From cf42c2e27c833995b49b04ac2bcc7e0edee9e079 Mon Sep 17 00:00:00 2001 From: Swapnesh Shah Date: Mon, 24 Feb 2020 17:44:02 +0000 Subject: [PATCH] [FIX] sale,payment: Encode Payment URL correctly Before this commit, Payment URL was not encoded correctly which can compute Payment refernece Wrongly on website. Eg, Enter Description which contains Special Characters Go to Payment Page using Computed URL. There will be wrong Payment Reference on Payment page. With this commit, We encode Payment reference before generating Payment URL. closes odoo/odoo#47387 X-original-commit: 6ebcc43d177b9333afa73ee90e976d57111aaf3d Signed-off-by: Nicolas Martinelli (nim) --- addons/payment/wizards/payment_link_wizard.py | 4 +++- addons/sale/wizard/sale_payment_link.py | 4 +++- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/addons/payment/wizards/payment_link_wizard.py b/addons/payment/wizards/payment_link_wizard.py index 1c309534d12..fb6e02b9cf5 100644 --- a/addons/payment/wizards/payment_link_wizard.py +++ b/addons/payment/wizards/payment_link_wizard.py @@ -3,6 +3,8 @@ import hashlib import hmac +from werkzeug import urls + from odoo import api, fields, models, _ from odoo.exceptions import ValidationError from odoo.tools import ustr, consteq @@ -59,7 +61,7 @@ class PaymentLinkWizard(models.TransientModel): def _generate_link(self): base_url = self.env['ir.config_parameter'].sudo().get_param('web.base.url') for payment_link in self: - payment_link.link = '%s/website_payment/pay?reference=%s&amount=%s¤cy_id=%s&partner_id=%s&access_token=%s' % (base_url, payment_link.description, payment_link.amount, payment_link.currency_id.id, payment_link.partner_id.id, payment_link.access_token) + payment_link.link = '%s/website_payment/pay?reference=%s&amount=%s¤cy_id=%s&partner_id=%s&access_token=%s' % (base_url, urls.url_quote(payment_link.description), payment_link.amount, payment_link.currency_id.id, payment_link.partner_id.id, payment_link.access_token) @api.model def check_token(self, access_token, partner_id, amount, currency_id): diff --git a/addons/sale/wizard/sale_payment_link.py b/addons/sale/wizard/sale_payment_link.py index 6ea2930fbd3..e6f4e1ded93 100644 --- a/addons/sale/wizard/sale_payment_link.py +++ b/addons/sale/wizard/sale_payment_link.py @@ -1,6 +1,8 @@ # -*- coding: utf-8 -*- # Part of Odoo. See LICENSE file for full copyright and licensing details. +from werkzeug import urls + from odoo import api, models @@ -26,4 +28,4 @@ class SalePaymentLink(models.TransientModel): """ Override of the base method to add the order_id in the link. """ base_url = self.env['ir.config_parameter'].sudo().get_param('web.base.url') for payment_link in self: - payment_link.link = '%s/website_payment/pay?reference=%s&amount=%s¤cy_id=%s&partner_id=%s&order_id=%s&access_token=%s' % (base_url, payment_link.description, payment_link.amount, payment_link.currency_id.id, payment_link.partner_id.id, payment_link.res_id, payment_link.access_token) + payment_link.link = '%s/website_payment/pay?reference=%s&amount=%s¤cy_id=%s&partner_id=%s&order_id=%s&access_token=%s' % (base_url, urls.url_quote(payment_link.description), payment_link.amount, payment_link.currency_id.id, payment_link.partner_id.id, payment_link.res_id, payment_link.access_token)