diff --git a/addons/gamification/models/badge.py b/addons/gamification/models/badge.py index 0fd69631650..509c95ad909 100644 --- a/addons/gamification/models/badge.py +++ b/addons/gamification/models/badge.py @@ -233,7 +233,7 @@ class GamificationBadge(models.Model): elif self.rule_auth == 'users' and self.env.user not in self.rule_auth_user_ids: return self.USER_NOT_VIP elif self.rule_auth == 'having': - all_user_badges = self.env['gamification.badge.user'].search([('user_id', '=', self.env.uid)]) + all_user_badges = self.env['gamification.badge.user'].search([('user_id', '=', self.env.uid)]).mapped('badge_id') if self.rule_auth_badge_ids - all_user_badges: return self.BADGE_REQUIRED diff --git a/addons/payment_authorize/models/payment.py b/addons/payment_authorize/models/payment.py index cd35782a506..e3251f7770a 100644 --- a/addons/payment_authorize/models/payment.py +++ b/addons/payment_authorize/models/payment.py @@ -6,6 +6,7 @@ from datetime import datetime import hashlib import hmac import logging +import string import time from odoo import _, api, fields, models @@ -53,8 +54,16 @@ class PaymentAcquirerAuthorize(models.Model): values['x_fp_sequence'], values['x_fp_timestamp'], values['x_amount'], - values['x_currency_code']]) - return hmac.new(values['x_trans_key'].encode('utf-8'), data.encode('utf-8'), hashlib.md5).hexdigest() + values['x_currency_code']]).encode('utf-8') + + # [BACKWARD COMPATIBILITY] Check that the merchant did update his transaction + # key to signature key (end of MD5 support from Authorize.net) + # The signature key is now '128-character hexadecimal format', while the + # transaction key was only 16-character. + if len(values['x_trans_key']) == 128: + return hmac.new(values['x_trans_key'].decode("hex").encode('utf-8'), data, hashlib.sha512).hexdigest().upper() + else: + return hmac.new(values['x_trans_key'].encode('utf-8'), data, hashlib.md5).hexdigest() @api.multi def authorize_form_generate_values(self, values): @@ -181,7 +190,7 @@ class TxAuthorize(models.Model): def _authorize_form_get_tx_from_data(self, data): """ Given a data dict coming from authorize, verify it and find the related transaction record. """ - reference, trans_id, fingerprint = data.get('x_invoice_num'), data.get('x_trans_id'), data.get('x_MD5_Hash') + reference, trans_id, fingerprint = data.get('x_invoice_num'), data.get('x_trans_id'), data.get('x_SHA2_Hash') or data.get('x_MD5_Hash') if not reference or not trans_id or not fingerprint: error_msg = _('Authorize: received data with missing reference (%s) or trans_id (%s) or fingerprint (%s)') % (reference, trans_id, fingerprint) _logger.info(error_msg) diff --git a/addons/payment_authorize/tests/test_authorize.py b/addons/payment_authorize/tests/test_authorize.py index 40d0d960b50..19747f0d60e 100644 --- a/addons/payment_authorize/tests/test_authorize.py +++ b/addons/payment_authorize/tests/test_authorize.py @@ -1,7 +1,5 @@ # -*- coding: utf-8 -*- -import hashlib -import hmac import time import unittest from lxml import objectify @@ -32,15 +30,6 @@ class AuthorizeCommon(PaymentAcquirerCommon): @odoo.tests.common.post_install(True) class AuthorizeForm(AuthorizeCommon): - def _authorize_generate_hashing(self, values): - data = '^'.join([ - values['x_login'], - values['x_fp_sequence'], - values['x_fp_timestamp'], - values['x_amount'], - ]) + '^' - return hmac.new(values['x_trans_key'].encode('utf-8'), data.encode('utf-8'), hashlib.md5).hexdigest() - def test_10_Authorize_form_render(self): self.assertEqual(self.authorize.environment, 'test', 'test without test environment') @@ -85,7 +74,7 @@ class AuthorizeForm(AuthorizeCommon): 'x_ship_to_state': None, } - form_values['x_fp_hash'] = self._authorize_generate_hashing(form_values) + form_values['x_fp_hash'] = self.env['payment.acquirer']._authorize_generate_hashing(form_values) # render the button res = self.authorize.render('SO004', 56.16, self.currency_usd.id, values=self.buyer_values) # check form result @@ -112,7 +101,9 @@ class AuthorizeForm(AuthorizeCommon): # typical data posted by authorize after client has successfully paid authorize_post_data = { 'return_url': u'/shop/payment/validate', + # x_MD5_Hash will be empty starting the 28th March 2019 'x_MD5_Hash': u'7934485E1C105940BE854208D10FAB4F', + 'x_SHA2_Hash': u'7D3AC844BE8CA3F649AB885A90D22CFE35B850338EC91D1A5ADD819A85FF948A3D777334A18CDE36821DC8F2B42A6E1950C1FF96B52B60F23201483A656195FB', 'x_account_number': u'XXXX0027', 'x_address': u'Huge Street 2/543', 'x_amount': u'320.00', diff --git a/addons/point_of_sale/static/src/js/screens.js b/addons/point_of_sale/static/src/js/screens.js index 08262f73336..045f0be7718 100644 --- a/addons/point_of_sale/static/src/js/screens.js +++ b/addons/point_of_sale/static/src/js/screens.js @@ -1307,7 +1307,7 @@ var ClientListScreenWidget = ScreenWidget.extend({ // what happens when we've just pushed modifications for a partner of id partner_id saved_client_details: function(partner_id){ var self = this; - this.reload_partners().then(function(){ + return this.reload_partners().then(function(){ var partner = self.pos.db.get_partner_by_id(partner_id); if (partner) { self.new_client = partner; diff --git a/addons/website_mass_mailing/i18n/website_mass_mailing.pot b/addons/website_mass_mailing/i18n/website_mass_mailing.pot index 150eddbbca8..8b3151bec24 100644 --- a/addons/website_mass_mailing/i18n/website_mass_mailing.pot +++ b/addons/website_mass_mailing/i18n/website_mass_mailing.pot @@ -76,6 +76,11 @@ msgstr "" msgid "Mailing Subscriptions" msgstr "" +#. module: website_mass_mailing +#: model:ir.ui.view,arch_db:website_mass_mailing.unsubscribe +msgid "Update my subscriptions" +msgstr "" + #. module: website_mass_mailing #. openerp-web #: code:addons/website_mass_mailing/static/src/js/website_mass_mailing.editor.js:21 @@ -170,4 +175,3 @@ msgstr "" #: model:ir.ui.view,arch_db:website_mass_mailing.s_newsletter_subscribe_popup msgid "your email..." msgstr "" - diff --git a/addons/website_mass_mailing/views/unsubscribe_templates.xml b/addons/website_mass_mailing/views/unsubscribe_templates.xml index ae0a10a9674..ca7be31bc50 100644 --- a/addons/website_mass_mailing/views/unsubscribe_templates.xml +++ b/addons/website_mass_mailing/views/unsubscribe_templates.xml @@ -30,7 +30,7 @@