Commit Graph
103 Commits
Author SHA1 Message Date
Nicolas Lempereur 95c9227cb3 [FIX] payment_authorize: >1m partner ok transaction
When creating a customer profile in Authorize.Net we specify a field
merchantCustomerId that is composed of:

  ODOO-{partner-id}-{8-random-characters}

But the limit of this field is of 20 characters:

https://developer.authorize.net/api/reference/index.html#payment-transactions

So if we have 1 million partner, we may have eg. a partner 1000005 that
would result in an ID `ODOO-1000005-af123c5b` that is too long and
results in an error.

With this changeset, the generated ID is truncated to 20 characters so
this should theorically be alright for up to 9.99*10^15 partners (the
postgres limit for an integer is 2.15*10^9 so this should be safe
enough).

opw-1962422
closes #32423

Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
2019-04-04 12:46:00 +00:00
Christophe Simonis c023d0784f [MERGE] forward port branch saas-11.3 up to ecd8c023b7 2019-03-08 16:10:55 +01:00
Christophe Simonis ecd8c023b7 [MERGE] forward port branch 11.0 up to e5f93b83c6 2019-03-08 15:08:16 +01:00
Christophe Simonis fabbcf1579 [MERGE] forward port branch saas-15 up to 21c84f1532 2019-03-08 14:10:38 +01:00
Christophe Simonis 21c84f1532 [MERGE] forward port branch saas-14 up to b47749effd 2019-03-08 13:09:26 +01:00
Romain Derie 88de931141 [FIX] payment_authorize: use SHA-512 instead of MD5 as not supported
Authorize.Net is phasing out the MD5 based hash use for transaction response
verification in favor of the SHA-512 based hash utilizing a Signature Key.

Instead of hashing with md5 the transaction key, it is now required to hash
the signature key (binary format) with SHA-512.

Support for MD5 will be dropped the 7th March 2019 for sandbox environment and
the 28th March 2019 for production environment, initially planned for the 14th.

Note that as of February 11, 2019 authorize removed the ability to configure or
update MD5 Hash setting in the Merchant Interface.
Merchants who had this setting configured have been emailed/contacted.

opw-1943030

Usefull links:
https://developer.authorize.net/support/hash_upgrade/
https://support.authorize.net/s/article/What-is-a-Signature-Key
https://support.authorize.net/s/article/MD5-Hash-End-of-Life-Signature-Key-Replacement
https://support.authorize.net/s/article/Do-I-need-to-upgrade-my-transaction-fingerprint-from-HMAC-MD5-to-HMAC-SHA512-and-how

closes odoo/odoo#31642

Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2019-03-08 10:14:57 +00:00
Christophe Simonis d11dc31e7a [MERGE] forward port branch 11.0 up to 617652bbfe 2019-01-10 17:59:26 +01:00
Jorge Pinna Puissant 13e47f508f [FIX] payment_authorize: customer profile without email
opw-1920083

Before this commit, an error arrived when creating a customer profile
without email.
Now, if the email don't exists we send an empty string to Authorize.

closes odoo/odoo#30075
2019-01-09 13:44:06 +00:00
Christophe Simonis 6a0675d36d [MERGE] forward port branch saas-11.3 up to e033114879 2019-01-11 18:56:24 +01:00
Adrian Torres 3f4f77fd9d [REF] *: adapt code to new related default behaviour
This commit adapts the business code to changes introduced by
the parent commit in order to keep the same behaviour as before.

All readonly=False fields will have to be checked afterwards to confirm
that the business case requires write access to the source field.
2018-09-27 12:10:23 +02:00
Christophe Simonis 49c3264ce0 [MERGE] forward port branch saas-11.3 up to 4850fb0838 2018-09-07 14:43:48 +02:00
Christophe Simonis f19e6ce561 [MERGE] forward port branch 11.0 up to 213759b03e 2018-09-05 18:52:27 +02:00
Nicolas MartinelliandGert Pellin 9999661cd0 [FIX] payment_authorize: add first name and last name
The `createCustomerProfileRequest` requires a first name and a last
name for several payment processors.

