Commit Graph
11 Commits
Author SHA1 Message Date
Saurabh Choraria f7c61e9412 [FIX] payment_{paypal,alipay}: update log for invalid notification origin
When the user configures PayPal/Alipay and in his PayPal/Alipay account he set
the IPN address to the webhook_url he receives a notification from PayPal/Alipay
with data. Then origin of that notification is checked and when PayPal/Alipay
sends 'invalid'/'false' as a response the error occurs.

To fix this issue the log is updated into a warning.

sentry-4116633764

closes odoo/odoo#121476

X-original-commit: 100f2526e91d781a01d959d08dc0ccfae4389061
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Signed-off-by: Saurabh Choraria (sauc) <sauc@odoo.com>
2023-05-16 06:49:56 +02:00
Horacio Tellez f7b8f07501 [IMP] payment: rename of acquirer to provider
Changing the name of model payment.acquirer to payment.provider
and everything that it touches. It is technically incorrect to
use the term "acquirer" for systems that only provide a service
of payment.
After this commit the model payment.acquirer and all related to
it will be renamed to payment.provider.

Task - 2842088

closes odoo/odoo#90899

Related: odoo/upgrade#3542
Related: odoo/documentation#1981
Related: odoo/enterprise#27131
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2022-09-09 13:38:08 +02:00
Antoine Vandevenne (anv) f4ca7290ac [IMP] payment(_*): search only once for the transaction
Before this commit, most acquirers needed to run several successive
searches for the transaction whose reference was received by a
controller in notification data. This is because the security checks
run on the notification data require access to the acquirer through the
transaction record which was immediately discarded.

Starting with this commit, all `*_feedback_data` method are no longer
decorated with `api.model` and can use the transaction record they're
called on if provided. They are also renamed to `*_notification_data`.

task-2737144

closes odoo/odoo#83850

Related: odoo/enterprise#23938
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-02-02 19:50:49 +00:00
Antoine Vandevenne (anv)andLucie Van Nieuwenhuyze 00259dc44a [IMP] payment_*: improve handling of webhook notifications
Notification handling in some acquirers presents a subset of the
following issues:
1. The signature of synchronous notifications (redirect payloads) is not
   checked. (Alipay, Authorize, Buckaroo, Mollie, PayU money, PayULatam)
2. When the signature check fails, we raise a ValidationError which
   counts as an HTTP 200 for some providers (it's not the case if they
   expect a specific string). (Adyen, Paypal,  Sips, Stripe)
3. If a ValidationError is raised when processing the feedback data, it
   is allowed to bubble up to the provider. (Alipay, Ogone)

The issues are respectively addressed as follows:
1. If the acquirer implements payments with redirection, make sure that
   if either makes a request to the provider to validate the data or
   that it verifies the signature. Verifying the origin of the request
   is not enough: the payload must be checked too.
2. Instead of raising ValidationError's, raise an HTTP 403 FORBIDDEN
   error if the signature check fails.
3. Wrap the call to `_handle_feedback_data` of the webhook method inside
   a try/except clause to catch any ValidationError, log a warning, and
   acknowledge the notification to avoid having the provider disable the
   webhook because of too many failures.

task-2688139
task-2693293

closes odoo/odoo#81607

Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Co-authored-by: Lucie Van Nieuwenhuyze <luvn@odoo.com>
2022-01-27 17:11:52 +00:00
Horacio Tellez 5badb3fca8 [IMP] payment(_*): normalize logs across all acquirers
The logs for payments contain the transaction reference whenever possible.
Before logs for transactions contained the reference or the id of the
transaction in an inconsitent way. No transactions are identified by
reference whenever possible.

The logs for payments for the same function on different acquirers should
have the same format. Same flow step for different acquirers had
information passed in different formats. Now at each step of a transaction
flow log messages have the same format regardless of the acquirer.

Overall the payment logs should have an uniform format. Hopefully
understanding log messages related to transactions should be easier, as
now log format is independent of the acquirer and transaction are easily
identified by reference.

Task - 2545450

closes odoo/odoo#79547

Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2021-11-29 15:40:54 +00:00
Jeremy Kersten 478068c829 [IMP] *: always use Odoo Response
This branch adds request.redirect on all requests.
In case of a front end request, we do an url_for to the location.

We removed redirect_with_hash that was only for retro compatibility

local_redirect has been renamed to redirect_query, and param keep_hash has been
removed and moved.

Default code for redirect is 303 now instead of 302.

Now redirect and redirect_query make local redirect by default, you need to
pass local=False to make external redirect.

All werkeug.utils.redirect has been replaced by request.redirect.

Http.redirect now use an http.Response type, and it become easy to add an
override like 'set_cookies' e.g.

Dispatch of a website.page return an http.response too, so we first need to
check if it is a cached version before to check if it is an Odoo Response.

Migrate your code:

http.redirect -> request.redirect(location, code, local)
http.local_redirect -> request.redirect_query(location, query, code, local)
http.redirect_with_hash -> request.redirect

Courtesy of odony for help and review ;)

closes odoo/odoo#72599

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-08 07:00:06 +00:00
Arnaud Joset 6b42234b8b [REF] payment_alipay: migrate Alipay to the new payment API
See the merge commit for more details.

task-2333027
2021-03-30 09:25:51 +02:00
Victor Feyens f0e059e601 [REF] payment* : state based publishing
Replace website_published and environment by a generic state on
payment.acquirer

Payment acquirers aren't enabled by default.  When setting their state to 'enabled' or 'test', it is verified the required fields for the provider are set.
2019-08-12 08:45:50 +00:00
Raphael Collet caf900e89e [FIX] *: use auth='public' in controllers that use request.env
The following trick used to work, because `sudo()` was actually making
an environment for the superuser to operate upon:

request.env[...].sudo().method(...)

It no longer works in general, since `sudo()` now makes an environment
in superuser mode but with `uid=None`!  It may still work by accident
for operations that never use `env.uid`, but is broken in general.

Using `auth='public'` fixes the problem by using the public user when no
user is available.

closes odoo/odoo#34297

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2019-07-04 11:32:22 +00:00
Nikunj Ladava 0aefe72b77 [FIX] payment_alipay: improvement as per the current payment
No need of return URL as '/payment/process' will handle all the cases for payment.
use of _set_transaction_state as per the state of the transaction.

closes - https://github.com/odoo/odoo/pull/33231
2019-05-08 07:05:11 +00:00
Nikunj Ladava e335d235f6 [ADD] payment_alipay: added new Alipay payment acquirer
This commit introduces the Alipay payment provider, a popular acquirer
in the Chinese market.

There are 2 possible ways to use this acquirer:
- express checkout mode (only available for merchants located in CN)
- standard checkout mode (availabe for foreign merchants)

Note that this provider does not support server-to-server payments,
tokenization or any other bells and whistles besides fees. There are no
specific behaviours related to this acquirer, it behaves like most 'form
based' payment acquirers with a form submission, s2s notification from
the provider as well as redirect in case the s2s did not reach the
server in time.

closes odoo/odoo#21855

Signed-off-by: Damien Bouvy (dbo) <dbo@odoo.com>
2019-05-03 11:40:05 +00:00