From c28ad2eae6a8346dd54c57e7173e0d71a566a29e Mon Sep 17 00:00:00 2001 From: "Antoine Vandevenne (anv)" Date: Wed, 15 Mar 2023 15:44:05 +0000 Subject: [PATCH] [FIX] payment_ogone: ensure token aliases are unique Prior to this commit, the generation of token aliases in Ogone relied on the util function `singularize_reference_prefix`, which is intended to make transaction references (and not token aliases!) more distinguishable by suffixing a timestamp accurate to the second. That util function does not guarantee the uniqueness of generated reference prefixes, which is okay because the final reference is further suffixed if the prefix happens to collide with an existing reference. Using the util to generate Ogone's token aliases, however, poses a problem because aliases *must* be unique. Otherwise, a customer saving a payment token at the same second as another customer would end up linking their payment method to the other customer's payment token. This commit drops the use of the util method and replaces it with a UUID. closes odoo/odoo#115580 X-original-commit: 61d833ffcd1562950126d3c87c92569fe35a8b08 Signed-off-by: Antoine Vandevenne (anv) --- addons/payment/utils.py | 4 ++++ addons/payment_ogone/models/payment_transaction.py | 3 ++- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/addons/payment/utils.py b/addons/payment/utils.py index a724984d239..8a05e30e871 100644 --- a/addons/payment/utils.py +++ b/addons/payment/utils.py @@ -57,6 +57,10 @@ def singularize_reference_prefix(prefix='tx', separator='-', max_length=None): If the `max_length` argument is passed, the end of the prefix can be stripped before singularizing to ensure that the result accounts for no more than `max_length` characters. + Warning: Generated prefixes are *not* uniques! This function should be used only for making + transaction reference prefixes more distinguishable and *not* for operations that require the + generated value to be unique. + :param str prefix: The custom prefix to singularize :param str separator: The custom separator used to separate the prefix from the suffix :param int max_length: The maximum length of the singularized prefix diff --git a/addons/payment_ogone/models/payment_transaction.py b/addons/payment_ogone/models/payment_transaction.py index 7089d4f2468..505afcfb0b1 100644 --- a/addons/payment_ogone/models/payment_transaction.py +++ b/addons/payment_ogone/models/payment_transaction.py @@ -2,6 +2,7 @@ import logging import pprint +import uuid from lxml import etree, objectify from werkzeug import urls @@ -83,7 +84,7 @@ class PaymentTransaction(models.Model): } if self.tokenize: rendering_values.update({ - 'ALIAS': payment_utils.singularize_reference_prefix(prefix='ODOO-ALIAS'), + 'ALIAS': f'ODOO-ALIAS-{uuid.uuid4().hex}', 'ALIASUSAGE': _("Storing your payment details is necessary for future use."), }) rendering_values.update({