From 7a4e90de8aef581cb78ddfbd3cb5f5abcc1137ec Mon Sep 17 00:00:00 2001 From: Nicolas Martinelli Date: Fri, 19 Jun 2020 11:45:10 +0000 Subject: [PATCH] [FIX] account_payment, payment: filter providers - Install 3 payment providers: P1: no countries set P2: country set to USA P3: country set to Canada - Activate online payment of invoices - Create an invoice for portal user A (country of user is USA) - Login with A - Pay the invoice All 3 providers are available, while only 1 & 2 should be available. The providers are filtered in the sale module, but not in the account module: https://github.com/odoo/odoo/blob/586ee04a6296c13868011b3afaca61be5c6ff3c6/addons/sale/controllers/portal.py#L190-L193 The same issue occurs with the direct link `/website_payment/pay`. We apply the same filtering in all modules. opw-2279710 closes odoo/odoo#53483 X-original-commit: aaac93b551e2a5f331dd14ee5aefbe4ced173691 Signed-off-by: Nicolas Martinelli (nim) --- addons/account_payment/controllers/portal.py | 2 +- addons/payment/controllers/portal.py | 23 +++++++++++++------- addons/payment/models/payment_acquirer.py | 8 ++++++- 3 files changed, 23 insertions(+), 10 deletions(-) diff --git a/addons/account_payment/controllers/portal.py b/addons/account_payment/controllers/portal.py index c5b86c47250..0f2476c04c2 100644 --- a/addons/account_payment/controllers/portal.py +++ b/addons/account_payment/controllers/portal.py @@ -9,7 +9,7 @@ class PortalAccount(PortalAccount): def _invoice_get_page_view_values(self, invoice, access_token, **kwargs): values = super(PortalAccount, self)._invoice_get_page_view_values(invoice, access_token, **kwargs) - payment_inputs = request.env['payment.acquirer']._get_available_payment_input(company=invoice.company_id) + payment_inputs = request.env['payment.acquirer']._get_available_payment_input(partner=invoice.partner_id, company=invoice.company_id) # if not connected (using public user), the method _get_available_payment_input will return public user tokens is_public_user = request.env.user._is_public() if is_public_user: diff --git a/addons/payment/controllers/portal.py b/addons/payment/controllers/portal.py index ece7f11dcd6..d3455abb75b 100644 --- a/addons/payment/controllers/portal.py +++ b/addons/payment/controllers/portal.py @@ -10,6 +10,7 @@ import werkzeug from odoo import http, _ from odoo.http import request +from odoo.osv import expression from odoo.tools import DEFAULT_SERVER_DATETIME_FORMAT, consteq, ustr from odoo.tools.float_utils import float_repr from datetime import datetime, timedelta @@ -207,14 +208,6 @@ class WebsitePayment(http.Controller): cid = user.company_id.id else: cid = user.company_id.id - acquirer_domain = [('state', 'in', ['enabled', 'test']), ('company_id', '=', cid)] - - if acquirer_id: - acquirers = env['payment.acquirer'].browse(int(acquirer_id)) - if order_id: - acquirers = env['payment.acquirer'].search(acquirer_domain) - if not acquirers: - acquirers = env['payment.acquirer'].search(acquirer_domain) # Check partner if not user._is_public(): @@ -233,6 +226,20 @@ class WebsitePayment(http.Controller): 'error_msg': kw.get('error_msg') }) + acquirer_domain = ['&', ('state', 'in', ['enabled', 'test']), ('company_id', '=', cid)] + if partner_id: + partner = request.env['res.partner'].browse([partner_id]) + acquirer_domain = expression.AND([ + acquirer_domain, + ['|', ('country_ids', '=', False), ('country_ids', 'in', [partner.country_id.id])] + ]) + if acquirer_id: + acquirers = env['payment.acquirer'].browse(int(acquirer_id)) + if order_id: + acquirers = env['payment.acquirer'].search(acquirer_domain) + if not acquirers: + acquirers = env['payment.acquirer'].search(acquirer_domain) + # s2s mode will always generate a token, which we don't want for public users valid_flows = ['form', 's2s'] if not user._is_public() else ['form'] values['acquirers'] = [acq for acq in acquirers if acq.payment_flow in valid_flows] diff --git a/addons/payment/models/payment_acquirer.py b/addons/payment/models/payment_acquirer.py index c529688356f..2e605b71b0a 100644 --- a/addons/payment/models/payment_acquirer.py +++ b/addons/payment/models/payment_acquirer.py @@ -13,6 +13,7 @@ from odoo.exceptions import ValidationError from odoo.tools.misc import DEFAULT_SERVER_DATETIME_FORMAT from odoo.tools.misc import formatLang from odoo.http import request +from odoo.osv import expression _logger = logging.getLogger(__name__) @@ -343,7 +344,12 @@ class PaymentAcquirer(models.Model): company = self.env.company if not partner: partner = self.env.user.partner_id - active_acquirers = self.search([('state', 'in', ['enabled', 'test']), ('company_id', '=', company.id)]) + + domain = expression.AND([ + ['&', ('state', 'in', ['enabled', 'test']), ('company_id', '=', company.id)], + ['|', ('country_ids', '=', False), ('country_ids', 'in', [partner.country_id.id])] + ]) + active_acquirers = self.search(domain) acquirers = active_acquirers.filtered(lambda acq: (acq.payment_flow == 'form' and acq.view_template_id) or (acq.payment_flow == 's2s' and acq.registration_view_template_id)) return {