When generating a link for a payment through the website_payment/pay
route, including the partner_id 'blindly' is somewhat of a security
issue since it means you could potentially create payments for any
partner of your choosing.
This commit instead introduces an access token mechanism where the
partner_id, amount and currency_id are used to generate a unique access
token that can be checked upon accessing the payment page. This token
is only checked if the partner_id field is set (otherwise this is just
an anonymous payment like any other).