# Function field inside form doesn't respect record rules

**URL:** https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395
**Category:** Developer
**Created:** [June 29, 2022, 3:23pm UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395 "2022-06-29T15:23:41Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![edbo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/e/f14d63/32.png) [@edbo](https://discuss.tryton.org/u/edbo)
#### Post date: [June 29, 2022, 3:23pm UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/1 "2022-06-29T15:23:41Z")

</div>

First, I’m upgrading an installation from 5.4 to version 6.4. Everything went smooth until access rights (which was kind of expected).

In this case we have a form where timesheet lines are shown. This is a `Function` field (`one2many`) which gets the timesheet lines based on the timesheet added (`many2one` from `timesheet.work`). This gives something like:

```python
timesheet = fields.Many2One('timesheet.work', 'Timesheet')
timesheet_lines = fields.Function(
    fields.One2Many('timesheet.line', None, 'Timesheet Lines',
        domain=[('work', '=', Eval('timesheet'))],
        depends=['timesheet']), '_get_timesheet_lines')

def _get_timesheet_lines(self, name):
    if self.timesheet:
        return [t.id for t in self.timesheet.timesheet_lines]
    return []

```

The timesheet lines then are restricted to only show the timesheet lines of the user. For this a new group was created and a new `Record Rule` added to the group which filters the timesheet lines based on the `employee`. This is where things go wrong. We now get an `UserError` which says that the user is not allowed to read records with `id ... ...` etc. And the list of timesheet lines is empty.

We tracked the error back to version 6.0. From that version the error shows up. The strange thing is that when the user directly goes to `Timesheet -> Lines` via the menu, it still works. The user only gets it’s own timesheet lines.

It seems we clearly missing something here. In the release notes of version 6.0 there is a sentence saying:

“The record rules are now only applied if `_check_access` is set in the context. This improves the multi-company support.”

Adding a print statement to the `_get_timesheet_lines` indeed the `_check_access` is `False`. Change the `_check_access` to `True` didn’t help either.

```auto
def _get_timesheet_lines(self, name):
    with Transaction().set_context(_check_access=True):
        if self.timesheet:
            return [t.id for t in self.timesheet.timesheet_lines]
    return []

```

What are we doing wrong here?

Adding an extra domain to the list is not an option because a group higher up is allowed to see all the timesheet lines from all the users on that timesheet.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [June 29, 2022, 4:40pm UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/2 "2022-06-29T16:40:54Z")

</div>

> [@edbo](#):
>
> “The record rules are now only applied if `_check_access` is set in the context. This improves the multi-company support.”

You are right this is what changed.

> [@edbo](#):
>
> Adding a print statement to the `_get_timesheet_lines` indeed the `_check_access` is `False`. Change the `_check_access` to `True` didn’t help either.

Because context applies only a new instances. You must make the search yourself to fill the function field.

PS:

> [@edbo](#):
>
> `domain=[('work', '=', Eval('timesheet'))],`

domain is pointless on Function fields without setter.

---

<div class="post-metadata">

### Author: ![edbo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/e/f14d63/32.png) [@edbo](https://discuss.tryton.org/u/edbo)
#### Post date: [June 29, 2022, 5:50pm UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/3 "2022-06-29T17:50:06Z")

</div>

> [@ced](#):
>
> > [@edbo](#):
> >
> > Adding a print statement to the `_get_timesheet_lines` indeed the `_check_access` is `False`. Change the `_check_access` to `True` didn’t help either.
> 
> Because context applies only a new instances. You must make the search yourself to fill the function field.

You lost me here. Do I need to do a `Pool().get('timesheet.line').search(...)` to get the ids?

> [@ced](#):
>
> PS:
> 
> > [@edbo](#):
> >
> > `domain=[('work', '=', Eval('timesheet'))],`
> 
> domain is pointless on Function fields without setter.

