**Steps to reproduce:** - Install pos_self_order. - Create a product with a price of any price, say 100. - Assign a tax of 10% to the product. - Create a new company and switch to it. - With the same product, add a new tax, say 20%. - Go back to the original company. - Open a bar (restaurant pos.config) that allows self order which also loads the product. - Open self order page and add the product. - [BUG] The product's price is not only 10%-taxed, but also 20%-taxed. **Explanation and fix** The issue is caused by use of sudo almost everywhere in the context of pos_self_order. This commit removes/reduces this use of sudo in many places and contextualize the records involved in the calculation such as pos.config, product.product, etc. to be the ones of the company and the user who opened the current pos.session. After this changes, only the taxes that belong to the company of the pos.config record are used in the price and tax calculations. closes odoo/odoo#131140 X-original-commit: 7ce7f3e21ad8f457742e27f88b7146c7d8fff5f3 Signed-off-by: David Monnom (moda) <moda@odoo.com> Signed-off-by: Joseph Caburnay (jcb) <jcb@odoo.com>
33 lines
951 B
Python
33 lines
951 B
Python
# -*- coding: utf-8 -*-
|
|
|
|
|
|
import werkzeug
|
|
|
|
from odoo.http import request
|
|
from odoo.addons.pos_self_order.models.pos_config import PosConfig
|
|
|
|
def get_any_pos_config_sudo() -> PosConfig:
|
|
"""
|
|
Returns a PosConfig that allows the QR code menu, if there is one,
|
|
or raises a NotFound otherwise
|
|
"""
|
|
return (
|
|
request.env["pos.config"].sudo().search([("self_order_view_mode", "=", True)], limit=1)
|
|
) or _raise(werkzeug.exceptions.NotFound())
|
|
|
|
def _raise(e):
|
|
raise e
|
|
|
|
def reduce_privilege(record_sudo, company, user=None):
|
|
"""
|
|
Returns a record with reduced privileges based on company and user.
|
|
If user is not provided, we keep the sudo privilege, but still, the record
|
|
will be scoped to the company.
|
|
"""
|
|
if record_sudo:
|
|
if user:
|
|
return record_sudo.sudo(False).with_company(company).with_user(user)
|
|
else:
|
|
return record_sudo.with_company(company)
|
|
return None
|