The following trick used to work, because `sudo()` was actually making an environment for the superuser to operate upon: request.env[...].sudo().method(...) It no longer works in general, since `sudo()` now makes an environment in superuser mode but with `uid=None`! It may still work by accident for operations that never use `env.uid`, but is broken in general. Using `auth='public'` fixes the problem by using the public user when no user is available. closes odoo/odoo#34297 Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
45 lines
1.3 KiB
Python
45 lines
1.3 KiB
Python
# -*- coding: utf-8 -*-
|
|
|
|
# Copyright 2015 Eezee-It
|
|
|
|
import json
|
|
import logging
|
|
import werkzeug
|
|
|
|
from odoo import http
|
|
from odoo.http import request
|
|
|
|
_logger = logging.getLogger(__name__)
|
|
|
|
|
|
class SipsController(http.Controller):
|
|
_notify_url = '/payment/sips/ipn/'
|
|
_return_url = '/payment/sips/dpn/'
|
|
|
|
def sips_validate_data(self, **post):
|
|
sips = request.env['payment.acquirer'].search([('provider', '=', 'sips')], limit=1)
|
|
security = sips.sudo()._sips_generate_shasign(post)
|
|
if security == post['Seal']:
|
|
_logger.debug('Sips: validated data')
|
|
return request.env['payment.transaction'].sudo().form_feedback(post, 'sips')
|
|
_logger.warning('Sips: data are corrupted')
|
|
return False
|
|
|
|
@http.route([
|
|
'/payment/sips/ipn/'],
|
|
type='http', auth='public', methods=['POST'], csrf=False)
|
|
def sips_ipn(self, **post):
|
|
""" Sips IPN. """
|
|
self.sips_validate_data(**post)
|
|
return ''
|
|
|
|
@http.route([
|
|
'/payment/sips/dpn'], type='http', auth="public", methods=['POST'], csrf=False)
|
|
def sips_dpn(self, **post):
|
|
""" Sips DPN """
|
|
try:
|
|
self.sips_validate_data(**post)
|
|
except:
|
|
pass
|
|
return werkzeug.utils.redirect('/payment/process')
|