From 15f27b2614a4d6f86ded20fc7b3d8e796a2db078 Mon Sep 17 00:00:00 2001 From: Denis Ledoux Date: Fri, 18 Mar 2016 18:45:12 +0100 Subject: [PATCH] [FIX] website_sale: always re-render the `pay now` button Before this revision, when a user tried to pay his cart with a first acquirer e.g. Ogone then came back to the shop (using the browser back button) then chose another acquirer e.g. Paypal a new transaction is created, due to the change of acquirer (following revision cb9d798) and therefore, the transaction has a new reference compared to the last payment transaction attempt (e.g. the ogone one) but, the old reference is still referenced within the `Pay now` form values, because the page wasn't re-rendered, because the user pressed the browser back button, and this doesn't refresh/re-render the page, and, therefore, the old reference was still referenced within the `Pay Now` form values. Therefore, the wrong reference was sent to the acquirer (e.g. paypal) and this prevented the payment validation at the payment feedback, as the new reference was expected in the feedback information, while we receive the older one. This revision makes sure to always re-render the `Pay now` form, so the transaction reference, as well as the other possible changes in the values, are correctly set, before sending the information to the acquirer. --- addons/website_quote/controllers/main.py | 22 ++++++++++++++++--- .../static/src/js/website_quotation.js | 6 +++-- addons/website_sale/controllers/main.py | 17 ++++++++++---- .../static/src/js/website_sale_payment.js | 4 ++-- 4 files changed, 38 insertions(+), 11 deletions(-) diff --git a/addons/website_quote/controllers/main.py b/addons/website_quote/controllers/main.py index 62c99412c31..122b72ff7a6 100644 --- a/addons/website_quote/controllers/main.py +++ b/addons/website_quote/controllers/main.py @@ -67,7 +67,7 @@ class sale_quote(http.Controller): for acquirer in values['acquirers']: acquirer.button = payment_obj.render( request.cr, SUPERUSER_ID, acquirer.id, - order.name, + '/', order.amount_total, order.pricelist_id.currency_id.id, values={ @@ -162,6 +162,10 @@ class sale_quote(http.Controller): # note dbo: website_sale code @http.route(['/quote//transaction/'], type='json', auth="public", website=True) def payment_transaction(self, acquirer_id, order_id): + return self.payment_transaction_token(acquirer_id, order_id, None) + + @http.route(['/quote//transaction//'], type='json', auth="public", website=True) + def payment_transaction_token(self, acquirer_id, order_id, token): """ Json method that creates a payment.transaction, used to create a transaction when the user clicks on 'pay now' button. After having created the transaction, the event continues and the user is redirected @@ -171,6 +175,7 @@ class sale_quote(http.Controller): user is redirected to the checkout page """ cr, uid, context = request.cr, request.uid, request.context + payment_obj = request.registry.get('payment.acquirer') transaction_obj = request.registry.get('payment.transaction') order = request.registry.get('sale.order').browse(cr, SUPERUSER_ID, order_id, context=context) @@ -211,5 +216,16 @@ class sale_quote(http.Controller): # confirm the quotation if tx.acquirer_id.auto_confirm == 'at_pay_now': request.registry['sale.order'].action_confirm(cr, SUPERUSER_ID, [order.id], context=dict(request.context, send_email=True)) - - return tx_id + return payment_obj.render( + request.cr, SUPERUSER_ID, tx.acquirer_id.id, + tx.reference, + order.amount_total, + order.pricelist_id.currency_id.id, + values={ + 'return_url': '/quote/%s/%s' % (order_id, token) if token else '/quote/%s' % order_id, + 'type': 'form', + 'alias_usage': _('If we store your payment information on our server, subscription payments will be made automatically.'), + 'partner_id': order.partner_shipping_id.id