From caf900e89ea292c56ed773232792a2aab19de8d5 Mon Sep 17 00:00:00 2001 From: Raphael Collet Date: Thu, 27 Jun 2019 15:00:41 +0000 Subject: [PATCH] [FIX] *: use `auth='public'` in controllers that use `request.env` The following trick used to work, because `sudo()` was actually making an environment for the superuser to operate upon: request.env[...].sudo().method(...) It no longer works in general, since `sudo()` now makes an environment in superuser mode but with `uid=None`! It may still work by accident for operations that never use `env.uid`, but is broken in general. Using `auth='public'` fixes the problem by using the public user when no user is available. closes odoo/odoo#34297 Signed-off-by: Olivier Dony (odo) --- addons/base_gengo/controller/main.py | 2 +- addons/im_livechat/controllers/main.py | 2 +- addons/link_tracker/controller/main.py | 2 +- addons/mail/controllers/bus.py | 4 ++-- addons/mail/controllers/main.py | 2 +- addons/mass_mailing/controllers/main.py | 14 +++++++------- addons/payment_adyen/controllers/main.py | 4 ++-- addons/payment_alipay/controllers/main.py | 4 ++-- addons/payment_buckaroo/controllers/main.py | 2 +- addons/payment_ogone/controllers/main.py | 6 +++--- addons/payment_paypal/controllers/main.py | 6 +++--- addons/payment_sips/controllers/main.py | 4 ++-- addons/payment_transfer/controllers/main.py | 2 +- addons/web/controllers/main.py | 2 +- 14 files changed, 28 insertions(+), 28 deletions(-) diff --git a/addons/base_gengo/controller/main.py b/addons/base_gengo/controller/main.py index 9349b15ab04..dac1dc2775e 100644 --- a/addons/base_gengo/controller/main.py +++ b/addons/base_gengo/controller/main.py @@ -8,7 +8,7 @@ from odoo.http import Controller, Response, request, route class website_gengo(Controller): - @route('/website/gengo_callback', type='http', auth='none', csrf=False) + @route('/website/gengo_callback', type='http', auth='public', csrf=False) def gengo_callback(self, **post): IrTranslationSudo = request.env['ir.translation'].sudo() if post and post.get('job') and post.get('pgk'): diff --git a/addons/im_livechat/controllers/main.py b/addons/im_livechat/controllers/main.py index 5703563e95d..8e56c2279f3 100644 --- a/addons/im_livechat/controllers/main.py +++ b/addons/im_livechat/controllers/main.py @@ -13,7 +13,7 @@ class LivechatController(http.Controller): # Note: the `cors` attribute on many routes is meant to allow the livechat # to be embedded in an external website. - @http.route('/im_livechat/external_lib.', type='http', auth='none') + @http.route('/im_livechat/external_lib.', type='http', auth='public') def livechat_lib(self, ext, **kwargs): # _get_asset return the bundle html code (script and link list) but we want to use the attachment content xmlid = 'im_livechat.external_lib' diff --git a/addons/link_tracker/controller/main.py b/addons/link_tracker/controller/main.py index d884967b5a6..b2fb720fa1e 100644 --- a/addons/link_tracker/controller/main.py +++ b/addons/link_tracker/controller/main.py @@ -9,7 +9,7 @@ from odoo.http import request class LinkTracker(http.Controller): - @http.route('/r/', type='http', auth='none', website=True) + @http.route('/r/', type='http', auth='public', website=True) def full_url_redirect(self, code, **post): country_code = request.session.geoip and request.session.geoip.get('country_code') or False request.env['link.tracker.click'].sudo().add_click( diff --git a/addons/mail/controllers/bus.py b/addons/mail/controllers/bus.py index 912aae3cacd..6ad8cc88870 100644 --- a/addons/mail/controllers/bus.py +++ b/addons/mail/controllers/bus.py @@ -34,7 +34,7 @@ class MailChatController(BusController): # -------------------------- # Anonymous routes (Common Methods) # -------------------------- - @route('/mail/chat_post', type="json", auth="none", cors="*") + @route('/mail/chat_post', type="json", auth="public", cors="*") def mail_chat_post(self, uuid, message_content, **kwargs): # find the author from the user session, which can be None author_id = False # message_post accept 'False' author_id, but