From e14ab697727d87773dbefba11453b9edca79fc68 Mon Sep 17 00:00:00 2001 From: "Lucas Perais (lpe)" Date: Fri, 1 Sep 2017 16:35:25 +0200 Subject: [PATCH] [FIX] point_of_sale: control if a cashier is in localstorage Before this commit, we could temporarily change cashier from A to B, and back to A seamlessly just by refreshing the page. This could be a security issue for a cashier is held responsible for its sales. This commit stores the cashier in localstorage, and with the right sets of methods, corrects the issue. OPW 767827 closes #19207 --- addons/point_of_sale/static/src/js/db.js | 7 +++++++ addons/point_of_sale/static/src/js/models.js | 4 +++- 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/addons/point_of_sale/static/src/js/db.js b/addons/point_of_sale/static/src/js/db.js index b2621118d4a..8c61f5ff6ae 100644 --- a/addons/point_of_sale/static/src/js/db.js +++ b/addons/point_of_sale/static/src/js/db.js @@ -500,6 +500,13 @@ var PosDB = core.Class.extend({ } return orders; }, + set_cashier: function(cashier) { + // Always update if the user is the same as before + this.save('cashier', cashier); + }, + get_cashier: function() { + return this.load('cashier'); + } }); return PosDB; diff --git a/addons/point_of_sale/static/src/js/models.js b/addons/point_of_sale/static/src/js/models.js index 31c678e107c..814856f4e5a 100644 --- a/addons/point_of_sale/static/src/js/models.js +++ b/addons/point_of_sale/static/src/js/models.js @@ -240,6 +240,7 @@ exports.PosModel = Backbone.Model.extend({ } self.db.set_uuid(self.config.uuid); + self.cashier = self.get_cashier(); var orders = self.db.get_orders(); for (var i = 0; i < orders.length; i++) { @@ -579,11 +580,12 @@ exports.PosModel = Backbone.Model.extend({ // returns the user who is currently the cashier for this point of sale get_cashier: function(){ - return this.cashier || this.user; + return this.db.get_cashier() || this.cashier || this.user; }, // changes the current cashier set_cashier: function(user){ this.cashier = user; + this.db.set_cashier(this.cashier); }, //creates a new empty order and sets it as the current order add_new_order: function(){