Setting IAP sandbox as the endpoint for IAP doesn't really neutralize
the IAP services, it only prevents buying credits for it.
The existing credits could still be consumed by mistake.
In this new version, the account is kept as is, but the "+disabled"
suffix is appended to it. This will effectively disable the service by
raising a `InsufficientCreditError` for every IAP transactions.
This solution has multiple advantages:
- It's easy to revert, removing the "+disabled" suffix will re-activate
the account.
- It's retrocompatible as it doesn't require a new field on the IAP
account model.
- It's safer as the "disabled" information is directly part of the
token, its logic is handled on the IAP side and thus common to all
services.
In this new version, the tokens need to be transformed as follows:
original token | neutralized token
--------------------|-------------------
abcd1234 | acbd1234+disabled
my_token+suffix123 | my_token+disabled
abc+disabled | abc+disabled
closesodoo/odoo#138455
X-original-commit: 550595d84b9689f3fcc00f840e9d9d6d521c5ea9
Signed-off-by: Florian Daloze (fda) <fda@odoo.com>
Signed-off-by: Louis Baudoux (lba) <lba@odoo.com>