From a629230fec60808e25c2a2be6d3b88cddccd79ed Mon Sep 17 00:00:00 2001 From: "Anita (anko)" Date: Mon, 18 Mar 2024 10:04:24 +0100 Subject: [PATCH] [FIX] payment_paypal: change access_token parameter name PayPal refuses to take access_token name parameter and throws an error to user that they need to log again. Since the Access Token is neeeded to cancel transaction, it is renamed to return_access_tkn. opw-3810686 closes odoo/odoo#158249 X-original-commit: e1ed847912b60bf09e13087963fad87afbed875c Signed-off-by: Antoine Vandevenne (anv) Signed-off-by: anko-odoo --- addons/payment_paypal/controllers/main.py | 7 ++++--- addons/payment_paypal/models/payment_transaction.py | 2 +- addons/payment_paypal/tests/test_paypal.py | 2 +- 3 files changed, 6 insertions(+), 5 deletions(-) diff --git a/addons/payment_paypal/controllers/main.py b/addons/payment_paypal/controllers/main.py index 1dc0cd71a05..147c812a33d 100644 --- a/addons/payment_paypal/controllers/main.py +++ b/addons/payment_paypal/controllers/main.py @@ -65,11 +65,12 @@ class PaypalController(http.Controller): @http.route( _cancel_url, type='http', auth='public', methods=['GET'], csrf=False, save_session=False ) - def paypal_return_from_canceled_checkout(self, tx_ref, access_token): + def paypal_return_from_canceled_checkout(self, tx_ref, return_access_tkn): """ Process the transaction after the customer has canceled the payment. :param str tx_ref: The reference of the transaction having been canceled. - :param str access_token: The access token to verify the authenticity of the request. + :param str return_access_tkn: The access token to verify the authenticity of the request. + PayPal forbids any parameter with the name "token" inside. """ _logger.info( "Handling redirection from Paypal for cancellation of transaction with reference %s", @@ -79,7 +80,7 @@ class PaypalController(http.Controller): tx_sudo = request.env['payment.transaction'].sudo()._get_tx_from_notification_data( 'paypal', {'item_number': tx_ref} ) - if not payment_utils.check_access_token(access_token, tx_ref): + if not payment_utils.check_access_token(return_access_tkn, tx_ref): raise Forbidden() tx_sudo._handle_notification_data('paypal', {}) diff --git a/addons/payment_paypal/models/payment_transaction.py b/addons/payment_paypal/models/payment_transaction.py index 413f91431b8..44d12f6e19c 100644 --- a/addons/payment_paypal/models/payment_transaction.py +++ b/addons/payment_paypal/models/payment_transaction.py @@ -38,7 +38,7 @@ class PaymentTransaction(models.Model): cancel_url = urls.url_join(base_url, PaypalController._cancel_url) cancel_url_params = { 'tx_ref': self.reference, - 'access_token': payment_utils.generate_access_token(self.reference), + 'return_access_tkn': payment_utils.generate_access_token(self.reference), } partner_first_name, partner_last_name = payment_utils.split_partner_name(self.partner_name) return { diff --git a/addons/payment_paypal/tests/test_paypal.py b/addons/payment_paypal/tests/test_paypal.py index 73a3155c27a..12aaf131cac 100644 --- a/addons/payment_paypal/tests/test_paypal.py +++ b/addons/payment_paypal/tests/test_paypal.py @@ -21,7 +21,7 @@ class PaypalTest(PaypalCommon, PaymentHttpCommon): cancel_url = self._build_url(PaypalController._cancel_url) cancel_url_params = { 'tx_ref': self.reference, - 'access_token': self._generate_test_access_token(self.reference), + 'return_access_tkn': self._generate_test_access_token(self.reference), } return { 'address1': 'Huge Street 2/543',