Commit Graph
35 Commits
Author SHA1 Message Date
Antoine Vandevenne (anv) a5bdad89f2 [REM] payment_ogone: remove the FlexCheckout API
Before this commit, the FlexCheckout API was used to process validation
operations only. It proved itself to be:
- unusable without making small payments with immediate refunds
- badly suited to PSD2 due to its Merchant Initiated Transactions (MIT)
- not worth the maintenance cost tied to its complexity given the simple
  flow that it implements
- inconvenient to integrate to standard payment flows
- poorly customizable in regard to the hosted tokenization page

This commit thus removes it entirely and drops Ogone's support for
validation operations with it.

task-2494916
2021-07-26 13:40:59 +00:00
Xavier Morel d60f73985b [FIX] payment_ogone: markupsafe HTML_ANSWER 2021-07-20 05:37:41 +00:00
Jeremy Kersten 478068c829 [IMP] *: always use Odoo Response
This branch adds request.redirect on all requests.
In case of a front end request, we do an url_for to the location.

We removed redirect_with_hash that was only for retro compatibility

local_redirect has been renamed to redirect_query, and param keep_hash has been
removed and moved.

Default code for redirect is 303 now instead of 302.

Now redirect and redirect_query make local redirect by default, you need to
pass local=False to make external redirect.

All werkeug.utils.redirect has been replaced by request.redirect.

Http.redirect now use an http.Response type, and it become easy to add an
override like 'set_cookies' e.g.

Dispatch of a website.page return an http.response too, so we first need to
check if it is a cached version before to check if it is an Odoo Response.

Migrate your code:

http.redirect -> request.redirect(location, code, local)
http.local_redirect -> request.redirect_query(location, query, code, local)
http.redirect_with_hash -> request.redirect

Courtesy of odony for help and review ;)

closes odoo/odoo#72599

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-08 07:00:06 +00:00
Antoine Vandevenne (anv) 1b2c7cbb43 [FIX] payment, payment_ogone: bring back the Hosted Payment Page API
With commit 139dd9d, the Hosted Payment Page API of Ogone was entirely
replaced by the FlexCheckout API. This new API allows customers to
tokenize a payment method for a later use without the need of making a
purchase. However, it proved itself to be less convenient for regular
purchases as it offers less payment options than the HPP, and payments
are no longer cardholder-initiated transactions but merchant-initiated
transactions which have a higher chance of triggering an authentication
check. Furthermore, the payment flow itself is more complicated than
before.

This commit brings back the Hosted Payment Page API to work in parallel
with the FlexCheckout API and the other APIs that were left untouched.
It will be exclusively used for making online payments with a new card.
The validation flow is managed by the FlexCheckout API while the
DirectLink API manages the payment by token and offline payment flows.

task-2494916

closes odoo/odoo#72991

X-original-commit: 4fa7b772c71979f61eb098ff8d005deba834527c
Signed-off-by: Toufik Benjaa (tbe) <tbe@odoo.com>
Signed-off-by: Antoine Vandevenne (anv) <AntoineVDV@users.noreply.github.com>
2021-06-30 12:18:50 +00:00
Antoine Vandevenne (anv)andToufik Ben Jaa 16b6217378 [FIX] payment_ogone: add backward compatibility for DirectLink URLs
As it is possible to hard-code the DirectLink URLs used by Odoo in the
backend of Ogone, some users might encounter payment issues after
migrating to 14.3+ if they did not replace those URLs by the new ones.

