Locked attachments can still be deleted from the chatter of an object
Module
DMS
Describe the bug
Locking an attachment of an object (example an attachment of an invoice) thru DMS still allows for the attachment to be deleted from the chatter of the invoice.
Expected behavior Deleting / modifying the attachment from the invoice should be blocked as well.
Tested on Odoo 16.
could you review this PR #385 to see if the issue is solved or not?
According to the defined rule https://github.com/OCA/dms/blob/16.0/dms/security/security.xml#L63 users will be able to delete files if they have locked them themselves (regardless of how they try to delete them).
Closing this as no issue then.
Sorry, my bad for not being clear enough. The problem is that:
- User A blocks a file
- User B can not delete it thru DMS but can delete it thru attachment
User A is an administrator, user B is a normal DMS user.
OK, reopening it.