Modules
9166 Odoo modules tracked across all registered organizations.
Active Pull Requests 60
46 fresh 14 rotting 0 rotten 4 duplicate
Security Findings
Results are approximate: found by automated static analysis, not a full security audit. Treat them as a starting point for manual review, not confirmed issues.
Errors 1
| Module | Code | Message |
|---|---|---|
| web | route-user-csrf-off | /web/session/fingerprint/check — HTTP endpoint 'Session.session_fingerprint_check' disables CSRF protection for unsafe methods with session authentication. Restore CSRF or verify an independent request-authentication mechanism prevents cross-site actions. · |
Warnings 285
| Module | Code | Message |
|---|---|---|
| account | route-public-sudo | /terms — Endpoint 'TermsController.terms_conditions' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| account | route-public-sudo | /my/journal/<int:journal_id>/unsubscribe — Endpoint 'PortalAccount.portal_my_journal_unsubscribe' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| account_peppol | route-public-csrf-off | /peppol/webhook/new-message — Public HTTP endpoint 'PeppolWebhookController.webhook_new_message' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| account_peppol | route-public-sudo | /peppol/webhook/new-message — Endpoint 'PeppolWebhookController.webhook_new_message' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| account_peppol | route-public-csrf-off | /peppol/webhook/message-state-update — Public HTTP endpoint 'PeppolWebhookController.webhook_message_update' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| account_peppol | route-public-sudo | /peppol/webhook/message-state-update — Endpoint 'PeppolWebhookController.webhook_message_update' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| account_peppol | route-public-csrf-off | /peppol/webhook/user-state-update — Public HTTP endpoint 'PeppolWebhookController.webhook_user_update' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| account_peppol | route-public-sudo | /peppol/webhook/user-state-update — Endpoint 'PeppolWebhookController.webhook_user_update' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| account_peppol | route-public-csrf-off | /peppol/authentication/webhook — Public HTTP endpoint 'PeppolAuthentication.peppol_authentication_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| account_peppol | route-public-sudo | /peppol/authentication/webhook — Endpoint 'PeppolAuthentication.peppol_authentication_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| auth_signup | route-public-sudo | /web/signup — Endpoint 'AuthSignupHome.web_auth_signup' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| auth_signup | route-public-sudo | /web/reset_password — Endpoint 'AuthSignupHome.web_auth_reset_password' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| auth_totp | route-public-sudo | /web/login/totp — Endpoint 'Home.web_totp' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| base_automation | route-public-csrf-off | /web/hook/<string:rule_uuid> — Public HTTP endpoint 'BaseAutomationController.call_webhook_http' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| base_automation | route-public-sudo | /web/hook/<string:rule_uuid> — Endpoint 'BaseAutomationController.call_webhook_http' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| base_import_module | route-public-csrf-off | /base_import_module/login_upload — Public HTTP endpoint 'ImportModule.login_upload' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| calendar | route-public-sudo | /calendar/ics/<int:calendar_event_id>/<string:access_token> — Endpoint 'CalendarController.calendar_get_ics_file' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| calendar | route-public-sudo | /calendar/join_videocall/<string:access_token> — Endpoint 'CalendarController.calendar_join_videocall' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| cloud_storage | route-public-csrf-off | /mail/rtc/recording/<int:call_history_id>/complete — Public HTTP endpoint 'CloudStorageRtcController.complete_recording' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| cloud_storage | route-public-sudo | /mail/rtc/recording/<int:call_history_id>/complete — Endpoint 'CloudStorageRtcController.complete_recording' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| digest | route-public-csrf-off | /digest/<int:digest_id>/unsubscribe_oneclik — Public HTTP endpoint 'DigestController.digest_unsubscribe_oneclick' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| digest | route-public-sudo | /digest/<int:digest_id>/unsubscribe — Endpoint 'DigestController.digest_unsubscribe' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| event | route-public-sudo | /event/<model("event.event"):event>/ics — Endpoint 'EventController.event_ics_file' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| event | route-public-sudo | /event/<int:event_id>/my_tickets — Endpoint 'EventController.event_my_tickets' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| hr_attendance | route-public-sudo | /hr_attendance/<token> — Endpoint 'HrAttendance.open_kiosk_mode' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| hr_attendance | route-public-sudo | /hr_attendance/attendance_employee_data — Endpoint 'HrAttendance.employee_attendance_data' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| hr_attendance | route-public-sudo | /hr_attendance/attendance_barcode_scanned — Endpoint 'HrAttendance.scan_barcode' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| hr_attendance | route-public-sudo | /hr_attendance/manual_selection — Endpoint 'HrAttendance.manual_selection' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| hr_attendance | route-public-sudo | /hr_attendance/update_break_duration — Endpoint 'HrAttendance.update_break_duration' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| hr_attendance | route-public-sudo | /hr_attendance/employees_infos — Endpoint 'HrAttendance.employees_infos' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| html_editor | route-public-sudo | /web_editor/shape/<module>/<path:filename>, /html_editor/shape/<module>/<path:filename> — Endpoint 'HTML_Editor.shape' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| http_routing | route-public-sudo | /website/translations — Endpoint 'Routing.get_website_translations' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| im_livechat | route-public-sudo | /im_livechat/support/<int:channel_id> — Endpoint 'LivechatController.support_page' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| im_livechat | route-public-sudo | /im_livechat/loader/<int:channel_id> — Endpoint 'LivechatController.loader' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| im_livechat | route-public-sudo | /im_livechat/history — Endpoint 'LivechatController.history_pages' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| im_livechat | route-public-sudo | /im_livechat/download_transcript/<int:channel_id> — Endpoint 'LivechatController.download_livechat_transcript' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| l10n_dk | route-public-csrf-off | /nemhandel/webhook/new-message — Public HTTP endpoint 'NemhandelWebhookController.webhook_nemhandel_new_message' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| l10n_dk | route-public-sudo | /nemhandel/webhook/new-message — Endpoint 'NemhandelWebhookController.webhook_nemhandel_new_message' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| l10n_dk | route-public-csrf-off | /nemhandel/webhook/message-state-update — Public HTTP endpoint 'NemhandelWebhookController.webhook_nemhandel_message_update' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| l10n_dk | route-public-sudo | /nemhandel/webhook/message-state-update — Endpoint 'NemhandelWebhookController.webhook_nemhandel_message_update' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| l10n_dk | route-public-csrf-off | /nemhandel/webhook/user-state-update — Public HTTP endpoint 'NemhandelWebhookController.webhook_nemhandel_user_update' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| l10n_dk | route-public-sudo | /nemhandel/webhook/user-state-update — Endpoint 'NemhandelWebhookController.webhook_nemhandel_user_update' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| l10n_eu_account_vies | route-public-csrf-off | /l10n_eu_account_vies/1/webhook_update_vies — Public HTTP endpoint 'L10nEUAccountViesWebhookController.webhook_update_vies' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| l10n_fr_pdp | route-public-csrf-off | /api/signaturit_authentication_status/1/webhooks — Public HTTP endpoint 'IapAuthenticationWebhook.notify_authentication_status' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| l10n_fr_pdp | route-public-sudo | /api/signaturit_authentication_status/1/webhooks — Endpoint 'IapAuthenticationWebhook.notify_authentication_status' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| l10n_fr_pdp | route-public-csrf-off | /peppol/webhook/new-regulatory-message — Public HTTP endpoint 'PdpWebhookController.webhook_regulatory_message' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| l10n_fr_pdp | route-public-sudo | /peppol/webhook/new-regulatory-message — Endpoint 'PdpWebhookController.webhook_regulatory_message' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| l10n_pe | route-public-sudo | /my/address/city_info/<model('res.city'):city> — Endpoint 'L10nPEPortalAccount.city_infos' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| l10n_tw_edi_ecpay | route-public-csrf-off | /invoice/ecpay/agreed_invoice_allowance/<int:invoice_id> — Public HTTP endpoint 'EcpayInvoiceController.agreed_invoice_allowance' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| link_tracker | route-public-sudo | /r/<string:code> — Endpoint 'LinkTracker.full_url_redirect' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| route-public-sudo | /mail/view — Endpoint 'MailController.mail_action_view' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
|
| route-public-csrf-off | /mail/unfollow — Public HTTP endpoint 'MailController.mail_action_unfollow' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
|
| route-public-sudo | /mail/unfollow — Endpoint 'MailController.mail_action_unfollow' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
|
| route-public-sudo | /mail/attachment/pdf_first_page/<int:attachment_id> — Endpoint 'AttachmentController.mail_attachment_pdf_first_page' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
|
| route-public-sudo | /mail/rtc/session/notify_call_members — Endpoint 'RtcController.session_call_notify' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
|
| route-public-csrf-off | /mail/rtc/recording/<int:call_history_id>/routing — Public HTTP endpoint 'RtcController.get_routing' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
|
| route-public-sudo | /mail/rtc/recording/<int:call_history_id>/routing — Endpoint 'RtcController.get_routing' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
|
