mirror of
https://github.com/OCA/web.git
synced 2025-02-22 13:21:25 +02:00
Only the admin user (sudo) is allowed to send notifications to other users. The normal users can only send notifications to themselves. This is to prevent attackers to craft malicious notifications and send them to other users using RPC. Correction based on the idea of @hbrunn
24 lines
530 B
Python
24 lines
530 B
Python
# Copyright 2016 ACSONE SA/NV
|
|
# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl).
|
|
|
|
{
|
|
'name': 'Web Notify',
|
|
'summary': """
|
|
Send notification messages to user""",
|
|
'version': '11.0.1.1.0',
|
|
'description': 'Web Notify',
|
|
'license': 'AGPL-3',
|
|
'author': 'ACSONE SA/NV,Odoo Community Association (OCA)',
|
|
'website': 'https://acsone.eu/',
|
|
'depends': [
|
|
'web',
|
|
'bus',
|
|
],
|
|
'data': [
|
|
'views/web_notify.xml'
|
|
],
|
|
'demo': [
|
|
],
|
|
'installable': True,
|
|
}
|