This commit adds back the URLs that were used by DirectLink prior to
14.3 and allows requests to target both the new and the old URLs.

task-2494916

closes odoo/odoo#72566

X-original-commit: 16ee2651ba7f537e3644da2fd80595896e3421fc
Signed-off-by: Antoine Vandevenne (anv) <AntoineVDV@users.noreply.github.com>
Co-authored-by: Toufik Ben Jaa <tbe@odoo.com>
2021-06-22 16:48:29 +00:00
Antoine Vandevenne (anv) c902e02317 [FIX] payment(_*), account_payment: fix post-refactoring issues
account_payment:
  - Processing fees computation was done based on the wrong country.
payment:
  - The acquirer's cancel message was missing from the
    /payment/confirmation page.
  - `redirect_form_view_id` field was declared with attribute 'name'
    instead of 'string'.
  - Uninstalling a payment acquirer would fail with a traceback.
  - The first acquirer was not automatically selected if it was the only
    selectable payment option of a 'manage' payment form.
  - Specifying a preferred acquirer to the /payment/pay page would show
    not acquirer at all if the preferred option was incompatible with
    the constraints, rather than falling back on showing all acquirers.
payment_adyen:
  - When the value of the API URL fields is malformed (e.g., missing the
    "https://"), clicking on the confirm button raised a traceback.
payment_ogone:
  - There was a typo in the return route.
payment_paypal:
  - PayPal acquirers were not filtered out if the currency was not not
    supported.
  - Returning to the webshop without paying would raise a traceback.

task-2494916

closes odoo/odoo#69996

X-original-commit: 4f7e463fb8b13506caa8aff0beeef5eb0720bf00
Related: odoo/enterprise#17997
Signed-off-by: Antoine Vandevenne (anv) <AntoineVDV@users.noreply.github.com>
2021-04-28 11:39:26 +00:00
Arnaud JosetandAntoine Vandevenne 61a02a7330 [REF] payment_ogone: migrate Ogone to the new payment API
In this commit, we take the opportunity to replace the previous unsecure
API with the new FlexCheckout API that implements payment methods
validation in a hosted page. Payment processing is still done with the
DirectLink API.

This commit also renames the module `payment_ingenico` to
`payment_ogone` as well as the referring strings ("Ogone" instead
of "Ingenico", ...).
A dedicated [MOV] commit is not used because neither the [MOV] commit
nor the adapted [REF] would be valid on its own.

See the merge commit for more details.

task-2333029
task-2313907
task-2334015

Co-authored-by: Antoine Vandevenne <anv@odoo.com>
2021-03-30 09:25:51 +02:00
Victor FeyensandWilliam Andre f1ae1675a0 [MOV] payment_ogone --> payment_ingenico
Co-Authored-By: William Andre <wan@odoo.com>
2019-08-12 08:44:25 +00:00
Raphael Collet caf900e89e [FIX] *: use auth='public' in controllers that use request.env
The following trick used to work, because `sudo()` was actually making
an environment for the superuser to operate upon:

request.env[...].sudo().method(...)

It no longer works in general, since `sudo()` now makes an environment
in superuser mode but with `uid=None`!  It may still work by accident
for operations that never use `env.uid`, but is broken in general.

Using `auth='public'` fixes the problem by using the public user when no
user is available.

closes odoo/odoo#34297

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2019-07-04 11:32:22 +00:00
Toufik Benjaa 6ed44181d0 [IMP] payment_*: payment acquirers error handling
This commit aims to improve the user experience when using payment acquirers. There currently are no error feedback with some acquirers, which leaves the user wondering what is going on and what is the real status of its payment.
In some cases, the user is currently being redirected to the home page even though the payment has failed. We want to make it more obvious to the user that something unexpected has happened by redirecting to an intermediate page that will provide good feedback on payments status.

Another goal of this commit is to order acquirers by sequence instead of by flow and to select the first acquirer by default. This feature was already implmented in commit fe294fd43e521bd2d339e962f43acf46c3d4cb97, some UI adaptations were needed though.

Related to task #36680
Closes #26958
2018-09-19 18:25:32 +02:00
Christophe Simonis d45c32baac [MERGE] forward port branch saas-15 up to bdd051bf78 2018-06-13 18:13:48 +02:00
Christophe Simonis 788750ea51 [MERGE] forward port branch 9.0 up to 444f0b6a7f 2018-06-13 10:50:43 +02:00
Toufik Benjaa 444f0b6a7f [IMP] payment_ogone: Avoid requesting already owned data from Ogone
- When receiving a S2S payment feedback from Ogone server, we call the method '_ogone_form_get_tx_from_data' which does a "pre-process" of the data to retrieve the payment.transaction linked to this payment.
  It also checks the hash signature of the data to be sure it comes from Ogone.
  Right after, we call "_ogone_s2s_validate" which make a HTTP call to ogone, to retrieve the data related to the transaction which were already sent by Ogone (maybe to be sure the data comes from Ogone?).

