From ed7f4ebb6afeff7e6759ebc28f55b81ccd9efedb Mon Sep 17 00:00:00 2001 From: Ryan Cen Date: Wed, 5 Apr 2023 19:44:30 +0000 Subject: [PATCH] [FIX] website_sale: CSRF token should not be cached Issue: CSRF token was being cached and this caused issues when the session id was updated. Post requests would continue to use the old CSRF token and it would not be able to be validated with the session id. Solution: Added the t-nocache attribute to every instance where csrf_token is called in the case that the session_id is different. This is changed to behave the same as the csrf token input in the products_item template. opw-3256880 closes odoo/odoo#117923 X-original-commit: 629d9cb15a6a6eb68756bad9da83cf0a81a3b5bd Signed-off-by: Antoine Vandevenne (anv) --- addons/website_sale/views/templates.xml | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/addons/website_sale/views/templates.xml b/addons/website_sale/views/templates.xml index 60b3e0056b3..7d38399f389 100644 --- a/addons/website_sale/views/templates.xml +++ b/addons/website_sale/views/templates.xml @@ -944,7 +944,7 @@

- +
@@ -1631,7 +1631,7 @@