From 82bde85030b58959bba8efddb13746e5dc3e4601 Mon Sep 17 00:00:00 2001 From: Romain Derie Date: Wed, 29 Nov 2017 12:44:12 +0100 Subject: [PATCH] [FIX] website_sale(_options): text in field qty throws error and/or create infinite quotations Before this commit: 1. If user wrote text in the quantity field to add to his cart, it would crash and show a server error. Now, if the user insert a non-valid quantity in the field, we set it to 1 Step to reproduce: With website_sale only - Go to a product page on the shop - Insert 'abc' in the quantity field and click 'Add to Cart' - Server will throw an error 'Can't parse float..' With website_sale_options - Go to a product page on the shop - Insert 'abc' in the quantity field and click 'Add to Cart' - Popup confirmation with optional product will show with 'NaN' in the qty - Click 'Proceed to checkout' - Server will throw an error 'Can't parse int..' 2. On the checkout, if user typed text in qty field it would create infinite quotations. Some modules (eg: website_event_sale) would hide this behavior because they override the RPC call to '/shop/cart/update_json' and throw an error on the RPC. Now, if user type incorrect integer quantity, we set the quantity to 1. Step to reproduce: 1. On base (website_sale only) - Add an item to your cart - On checkout page, set qty to 'abcd' or whatever text - Check your browser console, every 500ms their will be a RPC call - Check your quotations in backend, their will be a new one every 500ms 2. On db-all - Add an item to your cart - Set qty to 'abcd' or whatever text - Check your browser console, it will throw an error on the second call This closes #20482, closes #20904 --- addons/website_sale/controllers/main.py | 3 +-- addons/website_sale/models/sale_order.py | 10 ++++++++++ addons/website_sale/static/src/js/website_sale.js | 9 ++++++++- addons/website_sale_options/controllers/main.py | 2 +- 4 files changed, 20 insertions(+), 4 deletions(-) diff --git a/addons/website_sale/controllers/main.py b/addons/website_sale/controllers/main.py index 44c35ff3c1f..fe39bf19f10 100644 --- a/addons/website_sale/controllers/main.py +++ b/addons/website_sale/controllers/main.py @@ -368,7 +368,7 @@ class website_sale(http.Controller): @http.route(['/shop/cart/update'], type='http', auth="public", methods=['POST'], website=True) def cart_update(self, product_id, add_qty=1, set_qty=0, **kw): - request.website.sale_get_order(force_create=1)._cart_update(product_id=int(product_id), add_qty=float(add_qty), set_qty=float(set_qty)) + request.website.sale_get_order(force_create=1)._cart_update(product_id=int(product_id), add_qty=add_qty, set_qty=set_qty) return request.redirect("/shop/cart") @http.route(['/shop/cart/update_json'], type='json', auth="public", methods=['POST'], website=True) @@ -377,7 +377,6 @@ class website_sale(http.Controller): if order.state != 'draft': request.website.sale_reset() return {} - value = order._cart_update(product_id=product_id, line_id=line_id, add_qty=add_qty, set_qty=set_qty) if not order.cart_quantity: request.website.sale_reset() diff --git a/addons/website_sale/models/sale_order.py b/addons/website_sale/models/sale_order.py index 3020158ddd7..ef6c4ddc043 100644 --- a/addons/website_sale/models/sale_order.py +++ b/addons/website_sale/models/sale_order.py @@ -79,6 +79,16 @@ class sale_order(osv.Model): """ Add or set product quantity, add_qty can be negative """ sol = self.pool.get('sale.order.line') + try: + if add_qty: + add_qty = float(add_qty) + except ValueError: + add_qty = 1 + try: + if set_qty: + set_qty = float(set_qty) + except ValueError: + set_qty = 0 quantity = 0 for so in self.browse(cr, uid, ids, context=context): if so.state != 'draft': diff --git a/addons/website_sale/static/src/js/website_sale.js b/addons/website_sale/static/src/js/website_sale.js index 8476977b724..32c18cb4d5b 100644 --- a/addons/website_sale/static/src/js/website_sale.js +++ b/addons/website_sale/static/src/js/website_sale.js @@ -153,6 +153,9 @@ $('.oe_website_sale').each(function () { return; } var value = parseInt($input.val() || 0, 10); + if (isNaN(value)) { + value = 1; + } var $dom = $(this).closest('tr'); var default_price = parseFloat($dom.find('.text-danger > span.oe_currency_value').text()); var $dom_optional = $dom.nextUntil(':not(.optional_product.info)'); @@ -173,7 +176,11 @@ $('.oe_website_sale').each(function () { 'set_qty': value}) .then(function (data) { $input.data('update_change', false); - if (value !== parseInt($input.val() || 0, 10)) { + var check_value = parseInt($input.val() || 0, 10); + if (isNaN(check_value)) { + check_value = 1; + } + if (value !== check_value) { $input.trigger('change'); return; } diff --git a/addons/website_sale_options/controllers/main.py b/addons/website_sale_options/controllers/main.py index bb7da99527d..8e8811665ef 100644 --- a/addons/website_sale_options/controllers/main.py +++ b/addons/website_sale_options/controllers/main.py @@ -42,7 +42,7 @@ class website_sale_options(website_sale): value = {} if add_qty or set_qty: value = order._cart_update(product_id=int(product_id), - add_qty=int(add_qty), set_qty=int(set_qty), + add_qty=add_qty, set_qty=set_qty, optional_product_ids=optional_product_ids) # options have all time the same quantity