Commit Graph
29 Commits
Author SHA1 Message Date
Laurent Desausoi 7593c073d2 [IMP] core: use inert SQL based neutralization
Before this commit the neutralize system introduced in v16 was using ORM
methods in order to change appropriate records. Although flexible, this approach
could lead to call some methods with side effects while neutralizing
(eg: overloads of write).

This patch converts the neutralize system to a safer "inert" SQL based approach
by migrating the generic method _neutralize to SQL files exposed in the
data folder.

Task id: 2961687

closes odoo/odoo#102792

X-original-commit: e5dbded9bb363351feff7ca8a56c7f8a6860f492
Related: odoo/enterprise#32580
Signed-off-by: Fabien Meghazi <fme@odoo.com>
2022-10-09 22:04:00 +02:00
Horacio Tellez f7b8f07501 [IMP] payment: rename of acquirer to provider
Changing the name of model payment.acquirer to payment.provider
and everything that it touches. It is technically incorrect to
use the term "acquirer" for systems that only provide a service
of payment.
After this commit the model payment.acquirer and all related to
it will be renamed to payment.provider.

Task - 2842088

closes odoo/odoo#90899

Related: odoo/upgrade#3542
Related: odoo/documentation#1981
Related: odoo/enterprise#27131
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2022-09-09 13:38:08 +02:00
Victor Feyens 4d6bd1ce33 [REF] payment_*: adapt to payment changes 2022-09-06 13:32:19 +02:00
Victor Feyens 987b0d49f9 [IMP] payment: clean test utils
All utilitary test methods will be private, to clearly separate
test methods and utils.

Task - 2848326

Part-of: odoo/odoo#90716
2022-05-31 19:17:20 +02:00
Xavier Morel 5463c1467c [FIX] payment_*: tests when running with a non-default port
For payment_buckaroo and payment_sips (at least) running with a
non-standard port is an issue to the `test_redirect_form_value` tests:
while the form and test will use respectively the base_url and the
configuration port, both check a response signature which is
predicated upon a base url of `http://127.0.0.1:8069`.

This means the test does not pass when run with a different port, and
may not pass if the database was installed with a different port
either (because this may have caused the `web.base_url` to be set to
the installation port).

The other payment modules don't seem to have such signature
verification and thus apparently don't mind running with non-default
port.

Update in 15.2: `test_webhook_notification_confirms_transaction` also
broke but differently, because the payment utils would fetch (and use)
the `web.base.url` they get confused if a db is installed using one
port then the tests are run using an other (or something along those
lines), despite `HttpCase` trying to set the `web.base.url` (could be
an ordering thing).

Anyway a working solution seems to be to *remove* the bespoke code
from `PaymentTestUtils` and fix `HttpCase.base_url()` so it uses the
right port (apparently that'd never been fixed). This does require
adapting the patch being forward-ported as `base_url` is now a
callable, not an attribute.

Also re-remove the attractive nuisance of the odoo.tests.common.PORT
constant which does not work: it is evaluated before the configuration
has been loaded and is thus always set to the default (8069).

closes odoo/odoo#86068

X-original-commit: c28c99f7399da91e1a6176d6f97d4fc947013cae
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-03-09 09:24:02 +00:00
Hubert Van de Walle (huvw) b9d3527c46 [IMP] payment_payulatam: support webhook notifications
task-2701097
opw-2627875

closes odoo/odoo#84581

X-original-commit: b82e6788921fc1f3b1ebeeb13eb79619416932f8
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-02-16 09:40:11 +00:00
Antoine Vandevenne (anv) c29d94a6e8 [IMP] payment_*: reuse the common reference in test data
closes odoo/odoo#84385

X-original-commit: 0482826b77939d326fd8519ba888aacd3afa2e99
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-02-11 11:40:23 +00:00
Antoine Vandevenne (anv) f4ca7290ac [IMP] payment(_*): search only once for the transaction
Before this commit, most acquirers needed to run several successive
searches for the transaction whose reference was received by a
controller in notification data. This is because the security checks
run on the notification data require access to the acquirer through the
transaction record which was immediately discarded.

Starting with this commit, all `*_feedback_data` method are no longer
decorated with `api.model` and can use the transaction record they're
called on if provided. They are also renamed to `*_notification_data`.

task-2737144

closes odoo/odoo#83850

Related: odoo/enterprise#23938
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-02-02 19:50:49 +00:00
Christophe Monniez dc0baf4948 [IMP] payment*: implement _neutralize method
An overridable model method was added in a previous commit in order to
neutralize a database.

This commit introduce the implementation of this method for the payment
modules.

Also, a `_neutralize_fields` helper method is added on the
PaymentAcquirer model to simplify the neutralization of the various
payment modules.

Part-of: odoo/odoo#67825
2022-02-01 09:54:07 +00:00
Antoine Vandevenne (anv)andLucie Van Nieuwenhuyze 54fa480c2e [IMP] payment_buckaroo: accept webhook notifications
Before this commit, it was not possible for a Buckaroo acquirer to
accept asynchronous notifications for payment updates. This is
important because, without them, an acquirer can only rely on
synchronous notifications (i.e. redirect requests from the provider's
checkout page) which can be unreliable and do not allow receiving
status updates, should payments take a bit longer to be confirmed by the
provider.