  So instead of calling "_ogone_s2s_validate" we now call "_ogone_s2s_validate_tree" which processes the data from Ogone.
  We are sure they come from Ogone, since they passed the hash signature when calling "_ogone_form_get_tx_from_data".
2018-06-12 18:27:24 +02:00
Olivier Dony c3769b2290 [FIX] payment_ogone: work around ingenico API bug
As of today, Ingenico platform 4.125 has non-uniform handling of the
PARAMPLUS parameters that can be passed as part of transaction metadata.

This parameter is documented as being parsed[1] as a series of
parameter-value pairs, to be passed as extra parameters to the feedback
transaction. Based on this, it seems that the PARAMPLUS value should not
be urlencoded globally, but each field value should be urlencoded, as
the Ingenico side will have to be able to parse and re-emit these
individual parameters.
In one case we were missing this urlencoding step, so this commit fixes
it.

Without this, the querydirect.asp API would return invalid XML data when
we retrieve the status of a transaction that used a PARAMPLUS value with
an '=' sign!

For example with PARAMPLUS passed as

        return_url=/payment/confirm?tx_id=123

the value returned by querydirect.asp would contain the following:
  (note the invalid extra quote character in the `return_url` param)

```
<?xml version="1.0"?>
<ncresponse
(...)
ED="1234"
return_url="/payment/confirm?tx_id="123"
SCORING=""
SCO_CATEGORY="G">
</ncresponse>
```

Url-encoding the value of the return_url in PARAMPLUS fixes this
nonsensical result.

However, the Ingenico API then fails to decode the parameter value when
passing it to the feedback URL, such as the ACCEPTURL we depend on.

As a workaround, since we only pass a single parameter inside
PARAMPLUS, we'll url-unquote it afterwards.

[1]
https://payment-services.ingenico.com/int/en/ogone/support/guides/integration%20guides/e-commerce#feedbackparameters_variablefeedbackparameters
2018-03-08 17:11:12 +01:00
fda-odoo c0e919b8eb [FIX] payment_ogone, payment_stripe, payment_authorize: give partner_id as parameter to s2s_process
If the page doesn't provide the partner_id, the three acquirer will now add it before process the payment.
2018-01-24 15:36:56 +01:00
tbe-odoo 2df9c22d80 [IMP] Payments & subscriptions: Improved Payments
- When registering a payment token, validating it using a payment of a small amount (~1.50€) followed by a refund allows ensuring
    that the payment method is valid (i.e. checksumming the card number simple ensure the number is valid but not that the card exists).
    This commit introduces a generic approach that must be implemented for each acquirer that has tokenization support.
    This commit also introduces a generic payment token registration/usage template that can be adapted according to one's need.
- Introducing a new payment form that handles payment, deletion and adding payment method (only for server2server for the moment).
- On /my/payment_method, changed strings 'Payment Acquirers' to 'Payment Methods' which is more clear.
- Stripe can now be used to pay subscriptions.
2017-08-14 08:30:59 +02:00
Thibault Delavallée c6f9109d4e [FIX] payment_ogone: do not crash if you can't process tx
Due to unexisting variable the method s2s/create controller was crashing
instead of returning an error when it did not successfully create
a token.
2017-07-28 13:51:51 +02:00
tbe-odoo 7d428c871b [IMP] payment, website_payment: generic mechanism to verify payment tokens on registration
When registering a payment token, validating it using a payment of a small amount followed by a refund
allows ensuring that the method is valid (i.e. checksumming the card number simple ensure the number
is valid but not that the card exists). This commit introduces a generic approach that must be implemented
for each acquirer that has tokenization support. This commit also introduces a generic payment token registration/usage template that can be adapted according to one's need.

