Skip to content

[18.0][FIX] sale_financial_risk: avoid writing on commercial_partner during compute on partner#536

Open
clementmbr wants to merge 1 commit intoOCA:18.0from
akretion:18-fix-sale-financial-risk
Open

[18.0][FIX] sale_financial_risk: avoid writing on commercial_partner during compute on partner#536
clementmbr wants to merge 1 commit intoOCA:18.0from
akretion:18-fix-sale-financial-risk

Conversation

@clementmbr
Copy link
Member

Currently Odoo is writing on a commercial_partner when doing _compute_risk_sale_order() on a partner (two different records).

It is against the expected behavior of a non-stored readonly computed field and can create security problems as the commercial_partner record is not necessary accessible by the Odoo user who is accessing the current partner's record.

cc @sebastienbeau

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant