From 16f2b3809daae548719e53a4fbe483ba8c3c7fa9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A9bastien=20Theys?= Date: Mon, 23 Dec 2019 13:14:21 +0000 Subject: [PATCH] [FIX] utm: prevent crash on /web/session/destroy MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A similar fix was originally done in [1], where the access to `env` was done before the parent dispatch. The issue was then reintroduced with [2], where the `env` was possibly accessed again after the dispatch. This works most of the time, but in the rare case where the session is destroyed during dispatch, which is the case on `/web/session/destroy`, accessing the environment after that point will crash. This issue didn't manifest before [3], because the `env` was always initialized during `checked_call` when calling the `clear` method on it (since `env` is a magic property). After that commit, the `clear` is not called if not necessary, therefore it might happen that the `env` is never initialized. This leads to the crash when trying to initialize it for the first time after the `db` attribute has been cleared during the destroy, since a `db` is required to initialize it. The current fix aims to prevent the crash. As opposed to [1] that actually kept the tracking fields by fetching them before the dispatch, it is decided on this commit to voluntarily lose the tracking fields when destroying the session, because keeping them would require too much refactoring for a fix in stable, but we also feel that it makes sense functionally: those tracking fields were maybe used for a specific purpose in the original database, but they might mean something completely different on another database. [1] 6780597f2d984a432341e70c8408de376c188fe0 [2] c78de22a098c810afa2c69a45220f83a8a8f45c0 [3] f6d56afba0ea96529b1419bf2ed4ac12fc5e98c1 closes #42260 closes odoo/odoo#42314 X-original-commit: 2ac11ce7a3f36a1572d886bc872facf339cb6516 Signed-off-by: Sébastien Theys (seb) --- addons/utm/models/ir_http.py | 3 +++ addons/utm/tests/__init__.py | 4 ++++ addons/utm/tests/test_routes.py | 14 ++++++++++++++ 3 files changed, 21 insertions(+) create mode 100644 addons/utm/tests/__init__.py create mode 100644 addons/utm/tests/test_routes.py diff --git a/addons/utm/models/ir_http.py b/addons/utm/models/ir_http.py index 8e2fac4bf0f..7de6922c3b6 100644 --- a/addons/utm/models/ir_http.py +++ b/addons/utm/models/ir_http.py @@ -14,6 +14,9 @@ class IrHttp(models.AbstractModel): def _set_utm(cls, response): if isinstance(response, Exception): return response + # the parent dispatch might destroy the session + if not request.db: + return response domain = cls.get_utm_domain_cookies() for var, dummy, cook in request.env['utm.mixin'].tracking_fields(): diff --git a/addons/utm/tests/__init__.py b/addons/utm/tests/__init__.py new file mode 100644 index 00000000000..37bd33ddc4d --- /dev/null +++ b/addons/utm/tests/__init__.py @@ -0,0 +1,4 @@ +# -*- coding: utf-8 -*- +# Part of Odoo. See LICENSE file for full copyright and licensing details. + +from . import test_routes diff --git a/addons/utm/tests/test_routes.py b/addons/utm/tests/test_routes.py new file mode 100644 index 00000000000..8bf70d72c93 --- /dev/null +++ b/addons/utm/tests/test_routes.py @@ -0,0 +1,14 @@ +# -*- coding: utf-8 -*- +# Part of Odoo. See LICENSE file for full copyright and licensing details. + +import odoo.tests + + +@odoo.tests.tagged('post_install', '-at_install') +class TestRoutes(odoo.tests.HttpCase): + + def test_01_web_session_destroy(self): + base_url = self.env['ir.config_parameter'].sudo().get_param('web.base.url') + self.authenticate('demo', 'demo') + res = self.opener.post(url=base_url + '/web/session/destroy', json={}) + self.assertEqual(res.status_code, 200)