Files
odoo_source/addons/payment_transfer/controllers/main.py
T
Christophe Simonis 7636b510a2 [ADD] *: CSRF protection in forms and routes
* make CSRF protection the default on all non-SAFE methods
  note: there currently is no way to call a CSRF-protected endpoint
  without a form-encoded entity-body as that's the only place we get the
  CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
  generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
  the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
  the purpose of a CSRF token in the database manager screens.
  There is no request database to obtain the
  secret and generate a CSRF token.
2015-10-01 01:36:50 +02:00

23 lines
750 B
Python

# -*- coding: utf-8 -*-
import logging
import pprint
import werkzeug
from openerp import http, SUPERUSER_ID
from openerp.http import request
_logger = logging.getLogger(__name__)
class OgoneController(http.Controller):
_accept_url = '/payment/transfer/feedback'
@http.route([
'/payment/transfer/feedback',
], type='http', auth='none', csrf=False)
def transfer_form_feedback(self, **post):
cr, uid, context = request.cr, SUPERUSER_ID, request.context
_logger.info('Beginning form_feedback with post data %s', pprint.pformat(post)) # debug
request.registry['payment.transaction'].form_feedback(cr, uid, post, 'transfer', context)
return werkzeug.utils.redirect(post.pop('return_url', '/'))