[FIX] utm: prevent crash on /web/session/destroy
A similar fix was originally done in [1], where the access to `env` was done before the parent dispatch. The issue was then reintroduced with [2], where the `env` was possibly accessed again after the dispatch. This works most of the time, but in the rare case where the session is destroyed during dispatch, which is the case on `/web/session/destroy`, accessing the environment after that point will crash. This issue didn't manifest before [3], because the `env` was always initialized during `checked_call` when calling the `clear` method on it (since `env` is a magic property). After that commit, the `clear` is not called if not necessary, therefore it might happen that the `env` is never initialized. This leads to the crash when trying to initialize it for the first time after the `db` attribute has been cleared during the destroy, since a `db` is required to initialize it. The current fix aims to prevent the crash. As opposed to [1] that actually kept the tracking fields by fetching them before the dispatch, it is decided on this commit to voluntarily lose the tracking fields when destroying the session, because keeping them would require too much refactoring for a fix in stable, but we also feel that it makes sense functionally: those tracking fields were maybe used for a specific purpose in the original database, but they might mean something completely different on another database. [1]6780597f2d[2]c78de22a09[3]f6d56afba0closes #42260 closes odoo/odoo#42314 X-original-commit: 2ac11ce7a3f36a1572d886bc872facf339cb6516 Signed-off-by: Sébastien Theys (seb) <seb@odoo.com>
This commit is contained in:
@@ -14,6 +14,9 @@ class IrHttp(models.AbstractModel):
|
||||
def _set_utm(cls, response):
|
||||
if isinstance(response, Exception):
|
||||
return response
|
||||
# the parent dispatch might destroy the session
|
||||
if not request.db:
|
||||
return response
|
||||
|
||||
domain = cls.get_utm_domain_cookies()
|
||||
for var, dummy, cook in request.env['utm.mixin'].tracking_fields():
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
||||
|
||||
from . import test_routes
|
||||
@@ -0,0 +1,14 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
||||
|
||||
import odoo.tests
|
||||
|
||||
|
||||
@odoo.tests.tagged('post_install', '-at_install')
|
||||
class TestRoutes(odoo.tests.HttpCase):
|
||||
|
||||
def test_01_web_session_destroy(self):
|
||||
base_url = self.env['ir.config_parameter'].sudo().get_param('web.base.url')
|
||||
self.authenticate('demo', 'demo')
|
||||
res = self.opener.post(url=base_url + '/web/session/destroy', json={})
|
||||
self.assertEqual(res.status_code, 200)
|
||||
Reference in New Issue
Block a user