Rémy Voet (ryv) d2c2f5bfc2 [FIX] core: invalid field should raise an Exception in domain
Since https://github.com/odoo/odoo/commit/5a998694a6f353da05d7f69e4c59b9e7dd139e27,
we don't crash anymore at https://github.com/odoo/odoo/commit/5a998694a6f353da05d7f69e4c59b9e7dd139e27#diff-fa4d9268d6e65e19aebec81c46038f0e496b91142588ed4d1c1bce7ff2338f2cL759
(at `field.auto_join`) if `len(path) > 1`, `field` is translated the
`left` is not only a field name (example: `"name.<something else>"`).
Because we trust `left` at this [point](https://github.com/odoo/odoo/blob/1bbdd77f0ee6bd632f5ade88b8b71c5576fa9053/odoo/osv/expression.py#L1339),
(we shouldn't, coming from https://github.com/odoo/odoo/pull/101115)
then SQL expression generated for translated field is unsafe
(SQL injection).

In case of translated field, check that `left` side is only a valid
field name. (if it is not, it will crash later in `__leaf_to_sql`).
In addition, use `field.name` instead of `left` when it is possible to
be more robust.

closes odoo/odoo#120565

Signed-off-by: Vincent Schippefilt (vsc) <vsc@odoo.com>
2023-05-09 18:26:52 +02:00
…
…
…
…
…

Build Status Tech Doc Help Nightly Builds

Odoo

Odoo is a suite of web based open source business apps.

The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...

Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.

Getting started with Odoo

For a standard installation please follow the Setup instructions from the documentation.

To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials

S
Description
No description provided
Readme LGPL-3.0
3.4 GiB
Languages
Python 49.6%
JavaScript 47.8%
SCSS 2%
CSS 0.3%
HTML 0.2%