On 25/06/13 15:57 +0200, Jean C wrote:
> > For me, validation should never depend on the user but maybe I miss a
> > case?
> >
> 
> Only thing I can imagine is if the validation needs to access
> read-protected data,
> but it does not seem to be affected by your change.

in _validate, root user is used to read records.

> I even think validation
> should
> be "sudo-ed" in order to be sure that no check method relies on the
> Transaction's
> user.

It was discussed when replacing _constraints by validate method but it
was decided to let it to be managed by developpers if needed otherwise
it would have required to decorate every validate method with the same
decorator.

-- 
Cédric Krier

B2CK SPRL
Rue de Rotterdam, 4
4000 Liège
Belgium
Tel: +32 472 54 46 59
Email/Jabber: [email protected]
Website: http://www.b2ck.com/

Attachment: pgpxAb5mPQh83.pgp
Description: PGP signature

Reply via email to