Commit Graph
61 Commits
Author SHA1 Message Date
Jérome Maes 4a76713490 [FIX] website_quote : avoid UnboundLocalError
Introduced in 0ce6e1543a, if we don't use a token to see the quotation, it crashes.
2016-04-12 15:28:50 +02:00
Christophe Simonis 79976bd779 [MERGE] forward port of branch saas-10 up to 6e95659 2016-04-01 19:10:34 +02:00
Christophe Simonis 6c8141a1df [MERGE] forward port of branch saas-10 up to 2483327 2016-04-01 16:15:35 +02:00
Denis Ledoux 895e77a336 [FIX] website_quote: utility method to determine the transaction type of an order
The transaction `type` of an order can depend according
to the order.

For instance, if the order leads to recurring payments,
the transaction type became `form_save`
instead of `form`.

This new method allow to easily override this `type` value
for other modules, so the entire button
rendering code does not have to be
copy/pasted.
2016-04-01 14:50:10 +02:00
Goffin Simon 0ce6e1543a [IMP] website_mail, website_quote: check token before browsing the order
Refactoring
2016-03-30 11:36:04 +02:00
Julien Louette 293c1c06e6 [IMP] website_quote: adding layout categories to website quotations 2016-03-25 11:34:26 +01:00
Denis Ledoux 06351ec607 [FIX] website_quote: pay multiple quotations in the same session
Since aae5647988,
the payment transaction ID is set in the session.

Unlike ecommerce carts, this is possible to open multiple
quotations at the same time
(one browser tab on SO001, another one on SO002),
and therefore to pay multiple quotes at the same time.

This revision makes sure to get from the session the transaction
of the right quote.

That way, the message "Your payment has been received, thank you for your trust.",
is not displayed when opening a new quote when another one was paid
just before.
2016-03-21 14:02:17 +01:00
Denis Ledoux 15f27b2614 [FIX] website_sale: always re-render the pay now button
Before this revision,
when a user tried to pay his cart with a first acquirer
e.g. Ogone
then came back to the shop (using the browser back button)
then chose another acquirer
e.g. Paypal
a new transaction is created, due to the change of acquirer
(following revision cb9d798)
and therefore, the transaction has a new reference compared
to the last payment transaction attempt (e.g. the ogone one)
but, the old reference is still referenced within
the `Pay now` form values, because the page wasn't re-rendered,
because the user pressed the browser back button, and this
doesn't refresh/re-render the page, and, therefore,
the old reference was still referenced within the `Pay Now`
form values.

Therefore, the wrong reference was sent to the acquirer
(e.g. paypal) and this prevented the payment validation
at the payment feedback, as the new reference was expected
in the feedback information, while we receive the older one.

This revision makes sure to always re-render the `Pay now`
form, so the transaction reference, as well as the other
possible changes in the values, are correctly set,
before sending the information to the acquirer.
2016-03-21 10:30:03 +01:00
Denis Ledoux aae5647988 [FIX] website_quote: port of f89e8f9df2
The above revision needs to be applied on website_quote
as well.
2016-03-21 10:30:03 +01:00
Denis Ledoux 6a1116e947 [FIX] website_quote: port of cb9d7982c1
The above revision need to be applied in website_quote
as well.
2016-03-21 10:30:03 +01:00
Christophe Simonis 499c2b8da5 [MERGE] forward port of branch saas-6 up to 580389a 2016-01-08 18:26:59 +01:00
Denis Ledoux ff72139aff [FIX] website_sale, website_quote: pay now confirmation email
When configuring the payment acquirer with the confirmation
`at_pay_now`, meaning the sale order has to be
confirmed when clicking on the "Pay now" button, instead
of waiting for the payment confirmation,
the confirmation email wasn't not sent.

opw-665697
2016-01-07 13:52:07 +01:00
Denis Ledoux 7dc2565878 [FIX] website_quote:
This revision is related to 7be2403cf5

The payment acquirers must be fetched if the quote
needs a payment.

Besides, as explained in the above revision, the state
`manual` no longer exists sales orders, and therefore
this must no longer be used to determine if a quote
needs a payment or not.

opw-660575
2015-12-22 11:43:03 +01:00
Denis Ledoux 7be2403cf5 [FIX] website_quote: condition to display the Pay Now button
Before this revision, the button "Pay now" on the quotation
in the frond-end was display only if the sale order
was in the state `manual` and that there was not
yet any payment transaction.

The thing is, since the release of 9.0,
the `manual`state no longer exists in `sale.order`,
and the pay now button was therefore never displayed.

