Extends stock event.registration with a signed QR ticket system, built to
complement rather than duplicate Odoo 19's existing barcode/badge
infrastructure. ticket_ref ('TIX-{event}-{seq}') and a QR code encoding
"ticket_ref|hmac_token" are added; the HMAC is signed with Odoo's own
per-database secret (ir.config_parameter 'database.secret', the same
mechanism core uses for password-reset tokens), so a copied/edited
ticket_ref without the matching signature is rejected as forged. A "Event
Ticket (QR)" PDF report is auto-attached to the core registration
confirmation email by adding it to event.event_subscription's
report_template_ids - no override of core mail-sending logic needed.
Adds the missing piece core doesn't provide: a mobile-friendly staff
check-in page at /event/checkin (gated on event.group_event_registration_desk),
built as a v19 "Interaction" (registry.category("public.interactions"),
the current replacement for legacy publicWidget) with manual ticket-ref
entry always available and camera scanning via the browser's native
BarcodeDetector API - avoiding a third-party CDN dependency and its
security/offline-reliability tradeoffs. Guards against forged tokens and
double check-in; a live per-event registered-vs-checked-in dashboard.
Two more real Odoo 19 surprises hit here: event.event has no more `state`
field at all (replaced by a stage_id/event.stage kanban system - my
check-in page's event picker now filters by date_end instead), and a
route type='json' should be type='jsonrpc' (json still works but is
deprecated).
Verified against a live Odoo 19 + Postgres 16 container: 9/9 tests pass
(ticket generation/uniqueness, valid/duplicate/forged/tampered token
handling, manual lookup), plus a full manual live run over HTTP - created
an event and registration via JSON-RPC, confirmed ticket_ref generation,
authenticated a session, hit /event/checkin/scan for a real check-in and
duplicate rejection, confirmed dashboard counts update, and loaded the
actual /event/checkin page (title, camera-button markup, and our JS
present in the served frontend bundle).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
54 lines
2.1 KiB
Python
54 lines
2.1 KiB
Python
from odoo import fields, http
|
|
from odoo.exceptions import AccessDenied
|
|
from odoo.http import request
|
|
|
|
|
|
def _require_registration_desk():
|
|
if not request.env.user.has_group('event.group_event_registration_desk'):
|
|
raise AccessDenied()
|
|
|
|
|
|
class EventCheckinController(http.Controller):
|
|
|
|
@http.route(['/event/checkin', '/event/checkin/<int:event_id>'], type='http', auth='user', website=True)
|
|
def checkin_page(self, event_id=None, **kwargs):
|
|
_require_registration_desk()
|
|
events = request.env['event.event'].search([('date_end', '>=', fields.Datetime.now())])
|
|
event = request.env['event.event'].browse(event_id) if event_id else events[:1]
|
|
return request.render('event_qr_ticketing.checkin_page', {
|
|
'events': events,
|
|
'event': event,
|
|
})
|
|
|
|
@http.route(['/event/checkin/scan'], type='jsonrpc', auth='user', website=True)
|
|
def checkin_scan(self, value=None, manual=False, **kwargs):
|
|
_require_registration_desk()
|
|
Registration = request.env['event.registration']
|
|
|
|
if manual:
|
|
status, registration = Registration._lookup_by_ticket_ref((value or '').strip())
|
|
else:
|
|
status, registration = Registration._verify_scanned_token(value)
|
|
|
|
result = {'status': status}
|
|
if registration:
|
|
result.update(
|
|
name=registration.name or registration.partner_id.name,
|
|
event=registration.event_id.name,
|
|
ticket_ref=registration.ticket_ref,
|
|
)
|
|
if status == 'ok':
|
|
registration.action_check_in()
|
|
|
|
return result
|
|
|
|
@http.route(['/event/checkin/dashboard/<int:event_id>'], type='jsonrpc', auth='user', website=True)
|
|
def checkin_dashboard(self, event_id, **kwargs):
|
|
_require_registration_desk()
|
|
event = request.env['event.event'].browse(event_id)
|
|
registrations = event.registration_ids.filtered(lambda r: r.state in ('open', 'done'))
|
|
return {
|
|
'registered': len(registrations),
|
|
'checked_in': len(registrations.filtered('checked_in')),
|
|
}
|