| mail_group | route-public-sudo | /groups — Endpoint 'PortalMailGroup.groups_index' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mail_group | route-public-sudo | /groups/<model("mail.group"):group>, /groups/<model("mail.group"):group>/page/<int:page> — Endpoint 'PortalMailGroup.group_view_messages' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mail_group | route-public-sudo | /groups/<model("mail.group"):group>/<model("mail.group.message"):message> — Endpoint 'PortalMailGroup.group_view_message' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mail_group | route-public-sudo | /groups/<model("mail.group"):group>/<model("mail.group.message"):message>/get_replies — Endpoint 'PortalMailGroup.group_message_get_replies' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mail_group | route-public-csrf-off | /group/<int:group_id>/unsubscribe_oneclick — Public HTTP endpoint 'PortalMailGroup.group_unsubscribe_oneclick' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| mail_group | route-public-sudo | /group/<int:group_id>/unsubscribe_oneclick — Endpoint 'PortalMailGroup.group_unsubscribe_oneclick' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mail_group | route-public-sudo | /group/subscribe-confirm — Endpoint 'PortalMailGroup.group_subscribe_confirm' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mail_plugin | route-public-sudo | /mail_client_extension/auth/access_token, /mail_plugin/auth/access_token — Endpoint 'Authenticate.auth_access_token' (auth="none") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| marketing_card | route-public-sudo | /cards/<model("card.card"):card>/card.jpg — Endpoint 'MarketingCardController.card_campaign_image' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| marketing_card | route-public-sudo | /cards/<model("card.card"):card>/preview — Endpoint 'MarketingCardController.card_campaign_preview' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| marketing_card | route-public-sudo | /cards/<model("card.card"):card>/redirect — Endpoint 'MarketingCardController.card_campaign_redirect' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| marketing_card | route-public-sudo | /cards/<model("card.card"):card>/share/linkedin — Endpoint 'MarketingCardLinkedinController.linkedin_share_start' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| marketing_card | route-public-sudo | MarketingCardLinkedinController.linkedin_share_callback — Endpoint 'MarketingCardLinkedinController.linkedin_share_callback' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing | route-public-csrf-off | /mailing/<int:mailing_id>/unsubscribe_oneclick — Public HTTP endpoint 'MassMailController.mailing_unsubscribe_oneclick' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| mass_mailing | route-public-sudo | /mailing/<int:mailing_id>/confirm_unsubscribe — Endpoint 'MassMailController.mailing_confirm_unsubscribe' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing | route-public-sudo | /mailing/list/update — Endpoint 'MassMailController.mailing_update_list_subscription' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing | route-public-sudo | /mailing/feedback — Endpoint 'MassMailController.mailing_send_feedback' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing | route-public-sudo | /mail/track/<int:mail_id>/<string:token>/blank.gif — Endpoint 'MassMailController.track_mail_open' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing | route-public-sudo | /r/<string:code>/m/<int:mailing_trace_id> — Endpoint 'MassMailController.full_url_redirect' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing | route-public-sudo | /mailing/report/unsubscribe — Endpoint 'MassMailController.mailing_report_deactivate' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing | route-public-sudo | /mailing/<int:mailing_id>/view — Endpoint 'MassMailController.mailing_view_in_browser' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing | route-public-sudo | /mailing/blocklist/add — Endpoint 'MassMailController.mail_blocklist_add' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing | route-public-sudo | /mailing/blocklist/remove — Endpoint 'MassMailController.mail_blocklist_remove' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing_sms | route-public-sudo | /sms/<int:mailing_id>/<string:trace_code> — Endpoint 'MailingSMSController.blacklist_page' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing_sms | route-public-sudo | /sms/<int:mailing_id>/unsubscribe/<string:trace_code> — Endpoint 'MailingSMSController.blacklist_number' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| mass_mailing_sms | route-public-sudo | /r/<string:code>/s/<int:sms_id_int> — Endpoint 'MailingSMSController.sms_short_link_redirect' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment | route-public-sudo | /payment/pay — Endpoint 'PaymentPortal.payment_pay' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment | route-public-sudo | /payment/confirmation — Endpoint 'PaymentPortal.payment_confirm' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_adyen | route-public-sudo | /payment/adyen/payment_methods — Endpoint 'AdyenController.adyen_payment_methods' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_adyen | route-public-sudo | /payment/adyen/payments — Endpoint 'AdyenController.adyen_payments' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_adyen | route-public-sudo | /payment/adyen/payments/details — Endpoint 'AdyenController.adyen_payment_details' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_adyen | route-public-csrf-off | /payment/adyen/return — Public HTTP endpoint 'AdyenController.adyen_return_from_3ds_auth' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_adyen | route-public-sudo | /payment/adyen/return — Endpoint 