or order.partner_invoice_id.id, + 'billing_partner_id': order.partner_invoice_id.id, + }, + context=dict(context, submit_class='btn btn-primary', submit_txt=_('Pay & Confirm'))) diff --git a/addons/website_quote/static/src/js/website_quotation.js b/addons/website_quote/static/src/js/website_quotation.js index cd821bf4f77..3221eeba0a4 100644 --- a/addons/website_quote/static/src/js/website_quotation.js +++ b/addons/website_quote/static/src/js/website_quotation.js @@ -209,8 +209,10 @@ odoo.define('website_quote.payment_method', function (require) { } var href = $(location).attr("href"); var order_id = href.match(/quote\/([0-9]+)/)[1]; - ajax.jsonRpc('/quote/' + order_id +'/transaction/' + acquirer_id, 'call', {}).then(function (data) { - $form.submit(); + var token = href.match(/quote\/[0-9]+\/([^\/?]*)/); + token = token ? token[1] : ''; + ajax.jsonRpc('/quote/' + order_id +'/transaction/' + acquirer_id + (token ? '/' + token : ''), 'call', {}).then(function (data) { + $(data).submit(); }); }); }); diff --git a/addons/website_sale/controllers/main.py b/addons/website_sale/controllers/main.py index fbb338cba53..e7dcd52a0b4 100644 --- a/addons/website_sale/controllers/main.py +++ b/addons/website_sale/controllers/main.py @@ -764,15 +764,13 @@ class website_sale(http.Controller): values.update(sale_order_obj._get_website_data(cr, uid, order, context)) if not values['errors']: - # find an already existing transaction - tx = request.website.sale_get_transaction() acquirer_ids = payment_obj.search(cr, SUPERUSER_ID, [('website_published', '=', True), ('company_id', '=', order.company_id.id)], context=context) values['acquirers'] = list(payment_obj.browse(cr, uid, acquirer_ids, context=context)) render_ctx = dict(context, submit_class='btn btn-primary', submit_txt=_('Pay Now')) for acquirer in values['acquirers']: acquirer.button = payment_obj.render( cr, SUPERUSER_ID, acquirer.id, - tx and tx.reference or request.env['payment.transaction'].get_next_reference(order.name), + '/', order.amount_total, order.pricelist_id.currency_id.id, values={ @@ -795,6 +793,7 @@ class website_sale(http.Controller): user is redirected to the checkout page """ cr, uid, context = request.cr, request.uid, request.context + payment_obj = request.registry.get('payment.acquirer') transaction_obj = request.registry.get('payment.transaction') order = request.website.sale_get_order(context=context) @@ -839,7 +838,17 @@ class website_sale(http.Controller): if tx.acquirer_id.auto_confirm == 'at_pay_now': request.registry['sale.order'].action_confirm(cr, SUPERUSER_ID, [order.id], context=dict(request.context, send_email=True)) - return tx_id + return payment_obj.render( + request.cr, SUPERUSER_ID, tx.acquirer_id.id, + tx.reference, + order.amount_total, + order.pricelist_id.currency_id.id, + values={ + 'return_url': '/shop/payment/validate', + 'partner_id': order.partner_shipping_id.id or order.partner_invoice_id.id, + 'billing_partner_id': order.partner_invoice_id.id, + }, + context=dict(context, submit_class='btn btn-primary', submit_txt=_('Pay Now'))) @http.route('/shop/payment/get_status/', type='json', auth="public", website=True) def payment_get_status(self, sale_order_id, **post): diff --git a/addons/website_sale/static/src/js/website_sale_payment.js b/addons/website_sale/static/src/js/website_sale_payment.js index 3166bd2b9c0..d16a91b8b86 100644 --- a/addons/website_sale/static/src/js/website_sale_payment.js +++ b/addons/website_sale/static/src/js/website_sale_payment.js @@ -29,8 +29,8 @@ $(document).ready(function () { if (! acquirer_id) { return false; } - ajax.jsonRpc('/shop/payment/transaction/' + acquirer_id, 'call', {}).then(function () { - $form.submit(); + ajax.jsonRpc('/shop/payment/transaction/' + acquirer_id, 'call', {}).then(function (data) { + $(data).submit(); }); });