- When registering a payment token, validating it using a payment of a small amount (~1.50€) followed by a refund allows ensuring
that the payment method is valid (i.e. checksumming the card number simple ensure the number is valid but not that the card exists).
This commit introduces a generic approach that must be implemented for each acquirer that has tokenization support.
This commit also introduces a generic payment token registration/usage template that can be adapted according to one's need.
- Introducing a new payment form that handles payment, deletion and adding payment method (only for server2server for the moment).
- On /my/payment_method, changed strings 'Payment Acquirers' to 'Payment Methods' which is more clear.
- Stripe can now be used to pay subscriptions.
Customer portal controller and templates contained in website_payment
module are moved to payment. This module now uses the customer portal
defined in portal module and most of website_payment code is moved
to payment.
website_payment now contain code really related to website, such as
payment acquirers configuration for website.
This commit moves the whole customer portal to the portal module.
It now completely uses portal and http_routing features and is not
dependent on website anymore.
An override of web controller is added in portal in order to redirect
portal users to /my instead of /web. That way once having the customer
portal installed all share users are correctly redirected to their
account.
All modules defining customer portal templates and controllers are
updated accordingly.
As this field is defined directly in payment and is displayed on
acquirer form view let us display it in tree view also directly
in payment instead of website payment.
This is a manual forward-port of commit 5f24bf5df7.
As this field is defined directly in payment and is displayed on
acquirer form view let us display it in tree view also directly
in payment instead of website payment.
When registering a payment token, validating it using a payment of a small amount followed by a refund
allows ensuring that the method is valid (i.e. checksumming the card number simple ensure the number
is valid but not that the card exists). This commit introduces a generic approach that must be implemented
for each acquirer that has tokenization support. This commit also introduces a generic payment token registration/usage template that can be adapted according to one's need.
payment_ogone: add support for tokens validation
* add provider, related on acquirer_id.provider, in order to display
certain piece of information on tx depending on their provider;
* better tx form view and partner address display;
* remove unnecessary notebook on tx form view as it is not used;
* rename Payment Acquirers menu into Payment Methods, easier to
understand;
* acquirer kanban view improved to install / activate / configure them
depending on their state;
* be able to publish / unpublish acquirers without having to wait for
website_payment to add a button;
Xpath has been altered and logos displayed in right column or portal.
The pupose of these logos is to know when you arrive on the website (ecommerce)
with which payment method you can paid.
* The compiled templates are cached per user, lang, inherit context values
* ir.ui.fields: attributes method return an dict, and record_to_html return only the content value of the field
* all rendered text use build_text and all attributes use build_attribute
* t-esc-options is removed and replace by format_value method
* AssetsBundle receive the list files and remains
* Fixes a bug that prevented the system to fetch the default provider
because the default_get call was wrong (wrong model + missing
company_id kwarg)
* Displays the amount as a monetary widget (to do that, the amount
must be sent as a float in the controller)
* Display the acquirer 'pre_msg' field to display eventual fees
This commit adds controller to list documents of customer, with pager and archive
widget to sort documents. Impacted documents are : quotations, sale order,
invoices, and issues.
Portal breadcrumd is improved too : add the home icon, and keep the query
params when using archive widget.
Some editable zones were added to templates, allowing people to customize
their frontend portal.
* make CSRF protection the default on all non-SAFE methods
note: there currently is no way to call a CSRF-protected endpoint
without a form-encoded entity-body as that's the only place we get the
CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
the purpose of a CSRF token in the database manager screens.
There is no request database to obtain the
secret and generate a CSRF token.
Split of website_portal into a generic (and mostly empty) website_portal and a sales-related website_portal_sale (sales order, quotes, invoices)
This allows other modules to extend website_portal without depending on sales
- cleaned feedback: same method naming as ogone, cleaned method, now called
by the controller. IPN basically works.
- cleaned controllers
- cleaned test module website_payment a bit about paypal
- added support of custom, to give and receive back custom values with paypal
bzr revid: tde@openerp.com-20131118123314-jkfomek10ncq7mlu
Added payment_acquirer_paypal and .._ogone modules. Those modules hold
the model / data / controllers related to the specific acquirer.
Also updated website_payment, to use website.menu instead of custom change
in header, as menus are now editable.
bzr revid: tde@openerp.com-20131107180444-bbzobquqq9o6pctv