This commit adds a webhook controller whose route can be configured in
Buckaroo Plaza (backend) to send asynchronous notifications.

task-2687586

closes odoo/odoo#82922

Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Co-authored-by: Lucie Van Nieuwenhuyze <luvn@odoo.com>
2022-01-31 17:47:39 +00:00
Antoine Vandevenne (anv)andLucie Van Nieuwenhuyze 00259dc44a [IMP] payment_*: improve handling of webhook notifications
Notification handling in some acquirers presents a subset of the
following issues:
1. The signature of synchronous notifications (redirect payloads) is not
   checked. (Alipay, Authorize, Buckaroo, Mollie, PayU money, PayULatam)
2. When the signature check fails, we raise a ValidationError which
   counts as an HTTP 200 for some providers (it's not the case if they
   expect a specific string). (Adyen, Paypal,  Sips, Stripe)
3. If a ValidationError is raised when processing the feedback data, it
   is allowed to bubble up to the provider. (Alipay, Ogone)

The issues are respectively addressed as follows:
1. If the acquirer implements payments with redirection, make sure that
   if either makes a request to the provider to validate the data or
   that it verifies the signature. Verifying the origin of the request
   is not enough: the payload must be checked too.
2. Instead of raising ValidationError's, raise an HTTP 403 FORBIDDEN
   error if the signature check fails.
3. Wrap the call to `_handle_feedback_data` of the webhook method inside
   a try/except clause to catch any ValidationError, log a warning, and
   acknowledge the notification to avoid having the provider disable the
   webhook because of too many failures.

task-2688139
task-2693293

closes odoo/odoo#81607

Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Co-authored-by: Lucie Van Nieuwenhuyze <luvn@odoo.com>
2022-01-27 17:11:52 +00:00
Antoine Vandevenne (anv) c1b914188a [FIX] payment_buckaroo: sort signing string's data keys in lower-case
Before this commit, the implementation of Buckaroo's method for
computing the signature of a dataset was upper-casing data keys before
sorting them, in order for the sort to be done in a case-insensitive
manner. The issue is that, as `ord('A') < ord('_') < ord('a')`, two keys
could be incorrectly swapped if they shared the same prefix and one of
the two contained an underscore. For example, `brq_transactions` would
be appended to the signing string before `brq_transaction_type` whereas,
if the sort was based on the upper-case keys, the second would be
appended before the first.

This commit changes the computation of the signature to rely on the
lower-case keys rather than upper-case keys in order to use the same
method as Buckaroo when they compute the signature on their end.

closes odoo/odoo#83202

X-original-commit: 0112d69252a8a8396f9509e240c741fa2e261fb3
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2022-01-21 16:50:09 +00:00
Laurent Smet 41438824f7 [FIX] payment*: Make tests inheriting of AccountTestInvoicingCommon
This makes tests independant of any demo data and ensure the company configuration is always consistent.
2021-05-18 05:18:52 +00:00
Barad Mahendrasinh 356c93a42d [REF] payment_buckaroo: migrate Buckaroo to the new payment API
See the merge commit for more details.

task-2333032
2021-03-30 09:25:51 +02:00
Laurent Smet 85e187ebb5 [IMP] payment(_*): Remove dependency to AccountTestCommon
l10n runbot builds are all failing when running at least one test depending of AccountTestCommon because it:
- doesn't create a sandboxed testing environnement to manage the multi-currency, multi-company, the default company's currency, the exchange rates...
- doesn't setup a testing user then all tests are done using the superuser.
- doesn't provide a fully setup chart of accounts: exchange difference journal is not set, accounts have bad types, etc...
- is run sometimes at-install.

--task: 2296213
2020-07-16 07:25:52 +00:00
Victor Feyens f0e059e601 [REF] payment* : state based publishing
Replace website_published and environment by a generic state on
payment.acquirer

Payment acquirers aren't enabled by default.  When setting their state to 'enabled' or 'test', it is verified the required fields for the provider are set.
2019-08-12 08:45:50 +00:00
Pierre Masereel 095a539f5c [FIX] payment_buckaroo: fix tests
Some values in the form have been changed in this commit:
https://github.com/odoo/odoo/commit/fc1389f8d881adfb94ea1b784fb7104b9eee5d2d
2019-03-29 14:14:07 +00:00
Pierre Masereel 132717c7b1 [FIX] payment_*: tests
PAYPAL
------

The paypal tests are not working working for two reasons:
- we check that there is no date in pending state on payment
transaction, but since the refactoring in this commit: https://github.com/odoo/odoo/commit/01216345e28374b554bfe95df82d607c591271cf
the date is always set before the validation of transaction.
- Since the changes on dates, the datetime field doesn't return a string
anymore and the comparison fails. So we convert the datetime to string
for the comparison.

BUCKAROO
--------

The buckaroo tests were not working for multiple reasons.

