From a0ff74b78de749b2cdfba8008299eb044bc7ebf2 Mon Sep 17 00:00:00 2001 From: Antonio Espinosa Date: Mon, 24 Oct 2016 19:06:55 +0200 Subject: [PATCH] [FIX] website_mail: do not propagate csrf_token to message_post method Indeed through portal users can post a message. Form used in order to do so include a csrf token. However this one should not be propagated to message_post because it is not a mail_message model field. This creates unnecessary warnings. Closes #13956 . --- addons/website_mail/controllers/main.py | 1 + 1 file changed, 1 insertion(+) diff --git a/addons/website_mail/controllers/main.py b/addons/website_mail/controllers/main.py index 64f11412aa1..7046695ef9c 100644 --- a/addons/website_mail/controllers/main.py +++ b/addons/website_mail/controllers/main.py @@ -65,6 +65,7 @@ def _message_post_helper(res_model='', res_id=None, message='', token='', token_ res = res.sudo() else: raise NotFound() + kw.pop('csrf_token', None) return res.with_context({'mail_create_nosubscribe': nosubscribe}).message_post(body=message, message_type=kw.pop('message_type', False) or "comment", subtype=kw.pop('subtype', False) or "mt_comment",