Daily updates from Odoo
Tuesday, July 7, 2026
1 change · saas-19.3
Security fixes and vulnerability patches
The Sign app now prevents Auto write from being enabled in situations where it could update records unintentionally or without a valid linked field. This reduces the risk of accidental or unauthorized changes to sensitive information while improving feedback when automatic updates cannot be completed.
Original PR description
Fix scenarios where the auto-write feature could fail or be unsafe: - Prevent unsafe mass updates: Users could enable auto-write in bulk without proper awareness, leading to unintended behavior. Additionally, the field could be manually exposed even when no linked model/field is set. we add safeguards and constraints to prevent enabling it in invalid cases. - Improve test coverage: Update test cases to ensure correct behavior when users have access to partner records but must not be allowed to update sensitive fields (e.g., email) of other users through those records. task-6147410