[FIX] payment: mask payment method keys in onboarding dialog

Before this commit the tokens from payment providers (PayPal, Stripe) are shown in plain text in the onboarding wizard.
This means that anyone with accounting rights can grab & copy tokens for PayPal & Stripe.
After this commit they're shielded off with a password=True option so they're not directly readable and copyable.

Steps to reproduce: Open an Odoo instance, go to Accounting > Invoices and click on the 'Set Payments' option for the onboarding wizard.
Next choose Paypal or Credit card in the dialog and see how tokens are shown in plain-text.

closes odoo/odoo#54861

X-original-commit: 65e201ecee3bc145c2ae76d59b6d2fd31c737872
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
This commit is contained in:
root
2020-07-23 15:41:13 +00:00
parent 07bafcb792
commit 98b0f01fc5
@@ -39,7 +39,7 @@
<field name="paypal_user_type" widget="radio" nolabel="1"/>
<field name="paypal_email_account" attrs="{'required': [('payment_method', '=', 'paypal')]}" string="Email"/>
<field name="paypal_seller_account" attrs="{'invisible': [('paypal_user_type', '=', 'new_user')], 'required': [('paypal_user_type', '!=', 'new_user'), ('payment_method', '=', 'paypal')]}" />
<field name="paypal_pdt_token" attrs="{'invisible': [('paypal_user_type', '=', 'new_user')], 'required': [('paypal_user_type', '!=', 'new_user'), ('payment_method', '=', 'paypal')]}" />
<field name="paypal_pdt_token" password="True" attrs="{'invisible': [('paypal_user_type', '=', 'new_user')], 'required': [('paypal_user_type', '!=', 'new_user'), ('payment_method', '=', 'paypal')]}" />
</group>
<p attrs="{'invisible': [('paypal_user_type', '!=', 'new_user')]}">
<span>Start selling directly without an account; an email will be sent by Paypal to create your new account and collect your payments.</span>
@@ -52,9 +52,9 @@
</div>
<div attrs="{'invisible': [('payment_method', '!=', 'stripe')]}">
<group>
<field name="stripe_secret_key"
<field name="stripe_secret_key" password="True"
attrs="{'required': [('payment_method', '=', 'stripe')]}" />
<field name="stripe_publishable_key"
<field name="stripe_publishable_key" password="True"
attrs="{'required': [('payment_method', '=', 'stripe')]}" />
</group>
<p>