[FIX] sale,payment: Encode Payment URL correctly

Before this commit, Payment URL was not encoded correctly which can compute Payment refernece Wrongly on website.

Eg,
  Enter Description which contains Special Characters
  Go to Payment Page using Computed URL.
  There will be wrong Payment Reference on Payment page.

With this commit, We encode Payment reference before generating Payment URL.

closes odoo/odoo#47387

X-original-commit: 6ebcc43d177b9333afa73ee90e976d57111aaf3d
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
This commit is contained in:
Swapnesh Shah
2020-03-11 12:25:06 +00:00
parent b6af34d30e
commit cf42c2e27c
2 changed files with 6 additions and 2 deletions
@@ -3,6 +3,8 @@
import hashlib
import hmac
from werkzeug import urls
from odoo import api, fields, models, _
from odoo.exceptions import ValidationError
from odoo.tools import ustr, consteq
@@ -59,7 +61,7 @@ class PaymentLinkWizard(models.TransientModel):
def _generate_link(self):
base_url = self.env['ir.config_parameter'].sudo().get_param('web.base.url')
for payment_link in self:
payment_link.link = '%s/website_payment/pay?reference=%s&amount=%s&currency_id=%s&partner_id=%s&access_token=%s' % (base_url, payment_link.description, payment_link.amount, payment_link.currency_id.id, payment_link.partner_id.id, payment_link.access_token)
payment_link.link = '%s/website_payment/pay?reference=%s&amount=%s&currency_id=%s&partner_id=%s&access_token=%s' % (base_url, urls.url_quote(payment_link.description), payment_link.amount, payment_link.currency_id.id, payment_link.partner_id.id, payment_link.access_token)
@api.model
def check_token(self, access_token, partner_id, amount, currency_id):
+3 -1
View File
@@ -1,6 +1,8 @@
# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
from werkzeug import urls
from odoo import api, models
@@ -26,4 +28,4 @@ class SalePaymentLink(models.TransientModel):
""" Override of the base method to add the order_id in the link. """
base_url = self.env['ir.config_parameter'].sudo().get_param('web.base.url')
for payment_link in self:
payment_link.link = '%s/website_payment/pay?reference=%s&amount=%s&currency_id=%s&partner_id=%s&order_id=%s&access_token=%s' % (base_url, payment_link.description, payment_link.amount, payment_link.currency_id.id, payment_link.partner_id.id, payment_link.res_id, payment_link.access_token)
payment_link.link = '%s/website_payment/pay?reference=%s&amount=%s&currency_id=%s&partner_id=%s&order_id=%s&access_token=%s' % (base_url, urls.url_quote(payment_link.description), payment_link.amount, payment_link.currency_id.id, payment_link.partner_id.id, payment_link.res_id, payment_link.access_token)