Skip to content

[FIX] report_aeroo: avoid display_name write when rendering records - #97

Closed
fw-bot-adhoc wants to merge 1 commit into
ingadhoc:19.0from
adhoc-dev:19.0-18.0-h-122297-mav-7166-fw
Closed

fw-bot-adhoc wants to merge 1 commit into
ingadhoc:19.0from
adhoc-dev:19.0-18.0-h-122297-mav-7166-fw

Conversation

@fw-bot-adhoc

Copy link
Copy Markdown

Problem

report_aeroo renders every ${...} expression through __filter. For recordset values it called _compute_display_name() directly:

return val._compute_display_name()

Calling the compute method outside the ORM compute protocol makes the record.display_name = ... assignment take Field.__set__'s business-logic branch (odoo/fields.py), which issues a real write() on the rendered model instead of only updating the cache.

Consequences:

  • Printing an aeroo report as a user without write access on the rendered model raises AccessError. This surfaced when a non-admin printed a report that renders a res.country record (e.g. ${o.partner_id.country_id}) — res.country is writable only by the Settings group. It only reproduced when the report was rendered as the acting user (e.g. IoT printing via render_and_send), not through channels that render elevated.
  • The method returns None, so the record was rendered empty.

Regression introduced in fa94921 (migration of name_get()[0][1] → _compute_display_name()).

Fix

Read display_name (computed into cache, no write), restoring the original name_get()[0][1] semantics:

return val[:1].display_name

How to verify

Render an aeroo report that outputs a record (e.g. ${o.partner_id.country_id}) as a user without write access on that model (non-admin, no Settings group). Before: AccessError on res.country and the value rendered empty. After: renders the display name, no write.

Ref: https://www.adhoc.inc/odoo/helpdesk.ticket/122297

Forward-Port-Of: #96

@roboadhoc

Copy link
Copy Markdown

Pull request status dashboard

@fw-bot-adhoc

Copy link
Copy Markdown
Author

@mav-adhoc @maq-adhoc cherrypicking of pull request #96 failed.

stdout:

Auto-merging report_aeroo/__manifest__.py
CONFLICT (content): Merge conflict in report_aeroo/__manifest__.py
Auto-merging report_aeroo/report_parser.py

Either perform the forward-port manually (and push to this branch, proceeding as usual) or close this PR (maybe?).

:shipit: you can use git-fw to re-do the forward-port for you locally.

⚠️ after resolving this conflict, you will need to merge it via @roboadhoc.

More info at https://github.com/odoo/odoo/wiki/Mergebot#forward-port

@fw-bot-adhoc

Copy link
Copy Markdown
Author

@mav-adhoc @maq-adhoc this forward port of #96 is awaiting action (not merged or closed).

3 similar comments
@fw-bot-adhoc

Copy link
Copy Markdown
Author

@mav-adhoc @maq-adhoc this forward port of #96 is awaiting action (not merged or closed).

@fw-bot-adhoc

Copy link
Copy Markdown
Author

@mav-adhoc @maq-adhoc this forward port of #96 is awaiting action (not merged or closed).

@fw-bot-adhoc

Copy link
Copy Markdown
Author

@mav-adhoc @maq-adhoc this forward port of #96 is awaiting action (not merged or closed).

@mav-adhoc
mav-adhoc force-pushed the 19.0-18.0-h-122297-mav-7166-fw branch 2 times, most recently from cb8763c to d776f3d Compare August 20, 2026 19:16
`__filter` called `_compute_display_name()` directly. Outside the ORM compute protocol that assignment goes through Field.__set__'s business-logic path and issues a real write() on the rendered model instead of only updating the cache. Printing an aeroo report as a user without write access on that model (e.g. res.country, writable only by the Settings group) raised AccessError; it also returned None so the value was not rendered.

Read display_name instead (computed into cache, no write), restoring the original name_get()[0][1] behaviour.

X-original-commit: b5f73b1
@mav-adhoc
mav-adhoc force-pushed the 19.0-18.0-h-122297-mav-7166-fw branch from d776f3d to 61cc3ae Compare August 20, 2026 19:17
@jcadhoc

jcadhoc commented Aug 21, 2026

Copy link
Copy Markdown

@roboadhoc r+ nobump

roboadhoc pushed a commit that referenced this pull request Aug 21, 2026
`__filter` called `_compute_display_name()` directly. Outside the ORM compute protocol that assignment goes through Field.__set__'s business-logic path and issues a real write() on the rendered model instead of only updating the cache. Printing an aeroo report as a user without write access on that model (e.g. res.country, writable only by the Settings group) raised AccessError; it also returned None so the value was not rendered.

Read display_name instead (computed into cache, no write), restoring the original name_get()[0][1] behaviour.

closes #97

X-original-commit: b5f73b1
Signed-off-by: Filoquin adhoc <maq@adhoc.com.ar>
Signed-off-by: Juan Carreras <jc@adhoc.com.ar>
@roboadhoc roboadhoc closed this in 2788d94 Aug 21, 2026
@roboadhoc
roboadhoc deleted the 19.0-18.0-h-122297-mav-7166-fw branch August 21, 2026 15:47
@roboadhoc roboadhoc added the 18.1 label Aug 21, 2026

This branch was successfully deployed

1 active deployment
merge — 61cc3ae8 Deployed Aug 21, 2026 by roboadhoc
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants