Before this commit, the lists of supported currencies by payment
provider were hard-coded in the Python scripts, which made them
unavailable to the users.
With this commit, the implemented initial lists of supported currencies
are displayed on the form view and are editable, because Odoo lists may
not be up-to-date. Empty lists do not trigger any filtering on the
payment providers to access payment methods.
For Authorize.net and Asiapay payment providers, the specific
`(authorize,asiapay)_currency_id` are removed and the generic payment
provider field `available_currency_ids` is restricted to a single-item
list when one of those providers is enabled.
task-2926016
closesodoo/odoo#101018
Related: odoo/enterprise#34158
Related: odoo/documentation#2788
Related: odoo/upgrade#4069
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
After a payment is processed by SIPS, a data object is posted back
to Odoo. The data has a `ScoreInfo` element that has more than one
`=` characters (e.g. `scoreInfo=A3;N;N#SC;N;TRANS=3:2;CUMUL=4500:250000`)
This causes the method `_sips_data_to_object` to break, because there
will be too many values to unpack.
To fix this, we should limit the data split to 2 values. This is the
same method used by SIPS to process data as well.
(See: https://github.com/worldline/Sips-International-non-FR-PHPlibrary/blob/master/lib/Sips/PaymentResponse.php#L73)
opw-3071315
closesodoo/odoo#107143
X-original-commit: 3dce793ad00b1c0b9f06c705f40e31666db74a06
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Signed-off-by: Pedram Bi Ria (pebr) <pebr@odoo.com>
Before this commit the neutralize system introduced in v16 was using ORM
methods in order to change appropriate records. Although flexible, this approach
could lead to call some methods with side effects while neutralizing
(eg: overloads of write).
This patch converts the neutralize system to a safer "inert" SQL based approach
by migrating the generic method _neutralize to SQL files exposed in the
data folder.
Task id: 2961687closesodoo/odoo#102792
X-original-commit: e5dbded9bb363351feff7ca8a56c7f8a6860f492
Related: odoo/enterprise#32580
Signed-off-by: Fabien Meghazi <fme@odoo.com>
Changing the name of model payment.acquirer to payment.provider
and everything that it touches. It is technically incorrect to
use the term "acquirer" for systems that only provide a service
of payment.
After this commit the model payment.acquirer and all related to
it will be renamed to payment.provider.
Task - 2842088
closesodoo/odoo#90899
Related: odoo/upgrade#3542
Related: odoo/documentation#1981
Related: odoo/enterprise#27131
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
Before this commit, most acquirers needed to run several successive
searches for the transaction whose reference was received by a
controller in notification data. This is because the security checks
run on the notification data require access to the acquirer through the
transaction record which was immediately discarded.
Starting with this commit, all `*_feedback_data` method are no longer
decorated with `api.model` and can use the transaction record they're
called on if provided. They are also renamed to `*_notification_data`.
task-2737144
closesodoo/odoo#83850
Related: odoo/enterprise#23938
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
An overridable model method was added in a previous commit in order to
neutralize a database.
This commit introduce the implementation of this method for the payment
modules.
Also, a `_neutralize_fields` helper method is added on the
PaymentAcquirer model to simplify the neutralization of the various
payment modules.
Part-of: odoo/odoo#67825
Notification handling in some acquirers presents a subset of the
following issues:
1. The signature of synchronous notifications (redirect payloads) is not
checked. (Alipay, Authorize, Buckaroo, Mollie, PayU money, PayULatam)
2. When the signature check fails, we raise a ValidationError which
counts as an HTTP 200 for some providers (it's not the case if they
expect a specific string). (Adyen, Paypal, Sips, Stripe)
3. If a ValidationError is raised when processing the feedback data, it
is allowed to bubble up to the provider. (Alipay, Ogone)
The issues are respectively addressed as follows:
1. If the acquirer implements payments with redirection, make sure that
if either makes a request to the provider to validate the data or
that it verifies the signature. Verifying the origin of the request
is not enough: the payload must be checked too.
2. Instead of raising ValidationError's, raise an HTTP 403 FORBIDDEN
error if the signature check fails.
3. Wrap the call to `_handle_feedback_data` of the webhook method inside
a try/except clause to catch any ValidationError, log a warning, and
acknowledge the notification to avoid having the provider disable the
webhook because of too many failures.
task-2688139
task-2693293
closesodoo/odoo#81607
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Co-authored-by: Lucie Van Nieuwenhuyze <luvn@odoo.com>
The logs for payments contain the transaction reference whenever possible.
