Antoine Vandevenne (anv) aab9d987f0 [FIX] website_sale: prevent users from modifying paid carts
Bug: Users are able to modify their eCommerce cart after it has been
paid when they fail to return to Odoo through the payment provider's
return route. This prevents the cart from being confirmed.

Steps to reproduce:
1. Install the payment provider Mollie and set it to test mode.
2. Go to the /shop page, add a product to the cart, and select Mollie
   for the payment.
3. On Mollie's hosted payment page, use the card number 4111111111111111
   with the expiry date 03/30 and the secret code 123. Select 'paid' as
   the payment outcome.
4. Confirm the payment but take care not to be redirected to the
   /payment/status route. For examples, close the tab before or comment
   out https://github.com/odoo/odoo/blob/15.0/addons/payment_mollie/controllers/main.py#L38.
5. Go back to /shop/cart and modify the cart.
6. Wait up to 20 minutes for the "payment: post-process transactions"
   cron to try to confirm the cart.
7. Check the cart's chatter: the confirmation failed because the cart's
   and transaction's amounts mismatch.

Explanation: The post-processing of the transaction is responsible for
confirming the cart, but it failed to be triggered because the user did
not visit the /payment/status page. The post-processing cron takes care
of pending post-processings after 10 to 20 minutes, which is long enough
for the user to modify their cart.

Fix: Force creating a new cart as soon as the current one is paid and is
being requested by the website.

task-2995504

closes odoo/odoo#102060

X-original-commit: 5f8674621cbf5919e10e32f29b66ae171fe05993
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
Signed-off-by: William Braeckman (wbr) <wbr@odoo.com>
2022-10-04 16:01:08 +02:00
2022-09-30 09:31:52 +02:00
2022-10-03 15:18:52 +02:00
…
…
…
2021-10-07 17:59:53 +00:00
2022-01-14 15:44:52 +00:00

Build Status Tech Doc Help Nightly Builds

Odoo

Odoo is a suite of web based open source business apps.

The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...

Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.

Getting started with Odoo

For a standard installation please follow the Setup instructions from the documentation.

To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials

S
Description
No description provided
Readme LGPL-3.0
3.4 GiB
Languages
Python 49.6%
JavaScript 47.8%
SCSS 2%
CSS 0.3%
HTML 0.2%