Tuesday, September 15, 2026
2 changes · 17.0
Security fixes and vulnerability patches
This change closes a privacy gap where employee referrers could download attachments from job applicants they were not allowed to view. Applicant attachments are now filtered so users only see files for candidates they are authorized to access, helping protect sensitive recruitment documents.
Original PR description
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce:…
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce: ---------------------------------------- - Install hr_recruitment and hr_referral - Create two applicants for the same job position - Make another user the interviewer of the first one and the referrer of the second - Add an attachment to the second user - Connect as this user - In recruitment, go to the job position page - Click on the attachment button at the top - The user can download the attachment even though they can't access the applicant because they aren't their interviewer Cause: ---------------------------------------- The rule `hr_applicant_referral_user_rule` gives a referrer read access to the `hr.applicant` record they referred, so we can show them a few safe fields (`partner_name`, `job_id`, etc.). But they cannot see the applicant because of the field `is_accessible_to_current_user` added in `hr_referral` to prevent access to non interviewer users. `action_open_attachments` lists attachments of every application on the job from `application_ids`, without checking `is_accessible_to_current_user`, so it leaks attachments of applications the current user can only access as a referrer. Solution: ---------------------------------------- Create `_get_attachments_domain()` which will check `is_accessible_to_current_user` with an override in `hr_referral`. opw-6446049
Referrers can no longer download attachments from referred applicants through the job position page when they do not have permission to view those applicants. This protects sensitive recruitment documents by ensuring attachment access follows the same visibility rules as applicant records.
Original PR description
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce:…
Issue: ---------------------------------------- A referrer could open and download the attachments of an applicant they referred without any right to see that applicant's. Steps to reproduce: ---------------------------------------- - Install hr_recruitment and hr_referral - Create two applicants for the same job position - Make another user the interviewer of the first one and the referrer of the second - Add an attachment to the second user - Connect as this user - In recruitment, go to the job position page - Click on the attachment button at the top - The user can download the attachment even though they can't access the applicant because they aren't their interviewer Cause: ---------------------------------------- The rule `hr_applicant_referral_user_rule` gives a referrer read access to the `hr.applicant` record they referred, so we can show them a few safe fields (`partner_name`, `job_id`, etc.). But they cannot see the applicant because of the field `is_accessible_to_current_user` added in `hr_referral` to prevent access to non interviewer users. `action_open_attachments` lists attachments of every application on the job from `application_ids`, without checking `is_accessible_to_current_user`, so it leaks attachments of applications the current user can only access as a referrer. Solution: ---------------------------------------- Create `_get_attachments_domain()` which will check `is_accessible_to_current_user` with an override in `hr_referral`. opw-6446049