Files
odoo_source/addons/website_payment
Victor Piryns (pivi) 0085074373 [FIX] website_payment: regenerate access_token for donation
Current behaviour:
If a user is making a donation with one amount,
but changes that amount on the payment page,
he lands on a 404 when processing the transaction.

Expected behaviour:
The transaction shouldn't land on a 404 if you just changed
the amount of the donation mid checkout.

Steps to reproduce:
- Install Website and the Donation widget from the website editor
- Add the Donation widget to a page
- Add add a payment method (for ex: Test)
- Make a donation for example of $10
- On the payment page, change the amount to another value
- Checkout, you land on a 404 page.

Reason for the problem:
When generating the `access_token`, it is based on the amount paid.
So at the beginning of the transaction, it is based on $10.
But during checkout, we have a new amount, therefor a new `access_token`
is generated upon ending the transaction. Since the 2 tokens are
different, we return a 404.

Fix:
During checkout we regenerate a new `access_token`, before going on
the landing page. This way the `access_token` will take the value of
the amount from the payment form, not the donation widget.
(The default value for the amount on the payment form is the one
selected from the donation widget)

Affected versions:
- 15.0
- saas-15.2
- saas-15.3
- 16.0
- master

opw-3059462

closes odoo/odoo#109817

X-original-commit: 78bc873eef6768cec87c7f2eb0d5324ccc9d6af5
Signed-off-by: Piryns Victor (pivi) <pivi@odoo.com>
2023-01-13 09:18:48 +01:00
..
…
…