Files
odoo_source/addons/project/security
damr 77b5499b4e [FIX] project: give read access on milestone to portal user
This commit's purpose is to give back to the portal user the access
rigth to read on the model project.milestone. This access was removed
because it was judge that it was not needed to give access to portal
user to an entire model. The issue it created is that while the name_get
still works, it is no longer possible to do a search on the milestone
field on the portal sharing

step to reproduce :
- install db with project and demo data
- log in with mitchel admin
- open the project app
- click on the 'share' option of the deco addict project
- select 'edit' and type 'joel' in the partner section. Select the
suggested portal user 'my company joel willis'
- click on 'send invitation'
- log out and log in with the portal user
- select the project menu
- click on the shared project 'deco addict'
- start typing in the search bar and select the 'milestone' option

An access right error is raised.

source of the issue :
The name_search function is not executed in sudo and since the
portal user has no read access on the project.milestone model,
an access right error is raised.

Solution :
Give the read access to the project.milestone model to portal user.
Ideally, that is something we'd like to avoid, but since the other
option is to execute the name_search in sudo, giving read access is the
better option. An ir.rule was also added to ensure that the portal user
has only access to the milestone linked to his shared project. A local
script was added, and the version of the manifest was changed in order
to trigger the script when the module is updated.
Some tests were added.

affected version 16.0 -> 17.0 (another fix will be applied in master)
ticket -
https://www.odoo.com/web#id=3548142&cids=1&model=project.task&view_type=form

closes odoo/odoo#144525

X-original-commit: d74a6ca46d208fbbe5142bcbb39d8985ee1e1f23
Signed-off-by: Xavier Bol (xbo) <xbo@odoo.com>
2023-12-01 21:10:54 +00:00
..