Before logs for transactions contained the reference or the id of the
transaction in an inconsitent way. No transactions are identified by
reference whenever possible.
The logs for payments for the same function on different acquirers should
have the same format. Same flow step for different acquirers had
information passed in different formats. Now at each step of a transaction
flow log messages have the same format regardless of the acquirer.
Overall the payment logs should have an uniform format. Hopefully
understanding log messages related to transactions should be easier, as
now log format is independent of the acquirer and transaction are easily
identified by reference.
Task - 2545450
closesodoo/odoo#79547
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Fix two issues:
The search of suitable payment token was searching on the journal_id
field of the payment acquirer that is no longer stored.
Change it to now search on the acquirer_id directly, since we have
this information.
The _inverse_journal_id method on payment acquirers would create
new payment line with the manual payment method when no provider
are given to an acquirer, or no payment method is existing for
a given provider. This would cause issues with the creation of
multiple line with the same name on a same journal, which would
trigger the constrains blocking that.
closesodoo/odoo#74990
X-original-commit: a3a2fcb0b299fafbf359ec9015da5c85cdb57b3a
Related: odoo/enterprise#20193
Signed-off-by: Laurent Smet <smetl@users.noreply.github.com>
Users may want to be able to have transactions coming from multiple
payment acquirers to be registered in the same journal.
This will allows that.
Task id #2414749closesodoo/odoo#67331
Related: odoo/upgrade#2500
Related: odoo/enterprise#17258
Signed-off-by: William André (wan) <wan@odoo.com>
Extend support for all currencies listed in the SIPS documentation,
including the decimal numbers per currency. Move this hardcoded data
is a less annoying place.
Remove unnecessary code (e.g. checking if there is more than one payment
with the same reference, which can't happen due to a SQL unique
constraint from the payment module).
Code clarity while I'm at it.
Task-2259942
closesodoo/odoo#51473
Related: odoo/upgrade#1216
Signed-off-by: Damien Bouvy (dbo) <dbo@odoo.com>
Prior to this revision, setting the provider to the 'test' mode caused
hardcoded values for merchantId, secret and keyVersion to be used
without any possibility to override them.
While somewhat useful, it was quite limiting since it used the 'simu'
environment of Atos Wordline, preventing you from testing any other
platform and from using the 'test' environment for Atos.
This revision removes these hardcoded values, which gives more
flexibility as far as testing goes at the cost of a bit more setup
(since you might need to change some values manually, notably the
keyVersion).
Task-2259942
The config param 'sips.key_version' was introduced "some time ago"
in revision a62480ad0f to allow setting the `keyVersion` POST param
to an arbitrary value, allowing other SIPS-comptatible providers to be
used with this module.
This revision (finally) converts this fix to a proper field.
Task-2259942
Using a few regex like
\((_\(.*%s.*)(\) % )([\w\[\]][\w .\[\]\(\)'"]*)\)
($1, $3))
Old syntax is still compatible but starts the migration to the new
syntax that catches error.
SIPS date format can be somewhat variable, some sanitation is required
before using the data raw for the ORM.
opw-2224926
X-original-commit: 620e987f326d6da7c3a9b2c1aca7bff16d9ce6c4
Co-authored-by: Nicolas Martinelli <nim@odoo.com>
With this commit, Selection fields with `required=True` which are
extended via `selection_add` are given proper ondelete policies to
ensure the cleanup of records containing these extended options during
uninstall of the extending module.
This commit also cleans up leftover uninstall hooks that were being used
to handle the same set of problems prior to the ondelete mechanism being
implemented for Selection fields.
closesodoo/odoo#46325
Related: odoo/enterprise#9117
Signed-off-by: Raphael Collet (rco) <rco@openerp.com>
SIPS date format can be somewhat variable, some sanitation is required
before using the data raw for the ORM.
opw-2224926
closesodoo/odoo#48604
X-original-commit: db998d39d7d692779a64522e168bba29b82f1d03
Signed-off-by: Damien Bouvy (dbo) <dbo@odoo.com>
- Activate SIPS
- Make a payment of 263.90 on the eCommerce
The SO is not confirmed because there is 0.01 of difference.
This is due to the fact that 263.90 * 100 = 26389.9999...
Using `round` instead of `int` prevents truncating the value.
opw-2179123
closesodoo/odoo#48169
X-original-commit: 60f9cea444df37e685b7f4312c9ff28c395822b3
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
The automaticResponseURL should not be the same as the one the customer
uses, as this might mess up with the payment processing page when the
customer actually returns.