Correct, there is a setter but for clarity I removed it here.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [June 29, 2022, 10:06pm UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/4 "2022-06-29T22:06:41Z")

</div>

> [@edbo](#):
>
> You lost me here. Do I need to do a `Pool().get('timesheet.line').search(...)` to get the ids?

Yes with the context `_check_access` set so the rule domain will be applied.

---

<div class="post-metadata">

### Author: ![edbo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/e/f14d63/32.png) [@edbo](https://discuss.tryton.org/u/edbo)
#### Post date: [June 30, 2022, 8:53am UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/5 "2022-06-30T08:53:47Z")

</div>

I changed the function to

```auto
def _get_timesheet_lines(self, name):
    pool = Pool()
    Lines = pool.get('timesheet.line')
    with Transaction().set_context(_check_access=True):
        if self.timesheet:
            lines = Lines.search(['work', '=', self.timesheet])
            return [t.id for t in lines]
    return []

```

And now the error is gone.

---

<div class="post-metadata">

### Author: ![JCavallo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/j/48db29/32.png) [@JCavallo](https://discuss.tryton.org/u/JCavallo)
#### Post date: [July 1, 2022, 7:29am UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/6 "2022-07-01T07:29:58Z")

</div>

For performances, I would suggest to convert the getter to a `classmethod`, to avoid looping searches if you need to load this field on multiple records at once

---

<div class="post-metadata">

### Author: ![edbo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/e/f14d63/32.png) [@edbo](https://discuss.tryton.org/u/edbo)
#### Post date: [July 1, 2022, 8:38am UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/7 "2022-07-01T08:38:07Z")

</div>

Thanks for the suggestion, but as the title says, this is inside a form. So no looping searches here. It’s even faster because there are less timesheet lines.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [July 1, 2022, 9:15am UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/8 "2022-07-01T09:15:30Z")

</div>

Another way would be to use a relate instead of a One2Many if there are a lot of timesheet lines. It also add the possibility to filter.

---

<div class="post-metadata">

### Author: ![edbo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/e/f14d63/32.png) [@edbo](https://discuss.tryton.org/u/edbo)
#### Post date: [July 1, 2022, 9:34am UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/9 "2022-07-01T09:34:33Z")

</div>

The user has also the possibility to add new timesheet lines from that `One2Many` which is working perfectly. Also the amount of timesheet lines are not that huge and most of the timesheets only contains two or three timesheet lines.

But what is a `relate`?

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [July 1, 2022, 9:36am UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/10 "2022-07-01T09:36:57Z")

</div>

> [@edbo](#):
>
> The user has also the possibility to add new timesheet lines from that `One2Many` which is working perfectly.

With a relate action it is also possible to add new record.

> [@edbo](#):
>
> But what is a `relate`?

It is an action with the keyword `form_relate` and a domain that is using `active_id`.

---

<div class="post-metadata">

### Author: ![edbo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/e/f14d63/32.png) [@edbo](https://discuss.tryton.org/u/edbo)
#### Post date: [July 1, 2022, 9:53am UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/11 "2022-07-01T09:53:09Z")

</div>

> [@ced](#):
>
> > [@edbo](#):
> >
> > But what is a `relate`?
> 
> It is an action with the keyword `form_relate` and a domain that is using `active_id`.

Ah, that one. It then will open a new tab with the timesheet lines. In this case that’s not something the user wants because now they have everything in one overview, can compare and confirm everything if needed.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [July 1, 2022, 9:56am UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/12 "2022-07-01T09:56:11Z")

</div>

> [@edbo](#):
>
> In this case that’s not something the user wants

Users are often wrong about UX decision 😉

---

<div class="post-metadata">

### Author: ![system](https://discuss-cdn.tryton.org/uploads/default/original/1X/c6f8ec0a40525cdcd50058c734283450a4b3d38b.png) [@system](https://discuss.tryton.org/u/system)
#### Post date: [July 31, 2022, 9:57am UTC](https://discuss.tryton.org/t/function-field-inside-form-doesnt-respect-record-rules/5395/13 "2022-07-31T09:57:05Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