STRIPE
------

The payment stripe tests were not working because:
- The reference set in transactions were not the same as the ones givent
to the payment provider.
- we were checking for a script tag in form that has been removed in
commit https://github.com/odoo/odoo/commit/7c639be4aadce20bf6662ab347470fadf9afd99f

AUTHORIZE
---------

This test cannot be tested on runbot due to its server to server way of
working

closes odoo/odoo#30105
2019-01-10 23:47:57 +00:00
qdp-odoo 01216345e2 [REF] account,payment(_*),sale*: downgrade transactions into debug items
It was very confusing for the user to distinct account.payment and payment.transaction. From now on, the transactions are
technical objects and, in the backend, we only refer to it in log messages (Front end will be adapted in the same fashion
later on). They are hidden in debug mode in accounting\configuration\payments as their purpose is now purely technical/log

This commit also aims to reduce the gap between the accounting app and the transactions: account.payment objects are
created/validated upon completion of transaction.

To ease the capture/voiding of pending transactions, the related buttons are now displayed directly on the SO/invoice
instead of the transactions.

Was task: https://www.odoo.com/web#id=35857&view_type=form&model=project.task&action=333&active_id=967&menu_id=4720
Was PR #24043

[FIX] add domain based on journal to payment tokens

Was opw: https://www.odoo.com/web?debug#id=1828206&view_type=form&model=project.task&menu_id=5200
2018-05-23 15:44:55 +02:00
Christophe Monniez b356b19033 [IMP] tests: Add the possibility to tag tests
Purpose: When running tests, all the tests for the installed/updated
files are done. This commit adds a 'tagged' decorator that can be used to
tag tests. Combined with a new 'test-tags' CLI option, it adds the ability
to filter which tests are executed. For example, @tagged('slow') will
add a tag 'slow' to the test. The CLI option 'test-tags="slow"' will
only run tests tagged 'slow'.

One can use prefixes to select cases with tags.
'+' or no prefix means that the tests tagged with this tag are selected
for execution. '-' prefix will exclude the tests tagged with this tag.
Exclusion takes precedence over inclusion.

Also, by default, all Odoo tests cases are tagged 'standard' and with
the technical name of the module.
This means that when selecting tests with the 'test-tags'
parameter, if '-standard' is not specified, all tests tags are
going to be executed.
When tagging tests, one can remove such automatic tag by prefixing the
tag name with '-'. E.g. @tagged('-standard') will remove the standard
tag from the test.

Another example, if one wants to test the 'sale' module alone,
even without adding any 'tagged' decorator thos tests can be selected
like that: --test-tags="sale"

Tests are selected or deselected using a TagsSelector. When instanciated,
 a string is passed with comma separated tests selectors like
'+slow,-standard'. When the 'check' method is called  with a test as argument,
it returns True or False if the test has to be executed or not.
2018-01-18 13:20:37 +01:00
Xavier Morel 01e3514147 [FIX] P3: urllib, urllib2 and urlparse
In Python 3, all of these were "consolidated" under urllib(.request,
.parse, .errors) which is inconvenient.

Since we already have hard dependencies on requests and
werkzeug(.urls, which is a backport of Python 3's unicode-aware
urllib.parse) migrate *everything* to that.

A sticking point is urllib2.URLError, those were (mostly) replaced by
the slightly more general IOError which URLError extends.
2017-05-15 12:26:30 +02:00
Raphael Collet 0783318f97 [FIX] adapt logger names 2016-09-02 17:28:13 +02:00
Rutul Raval 14d761b986 [MIG] payment_buckaroo: new API
No functional change.
2016-07-06 15:10:46 +02:00
Martin Geubelle 1d777d6d95 [IMP] payment, payment_*: acquirers installation
The installation of a new acquirer was a bit complicated : from settings,
check the acquirer, then apply (install the module) then list view of
acquirer and finally edit it in form view.

This needed to be simplified. The payment acquirers are pre-filled
in payment. From the kanban view an `Install` button installs and
redirects to the form field.
2016-03-10 13:41:07 +01:00
Martin Trigaux 8b4f052a38 [MERGE] Forwardport of branch saas-6 up to c649bb0df 2016-01-05 18:28:06 +01:00
Martin Trigaux 6efc371291 [FIX] payment_buckaroo: parameters case
Quoting Buckaroo Payment Engine 3.0 Implementation Manual:
Note: parameter names are not case sensitive (both in the request and in the
response). Parameter values are case sensitive.

Using data.get(BRQ_PAYMENT') is unreliable and may break in the future.

Update test to use different case.

opw 665439
2015-12-30 10:09:23 +01:00
Deep Bundela f76c78d598 [IMP] payment_*: use standard fields to store tx information instead of adding specific fields for every.payment.provider 2015-09-04 16:08:22 +02:00
Xavier Morel 65cd4a2a33 [FIX] remove deprecated checks/fast_suite test attributes from standard modules 2015-01-15 14:31:40 +01:00
Thibault Delavallée d22e515d52 [MERGE] [ADD] module: payment_buckaroo acquirer: manage payments using Buckaroo. 2014-05-27 16:57:31 +02:00