From 97658791306349456761ba4c18d504f861e3bb98 Mon Sep 17 00:00:00 2001 From: Fabio Barbero Date: Wed, 17 Nov 2021 12:50:21 +0000 Subject: [PATCH] [IMP] auth_signup: redirect activated user to login on signup link Purpose ======= When a user receives an email to activate their account, allow them to click on the "Activate Account" button after the account has already been activated instead of showing a "Invalid signup token" error. Specifications ============= Add a parameter p_id to the sign up url to check if the partner has already activated their account (if their user_ids state is not new) and redirect them to login otherwise. Task-2680414 closes odoo/odoo#79936 Signed-off-by: Thibault Delavallee (tde) --- addons/auth_signup/controllers/main.py | 11 +++++++++++ addons/auth_signup/models/res_partner.py | 2 +- addons/portal/data/mail_template_data.xml | 3 --- addons/web/controllers/home.py | 2 +- 4 files changed, 13 insertions(+), 5 deletions(-) diff --git a/addons/auth_signup/controllers/main.py b/addons/auth_signup/controllers/main.py index f3afc75911d..0348edb4511 100644 --- a/addons/auth_signup/controllers/main.py +++ b/addons/auth_signup/controllers/main.py @@ -2,6 +2,7 @@ # Part of Odoo. See LICENSE file for full copyright and licensing details. import logging import werkzeug +from werkzeug.urls import url_encode from odoo import http, tools, _ from odoo.addons.auth_signup.models.res_users import SignupError @@ -60,6 +61,11 @@ class AuthSignupHome(Home): _logger.error("%s", e) qcontext['error'] = _("Could not create a new account.") + elif 'signup_email' in qcontext: + user = request.env['res.users'].sudo().search([('email', '=', qcontext.get('signup_email')), ('state', '!=', 'new')], limit=1) + if user: + return request.redirect('/web/login?%s' % url_encode({'login': user.login, 'redirect': '/web'})) + response = request.render('auth_signup.signup', qcontext) response.headers['X-Frame-Options'] = 'SAMEORIGIN' response.headers['Content-Security-Policy'] = "frame-ancestors 'self'" @@ -93,6 +99,11 @@ class AuthSignupHome(Home): except Exception as e: qcontext['error'] = str(e) + elif 'signup_email' in qcontext: + user = request.env['res.users'].sudo().search([('email', '=', qcontext.get('signup_email')), ('state', '!=', 'new')], limit=1) + if user: + return request.redirect('/web/login?%s' % url_encode({'login': user.login, 'redirect': '/web'})) + response = request.render('auth_signup.reset_password', qcontext) response.headers['X-Frame-Options'] = 'SAMEORIGIN' response.headers['Content-Security-Policy'] = "frame-ancestors 'self'" diff --git a/addons/auth_signup/models/res_partner.py b/addons/auth_signup/models/res_partner.py index 6ac638e974b..a77f67a5b4d 100644 --- a/addons/auth_signup/models/res_partner.py +++ b/addons/auth_signup/models/res_partner.py @@ -58,7 +58,7 @@ class ResPartner(models.Model): route = 'login' # the parameters to encode for the query - query = dict(db=self.env.cr.dbname) + query = {'db': self.env.cr.dbname, 'signup_email': partner.email} signup_type = self.env.context.get('signup_force_type_in_url', partner.sudo().signup_type or '') if signup_type: route = 'reset_password' if signup_type == 'reset' else signup_type diff --git a/addons/portal/data/mail_template_data.xml b/addons/portal/data/mail_template_data.xml index 5f602a1f191..d22ffb586be 100644 --- a/addons/portal/data/mail_template_data.xml +++ b/addons/portal/data/mail_template_data.xml @@ -41,9 +41,6 @@ Activate Account - - Log in - Welcome to our company's portal. diff --git a/addons/web/controllers/home.py b/addons/web/controllers/home.py index f0f08d30f91..7b46be35d32 100644 --- a/addons/web/controllers/home.py +++ b/addons/web/controllers/home.py @@ -21,7 +21,7 @@ _logger = logging.getLogger(__name__) # Shared parameters for all login/signup flows SIGN_UP_REQUEST_PARAMS = {'db', 'login', 'debug', 'token', 'message', 'error', 'scope', 'mode', 'redirect', 'redirect_hostname', 'email', 'name', 'partner_id', - 'password', 'confirm_password', 'city', 'country_id', 'lang'} + 'password', 'confirm_password', 'city', 'country_id', 'lang', 'signup_email'} LOGIN_SUCCESSFUL_PARAMS = set()