Thursday, July 30, 2020
1 change · master
Security fixes and vulnerability patches
This fixes permissions so Expense Team Approvers only have the access needed for expense approvals, rather than broad accounting capabilities. It reduces the risk of users viewing or changing accounting data outside their role.
Original PR description
1. Apply same logic for sale and purchase user. 2. The group Expense Team Approuver can write/create/unlink, it is opposite than https://github.com/odoo/odoo/blob/13.0/addons/hr_expense/security/ir.model.access.csv#L15 and https://github.com/odoo/odoo/blob/13.0/addons/hr_expense/security/ir.model.access.csv#L16 opw:2275116