* make CSRF protection the default on all non-SAFE methods note: there currently is no way to call a CSRF-protected endpoint without a form-encoded entity-body as that's the only place we get the CSRF token from. * simple CSRF token generation: just use the HMAC'd session id, no generating a new random token per session then HMAC it * use constant-time equal function to avoid timing attacks * assert that a database secret is configured before hashing/validating the CSRF token * opt-out database manager from CSRF: The super-admin password serves the purpose of a CSRF token in the database manager screens. There is no request database to obtain the secret and generate a CSRF token.
23 lines
750 B
Python
23 lines
750 B
Python
# -*- coding: utf-8 -*-
|
|
import logging
|
|
import pprint
|
|
import werkzeug
|
|
|
|
from openerp import http, SUPERUSER_ID
|
|
from openerp.http import request
|
|
|
|
_logger = logging.getLogger(__name__)
|
|
|
|
|
|
class OgoneController(http.Controller):
|
|
_accept_url = '/payment/transfer/feedback'
|
|
|
|
@http.route([
|
|
'/payment/transfer/feedback',
|
|
], type='http', auth='none', csrf=False)
|
|
def transfer_form_feedback(self, **post):
|
|
cr, uid, context = request.cr, SUPERUSER_ID, request.context
|
|
_logger.info('Beginning form_feedback with post data %s', pprint.pformat(post)) # debug
|
|
request.registry['payment.transaction'].form_feedback(cr, uid, post, 'transfer', context)
|
|
return werkzeug.utils.redirect(post.pop('return_url', '/'))
|