Reference:
https://developer.authorize.net/api/reference/#customer-profiles-create-customer-profile

opw-1878218

Co-authored-by: Gert Pellin <gpe@odoo.com>
2018-09-04 08:25:46 +02:00
Nicolas Martinelli 078c3ec492 [FIX] payment_authorize: remove incorrect fields
`firstName` and `lastName` should be filled in for Australia, but the
implementation is not correct since:
- it assumes that the name is first name + last name, which is not the
  case in all countries (e.g. France)
- it doesn't take into account that the name could be a company name

This reverts commit 26974d4e5f.
2018-08-31 13:37:25 +02:00
Gert Pellin 26974d4e5f [FIX] payment_authorize: add required fields for wespac Australia (#26709)
for the payment processor wespac there are required fields we do not send.

required:
•Card Number
•Expiration Date
•Amount
•First Name
•Last Name
•Address
•City
•State/Province**
•Zip Code (Postal Code/Postcode)**
•Country
•Email

** These fields are optional if the billing address is not in the U.S. or Canada. If the address is in the U.S. or Canada, the two-digit State/Province code must be provided, along with the Zip/Postal Code.
2018-08-31 11:29:38 +02:00
Christophe Simonis 73652a0b19 [MERGE] forward port branch saas-11.3 up to 50860317cc
Note: 1aacc96262 has been ignored and will
be forward-ported later
2018-06-15 13:27:27 +02:00
Christophe Simonis af1853775f [MERGE] forward port branch 11.0 up to e3658d6f56 2018-06-12 16:49:11 +02:00
Nicolas Martinelli e9b21c37f4 [FIX] payment_authorize: state code
According to Authorize.net documentation, the state code should only be
used for United States. For the other countries, use the state name
instead.

opw-1854278
2018-06-11 08:11:39 +02:00
qdp-odoo 01216345e2 [REF] account,payment(_*),sale*: downgrade transactions into debug items
It was very confusing for the user to distinct account.payment and payment.transaction. From now on, the transactions are
technical objects and, in the backend, we only refer to it in log messages (Front end will be adapted in the same fashion
later on). They are hidden in debug mode in accounting\configuration\payments as their purpose is now purely technical/log

This commit also aims to reduce the gap between the accounting app and the transactions: account.payment objects are
created/validated upon completion of transaction.

To ease the capture/voiding of pending transactions, the related buttons are now displayed directly on the SO/invoice
instead of the transactions.

Was task: https://www.odoo.com/web#id=35857&view_type=form&model=project.task&action=333&active_id=967&menu_id=4720
Was PR #24043

[FIX] add domain based on journal to payment tokens

Was opw: https://www.odoo.com/web?debug#id=1828206&view_type=form&model=project.task&menu_id=5200
2018-05-23 15:44:55 +02:00
Christophe Simonis 5f2d080cf8 [MERGE] forward port branch 11.0 up to ad825b673b 2018-04-16 18:34:56 +02:00
Nicolas Martinelli b7462ca224 [FIX] payment_authorize: number of decimals
- Create a SO of 56.16
- Send the payment link to the customer

At payment, the transaction is refused by Authorize because of an
invalid amount.

When looking closely, the data sent to Authorize contains the amount
56.160000000001. This is due to the float representation. To avoid this,
we use `float_repr` instead of `str`.

opw-1832468
2018-04-10 16:05:23 +02:00
Christophe Simonis 87a0f4dc4c [MERGE] forward port branch 11.0 up to b33d5af4a7 2018-03-27 18:22:18 +02:00
Christophe Simonis a9542240fc [MERGE] forward port branch saas-14 up to ce5b4b6512 2018-03-27 16:41:47 +02:00
Nicolas Martinelli 3a654ce256 [FIX] payment_authorize: ZIP code is optional
The ZIP code is an optional field, therefore we should not block the
user.
2018-03-27 12:55:01 +02:00
Nicolas Martinelli f289451ce5 [FIX] payment_authorize: raise error if missing ZIP
The ZIP code is an optional field. When saving a payment method, this
generates a traceback since `partner.zip` is `False` while the field
expects a `string`.

opw-1829829
2018-03-27 12:53:36 +02:00
Christophe Simonis e0345a4a3f [MERGE] forward port branch 11.0 up to 2835d29979 2018-03-20 11:45:11 +01:00
Christophe Simonis 4715d7e35a [MERGE] forward port branch saas-15 up to 0d55241185 2018-03-19 19:29:58 +01:00
Christophe Simonis 0d55241185 [MERGE] forward port branch saas-14 up to 82effcca83 2018-03-19 18:26:25 +01:00
Toufik Benjaa 62b80d1da2 [FIX] payment_authorize: crash on invalid expiry date
- This commit fixes crashes occuring when the expiry date for a credit card was invalid.
  Instead of crashing we now warn the customer that the expiry date is invalid.
2018-03-16 18:32:21 +01:00
Christophe Simonis cb50970f3f [MERGE] forward port branch 11.0 up to eefe879a37 2018-01-25 15:41:45 +01:00
fda-odoo eefe879a37 [MERGE] fix payment flow with acquirers in e-commerce, invoices and quotations
As some flows were broken, this set of fixs improve the different routes for all acquirers
See commit messages for more information

