[FIX] payment_stripe: use idempotency key only when offline

To Reproduce
============
- on a db with sales, website and Stripe payment aquirer activated
- on the portal of a user add two payment methods, an expired card
and a valid one
- create a SO and generate its payment link
- try to pay with the invalid card first -> and error (card was declined)
- try to pay with the valid card -> error (same idempotency key)

Problem
=======
the generation of the idempotency key is based only on dbuuid, transaction's
reference and the scope. So in this use case it will generate the same key.

Solution
========
The idempotency key prevents issues where the customer is charged twice for
the same thing. In this case, we don't want to prevent anything since the
customer is on the page. It's suggested to use idempotency keys only for offline
payment when the customer is not in front of the payment page (e.g. when the cron
charges the customer for his subscription)

opw-3091354

closes odoo/odoo#108163

X-original-commit: 089387087010ae917494d5072f00d72c572b7d09
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Signed-off-by: abla001 <abla@odoo.com>
This commit is contained in:
Abdelouahab (abla)
2022-12-16 14:49:58 +01:00
committed by Antoine Vandevenne (anv)
parent 13f31d046c
commit 608aa8ca88
@@ -218,9 +218,10 @@ class PaymentTransaction(models.Model):
'payment_intents',
payload=self._stripe_prepare_payment_intent_payload(payment_by_token=True),
offline=self.operation == 'offline',
# Prevent multiple offline payments by token (e.g., due to a cursor rollback).
idempotency_key=payment_utils.generate_idempotency_key(
self, scope='payment_intents_token'
), # Prevent multiple offline payments by token (e.g., due to a cursor rollback).
) if self.operation == 'offline' else None,
)
else: # 'online_direct' (express checkout).
response = self.provider_id._stripe_make_request(