Monday, September 14, 2026
3 changes · master
Security fixes and vulnerability patches
Project and task access is now managed separately from follower notifications, so customers and team members can keep visibility without receiving unwanted chatter emails. The update also adds clearer read-only and edit sharing modes, improves portal task assignment, and prevents sensitive sharing links from being exposed in chatter.
Original PR description
Currently, portal users get access to the projects and tasks they follow. This tightly couples communication with access rights, creating a frustrating experience for customers: they receive chatter…
Currently, portal users get access to the projects and tasks they follow. This tightly couples communication with access rights, creating a frustrating experience for customers: they receive chatter notifications about tasks they are not actively interested in, but if they unfollow to stop the spam, they completely lose access to view the task. This PR fundamentally separates the concepts of "followers" (communication) and "collaborators" (access rights), allowing us to decouple email notifications from project and task visibility. ### Implementation & Progression This refactoring was implemented in distinct phases : Collaborator Split for Edit Access: Migrated portal users with limited_edit access away from the follower-based access model, relying instead on explicit project.collaborator records and shifting the restriction from row level to fields level. Read-Only Project Sharing: Introduced a new read-only project sharing view. This allows us to support collaborators with view access, ensuring they can browse the portal without needing to be injected into the followers list. Internal User Split: Extended the collaborator/follower separation to internal users to unify the access logic across all user types. task-6453619
Point of Sale self-invoicing now prevents unauthorized changes to customer records and checks that required invoicing details are present before creating invoices. This protects customer data integrity while still allowing valid users to complete invoicing, and includes a small ticket screen display fix.
Original PR description
Before this commit: ------------------- - During self-invoicing, a public user could create a new customer or update the current order's customer data by submitting the self-invoicing form, without any access rights validation. - For logged-in users (portal or internal), invoice generation could proceed even when the user or the selected customer lacked the required invoicing information. After this commit: ------------------- - During self-invoicing, a public user can create a new customer for the order, but cannot modify the existing customer linked to the order. - For logged-in users (portal or internal), required customer information is validated before generating an invoice. Customer data can only be updated when the customer is the logged-in user's partner or a child contact of that partner. Extra fix: - Handling fix for numpad visible for draft order in ticket screen. Task-6272660 Forward-Port-Of: odoo/odoo#287482 Forward-Port-Of: odoo/odoo#270112
This update fixes cases where portal users could change a task status but were blocked by related deadline permissions. It also tightens access around private project timesheets and prevents task creation from shared Gantt views when required deadline fields are read-only.
Original PR description
in some cases portal users can update state but they are not allowed to update date_deadline task: 6453619