From 444f0b6a7f62f8066f754e16f792f3901904249b Mon Sep 17 00:00:00 2001 From: Toufik Benjaa Date: Tue, 5 Jun 2018 14:55:14 +0200 Subject: [PATCH] [IMP] payment_ogone: Avoid requesting already owned data from Ogone - When receiving a S2S payment feedback from Ogone server, we call the method '_ogone_form_get_tx_from_data' which does a "pre-process" of the data to retrieve the payment.transaction linked to this payment. It also checks the hash signature of the data to be sure it comes from Ogone. Right after, we call "_ogone_s2s_validate" which make a HTTP call to ogone, to retrieve the data related to the transaction which were already sent by Ogone (maybe to be sure the data comes from Ogone?). So instead of calling "_ogone_s2s_validate" we now call "_ogone_s2s_validate_tree" which processes the data from Ogone. We are sure they come from Ogone, since they passed the hash signature when calling "_ogone_form_get_tx_from_data". --- addons/payment_ogone/controllers/main.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/payment_ogone/controllers/main.py b/addons/payment_ogone/controllers/main.py index 3137f619d2d..f82df1c7d27 100644 --- a/addons/payment_ogone/controllers/main.py +++ b/addons/payment_ogone/controllers/main.py @@ -50,7 +50,7 @@ class OgoneController(http.Controller): payment = request.registry.get('payment.transaction') try: tx = payment._ogone_form_get_tx_from_data(cr, uid, kwargs, context=context) - payment._ogone_s2s_validate(tx) + payment._ogone_s2s_validate_tree(tx, kwargs) except ValidationError: return 'ko'