associated to this
column is not always valid, as this m2m field can appear empty for the
current user but still have records in it that the current user does not
have access to. Such records won't be returned by a search performed
using the domain returned by the read_group for the False column.

closes odoo/odoo#143233

Signed-off-by: Rémy Voet (ryv) <ryv@odoo.com>
2023-11-28 21:20:59 +00:00
..
…
…
2023-10-26 19:39:28 +00:00