diff --git a/addons/payment/controllers/portal.py b/addons/payment/controllers/portal.py index ed8cc4826dc..0afb35cda7d 100644 --- a/addons/payment/controllers/portal.py +++ b/addons/payment/controllers/portal.py @@ -208,9 +208,7 @@ class PaymentPortal(portal.CustomerPortal): tx_sudo = self._create_transaction( amount=amount, currency_id=currency_id, partner_id=partner_id, **kwargs ) - if tx_sudo.operation == 'validation': - # The amount and currency have been chosen for the validation, recompute the access token - self._update_landing_route(tx_sudo) + self._update_landing_route(tx_sudo, access_token) # Add the required parameters to the route return tx_sudo._get_processing_values() def _create_transaction( @@ -305,20 +303,22 @@ class PaymentPortal(portal.CustomerPortal): return tx_sudo @staticmethod - def _update_landing_route(tx_sudo): - """ Recompute the access token stored in the landing route of validation transactions. + def _update_landing_route(tx_sudo, access_token): + """ Add the mandatory parameters to the route and recompute the access token if needed. - The generic landing route require the tx id and access token to be provided, since there is + The generic landing route requires the tx id and access token to be provided since there is no document to rely on. The access token is recomputed in case we are dealing with a validation transaction (acquirer-specific amount and currency). :param recordset tx_sudo: The transaction whose landing routes to update, as a `payment.transaction` record. + :param str access_token: The access token used to authenticate the partner :return: None """ - access_token = payment_utils.generate_access_token( - tx_sudo.partner_id.id, tx_sudo.amount, tx_sudo.currency_id.id - ) + if tx_sudo.operation == 'validation': + access_token = payment_utils.generate_access_token( + tx_sudo.partner_id.id, tx_sudo.amount, tx_sudo.currency_id.id + ) tx_sudo.landing_route = f'{tx_sudo.landing_route}' \ f'?tx_id={tx_sudo.id}&access_token={access_token}' diff --git a/addons/payment/tests/test_flows.py b/addons/payment/tests/test_flows.py index ff5c3dbca6c..5f04126d6b6 100644 --- a/addons/payment/tests/test_flows.py +++ b/addons/payment/tests/test_flows.py @@ -59,6 +59,7 @@ class TestFlows(PaymentCommon, PaymentHttpCommon): self.assertEqual(tx_sudo.currency_id.id, self.currency.id) self.assertEqual(tx_sudo.partner_id.id, self.partner.id) self.assertEqual(tx_sudo.reference, self.reference) + # processing_values == given values self.assertEqual(processing_values['acquirer_id'], self.acquirer.id) self.assertEqual(processing_values['amount'], self.amount) @@ -66,6 +67,10 @@ class TestFlows(PaymentCommon, PaymentHttpCommon): self.assertEqual(processing_values['partner_id'], self.partner.id) self.assertEqual(processing_values['reference'], self.reference) + # Verify computed values not provided, but added during the flow + self.assertIn("tx_id=", tx_sudo.landing_route) + self.assertIn("access_token=", tx_sudo.landing_route) + if flow == 'redirect': # In redirect flow, we verify the rendering of the dummy test form redirect_form_info = self._extract_values_from_html_form( diff --git a/addons/website_payment/controllers/portal.py b/addons/website_payment/controllers/portal.py index 7fb50e15725..a8d0b198f0c 100644 --- a/addons/website_payment/controllers/portal.py +++ b/addons/website_payment/controllers/portal.py @@ -75,7 +75,7 @@ class PaymentPortal(payment_portal.PaymentPortal): }) elif not tx_sudo.partner_country_id: tx_sudo.partner_country_id = kwargs['partner_details']['country_id'] - self._update_landing_route(tx_sudo) + self._update_landing_route(tx_sudo, access_token) # Send a notification to warn that a donation has been made recipient_email = kwargs['donation_recipient_email']