Before this commit, most acquirers needed to run several successive searches for the transaction whose reference was received by a controller in notification data. This is because the security checks run on the notification data require access to the acquirer through the transaction record which was immediately discarded. Starting with this commit, all `*_feedback_data` method are no longer decorated with `api.model` and can use the transaction record they're called on if provided. They are also renamed to `*_notification_data`. task-2737144 closes odoo/odoo#83850 Related: odoo/enterprise#23938 Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
20 lines
664 B
Python
20 lines
664 B
Python
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
|
|
|
import logging
|
|
import pprint
|
|
|
|
from odoo import http
|
|
from odoo.http import request
|
|
|
|
_logger = logging.getLogger(__name__)
|
|
|
|
|
|
class TransferController(http.Controller):
|
|
_accept_url = '/payment/transfer/feedback'
|
|
|
|
@http.route(_accept_url, type='http', auth='public', methods=['POST'], csrf=False)
|
|
def transfer_form_feedback(self, **post):
|
|
_logger.info("handling redirection from Transfer with data:\n%s", pprint.pformat(post))
|
|
request.env['payment.transaction'].sudo()._handle_notification_data('transfer', post)
|
|
return request.redirect('/payment/status')
|