Add some logging while I'm here, and remove a useless write on a
non-existing field that generates log warnings (but nothing else).
closesodoo/odoo#46047
X-original-commit: 2e25ff3b1114a222ae8cff76c2ce8d31adf599e4
Signed-off-by: Damien Bouvy (dbo) <dbo@odoo.com>
Fine-tunning of 937b5c076e7175bec664ed0cf4b77505e342f1e2
Have a multiwebsite setup
have a payment installed for one of the two websites
Make an order on that website and try to pay
Before this commit, the transaction doesn't come back to odoo's
payment success controller
This was because the return url was set to the web base url ICP
After this commit, the payment success page is opened as we took
the request's url as the return url
opw-2080352
closesodoo/odoo#39643
X-original-commit: a9fb15b33fd041ee420581a5ba450017db06e0c7
Signed-off-by: Jorge Pinna Puissant (jpp) <jpp@odoo.com>
The production/test urls were inverted.
opw:2061123
closesodoo/odoo#36623
X-original-commit: 5325c4388c5cae38b78b88d74220f3a5dca3fc26
Signed-off-by: Simon Goffin (sig) <sig@openerp.com>
Steps to reproduce the bug:
- When trying to publish the sips payment acquirer not in debug mode
Bug:
It raised a access rights error because the fields: sips_test_url, sips_prod_url, sips_version
were not readable in function _check_required_if_provider and a default value was set for all
these fields.
opw:2061123
closesodoo/odoo#36346
Signed-off-by: Simon Goffin (sig) <sig@openerp.com>
Replace website_published and environment by a generic state on
payment.acquirer
Payment acquirers aren't enabled by default. When setting their state to 'enabled' or 'test', it is verified the required fields for the provider are set.
Multi is the default api for methods, it is not necessary to explicitly
decorate methods with it, adds clutter and most people use it because
they see that the rest of the code uses it.
Done with `find . -type f -name '*.py' | xargs sed -i '/@api.multi/d'`
Sips does not accept special characters as a transaction reference.
Replacing '-' solve this issue.
Parsing Sips response was failing when the return url had query parameters.
This was due to the split on '='. Encoding the url solve this issue.
It was very confusing for the user to distinct account.payment and payment.transaction. From now on, the transactions are
technical objects and, in the backend, we only refer to it in log messages (Front end will be adapted in the same fashion
later on). They are hidden in debug mode in accounting\configuration\payments as their purpose is now purely technical/log
This commit also aims to reduce the gap between the accounting app and the transactions: account.payment objects are
created/validated upon completion of transaction.
To ease the capture/voiding of pending transactions, the related buttons are now displayed directly on the SO/invoice
instead of the transactions.
Was task: https://www.odoo.com/web#id=35857&view_type=form&model=project.task&action=333&active_id=967&menu_id=4720
Was PR #24043
[FIX] add domain based on journal to payment tokens
Was opw: https://www.odoo.com/web?debug#id=1828206&view_type=form&model=project.task&menu_id=5200
The field `transactionReference` of Sips must contain only
alphanumerical characters. Previous commit 31dc6b888e solved
the special case of several attempts to pay, but a much simpler case may
appear in v11. Paying an invoice is likely to fail since the reference
contains by default `/`.
In the previous commit, we could simply modify the common `payment`
module code. In this specific case, however, we only change the
reference if the acquirer is Sips.
opw-1841483
Some sips provider don't use 2 as key_version.
E.g. mercanet uses '1' as production key.
Now we allow to override it in Ir Config Parameter for stable version.
Todo:
Need to make it customizable by end user into the configuration of acquirer.
Courtesy of BEK for reporting
Sips is generic, and others services that Atos use the same protocol.
It is not user-friendly, but that allow user to use alternative service
like 'Sogenactif'.
In next version, we need to add field on config to specify it and the
InterfaceVersion that can differ according to the provider.
The license info for these modules was a leftover from previous versions.
Once integrated in Odoo Community they share the same license as all
other modules, as mentioned in the LICENSE notice at the top of the
files.
opw-743686
In Python 3, all of these were "consolidated" under urllib(.request,
.parse, .errors) which is inconvenient.
Since we already have hard dependencies on requests and
werkzeug(.urls, which is a backport of Python 3's unicode-aware
urllib.parse) migrate *everything* to that.
A sticking point is urllib2.URLError, those were (mostly) replaced by
the slightly more general IOError which URLError extends.