[FIX] website_sale: avoid traceback when category don't exists

In case the category is given in GET, ?category_id=xx, we cannot guarantee that
the category exists

This commit closes #24235
This commit is contained in:
Jeremy Kersten
2018-04-20 16:00:30 +02:00
parent 4d88e8e822
commit b16c4f50d4
+7 -4
View File
@@ -2,7 +2,7 @@
# Part of Odoo. See LICENSE file for full copyright and licensing details.
import json
import logging
from werkzeug.exceptions import Forbidden
from werkzeug.exceptions import Forbidden, NotFound
from odoo import http, tools, _
from odoo.http import request
@@ -193,6 +193,11 @@ class WebsiteSale(http.Controller):
else:
ppg = PPG
if category:
category = request.env['product.public.category'].search([('id', '=', int(category))], limit=1)
if not category:
raise NotFound()
attrib_list = request.httprequest.args.getlist('attrib')
attrib_values = [map(int, v.split("-")) for v in attrib_list if v]
attributes_ids = set([v[0] for v in attrib_values])
@@ -213,9 +218,6 @@ class WebsiteSale(http.Controller):
url = "/shop"
if search:
post["search"] = search
if category:
category = request.env['product.public.category'].browse(int(category))
url = "/shop/category/%s" % slug(category)
if attrib_list:
post['attrib'] = attrib_list
@@ -224,6 +226,7 @@ class WebsiteSale(http.Controller):
parent_category_ids = []
if category:
url = "/shop/category/%s" % slug(category)
parent_category_ids = [category.id]
current_category = category
while current_category.parent_id: