Files
odoo_source/addons/payment_sips/controllers/main.py
T
Raphael Collet caf900e89e [FIX] *: use auth='public' in controllers that use request.env
The following trick used to work, because `sudo()` was actually making
an environment for the superuser to operate upon:

request.env[...].sudo().method(...)

It no longer works in general, since `sudo()` now makes an environment
in superuser mode but with `uid=None`!  It may still work by accident
for operations that never use `env.uid`, but is broken in general.

Using `auth='public'` fixes the problem by using the public user when no
user is available.

closes odoo/odoo#34297

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2019-07-04 11:32:22 +00:00

45 lines
1.3 KiB
Python

# -*- coding: utf-8 -*-
# Copyright 2015 Eezee-It
import json
import logging
import werkzeug
from odoo import http
from odoo.http import request
_logger = logging.getLogger(__name__)
class SipsController(http.Controller):
_notify_url = '/payment/sips/ipn/'
_return_url = '/payment/sips/dpn/'
def sips_validate_data(self, **post):
sips = request.env['payment.acquirer'].search([('provider', '=', 'sips')], limit=1)
security = sips.sudo()._sips_generate_shasign(post)
if security == post['Seal']:
_logger.debug('Sips: validated data')
return request.env['payment.transaction'].sudo().form_feedback(post, 'sips')
_logger.warning('Sips: data are corrupted')
return False
@http.route([
'/payment/sips/ipn/'],
type='http', auth='public', methods=['POST'], csrf=False)
def sips_ipn(self, **post):
""" Sips IPN. """
self.sips_validate_data(**post)
return ''
@http.route([
'/payment/sips/dpn'], type='http', auth="public", methods=['POST'], csrf=False)
def sips_dpn(self, **post):
""" Sips DPN """
try:
self.sips_validate_data(**post)
except:
pass
return werkzeug.utils.redirect('/payment/process')