dms icon indicating copy to clipboard operation
dms copied to clipboard

Locked attachments can still be deleted from the chatter of an object

Open lorenzomorandini opened this issue 1 year ago • 5 comments

Module

DMS

Describe the bug

Locking an attachment of an object (example an attachment of an invoice) thru DMS still allows for the attachment to be deleted from the chatter of the invoice.

Expected behavior Deleting / modifying the attachment from the invoice should be blocked as well.

Tested on Odoo 16.

lorenzomorandini avatar Dec 09 '24 14:12 lorenzomorandini

could you review this PR #385 to see if the issue is solved or not?

kobros-tech avatar Mar 25 '25 02:03 kobros-tech

According to the defined rule https://github.com/OCA/dms/blob/16.0/dms/security/security.xml#L63 users will be able to delete files if they have locked them themselves (regardless of how they try to delete them).

victoralmau avatar Mar 25 '25 07:03 victoralmau

Closing this as no issue then.

pedrobaeza avatar Mar 25 '25 07:03 pedrobaeza

Sorry, my bad for not being clear enough. The problem is that:

  • User A blocks a file
  • User B can not delete it thru DMS but can delete it thru attachment

User A is an administrator, user B is a normal DMS user.

lorenzomorandini avatar Mar 25 '25 08:03 lorenzomorandini

OK, reopening it.

pedrobaeza avatar Mar 25 '25 08:03 pedrobaeza