Thanks to @jpr-odoo for his first implementation and to @tde and @fgi
2018-01-25 13:12:25 +01:00
fda-odoo daf6ab1c87 [FIX] Payment, payment_authorize: show an error if customer doesn't have a complete profil on authorize.net payment.
If the user has no Zip code, country or city, authorize refuse the payment, but Odoo doens't show any error.
The commit invite the user to log in in this case or to fill his missing information
2018-01-24 15:28:53 +01:00
Christophe Simonis fa1f2132e7 [MERGE] forward port branch 11.0 up to 950d9b2369 2018-01-22 17:47:32 +01:00
Christophe Simonis 950d9b2369 [MERGE] forward port branch saas-16 up to dfe7f00e78 2018-01-22 16:38:01 +01:00
Christophe Simonis a3d3e5e7fe [MERGE] forward port branch saas-15 up to 50d87ae81b 2018-01-22 14:42:09 +01:00
Christophe Simonis 50d87ae81b [MERGE] forward port branch saas-14 up to 3d673b5900 2018-01-22 13:33:58 +01:00
Atchuthan, Sodexis 171ce8fb2a [FIX] payment_authorize: Credit cards expiration date
- Fixes the validation for credit cards expiration date.

In the courtesy of @SodexisTeam
2018-01-18 15:21:18 +01:00
Christophe Simonis 362f0489d0 [MERGE] forward port branch 11.0 up to fe22a0f9ca 2018-01-03 12:28:52 +01:00
Adrian Torres 864ca5075f [FIX] authorize: add error-checking
Previous to this commit, if a user hadn't properly set up his
Authorize.net credentials, when getting a response from Authorize.net's
servers, we would expect some attributes to be in the response's body,
but this is not the case if the credentials are wrong, thus we would
have an unexpected error like "NoneType object has no attribute text"
which is only a sympton of the real error (bad credentials and no
error-checking).

This is fixed by checking if the response body contains an error
message, if it is the case we raise an UserError with the error code and
the error message (which is only shown if debug mode is activated).

OPW 788261
2018-01-03 08:39:28 +01:00
tbe-odoo 00b6b26b44 [FIX] payment_authorize: Avoid logging credit card credentials 2017-12-01 13:59:49 +01:00
Christophe Simonis 2f99470458 [MERGE] forward port branch 11.0 up to c201cf2b77 2017-12-01 12:55:02 +01:00
tbe-odoo c32de79237 [ADD] payments: Logging payment transaction operations
- Logging data sent & received to/from payment acquirers to be able to track failed payments.
2017-12-01 10:06:30 +01:00
Christophe Simonis 42264d8dcb [MERGE] forward port branch saas-16 up to 5d7ad2b16c 2017-11-30 18:43:08 +01:00
Christophe Simonis ab084d580f [MERGE] forward port branch saas-15 up to 98539336a5 2017-11-30 15:27:59 +01:00
Christophe Simonis 98539336a5 [MERGE] forward port branch saas-14 up to b780e4a0e4 2017-11-30 14:44:49 +01:00
Damien Bouvy fc69b37cf7 [FIX] payment_authorize: stop raising on 'Error' authorize status
It seems that Authorize.net returns an 'Error' status when transactions
fail (note that it can also return an Ok status for different types of
failures).

This is incoherent with the way the authorize requests are processed,
since an Error resultCode will raise a ValidationError, rollbacking the
complete cursor transaction. This makes little sense, since there should
be a trace of the payment.transaction in the backend (preferably with an
explanation for the failure).

This fix adds an error processing step to the response handling of
authorize.net - while before, it was assumed that an 'error' result
meant an issue in communication/setup, now it is treated as an error
in payment and the payment.transaction status is set accordingly.

I've added a test for this and it was green (pinky promise), but this
particular test suite is deactivated (or perhaps only on nightly, I need
to check the nightly process with @nim-odoo).
2017-11-27 08:27:53 +01:00
Damien Bouvy 93b5ce67ac Revert "[FIX] payment_authorize: add some debug logging"
This reverts commit fb093726d7.

In my hurry, I forgot part of this debug feature, which made it crash
because I tried to stringify a element instead of a tree
2017-11-20 19:22:56 +01:00
Damien Bouvy fb093726d7 [FIX] payment_authorize: add some debug logging
If not [FIX], then [HELP TO FIX] at least
2017-11-20 16:50:49 +01:00
Christophe Simonis 017ee5eab3 [MERGE] forward port branch saas-17 up to 877e709871 2017-08-24 13:17:53 +02:00
Xavier Morel 481a00dc4b [FIX] P3: hash/hmac payload must be bytes 2017-08-20 23:25:54 +02:00