Commit Graph
4 Commits
Author SHA1 Message Date
Horacio Tellez ddda5d4a26 [IMP] payment: allow the public user to pay with tokens
Before this commit the public user did not have access to tokens or the
possibility of saving payment methods.

When receiving a link to pay the customer (even if not logged in) should
be able to use tokens saved by the parter of the document and also save
new payment methods. This is intuitively correct: as the possesor of the
link, the customer have rights to pay with tokens linked to the partner.

After this commit tokens linked to the partner of the document will be
visible to the public user and also the possibily to save payment
methods.

Task - 2799296

closes odoo/odoo#104472

Related: odoo/enterprise#34792
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2023-03-08 11:36:53 +01:00
Horacio Tellez 0f2de18849 [IMP] payment: only give access to tokens when required by the flow
Until this point the access to tokens was somehow arbitrary and
illogical.
After this commit we will uniformize the tokens access rule where by
default an user can only access its own tokens by default and in
function of the use case then relax the rules.

Task - 2832561

closes odoo/odoo#104808

Related: odoo/enterprise#33541
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2023-02-17 13:06:53 +01:00
Laura Schauer c1b41bcd08 [IMP] payment(_*): allow dynamic token name
Before this commit, tokens were prefixed with usually 12 X’s. To improve
readability, modernity and to shorten the length, this commit changes
token prefixes to a standard of •••• 1111.

task-2832669

closes odoo/odoo#94978

Related: odoo/upgrade#3738
Related: odoo/enterprise#29190
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-08-19 14:28:08 +02:00
Laura Schauer 2ee4251d07 [IMP] payment(_adyen, _authorize): disable tokens of disabled acquirers
Before this commit, zombie payment tokens (= tokens linked to disabled
acquirers) could still
1) be used by internal users and
2) reactivated when the acquirer’s state changed to ‘test’ or ‘enabled’.
This is not desirable because zombie tokens should neither be used,
nor reactivated.

After this commit, all tokens related to an acquirer are unassigned
from linked documents and archived as soon as the acquirer’s state is
changed to ‘disabled’. Creating a payment with an archived token is
prohibited. In addition, archived tokens cannot be un-archived anymore.

task-2649806

closes odoo/odoo#93774

Related: odoo/enterprise#28661
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-07-12 03:09:44 +02:00