not 'None' @@ -46,7 +46,7 @@ class MailChatController(BusController): message = mail_channel.sudo().with_context(mail_create_nosubscribe=True).message_post(author_id=author_id, email_from=False, body=body, message_type='comment', subtype='mail.mt_comment') return message and message.id or False - @route(['/mail/chat_history'], type="json", auth="none", cors="*") + @route(['/mail/chat_history'], type="json", auth="public", cors="*") def mail_chat_history(self, uuid, last_id=False, limit=20): channel = request.env["mail.channel"].sudo().search([('uuid', '=', uuid)], limit=1) if not channel: diff --git a/addons/mail/controllers/main.py b/addons/mail/controllers/main.py index 38c4cbb3509..b540d428ba0 100644 --- a/addons/mail/controllers/main.py +++ b/addons/mail/controllers/main.py @@ -189,7 +189,7 @@ class MailController(http.Controller): subtypes_list = sorted(subtypes_list, key=lambda it: (it['parent_model'] or '', it['res_model'] or '', it['internal'], it['sequence'])) return subtypes_list - @http.route('/mail/view', type='http', auth='none') + @http.route('/mail/view', type='http', auth='public') def mail_action_view(self, model=None, res_id=None, access_token=None, **kwargs): """ Generic access point from notification emails. The heuristic to choose where to redirect the user is the following : diff --git a/addons/mass_mailing/controllers/main.py b/addons/mass_mailing/controllers/main.py index fda77b95c95..a03435fddef 100644 --- a/addons/mass_mailing/controllers/main.py +++ b/addons/mass_mailing/controllers/main.py @@ -80,7 +80,7 @@ class MassMailController(http.Controller): }) return request.redirect('/web') - @http.route('/mail/mailing/unsubscribe', type='json', auth='none') + @http.route('/mail/mailing/unsubscribe', type='json', auth='public') def unsubscribe(self, mailing_id, opt_in_ids, opt_out_ids, email, res_id, token): mailing = request.env['mail.mass_mailing'].sudo().browse(mailing_id) if mailing.exists(): @@ -91,7 +91,7 @@ class MassMailController(http.Controller): return True return 'error' - @http.route('/mail/track//blank.gif', type='http', auth='none') + @http.route('/mail/track//blank.gif', type='http', auth='public') def track_mail_open(self, mail_id, **post): """ Email tracking. """ request.env['mail.mail.statistics'].sudo().set_opened(mail_mail_ids=[mail_id]) @@ -101,7 +101,7 @@ class MassMailController(http.Controller): return response - @http.route('/r//m/', type='http', auth="none") + @http.route('/r//m/', type='http', auth="public") def full_url_redirect(self, code, stat_id, **post): # don't assume geoip is set, it is part of the website module # which mass_mailing doesn't depend on @@ -115,7 +115,7 @@ class MassMailController(http.Controller): ) return werkzeug.utils.redirect(request.env['link.tracker'].get_url_from_code(code), 301) - @http.route('/mailing/blacklist/check', type='json', auth='none') + @http.route('/mailing/blacklist/check', type='json', auth='public') def blacklist_check(self, mailing_id, res_id, email, token): if not self._valid_unsubscribe_token(mailing_id, res_id, email, token): return 'unauthorized' @@ -126,7 +126,7 @@ class MassMailController(http.Controller): return False return 'error' - @http.route('/mailing/blacklist/add', type='json', auth='none') + @http.route('/mailing/blacklist/add', type='json', auth='public') def blacklist_add(self, mailing_id, res_id, email, token): if not self._valid_unsubscribe_token(mailing_id, res_id, email, token): return 'unauthorized' @@ -138,7 +138,7 @@ class MassMailController(http.Controller): return True return 'error' - @http.route('/mailing/blacklist/remove', type='json', auth='none') + @http.route('/mailing/blacklist/remove', type='json', auth='public') def blacklist_remove(self, mailing_id, res_id, email, token): if not self._valid_unsubscribe_token(mailing_id, res_id, email, token): return 'unauthorized' @@ -150,7 +150,7 @@ class MassMailController(http.Controller): return True return 'error' - @http.route('/mailing/feedback', type='json', auth='none') + @http.route('/mailing/feedback', type='json', auth='public') def