Daily updates from Odoo
Friday, July 17, 2026
3 changes
1 change
Security fixes and vulnerability patches
Employee payroll fields for several country-specific payroll modules are now only visible to authorized payroll users. This helps prevent non-payroll staff from accessing sensitive payroll information and keeps permissions consistent across employee records.
Original PR description
This commit adds `groups="hr_payroll.group_hr_payroll_user"` to all fields displayed inside payroll tab in the form view of employee to make sure those fields are only accessible to payroll users. runbot-error-234071 Forward-Port-Of: odoo/enterprise#123420 Forward-Port-Of: odoo/enterprise#122293
1 change
Security fixes and vulnerability patches
Employee payroll fields in several country payroll modules are now limited to authorized payroll users. This helps prevent non-payroll staff from viewing sensitive payroll-related employee information.
Original PR description
This commit adds `groups="hr_payroll.group_hr_payroll_user"` to all fields displayed inside payroll tab in the form view of employee to make sure those fields are only accessible to payroll users. runbot-error-234071 Forward-Port-Of: odoo/enterprise#123420 Forward-Port-Of: odoo/enterprise#122293
1 change
Security fixes and vulnerability patches
This change prevents database API keys from being exposed through regular application access or accidentally shown in the user interface. It reduces the risk of sensitive credentials being leaked during normal use, including screen sharing or streaming.
Original PR description
The aim of this commit is to harden the security of the `database_api_key` field. Before this commit: The field could be retrieved through the orm and could be leaked if the access rights were bypassed. A streamer pasting the key in the field could also leak his api key by mistake. After this commit: The only way to access the field is through direct SQL access. The api key isn't shown anymore in the UI: - The UI doesn't receive the key from the backend: it receives dummy **** - The field in the form view display dots instead of any char to prevent leaking the key by mistake. Task-id: None Forward-Port-Of: odoo/enterprise#124277 Forward-Port-Of: odoo/enterprise#122163