- discourage users from changing the currency's rounding precision by
making it editable only before the currency is saved;
- remove the hard-coded dict of minor units that util functions rely on.
task-3076355
closesodoo/odoo#119308
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Prior to this commit, the generation of token aliases in Ogone relied
on the util function `singularize_reference_prefix`, which is intended
to make transaction references (and not token aliases!) more
distinguishable by suffixing a timestamp accurate to the second. That
util function does not guarantee the uniqueness of generated reference
prefixes, which is okay because the final reference is further suffixed
if the prefix happens to collide with an existing reference.
Using the util to generate Ogone's token aliases, however, poses a
problem because aliases *must* be unique. Otherwise, a customer saving a
payment token at the same second as another customer would end up
linking their payment method to the other customer's payment token.
This commit drops the use of the util method and replaces it with a UUID.
closesodoo/odoo#115580
X-original-commit: 61d833ffcd1562950126d3c87c92569fe35a8b08
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Steps to reproduce:
1- install ecommerce - payment_stripe
2- configure stripe testing credentials
3- edit main currency to have more decimal places (assume 4 instead
of 2 for USD)
4- add product p to cart (assume p.price = 100 USD)
5- checkout with stripe
6- the price is 10,000 USD instead of 100 USD
Bug:
Stripe expects the amount in the smallest unit possible for the
currency. https://stripe.com/docs/currencies#zero-decimal
This differs from a currency to another according to
https://en.wikipedia.org/wiki/ISO_4217#Minor_unit_fractions
`to_minor_currency_units` uses the decimal places of the currency by
default which will produce wrong values
Fix:
use currency exponent table built from
https://en.wikipedia.org/wiki/ISO_4217#Minor_unit_fractions
default behavior (for a currency that is not available) is not changed
OPW-3058173
closesodoo/odoo#106936
X-original-commit: 703ed2b4e162ff0a7b621e3cf8b92b8eb7fddff8
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Video 1 (Issue): https://drive.google.com/file/d/1oXYcDJgaT9gmhkjE08yJlXwIL1qPwS1Y/view?usp=sharing
Issue:
When using the register payment with a token with any of the payment acquirers,
if there is a concurrent access error during the reconciliation process,
the payment intent is sent multiple times to the acquirer, making the card charged multiple times.
Steps to reproduce:
-Have a V14 database (only tested this version) with sale_mmanagement, payment_stripe and invoicing
-Configure Stripe with your public and secret key (2FA is now enforced for Stripe accounts, therefore,
we don't have a generic test account anymore. You have to create your own.It is quite fast and easy to do)
-Have a portal user PU with an already registered payment token PT
-Go to Invoicing
-Create a new invoice I:
-Customer PU
-Add anything in invoice lines
-Confirm I
-Register a payment for I:
-Journal: Stripe
-Saved Payment token: PT
AT THIS STEP, YOU MUST ENSURE A CONCURRENT ACCESS ERROR WILL RAISE DURING THE RECONCILIATION
-Create Payment
Log analysis:
A first payment intent is sent to Stripe. The card is charged and Stripe answers that all went as expected.
We try to process the payment, but a concurrent access error occurs.
A retry is done.
A payment intent is sent again to Stripe, The card is charged AGAIN and Stripe answers that all went as expected.
We try to process the payment, but a concurrent access error occurs.
For each retry, the intent is sent and the card is charged.
If the first retry succeeds, then Odoo can finish the process. There will be only 1 payment transaction on Odoo's side
(others have been rollbacked) but there will be 3 on Stripe's side and the card will be charged 3 times.
This PR mitigate this behaviour.
It doesn't address the root cause but by adding the idempotency key to the headers with the hash of the transaction
reference and the database UUID, we prevent mutliple payments to happen.
OPW-2662964
closesodoo/odoo#103515
X-original-commit: 5fe1c1bbba4d754eed7e8927b82752969d6f563d
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Before this commit, tokens were prefixed with usually 12 X’s. To improve
readability, modernity and to shorten the length, this commit changes
token prefixes to a standard of •••• 1111.
task-2832669
closesodoo/odoo#94978
Related: odoo/upgrade#3738
Related: odoo/enterprise#29190
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Before this commit, the `major_amount` was rounded before the conversion
to the minor currency unit, leading to an approximation error when
multiplying a float.
After this commit, the conversion of the `major_ amount` to the minor
currency unit is done before the rounding, ensuring no float approximation.
closesodoo/odoo#94698
X-original-commit: 4a4e0129c09e2db11c46a90a07704dc37cb4fb20
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Before this commit, users may saw the capture and void buttons but
couldn't use them.
As capture or void actions need to access acquirer-related fields,
these actions are now sudoed to allow any users that see the button
to use it.
The access rules and rights are also checked before executing the action
to avoid abusive RPC calls.
task-2785144
closesodoo/odoo#91923
X-original-commit: 2e351d6ff9b7f72b486e83c827ff6e15a05c3331
Signed-off-by: Valentin Chevalier <vcr@odoo.com>
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
If a payment request is made from a cron (e.g., Subscriptions' cron for
recurring payments), the worker is not bound to an HTTP request and
therefore the value of `request.httprequest.remote_addr` is an instance
of the 'LocalProxy' object, which is not serializable.
If we're in this scenario, don't send the customer IP address.
task-2494916
closesodoo/odoo#71717
X-original-commit: e85464ad2281f25cbaf7ded0c1e5d7659a322696
Signed-off-by: Antoine Vandevenne (anv) <AntoineVDV@users.noreply.github.com>
Co-authored-by: Toufik Ben Jaa <tbe@odoo.com>
This commit replaces the old online payments API of the `payment`
module with the new one and adapts to it all the implementing modules.
See the merge commit for more details.
task-2085989
task-2119838
task-2165982
task-2289255
Co-authored-by: Victor Feyens <vfe@odoo.com>