[tryton-debian-vcs] tryton-server branch upstream-3.4 updated. upstream/3.4.9-1-gb68496e
Mathias Behrle
tryton-debian-vcs at alioth.debian.org
Wed Feb 10 19:55:48 UTC 2016
The following commit has been merged in the upstream-3.4 branch:
https://alioth.debian.org/plugins/scmgit/cgi-bin/gitweb.cgi/?p=tryton/tryton-server.git;a=commitdiff;h=upstream/3.4.9-1-gb68496e
commit b68496e721c049ad29cc5be175acd24a54172490
Author: Mathias Behrle <mathiasb at m9s.biz>
Date: Wed Feb 10 18:23:33 2016 +0100
Adding upstream version 3.4.10.
Signed-off-by: Mathias Behrle <mathiasb at m9s.biz>
diff --git a/CHANGELOG b/CHANGELOG
index d01024b..65627ee 100644
--- a/CHANGELOG
+++ b/CHANGELOG
@@ -1,3 +1,8 @@
+Version 3.4.10 - 2016-02-06
+* Bug fixes (see mercurial logs for details)
+* Don't read historized user when evaluating record rules as it could lead to
+ past privilege escalation.
+
Version 3.4.9 - 2016-01-11
* Bug fixes (see mercurial logs for details)
diff --git a/PKG-INFO b/PKG-INFO
index 216949e..cbc5848 100644
--- a/PKG-INFO
+++ b/PKG-INFO
@@ -1,6 +1,6 @@
Metadata-Version: 1.1
Name: trytond
-Version: 3.4.9
+Version: 3.4.10
Summary: Tryton server
Home-page: http://www.tryton.org/
Author: Tryton
diff --git a/trytond.egg-info/PKG-INFO b/trytond.egg-info/PKG-INFO
index 216949e..cbc5848 100644
--- a/trytond.egg-info/PKG-INFO
+++ b/trytond.egg-info/PKG-INFO
@@ -1,6 +1,6 @@
Metadata-Version: 1.1
Name: trytond
-Version: 3.4.9
+Version: 3.4.10
Summary: Tryton server
Home-page: http://www.tryton.org/
Author: Tryton
diff --git a/trytond/ir/rule.py b/trytond/ir/rule.py
index 0c60fe7..16fddce 100644
--- a/trytond/ir/rule.py
+++ b/trytond/ir/rule.py
@@ -142,7 +142,7 @@ class Rule(ModelSQL, ModelView):
def _get_context():
User = Pool().get('res.user')
user_id = Transaction().user
- with Transaction().set_context(_check_access=False):
+ with Transaction().set_context(_check_access=False, _datetime=None):
user = User(user_id)
return {
'user': user,
diff --git a/trytond/version.py b/trytond/version.py
index 913ed6b..f40efab 100644
--- a/trytond/version.py
+++ b/trytond/version.py
@@ -1,6 +1,6 @@
#This file is part of Tryton. The COPYRIGHT file at the top level of
#this repository contains the full copyright notices and license terms.
PACKAGE = "trytond"
-VERSION = "3.4.9"
+VERSION = "3.4.10"
LICENSE = "GPL-3"
WEBSITE = "http://www.tryton.org/"
--
tryton-server
More information about the tryton-debian-vcs
mailing list