Skip to content

[IMP] helpdesk_mgmt_fieldservice: review fsm_order_close_wizard security - #1092

Open
SirPyTech wants to merge 2 commits into
OCA:18.0from
PyTech-SRL:18.0-helpdesk-wizard-security
Open

SirPyTech wants to merge 2 commits into
OCA:18.0from
PyTech-SRL:18.0-helpdesk-wizard-security

Conversation

@SirPyTech

Copy link
Copy Markdown
Contributor

Proposing again a fix that was already proposed for 14.0 in #593 and #404, and for 16.0 in #921 (including a test 🚀) hoping the 4th time's the charm 🍀


This commit reviews the security rules around the fsm_order_close_wizard.

The "Complete" button on the fsm.order triggered an access error for fieldservice.group_fsm_user_own. The commit allows fieldservice.group_fsm_user_own to use the wizard as well. However, the wizard is now only shown if the user also has write permission on the specific ticket (so as to play nice with a variety of setups, including helpdesk_mgmt.group_helpdesk_user_own).

If the user has permission to write on the ticket, the wizard will be shown as before; otherwise it will simply be skipped, but the fsm.order will be closed as it should.

There's also some code cleanup on the wizard, such as removing the unused team_id field.

@OCA-git-bot OCA-git-bot added series:18.0 mod:helpdesk_mgmt_fieldservice Module helpdesk_mgmt_fieldservice labels Aug 25, 2026
@SirPyTech
SirPyTech force-pushed the 18.0-helpdesk-wizard-security branch from 4ee59f2 to 2463372 Compare August 25, 2026 08:09
This commit reviews the security rules around the fsm_order_close_wizard.

The "Complete" button on the fsm.order triggered an access error for fieldservice.group_fsm_user_own. The commit allows fieldservice.group_fsm_user_own to use the wizard as well. However, the wizard is now only shown if the user also has write permission on the specific ticket (so as to play nice with a variety of setups, including helpdesk_mgmt.group_helpdesk_user_own).

If the user has permission to write on the ticket, the wizard will be shown as before; otherwise it will simply be skipped, but the fsm.order will be closed as it should.

There's also some code cleanup on the wizard, such as removing the unused team_id field.

Co-authored-by: Simone Rubino <simone.rubino@pytech.it>
@SirPyTech
SirPyTech force-pushed the 18.0-helpdesk-wizard-security branch from 2463372 to a1b5267 Compare August 25, 2026 08:29

@HekkiMelody HekkiMelody left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review, LGTM

Comment thread helpdesk_mgmt_fieldservice/models/fsm_order.py
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

mod:helpdesk_mgmt_fieldservice Module helpdesk_mgmt_fieldservice series:18.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants