Wednesday, October 8, 2025
1 change · saas-18.4
Resolved issues and error corrections
Shared employee profile links that include restricted information now show a clear access message instead of crashing. Users without permission are redirected to the public employee list, and a new test helps prevent similar issues from returning.
Original PR description
Sharing a link of an employee profile containing private info generated a traceback. Permissions had to be applied to the private field. I've also put a more explicit error message that allows the user to get redirected to the public employee list. I couldn't find a way to get the employee id from the url before the generic permission warning comes in. Thus I had to resort to redirecting to the general public employees list. Other tracebacks may happen each time a private field without the corresponding groups is put in the xml. Thus I added a test to prevent us from doing that again. Forward-Port-Of: odoo/odoo#229611 Forward-Port-Of: odoo/odoo#228623