[FIX] website_sale: CSRF token should not be cached

Issue:
CSRF token was being cached and this caused issues when the session id was updated.
Post requests would continue to use the old CSRF token and it would not be able to be validated with the session id.

Solution:
Added the t-nocache attribute to every instance where csrf_token is called in the case that the session_id is different.
This is changed to behave the same as the csrf token input in the products_item template.

opw-3256880

closes odoo/odoo#117923

X-original-commit: 629d9cb15a6a6eb68756bad9da83cf0a81a3b5bd
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
This commit is contained in:
Ryan Cen
2023-04-12 14:02:32 +02:00
parent 9e6d230715
commit ed7f4ebb6a
+6 -6
View File
@@ -944,7 +944,7 @@
</t>
<p t-field="product.description_sale" class="text-muted my-2" placeholder="A short description that will also appear on documents." />
<form t-if="product._is_add_to_cart_possible()" action="/shop/cart/update" method="POST">
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" />
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" t-nocache="The csrf token must always be up to date."/>
<div class="js_product js_main_product mb-3">
<div>
<t t-call="website_sale.product_price"/>
@@ -1631,7 +1631,7 @@
<template id='coupon_form' name='Coupon form'>
<form t-att-action="'/shop/pricelist%s' % (redirect and '?r=' + redirect or '')"
method="post" name="coupon_code">
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" />
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" t-nocache="The csrf token must always be up to date."/>
<div class="input-group w-100">
<input name="promo" class="form-control" type="text" placeholder="code..." t-att-value="website_sale_order.pricelist_id.code or None"/>
<a href="#" role="button" class="btn btn-secondary a-submit">Apply</a>
@@ -1685,7 +1685,7 @@
<div class="row mt8">
<div class="col-md-12 col-lg-12 one_kanban">
<form action="/shop/address" method="post" class=''>
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" />
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" t-nocache="The csrf token must always be up to date."/>
<a role="button" href="#" class='a-submit btn btn-secondary mb-2 btn-block'>
<i class="fa fa-plus-square"/>
<span>Add an address</span>
@@ -1726,7 +1726,7 @@
<template id="address_kanban" name="Kanban address">
<form action="/shop/checkout" method="POST" class="d-none">
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" />
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" t-nocache="The csrf token must always be up to date."/>
<input type="hidden" name="partner_id" t-att-value="contact.id" />
<t t-if='edit_billing'>
<input type="hidden" name="callback" value="/shop/checkout?use_billing" />
@@ -1896,7 +1896,7 @@
</t>
</div>
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" />
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" t-nocache="The csrf token must always be up to date."/>
<input type="hidden" name="submitted" value="1" />
<input type="hidden" name="partner_id" t-att-value="partner_id or '0'" />
<input type="hidden" name="callback" t-att-value="callback" />
@@ -1997,7 +1997,7 @@
</div>
<div class="js_payment mt-3" t-if="not website_sale_order.amount_total" id="payment_method" name="o_website_sale_free_cart">
<form target="_self" action="/shop/payment/validate" method="post">
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" />
<input type="hidden" name="csrf_token" t-att-value="request.csrf_token()" t-nocache="The csrf token must always be up to date."/>
<t t-call="website_sale.payment_footer">
<t t-set="submit_button_label">Confirm Order</t>
</t>