ff51570aed8aaa2061cf93ca98d10b7caa942553
Summary ------- Currently, when you send an invoice, every recipient receives the link including the access token. Only the invoice's customer and manually added recipients should receive the token. Steps to reproduce ------------------ * Create and validate an invoice * Add a follower `F `to the invoice * Click on the Send & Print button, then add a recipient `R` who is not the customer associated with the invoice * Proceed to send the invoice. * Access the emails that were sent * Using an incognito or private browsing window, open the `View Invoice` link for each of the 3 recipients. You should see that all the links give access to the invoice. What should happen is that only partner `R` and the invoice's customer should haveaccess to the invoice. `F` should be asked to login. Cause ----- Issue was introduced by 95c585f Fix --- Add a new notification group for partners that were manually added as recipients, and give that group access to the invoice. opw-3385302 closes odoo/odoo#146575 X-original-commit: 755814ea170adbade23692767fcb17b5422863e7 Signed-off-by: Brice Bartoletti (bib) <bib@odoo.com> Signed-off-by: Séna Serge Nshimiyimana (sesn) <sesn@odoo.com>
…
…
…
Odoo
Odoo is a suite of web based open source business apps.
The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...
Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.
Getting started with Odoo
For a standard installation please follow the Setup instructions from the documentation.
To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials
Languages
Python
49.6%
JavaScript
47.8%
SCSS
2%
CSS
0.3%
HTML
0.2%