From f4105eb9c7010f8693e5d2fd20c0bd9d9cc2e483 Mon Sep 17 00:00:00 2001 From: Romain Derie Date: Tue, 8 Oct 2019 14:16:21 +0000 Subject: [PATCH] [FIX] website: prevent endless loop if homepage is unpublished.. .. and first menu is a container with # as url. There is a particular case where the / url would loop endlessly. 1. Unpublished the homepage / 2. Edit the menu so the first menu is a container. There is a hint telling you a container menu should have its URL set to `#` as a good practice. 3. This will lead to endless loop for public user as the code will check if the homepage can be accessed. Since it is unpublished, it will then fallback on the first menu which is not '/' and redirect to it. Sadly, the code was not expecting `#` to be handled as `/`. opw-2081969 closes odoo/odoo#38234 X-original-commit: cff11bdb66f1dda41cf333a28b67df7ef20a3de9 Signed-off-by: Romain Derie (rde) --- addons/website/controllers/main.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/website/controllers/main.py b/addons/website/controllers/main.py index e1252e0e23b..5bb0f610500 100644 --- a/addons/website/controllers/main.py +++ b/addons/website/controllers/main.py @@ -77,7 +77,7 @@ class Website(Home): else: top_menu = request.website.menu_id first_menu = top_menu and top_menu.child_id and top_menu.child_id.filtered(lambda menu: menu.is_visible) - if first_menu and first_menu[0].url not in ('/', '') and (not (first_menu[0].url.startswith(('/?', '/#', ' ')))): + if first_menu and first_menu[0].url not in ('/', '', '#') and (not (first_menu[0].url.startswith(('/?', '/#', ' ')))): return request.redirect(first_menu[0].url) raise request.not_found()