metatroncubeswdev b94ee06d3a fix: anonymous access to auth='user' pages crashed with 500 instead of redirecting to login
Reported: clicking "Post a Listing" on /classifieds while logged out threw
a raw 500 instead of prompting login.

Root cause is upstream, in this Odoo 19 build's own http.py: when
auth='user' raises SessionExpiredException for an anonymous visitor,
Request._serve_db's `finally: self.env = None` clears the request env
before the exception reaches the website error handler, which then tries
to build the login redirect via self.env['ir.http']._redirect(...) and
crashes with TypeError: 'NoneType' object is not subscriptable. This
isn't specific to any one route - it reproduces on every auth='user' +
website=True page hit anonymously, including stock Odoo's own /my (traced
this back to the true cause rather than continuing to treat it as an
unrelated environment quirk, since it now has a real reported symptom).

Since core can't be patched here, worked around it at the route level
across all 9 affected pages (classifieds new/my/renew, membership
my/renew/card, benefits my, school attendance, portal my/school, event
checkin): switched from auth='user' to auth='public' and added an
explicit `if request.env.user._is_public(): return request.redirect(...)`
check at the top of each handler, before Odoo's own auth layer ever gets
a chance to raise. The jsonrpc AJAX endpoints (attendance save, checkin
scan/dashboard) were left on auth='user' since they return a JSON error
rather than attempting an HTML redirect, so they don't hit this path.

Verified against a live Odoo 19 + Postgres 16 container: reproduced the
original crash pre-fix, then confirmed all 9 previously-broken routes now
303-redirect to /web/login?redirect=<path> when hit anonymously, that the
login page carries the redirect target, that logged-in access is
unaffected (200), and that the separate "logged in but lacking a required
group" case (event check-in without Registration Desk) still degrades
gracefully to a clean 403 rather than a crash. Full regression: 48/48
tests pass across the six touched modules.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-17 23:06:30 -04:00

66 lines
2.7 KiB
Python

from odoo import http
from odoo.addons.portal.controllers.portal import CustomerPortal
from odoo.http import request
def _redirect_to_login_if_public(path):
"""Manual login-required redirect - see community_classifieds for why this
is needed instead of auth='user' (a bug in this Odoo version's own
SessionExpiredException -> login-redirect handling)."""
if request.env.user._is_public():
return request.redirect(f'/web/login?redirect={path}')
return None
class MembershipPortal(CustomerPortal):
def _prepare_home_portal_values(self, counters):
values = super()._prepare_home_portal_values(counters)
if 'membership_count' in counters:
partner = request.env.user.partner_id
values['membership_count'] = 1 if partner.membership_state != 'none' else 0
return values
@http.route(['/my/membership'], type='http', auth='public', website=True)
def portal_my_membership(self, **kwargs):
redirect = _redirect_to_login_if_public('/my/membership')
if redirect:
return redirect
partner = request.env.user.partner_id
return request.render('community_membership.portal_my_membership', {
'partner': partner,
'page_name': 'membership',
})
@http.route(['/my/membership/renew'], type='http', auth='public', website=True)
def portal_membership_renew(self, **kwargs):
redirect = _redirect_to_login_if_public('/my/membership/renew')
if redirect:
return redirect
partner = request.env.user.partner_id
invoice = request.env['account.move'].sudo().search([
('partner_id', '=', partner.id),
('move_type', '=', 'out_invoice'),
('state', '=', 'draft'),
], order='create_date desc', limit=1)
if not invoice:
invoice = partner.sudo()._create_renewal_invoice()
if not invoice:
return request.redirect('/my/membership')
return request.redirect(f'/my/invoices/{invoice.id}')
@http.route(['/my/membership/card'], type='http', auth='public', website=True)
def portal_membership_card(self, **kwargs):
redirect = _redirect_to_login_if_public('/my/membership/card')
if redirect:
return redirect
partner = request.env.user.partner_id
pdf_content, _report_type = request.env['ir.actions.report'].sudo()._render_qweb_pdf(
'community_membership.action_report_membership_card', res_ids=partner.ids,
)
return request.make_response(pdf_content, headers=[
('Content-Type', 'application/pdf'),
('Content-Length', len(pdf_content)),
('Content-Disposition', 'attachment; filename=membership-card.pdf'),
])