Files
odoo_source/addons/website_payment
Benoit Socias 768db8390d [FIX] website, website_payment: exclude Donation snippet from cache
Since [1] the CSRF token used by the donation snippet's form did end up
being cached for new visitors that did not have a session id yet.
This made the validation of the token fail when using the form because
the token from the very first new visitor on the worker was reused.

After this commit pages that contain a Donation snippet are not cached
anymore in order to always get a fresh CSRF token - similarly to what is
done for the form snippet.

When using incognito mode the csrf token is sometimes not recognized
during navigation to the donation payment page.
Simple sequence to reproduce it:
- drop a Donation snippet on the Home page
- use Firefox and do not log in
- in normal browser, select 25 then press Donate Now
- open an incognito browser, select 50 then press Donate Now
=> 400 Bad Request
Alternative (any browser):
- open page with Donation snippet in incognito window
- remove session id from cookies using developer tools
- close window
- reopen page in a new incognito window
- try to donate
=> 400 Bad Request

[1]: https://github.com/odoo/odoo/commit/7fccbac004628093da49016f75370a84bba49465

opw-2774065

closes odoo/odoo#88184

X-original-commit: 16c9b103195f342f8bcca928a53121dbe4480d58
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
2022-04-07 13:24:20 +02:00
..
…
…