From 889fbffb7f1761b005c947a6f2de22bae2e6e811 Mon Sep 17 00:00:00 2001 From: "Antoine Vandevenne (anv)" Date: Wed, 6 Jul 2022 15:01:59 +0000 Subject: [PATCH] [FIX] payment: hide the tokenization input when required by the provider Due to an oversight, the "Save my payment details" checkbox was shown on the inline payment form of SEPA Direct Debit acquirers, which should never happen because the transaction is *always* tokenized with those. With this commit, the `_is_tokenization_required` method is slightly refactored to read the provider from the current `payment.acquirer` record rather than from the kwargs. This conveniently fixes the issue and prevents it from happening again elsewhere. closes odoo/odoo#95519 X-original-commit: ebeebd87ed6d687b96dda3006b81356dfa76d0a0 Related: odoo/enterprise#29237 Signed-off-by: Antoine Vandevenne (anv) --- addons/payment/controllers/portal.py | 13 +++++-------- addons/payment/models/payment_acquirer.py | 4 +--- 2 files changed, 6 insertions(+), 11 deletions(-) diff --git a/addons/payment/controllers/portal.py b/addons/payment/controllers/portal.py index e6a6277355c..b3b7a32e3bc 100644 --- a/addons/payment/controllers/portal.py +++ b/addons/payment/controllers/portal.py @@ -173,11 +173,11 @@ class PaymentPortal(portal.CustomerPortal): :rtype: dict """ show_tokenize_input_mapping = {} - for acquirer in acquirers_sudo: - show_tokenize_input = acquirer.allow_tokenization \ - and not acquirer._is_tokenization_required(**kwargs) \ + for acquirer_sudo in acquirers_sudo: + show_tokenize_input = acquirer_sudo.allow_tokenization \ + and not acquirer_sudo._is_tokenization_required(**kwargs) \ and logged_in - show_tokenize_input_mapping[acquirer.id] = show_tokenize_input + show_tokenize_input_mapping[acquirer_sudo.id] = show_tokenize_input return show_tokenize_input_mapping def _get_payment_page_template_xmlid(self, **kwargs): @@ -282,14 +282,11 @@ class PaymentPortal(portal.CustomerPortal): if flow in ['redirect', 'direct']: # Direct payment or payment with redirection acquirer_sudo = request.env['payment.acquirer'].sudo().browse(payment_option_id) token_id = None - tokenization_required_or_requested = acquirer_sudo._is_tokenization_required( - provider=acquirer_sudo.provider, **kwargs - ) or tokenization_requested tokenize = bool( # Don't tokenize if the user tried to force it through the browser's developer tools acquirer_sudo.allow_tokenization # Token is only created if required by the flow or requested by the user - and tokenization_required_or_requested + and (acquirer_sudo._is_tokenization_required(**kwargs) or tokenization_requested) ) elif flow == 'token': # Payment by token token_sudo = request.env['payment.token'].sudo().browse(payment_option_id) diff --git a/addons/payment/models/payment_acquirer.py b/addons/payment/models/payment_acquirer.py index 53cf377eed7..3f4c7583877 100644 --- a/addons/payment/models/payment_acquirer.py +++ b/addons/payment/models/payment_acquirer.py @@ -343,14 +343,12 @@ class PaymentAcquirer(models.Model): compatible_acquirers = self.env['payment.acquirer'].search(domain) return compatible_acquirers - @api.model - def _is_tokenization_required(self, provider=None, **kwargs): + def _is_tokenization_required(self, **kwargs): """ Return whether tokenizing the transaction is required given its context. For a module to make the tokenization required based on the transaction context, it must override this method and return whether it is required. - :param str provider: The provider of the acquirer handling the transaction :param dict kwargs: The transaction context. This parameter is not used here :return: Whether tokenizing the transaction is required :rtype: bool