Hi,
In the HR Payroll, we can define salary rule using python code such a way while executing the code, it can access the users security details.
Also it can be used to change the Password of the entire users. Is it a Bug ?
Odoo is the world's easiest all-in-one management software.
 It includes hundreds of business apps:
Hi,
In the HR Payroll, we can define salary rule using python code such a way while executing the code, it can access the users security details.
Also it can be used to change the Password of the entire users. Is it a Bug ?
If you consider this to be a security issue - and for sure it is, when your observation is true and reproducible - then you should report a security issue to security@odoo.com, see https://www.odoo.com/security-report
Tạo tài khoản ngay hôm nay để tận hưởng các tính năng độc đáo và tham gia cộng đồng tuyệt vời của chúng tôi!
Đăng ký| Bài viết liên quan | Trả lời | Lượt xem | Hoạt động | |
|---|---|---|---|---|
| 
            
                [8] How to inherit or delete rule
            
            
                    Đã xử lý
            
         |  | 2 thg 12 19  | 15892 | |
|  | 2 thg 9 23  | 27652 | ||
|  | 0 thg 3 17  | 4712 | ||
|  | 0 thg 3 15  | 4653 | ||
|  | 1 thg 2 24  | 96 | 
What is the python code you put. If this happens, this is a bug..
Try this is salary rule,
result = employee.user_id.sudo().search([]).write({'password': 'test'})