metatroncubeswdev b94ee06d3a fix: anonymous access to auth='user' pages crashed with 500 instead of redirecting to login
Reported: clicking "Post a Listing" on /classifieds while logged out threw
a raw 500 instead of prompting login.

Root cause is upstream, in this Odoo 19 build's own http.py: when
auth='user' raises SessionExpiredException for an anonymous visitor,
Request._serve_db's `finally: self.env = None` clears the request env
before the exception reaches the website error handler, which then tries
to build the login redirect via self.env['ir.http']._redirect(...) and
crashes with TypeError: 'NoneType' object is not subscriptable. This
isn't specific to any one route - it reproduces on every auth='user' +
website=True page hit anonymously, including stock Odoo's own /my (traced
this back to the true cause rather than continuing to treat it as an
unrelated environment quirk, since it now has a real reported symptom).

Since core can't be patched here, worked around it at the route level
across all 9 affected pages (classifieds new/my/renew, membership
my/renew/card, benefits my, school attendance, portal my/school, event
checkin): switched from auth='user' to auth='public' and added an
explicit `if request.env.user._is_public(): return request.redirect(...)`
check at the top of each handler, before Odoo's own auth layer ever gets
a chance to raise. The jsonrpc AJAX endpoints (attendance save, checkin
scan/dashboard) were left on auth='user' since they return a JSON error
rather than attempting an HTML redirect, so they don't hit this path.

Verified against a live Odoo 19 + Postgres 16 container: reproduced the
original crash pre-fix, then confirmed all 9 previously-broken routes now
303-redirect to /web/login?redirect=<path> when hit anonymously, that the
login page carries the redirect target, that logged-in access is
unaffected (200), and that the separate "logged in but lacking a required
group" case (event check-in without Registration Desk) still degrades
gracefully to a clean 403 rather than a crash. Full regression: 48/48
tests pass across the six touched modules.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-17 23:06:30 -04:00

Community OS

A brand-neutral, resellable suite of Odoo 19 Community modules for community and cultural organizations. First deployment: the Tamil Nadu Cultural Society of Canada (TNCSC).

Vendor: Metatroncube Software Solutions LLP · Waterloo, Ontario Target platform: Odoo 19 Community Edition (LGPL-3) · PostgreSQL 16 · Python 3.12

community_* is a placeholder module prefix. Replace it with a unique vendor prefix before publishing to the Odoo App Store so technical names never collide with anything already listed.

Layered architecture

┌─────────────────────────────────────────────────────────────┐
│  DEPLOYMENT LAYER  (per client — data only, no logic)        │
│  tncsc_deployment:  branding, tiers & prices, chart of        │
│  accounts, email copy, website pages, user groups             │
└───────────────▲─────────────────────────────────────────────┘
                │ depends on
┌───────────────┴─────────────────────────────────────────────┐
│  PRODUCT LAYER  (brand-neutral, resellable, LGPL-3)          │
│  community_membership   event_qr_ticketing   community_school │
│  community_classifieds  community_benefits    community_interac│
│  community_theme_base   community_portal                      │
└───────────────▲─────────────────────────────────────────────┘
                │ depends only on
┌───────────────┴─────────────────────────────────────────────┐
│  ODOO 19 COMMUNITY CORE  (never Enterprise)                  │
└─────────────────────────────────────────────────────────────┘

Product-layer modules never mention a client name, never hardcode a price, a colour, an account code, or an email address. Anything client-specific is a configuration record, seeded only by a *_deployment module. Landing a new client means writing a new clientname_deployment module — the product code never changes.

Modules

Product layer (brand-neutral, sellable)

Module Purpose
community_theme_base Configurable brand tokens (colours, logo, fonts) via settings
community_membership Member profiles, tiers, family grouping, renewals, QR membership card
event_qr_ticketing QR ticket per event registration, staff check-in / verification
community_school Programs, classes, enrollment, attendance, LMS link, parent portal
community_classifieds Member-gated classifieds board with moderation and auto-expiry
community_benefits Benefit centres and per-tier member benefit entitlements
community_interac Interac e-Transfer semi-automated payment provider (Canada)
community_portal Unified member portal dashboard, soft-detects installed modules

Deployment layer (per client — data only)

Module Purpose
tncsc_deployment TNCSC branding, tiers/prices, chart of accounts, email copy, website pages, user groups

Local development

cd deploy
docker compose up

Odoo will be available at http://localhost:8069. The ../addons folder is mounted read-write, so changes to module code are picked up on restart (dev mode reload is enabled in deploy/odoo.conf).

Licensing & resellability guardrails

  1. Every product module is licensed LGPL-3.
  2. No community_* module may depend on an Odoo Enterprise module — see Appendix A in the project plan for the Community-only allowlist.
  3. No client identity (name, email, colour, price, account code) may appear in a product module. This is enforced in CI by scripts/check_brand_leak.py.
  4. All client-variable behaviour is configuration data, seeded by the deployment layer, never a literal in product code.
  5. Every product module ships an App-Store-ready manifest, a tests/ package, and a static/description/index.html listing page.

See CommunityOS_Implementation_Plan_for_Claude_Code.md for the full, phase-by-phase build plan.

CI

.github/workflows/ci.yml installs every module against Odoo 19 + Postgres 16 with --test-enable, runs the brand-leak grep, and lints with flake8 / pylint-odoo.

Description
No description provided
Readme 5.6 MiB
Languages
Python 94.6%
JavaScript 3.3%
HTML 2.1%