Daily updates from Odoo
Friday, March 29, 2019
1 change
Security fixes and vulnerability patches
This change removes broad attachment read access for portal users, relying instead on specific pages and controllers to grant access only when appropriate. This helps ensure shared documents and digital sale files follow the intended business rules for visibility.
Original PR description
Description of the issue/feature this PR addresses: Current behavior before PR: Desired behavior after PR is merged: -- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr