Commit Graph
21 Commits
Author SHA1 Message Date
Horacio Tellez 5badb3fca8 [IMP] payment(_*): normalize logs across all acquirers
The logs for payments contain the transaction reference whenever possible.
Before logs for transactions contained the reference or the id of the
transaction in an inconsitent way. No transactions are identified by
reference whenever possible.

The logs for payments for the same function on different acquirers should
have the same format. Same flow step for different acquirers had
information passed in different formats. Now at each step of a transaction
flow log messages have the same format regardless of the acquirer.

Overall the payment logs should have an uniform format. Hopefully
understanding log messages related to transactions should be easier, as
now log format is independent of the acquirer and transaction are easily
identified by reference.

Task - 2545450

closes odoo/odoo#79547

Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2021-11-29 15:40:54 +00:00
Antoine Vandevenne (anv) 0885212a83 [FIX] payment_adyen: prevent creating a new session for returning users
Before this commit, users returning from Adyen to Odoo after payment
could see their session renewed, depending on their browser's
implementation of the `SameSite` cookie attribute. This prevented Odoo
from retrieving the transaction from the users' session.

This commit flags the return route of Adyen with `save_session=False`,
hence allowing all users to immediately post-process their transactions
when they return to Odoo.

While we're at it, the docstrings of the return routes of PayUmoney and
SIPS' have been updated for better clarity.

closes odoo/odoo#74763

Signed-off-by: Antoine Vandevenne (anv) <AntoineVDV@users.noreply.github.com>
2021-08-05 13:31:09 +00:00
Jeremy Kersten 478068c829 [IMP] *: always use Odoo Response
This branch adds request.redirect on all requests.
In case of a front end request, we do an url_for to the location.

We removed redirect_with_hash that was only for retro compatibility

local_redirect has been renamed to redirect_query, and param keep_hash has been
removed and moved.

Default code for redirect is 303 now instead of 302.

Now redirect and redirect_query make local redirect by default, you need to
pass local=False to make external redirect.

All werkeug.utils.redirect has been replaced by request.redirect.

Http.redirect now use an http.Response type, and it become easy to add an
override like 'set_cookies' e.g.

Dispatch of a website.page return an http.response too, so we first need to
check if it is a cached version before to check if it is an Odoo Response.

Migrate your code:

http.redirect -> request.redirect(location, code, local)
http.local_redirect -> request.redirect_query(location, query, code, local)
http.redirect_with_hash -> request.redirect

Courtesy of odony for help and review ;)

closes odoo/odoo#72599

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-08 07:00:06 +00:00
Adrien Widart 0a87cd21fd [FIX] payment_sips: prevent clearing the session cookie
When buying a product on website shop, after the payment with SIPS, the
page is redirected to an Error message: "We are not able to find your
payment, but don't worry. You should receive an email confirming your
payment in a few minutes. If the payment hasn't been confirmed you can
contact us."

To reproduce the error:
1. In Payment Acquirers, enable Sips
2. Go on website shop
3. Add a product to the cart, Checkout
4. Pay with Sips
    - Visa card number: 4100000000000000
5. Back to Web-shop, if the payment has been successfully processed,
repeat steps 2 -> 4

Error: The message "Your payment has been successfully processed. Thank
you!" is not displayed. Instead, the message "We are not able [...] you
can contact us." is displayed.

This message is displayed when:
https://github.com/odoo/odoo/blob/5945806c151b13d9d4cc13aa0a6c96a6b1bbad5f/addons/payment/controllers/portal.py#L65-L69
i.e., when the transactions list is empty. Here is how to get the list:
https://github.com/odoo/odoo/blob/5945806c151b13d9d4cc13aa0a6c96a6b1bbad5f/addons/payment/controllers/portal.py#L38-L42
It uses the session of the request. The cookie `session_id` is used to
identify the current session. However, after the payment on SIPS, the
page is redirected to `/payment/sips/dpn` with a POST request. Since the
session cookie has the attribute `SameSite=Lax` and the HTTP request is
a POST, the cookie will be filtered out:
https://drive.google.com/file/d/1xfx3YWkfonO3nK-8Rew45uSoR4lkpjpY/view?usp=sharing
(Browser information: This cookie didn't specify a "SameSite" attribute
when it was stored and was defaulted to "SameSite=Lax," and was blocked
because the request was made from a different site and was not initiated
by a top-level navigation. The cookie had to have been set with
"SameSite=None" to enable cross-site usage)
As a result, the server creates a new one. This is the reason why the
transactions list is empty: the list is based on a new session.

Adding the attribute `save_session = False` to the route will prevent
the server from creating a new session cookie and add it in the POST
response.

OPW-2518377

closes odoo/odoo#72611

X-original-commit: 9637a287923c6b82acfd487ed32d6bbc1fdf74b6
Signed-off-by: Antoine Vandevenne (anv) <AntoineVDV@users.noreply.github.com>
Signed-off-by: Adrien Widart <adwid@users.noreply.github.com>
2021-06-23 10:21:04 +00:00
Kevin Baptiste a9ac72d821 [REF] payment_sips: migrate Sips to the new payment API
See the merge commit for more details.

task-2333041
2021-03-30 09:25:51 +02:00
Damien Bouvy bb9ae7b08b [IMP] payment_sips: code improvements
Extend support for all currencies listed in the SIPS documentation,
including the decimal numbers per currency. Move this hardcoded data
is a less annoying place.

Remove unnecessary code (e.g. checking if there is more than one payment
with the same reference, which can't happen due to a SQL unique
constraint from the payment module).

Code clarity while I'm at it.

Task-2259942

closes odoo/odoo#51473

Related: odoo/upgrade#1216
Signed-off-by: Damien Bouvy (dbo) <dbo@odoo.com>
2020-08-17 13:21:08 +00:00
Damien Bouvy f023d89dba [FIX] payment_sips: stop log pollution
SIPS sometimes send empty notifications. I have been unable to find out
why or to reproduce the issue; it seems to be linked to a delay on their
end since these notifications usually arrive after a customer is
redirected back to Odoo (at least on their test account).

I'd rather log a warning for those cases (since nothing is wrong on
Odoo's side, there's just no info to act upon) instead of a full
traceback.

closes odoo/odoo#49335

X-original-commit: 100ef1bdb7b90edbeccfa6cd10297acb824b8083
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
2020-04-09 14:07:07 +00:00
Damien Bouvy 085c977af5 [FIX] payment_sips: correct automaticResponse URL
The automaticResponseURL should not be the same as the one the customer
uses, as this might mess up with the payment processing page when the
customer actually returns.

Add some logging while I'm here, and remove a useless write on a
non-existing field that generates log warnings (but nothing else).

closes odoo/odoo#46047

X-original-commit: 2e25ff3b1114a222ae8cff76c2ce8d31adf599e4
Signed-off-by: Damien Bouvy (dbo) <dbo@odoo.com>
2020-02-24 09:59:31 +00:00
Raphael Collet caf900e89e [FIX] *: use auth='public' in controllers that use request.env
The following trick used to work, because `sudo()` was actually making
an environment for the superuser to operate upon:

request.env[...].sudo().method(...)

It no longer works in general, since `sudo()` now makes an environment
in superuser mode but with `uid=None`!  It may still work by accident
for operations that never use `env.uid`, but is broken in general.

Using `auth='public'` fixes the problem by using the public user when no
user is available.

closes odoo/odoo#34297

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2019-07-04 11:32:22 +00:00
Toufik Benjaa 6ed44181d0 [IMP] payment_*: payment acquirers error handling
This commit aims to improve the user experience when using payment acquirers. There currently are no error feedback with some acquirers, which leaves the user wondering what is going on and what is the real status of its payment.
In some cases, the user is currently being redirected to the home page even though the payment has failed. We want to make it more obvious to the user that something unexpected has happened by redirecting to an intermediate page that will provide good feedback on payments status.

Another goal of this commit is to order acquirers by sequence instead of by flow and to select the first acquirer by default. This feature was already implmented in commit fe294fd43e521bd2d339e962f43acf46c3d4cb97, some UI adaptations were needed though.

Related to task #36680
Closes #26958
2018-09-19 18:25:32 +02:00
Olivier Dony ba15df47cb [MERGE] Forward-port saas-15 up to 17b847c0f6 2017-06-01 01:10:29 +02:00
Olivier Dony 7a443aabf9 [MERGE] Forward-port saas-11 up to 6490e652c3 2017-05-16 14:56:02 +02:00
Olivier Dony 1070b83e14 [FIX] l10n_cn*, payment_sips: clarify obsolete licensing info
The license info for these modules was a leftover from previous versions.

Once integrated in Odoo Community they share the same license as all
other modules, as mentioned in the LICENSE notice at the top of the
files.

opw-743686
2017-05-16 13:42:10 +02:00
xmo-odoo b4429c2a91 [FIX] Various P3-related import changes
* LDAP import: python-ldap is not python3-compatible, pyldap is

  Warning: only supported from debian Stretch (current testing)?
  https://packages.debian.org/search?searchon=names&keywords=pyldap

* implicitly relative imports
* imports of moved or removed stdlib modules

issue #8530
2017-04-28 09:06:53 +02:00
Christophe Simonis 298e2032ea [MERGE] forward port branch saas-12 up to 9f28139 2016-09-09 18:13:31 +02:00
Christophe Simonis af87c57e51 [MERGE] forward port branch saas-6 up to f98665f 2016-09-09 11:26:15 +02:00
Ravi Gohil b226510840 [IMP] payment_*: avoid access error on provider model
As provider model is intended to be used internally restricting the read of
some private fields to the employee group avoid creating access issues.
2016-09-06 10:20:41 +02:00
Thibault Delavallée 28ca53c70e [CLN] payment_sips: cleaning and guidelines
As this module is already in new API only small linting is performed.
2016-07-06 15:10:48 +02:00
Goffin Simon 32c8280a02 [FIX] payment_adyen, payment_authorize, payment_buckaroo, payment_paypal, payment_sips: Disable csrf on callbacks
Inspired from 2099f15d67

opw:653341
2015-11-24 11:35:57 +01:00
Leonardo Rochael Almeida 60af7cac02 [IMP] replace simplejson with stdlib json
The stdlib version of the json library is more recent than the 3.5.3
version we are pinning in `requirements.txt`

There is no reason to use it.

Closes #6940
2015-09-28 10:53:32 +02:00
Aristobulo Meneses b2193e6734 [ADD] payment_sips
contains acquirer definition to support Atos Wordline online payments
Courtesy of Eezee-It

Closes #6684
2015-07-24 18:10:57 +02:00