Skip to content

Conversation

@clementmbr
Copy link
Member

Currently Odoo is writing on a commercial_partner when doing _compute_risk_sale_order() on a partner (two different records).

It is against the expected behavior of a non-stored readonly computed field and can create security problems as the commercial_partner record is not necessary accessible by the Odoo user who is accessing the current partner's record.

cc @sebastienbeau

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant