In 6.1.1 some readonly fields aren't.
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Odoo GTK Client (MOVED TO GITHUB) |
New
|
Undecided
|
Unassigned |
Bug Description
GTK Client 6.1.1
Kubuntu 12.04 and Windows XP
I have a number of fields which are marked readonly using attrs in the view xml, eg.
<field name="truck_
<field name="weigh_
These should (and in 6.0 did) appear grayed out and be uneditable.
In 6.1 they are not grayed out and they are editable.
The integer value is reverted on saving (OK), the date field is not.
If I change 'readonly' to 'invisible' the fields are still displayed.
The web client works as it should.
I won't mark this a security issue but it does mean some of my users can change some data
that they shouldn't be able to.
I tracked it down. In 6.0 the server was testing against True. In 6.1 it tests against False. Explicitly setting permit_write to False if it's not True has solved the problem.