From this revision, the condition to display the button
is based on the `invoice_status`, which need to be `to_invoice`,
meaning there is something to pay:
 - The sale.order needs to be in states `sale` or `done`
 - At least one line has to be invoiced:
   - If the product has the `invoice_policy` set to `order`
   - or if the product has the 'invoice_policy` set to `delivery`,
     and at least one quantity has been delivered.

opw-659931
2015-12-17 14:40:37 +01:00
Denis Ledoux f9efc14440 [MERGE] forward port of branch saas-6 up to cea0a80252 2015-11-02 17:24:30 +01:00
Denis Ledoux c8d6b36632 [MERGE] forward port of branch saas-6 up to a0c64bebe6 2015-10-28 12:01:30 +01:00
Nicolas Martinelli d9c2d03532 [FIX] website_quote: fix Sign & Confirm
Commit 7636b51 modifies the route from JSON to HTTP by mistake. Indeed,
the route /quote/accept is called from an ajax.jsonRpc request, not from
the `method="POST" t-attf-action="/quote/accept` which can be found in
website_quotation.xml.

The t-attf-action is actually only used to recover the order_id and the
token in website_quotation.js.

opw-652874
Closes #9227
Fixes #9226
2015-10-28 08:02:24 +01:00
Goffin Simon b49e52ed04 [IMP] website_quote: Payment provider not set
The fields "payment_acquirer_id" and "payment_tx_id" were not set in the quotation
when selecting a payment method in the online quote.
Inspired from function payment_transaction in addons/website_sale/controllers/main.py

opw:652733
2015-10-26 10:16:40 +01:00
Denis Ledoux a0c64bebe6 [MERGE] forward port of branch 8.0 up to 8209368 2015-10-14 12:28:22 +02:00
Damien Bouvy 486cd33091 [FIX] website_quote: prevent modifying the quote state if it's already been processed
Before this fix, it was possible to validate then cancel a quote (or the other way around) simply by using two tabs in your browser. From now on, we only validate/cancel a quote if it's the 'sent' state and advise the customer of the situation if he tries to abuse the process.
2015-10-12 10:43:46 +02:00
Christophe Simonis 7636b510a2 [ADD] *: CSRF protection in forms and routes
* make CSRF protection the default on all non-SAFE methods
  note: there currently is no way to call a CSRF-protected endpoint
  without a form-encoded entity-body as that's the only place we get the
  CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
  generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
  the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
  the purpose of a CSRF token in the database manager screens.
  There is no request database to obtain the
  secret and generate a CSRF token.
2015-10-01 01:36:50 +02:00
Damien Bouvy 95b6bafec9 [FIX] website_quote: when paying from the frontend, do not explicitly set the partner_country_id; it is automatically handled by the payment.transaction create is the partner is set 2015-09-08 16:31:54 +02:00
Damien Bouvy 063ad00442 [FIX] sale: function changed name in refactoring is now applied everywhere
Somehow, we forgot to change some calls to action_button_confirm the to new action_confirm on the sale.order object
This applies to the following modules:
portal_sale
website_event
website_quote
website_sale
2015-09-04 16:08:22 +02:00
Damien Bouvy 526f27ddac [IMP] payment,payment_*,website_quote,website_sale: new rendering mechanism compatibility for payment providers
merge *ALL* the dicts

The form rendering used to receive a dict for partner information and a dict for tx information and to transmit another dict to the qweb template; now everything is done in a single dict
2015-09-04 16:08:22 +02:00
Damien Bouvy f8a98d977e [IMP] payment: usability improvements
- general:
    - add payment.method and payment.transaction menu in invoicing
- payment.acquirer:
    - add image field
    - add stat button to see payment.transaction objects
- payment.transaction:
    - language field is now a selection instead of a char
    - rename s2s_cb_eval field in callback_eval
    - form view cleaning
    - on_change_partner_id now fills in the partner details
    - add an ir.sequence for transaction name
    - add a many2one to payment.method
    - country defaults to the country of the company
- payment.method:
    - add a one2many to payment.transaction
    - add a stat button to see payment.transaction objects

[IMP] website_quote: rename s2s_cb_eval payment.transaction field to callback_eval

[IMP] payment_* (all providers): add image data and rename s2s_cb_eval field to callback_eval
2015-09-04 16:08:21 +02:00
Damien Bouvy 61ffceb3ba [FIX] website_quote: sale refactoring compatibility (probably not the last time I use this commit message *sigh*)
[IMP] sale: you got anymore of that inheritance?
2015-08-31 21:56:18 +02:00
Christophe Simonis edeceba7df [MERGE] forward port of branch saas-6 up to 7a768a4
Due to `sale` rewrite (94716a3f14),
the commit 503820acb6 has been partially
ignored (in sale.order.line) and will be rewritten later using new-api.
2015-08-28 15:07:16 +02:00
Nicolas Martinelli 0414c9dd6a [IMP] web, website*: adaptation due to the new Sale module
Major changes:
- No use of UoS anymore
- Specific method to calculate delivery

Reason: complete rewrite of the Sale module.