payment_ogone: add support for tokens validation
2017-07-14 11:57:19 +02:00
Xavier Morel 07ab8b6cd2 [FIX] P3: Exception.message removed 2017-05-12 16:15:40 +02:00
xmo-odoo b4429c2a91 [FIX] Various P3-related import changes
* LDAP import: python-ldap is not python3-compatible, pyldap is

  Warning: only supported from debian Stretch (current testing)?
  https://packages.debian.org/search?searchon=names&keywords=pyldap

* implicitly relative imports
* imports of moved or removed stdlib modules

issue #8530
2017-04-28 09:06:53 +02:00
Xavier Morel 3979f6802e [#8530] convert exception handlers to except..as syntax
Futurize fixers:
* lib2to3.fixes.fix_except
2017-04-11 14:53:29 +02:00
Christophe Simonis 440c8cc7c9 [FIX] payment_ogone: process s2s requests as sudo 2016-11-24 16:42:43 +01:00
Damien Bouvy 3321d9c1ca [FIX] payment_ogone: serialize correctly & validate with sudo 2016-11-23 14:59:52 +01:00
Jeremy Kersten 6f03ab45a8 [IMP] website_sale: allow to use payment.token to pay on eCommerce
This commit add as (sub) payment method all (owns) tokens from this acquirer.

Tested with Ogone with success
2016-08-30 17:50:44 +02:00
Ravi Gadhia 4ef937ed38 [MIG] payment_ogone: new API
No functional change.
2016-07-06 15:10:47 +02:00
Goffin Simon 32c8280a02 [FIX] payment_adyen, payment_authorize, payment_buckaroo, payment_paypal, payment_sips: Disable csrf on callbacks
Inspired from 2099f15d67

opw:653341
2015-11-24 11:35:57 +01:00
Christophe Simonis 7636b510a2 [ADD] *: CSRF protection in forms and routes
* make CSRF protection the default on all non-SAFE methods
  note: there currently is no way to call a CSRF-protected endpoint
  without a form-encoded entity-body as that's the only place we get the
  CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
  generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
  the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
  the purpose of a CSRF token in the database manager screens.
  There is no request database to obtain the
  secret and generate a CSRF token.
2015-10-01 01:36:50 +02:00
Damien Bouvy e4a93776b3 [FIX] payment_ogone: s2s feedback controller does not need authentication and function name error no longer prevents tx validation 2015-08-05 11:42:24 +02:00
Damien Bouvy 247867b8a3 [FIX] payment_ogone: jsonrpc calls give params as kwargs 2015-06-25 17:49:35 +02:00
Damien Bouvy ef86cfaa1c [IMP] payment_ogone: add support for s2s payments 2015-06-15 14:57:15 +02:00
Fabien Meghazi e974e1fbea [REM] remove disable_db and ensure_db() from addons
bzr revid: fme@openerp.com-20140130092308-s24a7h2mhzuaasf1
2014-01-30 10:23:08 +01:00
Fabien Meghazi c4e48e2388 [REM] Removed auth='admin' from modules
bzr revid: fme@openerp.com-20140129171520-wkz8ot4pa63utoi3
2014-01-29 18:15:20 +01:00
Thibault Delavallée a7908b63bd [FIX] payment_*: fixed return controlers, now using werkzeug redirection
bzr revid: tde@openerp.com-20140124145923-fsyv2tm5z92m1je1
2014-01-24 15:59:23 +01:00
Thibault Delavallée 164a1ab180 [IMP] payment_*: routes as admin, remove website parameter in routes
bzr revid: tde@openerp.com-20140123154924-r1cylz0fobzav90y
2014-01-23 16:49:24 +01:00
Thibault Delavallée 0b69bad996 [RENAME] payment_acquirer_* -> payment_ *
bzr revid: tde@openerp.com-20140122175702-1h1e51z4njt4s70w
2014-01-22 18:57:02 +01:00