From a8465d523516b97c613296568a326cb141d5fd23 Mon Sep 17 00:00:00 2001 From: KolushovAlexandr Date: Tue, 7 Aug 2018 12:44:10 +0000 Subject: [PATCH 1/6] [IMP] point_of_sale saved_client_details method closes odoo/odoo#26220 Signed-off-by: Quentin Lejeune (qle) --- addons/point_of_sale/static/src/js/screens.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/point_of_sale/static/src/js/screens.js b/addons/point_of_sale/static/src/js/screens.js index 2b397e10a2e..02069ce2cdd 100644 --- a/addons/point_of_sale/static/src/js/screens.js +++ b/addons/point_of_sale/static/src/js/screens.js @@ -1247,7 +1247,7 @@ var ClientListScreenWidget = ScreenWidget.extend({ // what happens when we've just pushed modifications for a partner of id partner_id saved_client_details: function(partner_id){ var self = this; - this.reload_partners().then(function(){ + return this.reload_partners().then(function(){ var partner = self.pos.db.get_partner_by_id(partner_id); if (partner) { self.new_client = partner; From eb62cd2c2b8eba2fceee4f0491a7f9a045de73d5 Mon Sep 17 00:00:00 2001 From: Suganthi Karunanithi Date: Tue, 26 Feb 2019 14:46:48 +0000 Subject: [PATCH 2/6] [FIX] gamification: badge auth for badge no error To avoid exception: TypeError: Mixing apples and oranges: gamification.badge() - gamification.badge.user(1,) when rule_auth of a badge is set to `having`. opw-1945440 closes #31436 closes #31595 Signed-off-by: Nicolas Lempereur (nle) --- addons/gamification/models/badge.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/gamification/models/badge.py b/addons/gamification/models/badge.py index 58553981ab7..842bd88f673 100644 --- a/addons/gamification/models/badge.py +++ b/addons/gamification/models/badge.py @@ -236,7 +236,7 @@ class GamificationBadge(models.Model): elif self.rule_auth == 'users' and self.env.user not in self.rule_auth_user_ids: return self.USER_NOT_VIP elif self.rule_auth == 'having': - all_user_badges = self.env['gamification.badge.user'].search([('user_id', '=', self.env.uid)]) + all_user_badges = self.env['gamification.badge.user'].search([('user_id', '=', self.env.uid)]).mapped('badge_id') if self.rule_auth_badge_ids - all_user_badges: return self.BADGE_REQUIRED From cc54194e130d4a93d9afdd7aedc7d35be2e03fed Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?R=C3=A9mi=20Rahir?= Date: Thu, 7 Mar 2019 15:33:01 +0000 Subject: [PATCH 3/6] [FIX] website_sale: filter fiscal positions on company MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit When creating a cart on the website, the website company was not considered which could end up with the selection of a fiscal position linked to a wrong company since the method is called in sudo. closes odoo/odoo#31673 Signed-off-by: Rémi Rahir (rar) --- addons/website_sale/models/sale_order.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/website_sale/models/sale_order.py b/addons/website_sale/models/sale_order.py index 111f208f60b..c98fb72deea 100644 --- a/addons/website_sale/models/sale_order.py +++ b/addons/website_sale/models/sale_order.py @@ -399,7 +399,7 @@ class Website(models.Model): country_code = request.session['geoip'].get('country_code') if country_code: country_id = request.env['res.country'].search([('code', '=', country_code)], limit=1).id - fp_id = request.env['account.fiscal.position'].sudo()._get_fpos_by_region(country_id) + fp_id = request.env['account.fiscal.position'].sudo().with_context(force_company=request.website.company_id.id)._get_fpos_by_region(country_id) sale_order.fiscal_position_id = fp_id else: # if no geolocation, use the public user fp From 98b2784d1e29629a7b39275f6580c76dbe3e2cab Mon Sep 17 00:00:00 2001 From: "Pedro M. Baeza" Date: Wed, 12 Dec 2018 16:02:25 +0000 Subject: [PATCH 4/6] [CLA] backport of e78af353fc7 to 10.0 Include cristinamartinrod in CLA of Tecnativa Needed for odoo/odoo#30774 --- doc/cla/corporate/tecnativa.md | 1 + 1 file changed, 1 insertion(+) diff --git a/doc/cla/corporate/tecnativa.md b/doc/cla/corporate/tecnativa.md index 72a73cbbe28..9f3601d16a0 100644 --- a/doc/cla/corporate/tecnativa.md +++ b/doc/cla/corporate/tecnativa.md @@ -20,3 +20,4 @@ Jairo Llopis jairo.llopis@tecnativa.com https://github.com/yajo Vicent Cubells vicent.cubells@tecnativa.com https://github.com/cubells Luis Montalba luis.montalba@tecnativa.com https://github.com/luismontalba David Vidal david.vidal@tecnativa.com https://github.com/chienandalu +Cristina Martín cristina.martin@tecnativa.com https://github.com/cristinamartinrod From ca1b201cec406898a765ff966473eee69323fef5 Mon Sep 17 00:00:00 2001 From: cristinamartinrod Date: Thu, 7 Mar 2019 12:53:19 +0000 Subject: [PATCH 5/6] [FIX] website_mass_mailing: translate button The text was in a value tag, making it untranslatable Closes odoo/odoo#30774 Signed-off-by: Martin Trigaux (mat) --- addons/website_mass_mailing/i18n/website_mass_mailing.pot | 6 +++++- addons/website_mass_mailing/views/unsubscribe_templates.xml | 2 +- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/addons/website_mass_mailing/i18n/website_mass_mailing.pot b/addons/website_mass_mailing/i18n/website_mass_mailing.pot index 6491c32c52a..7480d32a965 100644 --- a/addons/website_mass_mailing/i18n/website_mass_mailing.pot +++ b/addons/website_mass_mailing/i18n/website_mass_mailing.pot @@ -81,6 +81,11 @@ msgstr "" msgid "Mailing Subscriptions" msgstr "" +#. module: website_mass_mailing +#: model:ir.ui.view,arch_db:website_mass_mailing.unsubscribe +msgid "Update my subscriptions" +msgstr "" + #. module: website_mass_mailing #. openerp-web #: code:addons/website_mass_mailing/static/src/js/website_mass_mailing.editor.js:22 @@ -166,4 +171,3 @@ msgstr "" #: model:ir.ui.view,arch_db:website_mass_mailing.s_newsletter_subscribe_popup msgid "your email..." msgstr "" - diff --git a/addons/website_mass_mailing/views/unsubscribe_templates.xml b/addons/website_mass_mailing/views/unsubscribe_templates.xml index 8f044491102..72e14adb05a 100644 --- a/addons/website_mass_mailing/views/unsubscribe_templates.xml +++ b/addons/website_mass_mailing/views/unsubscribe_templates.xml @@ -28,7 +28,7 @@
- +
From 88de93114161a2b9a86f32a1b77201dac47e0756 Mon Sep 17 00:00:00 2001 From: Romain Derie Date: Fri, 1 Mar 2019 17:17:23 +0000 Subject: [PATCH 6/6] [FIX] payment_authorize: use SHA-512 instead of MD5 as not supported Authorize.Net is phasing out the MD5 based hash use for transaction response verification in favor of the SHA-512 based hash utilizing a Signature Key. Instead of hashing with md5 the transaction key, it is now required to hash the signature key (binary format) with SHA-512. Support for MD5 will be dropped the 7th March 2019 for sandbox environment and the 28th March 2019 for production environment, initially planned for the 14th. Note that as of February 11, 2019 authorize removed the ability to configure or update MD5 Hash setting in the Merchant Interface. Merchants who had this setting configured have been emailed/contacted. opw-1943030 Usefull links: https://developer.authorize.net/support/hash_upgrade/ https://support.authorize.net/s/article/What-is-a-Signature-Key https://support.authorize.net/s/article/MD5-Hash-End-of-Life-Signature-Key-Replacement https://support.authorize.net/s/article/Do-I-need-to-upgrade-my-transaction-fingerprint-from-HMAC-MD5-to-HMAC-SHA512-and-how closes odoo/odoo#31642 Signed-off-by: Romain Derie (rde) --- addons/payment_authorize/models/payment.py | 13 +++++++++++-- addons/payment_authorize/tests/test_authorize.py | 15 +++------------ 2 files changed, 14 insertions(+), 14 deletions(-) diff --git a/addons/payment_authorize/models/payment.py b/addons/payment_authorize/models/payment.py index 73c7c044e0a..6c31e7a499e 100644 --- a/addons/payment_authorize/models/payment.py +++ b/addons/payment_authorize/models/payment.py @@ -5,6 +5,7 @@ from datetime import datetime import hashlib import hmac import logging +import string import time import urlparse @@ -54,7 +55,15 @@ class PaymentAcquirerAuthorize(models.Model): values['x_fp_timestamp'], values['x_amount'], values['x_currency_code']]) - return hmac.new(str(values['x_trans_key']), data, hashlib.md5).hexdigest() + + # [BACKWARD COMPATIBILITY] Check that the merchant did update his transaction + # key to signature key (end of MD5 support from Authorize.net) + # The signature key is now '128-character hexadecimal format', while the + # transaction key was only 16-character. + if len(values['x_trans_key']) == 128: + return hmac.new(values['x_trans_key'].decode("hex"), data, hashlib.sha512).hexdigest().upper() + else: + return hmac.new(str(values['x_trans_key']), data, hashlib.md5).hexdigest() @api.multi def authorize_form_generate_values(self, values): @@ -172,7 +181,7 @@ class TxAuthorize(models.Model): def _authorize_form_get_tx_from_data(self, data): """ Given a data dict coming from authorize, verify it and find the related transaction record. """ - reference, trans_id, fingerprint = data.get('x_invoice_num'), data.get('x_trans_id'), data.get('x_MD5_Hash') + reference, trans_id, fingerprint = data.get('x_invoice_num'), data.get('x_trans_id'), data.get('x_SHA2_Hash') or data.get('x_MD5_Hash') if not reference or not trans_id or not fingerprint: error_msg = _('Authorize: received data with missing reference (%s) or trans_id (%s) or fingerprint (%s)') % (reference, trans_id, fingerprint) _logger.info(error_msg) diff --git a/addons/payment_authorize/tests/test_authorize.py b/addons/payment_authorize/tests/test_authorize.py index 35be8a99b17..2d1d7665ce3 100644 --- a/addons/payment_authorize/tests/test_authorize.py +++ b/addons/payment_authorize/tests/test_authorize.py @@ -1,7 +1,5 @@ # -*- coding: utf-8 -*- -import hashlib -import hmac import time import urlparse import unittest @@ -32,15 +30,6 @@ class AuthorizeCommon(PaymentAcquirerCommon): @odoo.tests.common.post_install(True) class AuthorizeForm(AuthorizeCommon): - def _authorize_generate_hashing(self, values): - data = '^'.join([ - values['x_login'], - values['x_fp_sequence'], - values['x_fp_timestamp'], - values['x_amount'], - ]) + '^' - return hmac.new(str(values['x_trans_key']), data, hashlib.md5).hexdigest() - def test_10_Authorize_form_render(self): self.assertEqual(self.authorize.environment, 'test', 'test without test environment') @@ -84,7 +73,7 @@ class AuthorizeForm(AuthorizeCommon): 'x_ship_to_state': None, } - form_values['x_fp_hash'] = self._authorize_generate_hashing(form_values) + form_values['x_fp_hash'] = self.env['payment.acquirer']._authorize_generate_hashing(form_values) # render the button res = self.authorize.render('SO004', 320.0, self.currency_usd.id, values=self.buyer_values) # check form result @@ -108,7 +97,9 @@ class AuthorizeForm(AuthorizeCommon): # typical data posted by authorize after client has successfully paid authorize_post_data = { 'return_url': u'/shop/payment/validate', + # x_MD5_Hash will be empty starting the 28th March 2019 'x_MD5_Hash': u'7934485E1C105940BE854208D10FAB4F', + 'x_SHA2_Hash': u'7D3AC844BE8CA3F649AB885A90D22CFE35B850338EC91D1A5ADD819A85FF948A3D777334A18CDE36821DC8F2B42A6E1950C1FF96B52B60F23201483A656195FB', 'x_account_number': u'XXXX0027', 'x_address': u'Huge Street 2/543', 'x_amount': u'320.00',