Responsible: fp, dbo, nim
2015-08-27 19:21:37 +02:00
Denis Ledoux af07b2a075 [MERGE] forward port of branch 8.0 up to 42ecf5e 2015-08-26 14:05:17 +02:00
Christophe Simonis ebedb92c73 [FIX] report: only set --viewport-size for some reports
viewport-size was add by 2254a97 (and changed by 0ea94b4) to force
wkhtmltopdf to use `col-md-*` bootstrap css classes. As this argument
change the `window` size and not the screen size, this lead to smaller
fonts and overflow issues in reports.
Only change it for reports that need it.

Closes #7882
2015-08-26 12:08:18 +02:00
Denis Ledoux 3b02e3d63d [FIX] sale*: company tax filtering
f26b94f had as goal to filter the taxes of the product
according to the company when the sale.order
was created/edited as SUPERUSER_ID
(Who ignores the record rules).

Unfortunetaly, to filter the taxes,
it used the company of the customer,
while it's actually the company of the order which
should be used.

Indeed, for instance,
partners can be shared among all companies.

It was way less simple to access the company
of the sale.order, this parameter being
not available in the on_change method signature.

This is the easiest way to solve this issue
without breaking the API / retro-compatibility.

opw-647819
2015-08-25 14:52:20 +02:00
Damien Bouvy 4aa3658adb [IMP] website_quote: use website_mail generic chatter 2015-08-07 01:47:06 +02:00
Christophe Simonis 2cf91d16a5 [MERGE] forward port of branch saas-6 up to 63e92cb 2015-07-22 16:17:54 +02:00
Damien Bouvy 73cb55284b [IMP] website_quote: payment could be exploited when using a public route, order confirmation is now done using a callback call
This commit implements the callback feature (s2s_cb_eval) on form transaction (up until now, it was only used on s2s transactions).
2015-07-07 15:46:47 +02:00
Christophe Simonis a304194936 [MERGE] forward port of branch saas-6 up to 81b5c60 2015-06-25 00:26:31 +02:00
Damien Bouvy de8d90e12e [IMP] website_quote: add payment management
Until now, you could only sign and confirm a sale order from the frontend.

From now on, you can also pay sale orders if the 'Immediate Payment'
option is checked on the sale order.
2015-06-15 14:57:16 +02:00
Olivier Dony 0bd4545348 [LEGAL] Use global LICENSE/COPYRIGHT files, remove boilerplate text
- Preserved explicit 3rd-party copyright notices
- Explicit boilerplate should not be necessary - copyright law applies
  automatically in all countries thanks to Berne Convention + WTO rules,
  and a reference to the applicable license is clear enough.
2015-06-02 03:16:04 +02:00
Damien Bouvy 5047f4ecad [IMP] website_quote: UOM onchange, respect pricelists on SO, layout fixes
* add on_change_uom behaviour to quote templates lines
* fixes frontend layout issues
* use action_button_confirm instead of signal_workflow
  when confirming the quote in the frontend to trigger
  all events properly
* adapt prices using pricelist on onchange_template_id
   on sale orders
2015-05-28 19:04:13 +02:00
Christophe Simonis fe2b5f35a4 [MERGE] forward port of branch saas-6 up to bf1e999 2015-05-28 14:27:38 +02:00
qdp-odoo c04065abd8 [IMP] accounting v9. Yeeeeaah 2015-05-05 17:28:04 +02:00
Jérome Maes ea022f0d4a [FIX] website_blog, website_sale, website_quote, website_slide : fix adding comment after mail migration
The commit 4b122ad41d rename the 'type' field of mail.message into 'message_type'. The change was not applied to the adding comment feature of website module. The comments were posted but not displayed.
2015-05-04 17:17:31 +02:00
Olivier Dony d90776454c [MERGE] Forward-port 8.0 bugfixes up to 0d591ca6df 2015-04-22 18:43:45 +02:00
Damien Bouvy 0d591ca6df [FIX] website_quote: accept button wasn't shown if no expiration date was set on the sale order 2015-04-22 16:47:47 +02:00
Christophe Simonis 63f2c13a87 [MERGE] forward port of branch 8.0 up to 2492503 2015-04-16 19:40:48 +02:00
Goffin Simon bd82569d51 [FIX] website_quote: online quotation
To show the translation linked to an order, the controller "/quote/<int:order_id>" must consider the context to browse
the order_id.

opw:632349
2015-04-16 15:30:38 +02:00
Nandan Jani d1d8802a40 [IMP] website_quote: support printing for the customer
Backport of master commit ed9f8fdbb4
2015-03-13 16:55:11 +01:00
Christophe Simonis 1b3fb3c4a8 [MERGE] forward port of branch 8.0 up to 222b2d3 2015-02-17 18:54:52 +01:00
Denis Ledoux 0e248245dd [FIX] website_quote: prevent to add options to a confirmed order 2015-02-12 14:10:14 +01:00
Leonardo Donelli 4a0b13ed92 [REF] remove vim modelines and resulting trailing blank lines
Let 2015 be a year without modelines!
cf #4174
2014-12-31 15:52:13 +01:00
jas 6ed3056ccf [IMP] website_quote : add action to update quotation button 2014-07-30 11:54:31 +02:00