Repository navigation
[FIX] report_aeroo: avoid display_name write when rendering records - #97
fw-bot-adhoc wants to merge 1 commit into
Conversation
|
@mav-adhoc @maq-adhoc cherrypicking of pull request #96 failed. stdout: Either perform the forward-port manually (and push to this branch, proceeding as usual) or close this PR (maybe?).
More info at https://github.com/odoo/odoo/wiki/Mergebot#forward-port |
|
@mav-adhoc @maq-adhoc this forward port of #96 is awaiting action (not merged or closed). |
3 similar comments
|
@mav-adhoc @maq-adhoc this forward port of #96 is awaiting action (not merged or closed). |
|
@mav-adhoc @maq-adhoc this forward port of #96 is awaiting action (not merged or closed). |
|
@mav-adhoc @maq-adhoc this forward port of #96 is awaiting action (not merged or closed). |
cb8763c to
d776f3d
Compare
`__filter` called `_compute_display_name()` directly. Outside the ORM compute protocol that assignment goes through Field.__set__'s business-logic path and issues a real write() on the rendered model instead of only updating the cache. Printing an aeroo report as a user without write access on that model (e.g. res.country, writable only by the Settings group) raised AccessError; it also returned None so the value was not rendered. Read display_name instead (computed into cache, no write), restoring the original name_get()[0][1] behaviour. X-original-commit: b5f73b1
d776f3d to
61cc3ae
Compare
|
@roboadhoc r+ nobump |
`__filter` called `_compute_display_name()` directly. Outside the ORM compute protocol that assignment goes through Field.__set__'s business-logic path and issues a real write() on the rendered model instead of only updating the cache. Printing an aeroo report as a user without write access on that model (e.g. res.country, writable only by the Settings group) raised AccessError; it also returned None so the value was not rendered. Read display_name instead (computed into cache, no write), restoring the original name_get()[0][1] behaviour. closes #97 X-original-commit: b5f73b1 Signed-off-by: Filoquin adhoc <maq@adhoc.com.ar> Signed-off-by: Juan Carreras <jc@adhoc.com.ar>

Problem
report_aeroorenders every${...}expression through__filter. For recordset values it called_compute_display_name()directly:Calling the compute method outside the ORM compute protocol makes the
record.display_name = ...assignment takeField.__set__'s business-logic branch (odoo/fields.py), which issues a realwrite()on the rendered model instead of only updating the cache.Consequences:
AccessError. This surfaced when a non-admin printed a report that renders ares.countryrecord (e.g.${o.partner_id.country_id}) —res.countryis writable only by the Settings group. It only reproduced when the report was rendered as the acting user (e.g. IoT printing viarender_and_send), not through channels that render elevated.None, so the record was rendered empty.Regression introduced in
fa94921(migration ofname_get()[0][1]→_compute_display_name()).Fix
Read
display_name(computed into cache, no write), restoring the originalname_get()[0][1]semantics:How to verify
Render an aeroo report that outputs a record (e.g.
${o.partner_id.country_id}) as a user without write access on that model (non-admin, no Settings group). Before:AccessErroronres.countryand the value rendered empty. After: renders the display name, no write.Ref: https://www.adhoc.inc/odoo/helpdesk.ticket/122297
Forward-Port-Of: #96