[FIX] payment_(adyen,paypal): discard invalid notification data

opw-3097856

closes odoo/odoo#120751

Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
This commit is contained in:
Antoine Vandevenne (anv)
2023-12-15 17:12:51 +00:00
parent e302e1b71c
commit 8d66636a76
5 changed files with 12 additions and 4 deletions
+1 -1
View File
@@ -78,7 +78,7 @@ class AdyenController(http.Controller):
# Check that the transaction details have not been altered. This allows preventing users
# from validating transactions by paying less than agreed upon.
if not payment_utils.check_access_token(
access_token, reference, converted_amount, partner_id
access_token, reference, converted_amount, currency_id, partner_id
):
raise ValidationError("Adyen: " + _("Received tampered payment request data."))
@@ -40,6 +40,7 @@ class PaymentTransaction(models.Model):
'access_token': payment_utils.generate_access_token(
processing_values['reference'],
converted_amount,
self.currency_id.id,
processing_values['partner_id']
)
}
+1 -1
View File
@@ -37,7 +37,7 @@ class AdyenTest(AdyenCommon, PaymentHttpCommon):
'odoo.addons.payment.utils.generate_access_token', new=self._generate_test_access_token
):
self.assertTrue(payment_utils.check_access_token(
processing_values['access_token'], self.reference, converted_amount, self.partner.id
processing_values['access_token'], self.reference, converted_amount, self.currency.id, self.partner.id
))
@mute_logger('odoo.addons.payment_adyen.models.payment_transaction')
@@ -100,6 +100,13 @@ class PaymentTransaction(models.Model):
self._set_canceled(_("The customer left the payment page."))
return
amount = notification_data.get('amt') or notification_data.get('mc_gross')
currency_code = notification_data.get('cc') or notification_data.get('mc_currency')
assert amount and currency_code, 'PayPal: missing amount or currency'
assert self.currency_id.compare_amounts(float(amount), self.amount) == 0, \
'PayPal: mismatching amounts'
assert currency_code == self.currency_id.name, 'PayPal: mismatching currency codes'
# Update the provider reference.
txn_id = notification_data.get('txn_id')
txn_type = notification_data.get('txn_type')
+2 -2
View File
@@ -30,9 +30,9 @@ class PaypalCommon(PaymentCommon):
'item_name': 'YourCompany: Test Transaction',
'item_number': cls.reference,
'last_name': 'Buyer',
'mc_currency': 'USD',
'mc_currency': cls.currency.name,
'mc_fee': '2.00',
'mc_gross': '50.00',
'mc_gross': str(cls.amount),
'notify_version': 'UNVERSIONED',
'payer_email': 'test-buyer@mail.odoo.com',
'payer_id': '59XDVNACRAZZK',