Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
erp5 erp5
  • Project overview
    • Project overview
    • Details
    • Activity
    • Releases
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Labels
    • Labels
  • Merge requests 136
    • Merge requests 136
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Operations
    • Operations
    • Environments
  • Analytics
    • Analytics
    • CI/CD
    • Repository
    • Value Stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Activity
  • Graph
  • Jobs
  • Commits
Collapse sidebar
  • nexedi
  • erp5erp5
  • Merge requests
  • !1957

Closed
Created Jun 18, 2024 by Titouan Soulard@tsoulardDeveloper
  • Report abuse
Report abuse

erp5_core: add `getVariationCategoryItemList` to `InventoryListBrain`

  • Overview 12
  • Commits 1
  • Pipelines 1
  • Changes 1

Description of the problem

When viewing inventory report dialog as a regular user (without access to portal_simulation), the following error occurs:

Error Type: Unauthorized
Error Value: You are not allowed to access 'getVariationCategoryItemList' in this context

This arises from the Resource_viewInventoryDialog view, which tries to access getVariationCategoryItemList.

Proposed solution

In order to fix it, I added getVariationCategoryItemList to the list of getters in InventoryListBrain, hence bypassing restriction on portal_simulation, which is not accessible by regular user.

I am not sure this is what needs to be done, and do not know how it could have worked in the past if it had (seems to be, but unsure if prod had been patched manually).

Especially, I saw https://lab.nexedi.com/nexedi/erp5-nexedi/-/commit/e8bf128401fed5237f5d2b04c8e7b85ea066b62f by @yusei, which I do not understand and seems to have a name close to what I would like. The added method getVariationCategoryValueListDict does not seems to be used anywhere, so would anyone be able to explain why it was introduced? And if it should be used instead of the one I am trying to fix?

/cc @romain @jerome @yusei

Assignee
Assign to
Reviewer
Request review from
None
Milestone
None
Assign milestone
Time tracking
Source branch: for-mr-caterpillar
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7