send_feedback(self, mailing_id, res_id, email, feedback, token): mailing = request.env['mail.mass_mailing'].sudo().browse(mailing_id) if mailing.exists() and email: diff --git a/addons/payment_adyen/controllers/main.py b/addons/payment_adyen/controllers/main.py index 7de5a6dc7ef..cc09d580050 100644 --- a/addons/payment_adyen/controllers/main.py +++ b/addons/payment_adyen/controllers/main.py @@ -16,7 +16,7 @@ class AdyenController(http.Controller): @http.route([ '/payment/adyen/return', - ], type='http', auth='none', csrf=False) + ], type='http', auth='public', csrf=False) def adyen_return(self, **post): _logger.info('Beginning Adyen form_feedback with post data %s', pprint.pformat(post)) # debug if post.get('authResult') not in ['CANCELLED']: @@ -25,7 +25,7 @@ class AdyenController(http.Controller): @http.route([ '/payment/adyen/notification', - ], type='http', auth='none', methods=['POST'], csrf=False) + ], type='http', auth='public', methods=['POST'], csrf=False) def adyen_notification(self, **post): tx = post.get('merchantReference') and request.env['payment.transaction'].sudo().search([('reference', 'in', [post.get('merchantReference')])], limit=1) if post.get('eventCode') in ['AUTHORISATION'] and tx: diff --git a/addons/payment_alipay/controllers/main.py b/addons/payment_alipay/controllers/main.py index 1f28217cabc..14fc05efca8 100644 --- a/addons/payment_alipay/controllers/main.py +++ b/addons/payment_alipay/controllers/main.py @@ -49,14 +49,14 @@ class AlipayController(http.Controller): return 'success' return "" - @http.route('/payment/alipay/return', type='http', auth="none", methods=['GET', 'POST']) + @http.route('/payment/alipay/return', type='http', auth="public", methods=['GET', 'POST']) def alipay_return(self, **post): """ Alipay return """ _logger.info('Beginning Alipay form_feedback with post data %s', pprint.pformat(post)) self._alipay_validate_data(**post) return werkzeug.utils.redirect('/payment/process') - @http.route('/payment/alipay/notify', type='http', auth='none', methods=['POST'], csrf=False) + @http.route('/payment/alipay/notify', type='http', auth='public', methods=['POST'], csrf=False) def alipay_notify(self, **post): """ Alipay Notify """ _logger.info('Beginning Alipay notification form_feedback with post data %s', pprint.pformat(post)) diff --git a/addons/payment_buckaroo/controllers/main.py b/addons/payment_buckaroo/controllers/main.py index 7fe17c8344f..1810355cc3c 100644 --- a/addons/payment_buckaroo/controllers/main.py +++ b/addons/payment_buckaroo/controllers/main.py @@ -21,7 +21,7 @@ class BuckarooController(http.Controller): '/payment/buckaroo/cancel', '/payment/buckaroo/error', '/payment/buckaroo/reject', - ], type='http', auth='none', csrf=False) + ], type='http', auth='public', csrf=False) def buckaroo_return(self, **post): """ Buckaroo.""" _logger.info('Buckaroo: entering form_feedback with post data %s', pprint.pformat(post)) # debug diff --git a/addons/payment_ogone/controllers/main.py b/addons/payment_ogone/controllers/main.py index 6bebff17f34..e6e4df7e41b 100644 --- a/addons/payment_ogone/controllers/main.py +++ b/addons/payment_ogone/controllers/main.py @@ -23,7 +23,7 @@ class OgoneController(http.Controller): '/payment/ogone/decline', '/payment/ogone/test/decline', '/payment/ogone/exception', '/payment/ogone/test/exception', '/payment/ogone/cancel', '/payment/ogone/test/cancel', - ], type='http', auth='none') + ], type='http', auth='public') def ogone_form_feedback(self, **post): """ Ogone contacts using GET, at least for accept """ _logger.info('Ogone: entering form_feedback with post data %s', pprint.pformat(post)) # debug @@ -110,13 +110,13 @@ class OgoneController(http.Controller): '/payment/ogone/validate/accept', '/payment/ogone/validate/decline', '/payment/ogone/validate/exception', - ], type='http', auth='none') + ], type='http', auth='public') def ogone_validation_form_feedback(self, **post): """ Feedback from 3d secure for a bank card validation """ request.env['payment.transaction'].sudo().form_feedback(post, 