[IMP] payment: customer is no longer able to see tokens for disabled acquirers.
Saved payments methods for disabled acquirers are no longer visible on the customer portal. It was fustrating for the customer to see saved payment methods that he was no longer able to use as they are disabled. Now the use should only be able to see payment methods that he can indeed use. Task - 2679695 closes odoo/odoo#79253 Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
This commit is contained in:
committed by
Victor Feyens
parent
dea661b215
commit
43cd3b4dfe
@@ -159,9 +159,15 @@ class PaymentPortal(portal.CustomerPortal):
|
||||
acquirers_sudo = request.env['payment.acquirer'].sudo()._get_compatible_acquirers(
|
||||
request.env.company.id, partner.id, force_tokenization=True, is_validation=True
|
||||
)
|
||||
tokens = set(partner.payment_token_ids).union(
|
||||
partner.commercial_partner_id.sudo().payment_token_ids
|
||||
) # Show all partner's tokens, regardless of which acquirer is available
|
||||
|
||||
# Get all partner's tokens for which acquirers are not disabled.
|
||||
tokens = request.env['payment.token'].search([
|
||||
('partner_id', 'in', [partner.id, partner.commercial_partner_id.id]),
|
||||
('acquirer_id', 'in', request.env['payment.acquirer'].sudo()._search([
|
||||
('state', 'in', ['enabled', 'test'])
|
||||
])
|
||||
)])
|
||||
|
||||
access_token = payment_utils.generate_access_token(partner.id, None, None)
|
||||
rendering_context = {
|
||||
'acquirers': acquirers_sudo,
|
||||
|
||||
@@ -151,8 +151,8 @@ class PaymentHttpCommon(PaymentTestUtils, HttpCase):
|
||||
url = self._build_url(uri)
|
||||
return self._make_http_get_request(url, {})
|
||||
|
||||
def get_tx_manage_context(self, **route_kwargs):
|
||||
response = self.portal_payment_method(**route_kwargs)
|
||||
def get_tx_manage_context(self):
|
||||
response = self.portal_payment_method()
|
||||
|
||||
self.assertEqual(response.status_code, 200)
|
||||
|
||||
|
||||
@@ -347,3 +347,30 @@ class TestFlows(PaymentCommon, PaymentHttpCommon):
|
||||
self.assertIn(
|
||||
"odoo.exceptions.ValidationError: The access token is invalid.",
|
||||
response.text)
|
||||
|
||||
def test_access_disabled_acquirers_tokens(self):
|
||||
self.partner = self.portal_partner
|
||||
|
||||
# Log in as user from Company A
|
||||
self.authenticate(self.portal_user.login, self.portal_user.login)
|
||||
|
||||
token = self.create_token()
|
||||
acquirer_b = self.acquirer.copy()
|
||||
acquirer_b.state = 'test'
|
||||
token_b = self.create_token(acquirer_id=acquirer_b.id)
|
||||
|
||||
# A partner should see all his tokens on the /my/payment_method route,
|
||||
# even if they are in other companies otherwise he won't ever see them.
|
||||
manage_context = self.get_tx_manage_context()
|
||||
self.assertEqual(manage_context['partner_id'], self.partner.id)
|
||||
self.assertIn(self.acquirer.id, manage_context['acquirer_ids'])
|
||||
self.assertIn(acquirer_b.id, manage_context['acquirer_ids'])
|
||||
self.assertIn(token.id, manage_context['token_ids'])
|
||||
self.assertIn(token_b.id, manage_context['token_ids'])
|
||||
|
||||
# Token of disabled acquirer(s) & disabled acquirers should not be shown
|
||||
self.acquirer.state = 'disabled'
|
||||
manage_context = self.get_tx_manage_context()
|
||||
self.assertEqual(manage_context['partner_id'], self.partner.id)
|
||||
self.assertEqual(manage_context['acquirer_ids'], [acquirer_b.id])
|
||||
self.assertEqual(manage_context['token_ids'], [token_b.id])
|
||||
|
||||
Reference in New Issue
Block a user