Reported: clicking "Post a Listing" on /classifieds while logged out threw a raw 500 instead of prompting login. Root cause is upstream, in this Odoo 19 build's own http.py: when auth='user' raises SessionExpiredException for an anonymous visitor, Request._serve_db's `finally: self.env = None` clears the request env before the exception reaches the website error handler, which then tries to build the login redirect via self.env['ir.http']._redirect(...) and crashes with TypeError: 'NoneType' object is not subscriptable. This isn't specific to any one route - it reproduces on every auth='user' + website=True page hit anonymously, including stock Odoo's own /my (traced this back to the true cause rather than continuing to treat it as an unrelated environment quirk, since it now has a real reported symptom). Since core can't be patched here, worked around it at the route level across all 9 affected pages (classifieds new/my/renew, membership my/renew/card, benefits my, school attendance, portal my/school, event checkin): switched from auth='user' to auth='public' and added an explicit `if request.env.user._is_public(): return request.redirect(...)` check at the top of each handler, before Odoo's own auth layer ever gets a chance to raise. The jsonrpc AJAX endpoints (attendance save, checkin scan/dashboard) were left on auth='user' since they return a JSON error rather than attempting an HTML redirect, so they don't hit this path. Verified against a live Odoo 19 + Postgres 16 container: reproduced the original crash pre-fix, then confirmed all 9 previously-broken routes now 303-redirect to /web/login?redirect=<path> when hit anonymously, that the login page carries the redirect target, that logged-in access is unaffected (200), and that the separate "logged in but lacking a required group" case (event check-in without Registration Desk) still degrades gracefully to a clean 403 rather than a crash. Full regression: 48/48 tests pass across the six touched modules. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
66 lines
2.6 KiB
Python
66 lines
2.6 KiB
Python
from odoo import fields, http
|
|
from odoo.exceptions import AccessDenied
|
|
from odoo.http import request
|
|
|
|
|
|
def _require_registration_desk():
|
|
if not request.env.user.has_group('event.group_event_registration_desk'):
|
|
raise AccessDenied()
|
|
|
|
|
|
def _redirect_to_login_if_public(path):
|
|
"""Manual login-required redirect - see community_classifieds for why this
|
|
is needed instead of auth='user' (a bug in this Odoo version's own
|
|
SessionExpiredException -> login-redirect handling)."""
|
|
if request.env.user._is_public():
|
|
return request.redirect(f'/web/login?redirect={path}')
|
|
return None
|
|
|
|
|
|
class EventCheckinController(http.Controller):
|
|
|
|
@http.route(['/event/checkin', '/event/checkin/<int:event_id>'], type='http', auth='public', website=True)
|
|
def checkin_page(self, event_id=None, **kwargs):
|
|
redirect = _redirect_to_login_if_public('/event/checkin')
|
|
if redirect:
|
|
return redirect
|
|
_require_registration_desk()
|
|
events = request.env['event.event'].search([('date_end', '>=', fields.Datetime.now())])
|
|
event = request.env['event.event'].browse(event_id) if event_id else events[:1]
|
|
return request.render('event_qr_ticketing.checkin_page', {
|
|
'events': events,
|
|
'event': event,
|
|
})
|
|
|
|
@http.route(['/event/checkin/scan'], type='jsonrpc', auth='user', website=True)
|
|
def checkin_scan(self, value=None, manual=False, **kwargs):
|
|
_require_registration_desk()
|
|
Registration = request.env['event.registration']
|
|
|
|
if manual:
|
|
status, registration = Registration._lookup_by_ticket_ref((value or '').strip())
|
|
else:
|
|
status, registration = Registration._verify_scanned_token(value)
|
|
|
|
result = {'status': status}
|
|
if registration:
|
|
result.update(
|
|
name=registration.name or registration.partner_id.name,
|
|
event=registration.event_id.name,
|
|
ticket_ref=registration.ticket_ref,
|
|
)
|
|
if status == 'ok':
|
|
registration.action_check_in()
|
|
|
|
return result
|
|
|
|
@http.route(['/event/checkin/dashboard/<int:event_id>'], type='jsonrpc', auth='user', website=True)
|
|
def checkin_dashboard(self, event_id, **kwargs):
|
|
_require_registration_desk()
|
|
event = request.env['event.event'].browse(event_id)
|
|
registrations = event.registration_ids.filtered(lambda r: r.state in ('open', 'done'))
|
|
return {
|
|
'registered': len(registrations),
|
|
'checked_in': len(registrations.filtered('checked_in')),
|
|
}
|