Before this commit, zombie payment tokens (= tokens linked to disabled acquirers) could still 1) be used by internal users and 2) reactivated when the acquirer’s state changed to ‘test’ or ‘enabled’. This is not desirable because zombie tokens should neither be used, nor reactivated. After this commit, all tokens related to an acquirer are unassigned from linked documents and archived as soon as the acquirer’s state is changed to ‘disabled’. Creating a payment with an archived token is prohibited. In addition, archived tokens cannot be un-archived anymore. task-2649806 closes odoo/odoo#93774 Related: odoo/enterprise#28661 Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
59 lines
2.4 KiB
Python
59 lines
2.4 KiB
Python
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
|
|
|
from unittest.mock import patch
|
|
|
|
from odoo.addons.payment import utils as payment_utils
|
|
from odoo.exceptions import UserError
|
|
from odoo.tests import tagged
|
|
from odoo.tools import mute_logger
|
|
|
|
from .common import AuthorizeCommon
|
|
|
|
|
|
@tagged('post_install', '-at_install')
|
|
class AuthorizeTest(AuthorizeCommon):
|
|
|
|
def test_compatible_acquirers(self):
|
|
# Note: in the test common, 'USD' is specified as authorize_currency_id
|
|
unsupported_currency = self._prepare_currency('CHF')
|
|
acquirers = self.env['payment.acquirer']._get_compatible_acquirers(
|
|
partner_id=self.partner.id,
|
|
currency_id=unsupported_currency.id,
|
|
company_id=self.company.id)
|
|
self.assertNotIn(self.authorize, acquirers)
|
|
acquirers = self.env['payment.acquirer']._get_compatible_acquirers(
|
|
partner_id=self.partner.id,
|
|
currency_id=self.currency_usd.id,
|
|
company_id=self.company.id)
|
|
self.assertIn(self.authorize, acquirers)
|
|
|
|
def test_processing_values(self):
|
|
"""Test custom 'access_token' processing_values for authorize acquirer."""
|
|
tx = self._create_transaction(flow='direct')
|
|
with mute_logger('odoo.addons.payment.models.payment_transaction'), \
|
|
patch(
|
|
'odoo.addons.payment.utils.generate_access_token',
|
|
new=self._generate_test_access_token
|
|
):
|
|
processing_values = tx._get_processing_values()
|
|
|
|
with patch(
|
|
'odoo.addons.payment.utils.generate_access_token', new=self._generate_test_access_token
|
|
):
|
|
self.assertTrue(payment_utils.check_access_token(
|
|
processing_values['access_token'], self.reference, self.partner.id,
|
|
))
|
|
|
|
def test_validation(self):
|
|
self.assertEqual(self.authorize.authorize_currency_id, self.currency_usd)
|
|
self.assertEqual(self.authorize._get_validation_amount(), 0.01)
|
|
self.assertEqual(self.authorize._get_validation_currency(), self.currency_usd)
|
|
|
|
def test_authorize_neutralize(self):
|
|
self.env['payment.acquirer']._neutralize()
|
|
|
|
self.assertEqual(self.acquirer.authorize_login, False)
|
|
self.assertEqual(self.acquirer.authorize_transaction_key, False)
|
|
self.assertEqual(self.acquirer.authorize_signature_key, False)
|
|
self.assertEqual(self.acquirer.authorize_client_key, False)
|