From b2ada74e5d4d1aac47fa34cbce63930e3675a8e4 Mon Sep 17 00:00:00 2001 From: Laurent Mignon Date: Fri, 26 Jun 2015 14:26:28 +0200 Subject: [PATCH] [FIX] fix security issue on account_invoice This fix seems ugly, but I cant figure why I've a security error when an invoice is displayed for a user without right on credit_control despite the attribute 'groups' declared on the field definition in the form view --- account_credit_control/invoice.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/account_credit_control/invoice.py b/account_credit_control/invoice.py index f74be82c0..69b747e8c 100644 --- a/account_credit_control/invoice.py +++ b/account_credit_control/invoice.py @@ -34,6 +34,9 @@ class AccountInvoice(models.Model): "setting.", readonly=True, copy=False, + groups="account_credit_control.group_account_credit_control_manager," + "account_credit_control.group_account_credit_control_user," + "account_credit_control.group_account_credit_control_info", ) credit_control_line_ids = fields.One2many(