Files
odoo_source/addons/payment_authorize/tests/test_authorize.py
T
Laura Schauer 2ee4251d07 [IMP] payment(_adyen, _authorize): disable tokens of disabled acquirers
Before this commit, zombie payment tokens (= tokens linked to disabled
acquirers) could still
1) be used by internal users and
2) reactivated when the acquirer’s state changed to ‘test’ or ‘enabled’.
This is not desirable because zombie tokens should neither be used,
nor reactivated.

After this commit, all tokens related to an acquirer are unassigned
from linked documents and archived as soon as the acquirer’s state is
changed to ‘disabled’. Creating a payment with an archived token is
prohibited. In addition, archived tokens cannot be un-archived anymore.

task-2649806

closes odoo/odoo#93774

Related: odoo/enterprise#28661
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-07-12 03:09:44 +02:00

59 lines
2.4 KiB
Python

# Part of Odoo. See LICENSE file for full copyright and licensing details.
from unittest.mock import patch
from odoo.addons.payment import utils as payment_utils
from odoo.exceptions import UserError
from odoo.tests import tagged
from odoo.tools import mute_logger
from .common import AuthorizeCommon
@tagged('post_install', '-at_install')
class AuthorizeTest(AuthorizeCommon):
def test_compatible_acquirers(self):
# Note: in the test common, 'USD' is specified as authorize_currency_id
unsupported_currency = self._prepare_currency('CHF')
acquirers = self.env['payment.acquirer']._get_compatible_acquirers(
partner_id=self.partner.id,
currency_id=unsupported_currency.id,
company_id=self.company.id)
self.assertNotIn(self.authorize, acquirers)
acquirers = self.env['payment.acquirer']._get_compatible_acquirers(
partner_id=self.partner.id,
currency_id=self.currency_usd.id,
company_id=self.company.id)
self.assertIn(self.authorize, acquirers)
def test_processing_values(self):
"""Test custom 'access_token' processing_values for authorize acquirer."""
tx = self._create_transaction(flow='direct')
with mute_logger('odoo.addons.payment.models.payment_transaction'), \
patch(
'odoo.addons.payment.utils.generate_access_token',
new=self._generate_test_access_token
):
processing_values = tx._get_processing_values()
with patch(
'odoo.addons.payment.utils.generate_access_token', new=self._generate_test_access_token
):
self.assertTrue(payment_utils.check_access_token(
processing_values['access_token'], self.reference, self.partner.id,
))
def test_validation(self):
self.assertEqual(self.authorize.authorize_currency_id, self.currency_usd)
self.assertEqual(self.authorize._get_validation_amount(), 0.01)
self.assertEqual(self.authorize._get_validation_currency(), self.currency_usd)
def test_authorize_neutralize(self):
self.env['payment.acquirer']._neutralize()
self.assertEqual(self.acquirer.authorize_login, False)
self.assertEqual(self.acquirer.authorize_transaction_key, False)
self.assertEqual(self.acquirer.authorize_signature_key, False)
self.assertEqual(self.acquirer.authorize_client_key, False)