[tryton-debian-vcs] tryton-server branch debian-jessie-3.4 updated. debian/3.4.9-1-2-g0438647
Mathias Behrle
tryton-debian-vcs at alioth.debian.org
Wed Feb 10 19:55:47 UTC 2016
The following commit has been merged in the debian-jessie-3.4 branch:
https://alioth.debian.org/plugins/scmgit/cgi-bin/gitweb.cgi/?p=tryton/tryton-server.git;a=commitdiff;h=debian/3.4.9-1-2-g0438647
commit 0438647f2be5ed908980e59813f3909af6949e02
Author: Mathias Behrle <mathiasb at m9s.biz>
Date: Wed Feb 10 18:23:34 2016 +0100
Releasing debian version 3.4.10-1.
Signed-off-by: Mathias Behrle <mathiasb at m9s.biz>
diff --git a/debian/changelog b/debian/changelog
index a87d59e..d94c30f 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,9 @@
+tryton-server (3.4.10-1) unstable; urgency=medium
+
+ * Merging upstream version 3.4.10.
+
+ -- Mathias Behrle <mathiasb at m9s.biz> Wed, 10 Feb 2016 18:23:33 +0100
+
tryton-server (3.4.9-1) unstable; urgency=medium
* Merging upstream version 3.4.9.
commit 0d0dd5a1650bd918544150ed7be18e6c03429473
Author: Mathias Behrle <mathiasb at m9s.biz>
Date: Wed Feb 10 18:23:33 2016 +0100
Merging upstream version 3.4.10.
diff --git a/CHANGELOG b/CHANGELOG
index d01024b..65627ee 100644
--- a/CHANGELOG
+++ b/CHANGELOG
@@ -1,3 +1,8 @@
+Version 3.4.10 - 2016-02-06
+* Bug fixes (see mercurial logs for details)
+* Don't read historized user when evaluating record rules as it could lead to
+ past privilege escalation.
+
Version 3.4.9 - 2016-01-11
* Bug fixes (see mercurial logs for details)
diff --git a/PKG-INFO b/PKG-INFO
index 216949e..cbc5848 100644
--- a/PKG-INFO
+++ b/PKG-INFO
@@ -1,6 +1,6 @@
Metadata-Version: 1.1
Name: trytond
-Version: 3.4.9
+Version: 3.4.10
Summary: Tryton server
Home-page: http://www.tryton.org/
Author: Tryton
diff --git a/trytond.egg-info/PKG-INFO b/trytond.egg-info/PKG-INFO
index 216949e..cbc5848 100644
--- a/trytond.egg-info/PKG-INFO
+++ b/trytond.egg-info/PKG-INFO
@@ -1,6 +1,6 @@
Metadata-Version: 1.1
Name: trytond
-Version: 3.4.9
+Version: 3.4.10
Summary: Tryton server
Home-page: http://www.tryton.org/
Author: Tryton
diff --git a/trytond/ir/rule.py b/trytond/ir/rule.py
index 0c60fe7..16fddce 100644
--- a/trytond/ir/rule.py
+++ b/trytond/ir/rule.py
@@ -142,7 +142,7 @@ class Rule(ModelSQL, ModelView):
def _get_context():
User = Pool().get('res.user')
user_id = Transaction().user
- with Transaction().set_context(_check_access=False):
+ with Transaction().set_context(_check_access=False, _datetime=None):
user = User(user_id)
return {
'user': user,
diff --git a/trytond/version.py b/trytond/version.py
index 913ed6b..f40efab 100644
--- a/trytond/version.py
+++ b/trytond/version.py
@@ -1,6 +1,6 @@
#This file is part of Tryton. The COPYRIGHT file at the top level of
#this repository contains the full copyright notices and license terms.
PACKAGE = "trytond"
-VERSION = "3.4.9"
+VERSION = "3.4.10"
LICENSE = "GPL-3"
WEBSITE = "http://www.tryton.org/"
--
tryton-server
More information about the tryton-debian-vcs
mailing list