'ogone') return werkzeug.utils.redirect("/payment/process") - @http.route(['/payment/ogone/s2s/feedback'], auth='none', csrf=False) + @http.route(['/payment/ogone/s2s/feedback'], auth='public', csrf=False) def feedback(self, **kwargs): try: tx = request.env['payment.transaction'].sudo()._ogone_form_get_tx_from_data(kwargs) diff --git a/addons/payment_paypal/controllers/main.py b/addons/payment_paypal/controllers/main.py index f9166ecf302..a3e87413747 100644 --- a/addons/payment_paypal/controllers/main.py +++ b/addons/payment_paypal/controllers/main.py @@ -86,7 +86,7 @@ class PaypalController(http.Controller): tx.sudo()._set_transaction_error('Unrecognized error from Paypal. Please contact your administrator.') return res - @http.route('/payment/paypal/ipn/', type='http', auth='none', methods=['POST'], csrf=False) + @http.route('/payment/paypal/ipn/', type='http', auth='public', methods=['POST'], csrf=False) def paypal_ipn(self, **post): """ Paypal IPN. """ _logger.info('Beginning Paypal IPN form_feedback with post data %s', pprint.pformat(post)) # debug @@ -96,7 +96,7 @@ class PaypalController(http.Controller): _logger.exception('Unable to validate the Paypal payment') return '' - @http.route('/payment/paypal/dpn', type='http', auth="none", methods=['POST', 'GET'], csrf=False) + @http.route('/payment/paypal/dpn', type='http', auth="public", methods=['POST', 'GET'], csrf=False) def paypal_dpn(self, **post): """ Paypal DPN """ _logger.info('Beginning Paypal DPN form_feedback with post data %s', pprint.pformat(post)) # debug @@ -106,7 +106,7 @@ class PaypalController(http.Controller): _logger.exception('Unable to validate the Paypal payment') return werkzeug.utils.redirect('/payment/process') - @http.route('/payment/paypal/cancel', type='http', auth="none", csrf=False) + @http.route('/payment/paypal/cancel', type='http', auth="public", csrf=False) def paypal_cancel(self, **post): """ When the user cancels its Paypal payment: GET on this route """ _logger.info('Beginning Paypal cancel with post data %s', pprint.pformat(post)) # debug diff --git a/addons/payment_sips/controllers/main.py b/addons/payment_sips/controllers/main.py index de3e90810ee..4135e48238f 100644 --- a/addons/payment_sips/controllers/main.py +++ b/addons/payment_sips/controllers/main.py @@ -27,14 +27,14 @@ class SipsController(http.Controller): @http.route([ '/payment/sips/ipn/'], - type='http', auth='none', methods=['POST'], csrf=False) + type='http', auth='public', methods=['POST'], csrf=False) def sips_ipn(self, **post): """ Sips IPN. """ self.sips_validate_data(**post) return '' @http.route([ - '/payment/sips/dpn'], type='http', auth="none", methods=['POST'], csrf=False) + '/payment/sips/dpn'], type='http', auth="public", methods=['POST'], csrf=False) def sips_dpn(self, **post): """ Sips DPN """ try: diff --git a/addons/payment_transfer/controllers/main.py b/addons/payment_transfer/controllers/main.py index 29a1d20d8e1..35a34831b00 100644 --- a/addons/payment_transfer/controllers/main.py +++ b/addons/payment_transfer/controllers/main.py @@ -14,7 +14,7 @@ class OgoneController(http.Controller): @http.route([ '/payment/transfer/feedback', - ], type='http', auth='none', csrf=False) + ], type='http', auth='public', csrf=False) def transfer_form_feedback(self, **post): _logger.info('Beginning form_feedback with post data %s', pprint.pformat(post)) # debug request.env['payment.transaction'].sudo().form_feedback(post, 'transfer') diff --git a/addons/web/controllers/main.py b/addons/web/controllers/main.py index 7aca92712a8..d77a4ea9e7e 100644 --- a/addons/web/controllers/main.py +++ b/addons/web/controllers/main.py @@ -619,7 +619,7 @@ class WebClient(http.Controller): return {"modules": translations_per_module, "lang_parameters": None} - @http.route('/web/webclient/translations/', type='http', auth="none") + @http.route('/web/webclient/translations/', type='http', auth="public") def translations(self, unique, mods=None, lang=None): """ Load the translations for the specified language and modules