'AdyenController.adyen_return_from_3ds_auth' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_adyen | route-public-csrf-off | AdyenController.adyen_webhook — Public HTTP endpoint 'AdyenController.adyen_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_adyen | route-public-sudo | AdyenController.adyen_webhook — Endpoint 'AdyenController.adyen_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_aps | route-public-csrf-off | APSController.aps_return_from_checkout — Public HTTP endpoint 'APSController.aps_return_from_checkout' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_aps | route-public-sudo | APSController.aps_return_from_checkout — Endpoint 'APSController.aps_return_from_checkout' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_aps | route-public-csrf-off | APSController.aps_webhook — Public HTTP endpoint 'APSController.aps_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_aps | route-public-sudo | APSController.aps_webhook — Endpoint 'APSController.aps_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_asiapay | route-public-csrf-off | AsiaPayController.asiapay_webhook — Public HTTP endpoint 'AsiaPayController.asiapay_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_asiapay | route-public-sudo | AsiaPayController.asiapay_webhook — Endpoint 'AsiaPayController.asiapay_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_authorize | route-public-sudo | AuthorizeController.authorize_payment — Endpoint 'AuthorizeController.authorize_payment' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_authorize | route-public-csrf-off | AuthorizeController.authorize_webhook — Public HTTP endpoint 'AuthorizeController.authorize_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_authorize | route-public-sudo | AuthorizeController.authorize_webhook — Endpoint 'AuthorizeController.authorize_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_buckaroo | route-public-csrf-off | BuckarooController.buckaroo_return_from_checkout — Public HTTP endpoint 'BuckarooController.buckaroo_return_from_checkout' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_buckaroo | route-public-sudo | BuckarooController.buckaroo_return_from_checkout — Endpoint 'BuckarooController.buckaroo_return_from_checkout' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_buckaroo | route-public-csrf-off | BuckarooController.buckaroo_webhook — Public HTTP endpoint 'BuckarooController.buckaroo_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_buckaroo | route-public-sudo | BuckarooController.buckaroo_webhook — Endpoint 'BuckarooController.buckaroo_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_custom | route-public-csrf-off | CustomController.custom_process_transaction — Public HTTP endpoint 'CustomController.custom_process_transaction' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_custom | route-public-sudo | CustomController.custom_process_transaction — Endpoint 'CustomController.custom_process_transaction' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_demo | route-public-sudo | PaymentDemoController.demo_simulate_payment — Endpoint 'PaymentDemoController.demo_simulate_payment' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_ecpay | route-public-csrf-off | EcpayController.ecpay_return_from_checkout — Public HTTP endpoint 'EcpayController.ecpay_return_from_checkout' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_ecpay | route-public-sudo | EcpayController.ecpay_return_from_checkout — Endpoint 'EcpayController.ecpay_return_from_checkout' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_ecpay | route-public-csrf-off | EcpayController.ecpay_webhook — Public HTTP endpoint 'EcpayController.ecpay_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_ecpay | route-public-sudo | EcpayController.ecpay_webhook — Endpoint 'EcpayController.ecpay_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_flutterwave | route-public-csrf-off | FlutterwaveController.flutterwave_webhook — Public HTTP endpoint 'FlutterwaveController.flutterwave_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_flutterwave | route-public-sudo | FlutterwaveController.flutterwave_webhook — Endpoint 'FlutterwaveController.flutterwave_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_iyzico | route-public-csrf-off | IyzicoController.iyzico_return_from_payment — Public HTTP endpoint 'IyzicoController.iyzico_return_from_payment' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_iyzico | route-public-csrf-off | IyzicoController.iyzico_webhook — Public HTTP endpoint 'IyzicoController.iyzico_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_mercado_pago | route-public-sudo | /payment/mercado_pago/payments — Endpoint 'MercadoPagoPaymentController.mercado_pago_payment' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_mercado_pago | route-public-csrf-off | MercadoPagoPaymentController.mercado_pago_webhook — Public HTTP endpoint 'MercadoPagoPaymentController.mercado_pago_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_mollie | route-public-csrf-off | MollieController.mollie_return_from_checkout — Public HTTP endpoint 'MollieController.mollie_return_from_checkout' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_mollie | route-public-csrf-off | MollieController.mollie_webhook — Public HTTP endpoint 'MollieController.mollie_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_nuvei | route-public-sudo | NuveiController.nuvei_return_from_checkout — Endpoint 'NuveiController.nuvei_return_from_checkout' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_nuvei | route-public-csrf-off | NuveiController.nuvei_webhook — Public HTTP endpoint 'NuveiController.nuvei_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_nuvei | route-public-sudo | NuveiController.nuvei_webhook — Endpoint 'NuveiController.nuvei_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_paymob | route-public-sudo | PaymobController.paymob_return_from_checkout — Endpoint 'PaymobController.paymob_return_from_checkout' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_paymob | route-public-csrf-off | PaymobController.paymob_webhook — Public HTTP endpoint 'PaymobController.paymob_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_paymob | route-public-sudo | PaymobController.paymob_webhook — Endpoint 'PaymobController.paymob_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_paypal | route-public-sudo | PaypalController.paypal_complete_order — Endpoint 'PaypalController.paypal_complete_order' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_paypal | route-public-csrf-off | PaypalController.paypal_webhook — Public HTTP endpoint 'PaypalController.paypal_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_payu | route-public-csrf-off | PayuController.payu_return_from_checkout — Public HTTP endpoint 'PayuController.payu_return_from_checkout' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_payu | route-public-sudo | PayuController.payu_return_from_checkout — Endpoint 'PayuController.payu_return_from_checkout' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_payu | route-public-csrf-off | PayuController.payu_webhook — Public HTTP endpoint 'PayuController.payu_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_payu | route-public-sudo | PayuController.payu_webhook — Endpoint 'PayuController.payu_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_razorpay | route-public-csrf-off | RazorpayController.razorpay_return_from_checkout — Public HTTP endpoint 'RazorpayController.razorpay_return_from_checkout' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_razorpay | route-public-sudo | RazorpayController.razorpay_return_from_checkout — Endpoint 'RazorpayController.razorpay_return_from_checkout' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_razorpay | route-public-csrf-off | RazorpayController.razorpay_webhook — Public HTTP endpoint 'RazorpayController.razorpay_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_razorpay | route-public-sudo | RazorpayController.razorpay_webhook — Endpoint 'RazorpayController.razorpay_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_redsys | route-public-sudo | RedsysController.redsys_return_from_checkout — Endpoint 'RedsysController.redsys_return_from_checkout' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_redsys | route-public-csrf-off | RedsysController.redsys_webhook — Public HTTP endpoint 'RedsysController.redsys_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_redsys | route-public-sudo | RedsysController.redsys_webhook — Endpoint 'RedsysController.redsys_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_stripe | route-public-sudo | StripeController.stripe_return — Endpoint 'StripeController.stripe_return' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_stripe | route-public-sudo | /payment/stripe/client_secret — Endpoint 'StripeController.stripe_acss_client_secret_route' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_stripe | route-public-csrf-off | StripeController.stripe_webhook — Public HTTP endpoint 'StripeController.stripe_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_stripe | route-public-sudo | StripeController.stripe_webhook — Endpoint 'StripeController.stripe_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_stripe | route-public-csrf-off | StripeController.stripe_apple_pay_get_domain_association_file — Public HTTP endpoint 'StripeController.stripe_apple_pay_get_domain_association_file' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_toss_payments | route-public-sudo | TossPaymentsController._toss_payments_success_return — Endpoint 'TossPaymentsController._toss_payments_success_return' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_toss_payments | route-public-sudo | TossPaymentsController._toss_payments_failure_return — Endpoint 'TossPaymentsController._toss_payments_failure_return' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_toss_payments | route-public-csrf-off | TossPaymentsController._toss_payments_webhook — Public HTTP endpoint 'TossPaymentsController._toss_payments_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_toss_payments | route-public-sudo | TossPaymentsController._toss_payments_webhook — Endpoint 'TossPaymentsController._toss_payments_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_worldline | route-public-sudo | WorldlineController.worldline_return_from_checkout — Endpoint 'WorldlineController.worldline_return_from_checkout' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_worldline | route-public-csrf-off | WorldlineController.worldline_webhook — Public HTTP endpoint 'WorldlineController.worldline_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_worldline | route-public-sudo | WorldlineController.worldline_webhook — Endpoint 'WorldlineController.worldline_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_xendit | route-public-csrf-off | XenditController.xendit_webhook — Public HTTP endpoint 'XenditController.xendit_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| payment_xendit | route-public-sudo | XenditController.xendit_webhook — Endpoint 'XenditController.xendit_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| payment_xendit | route-public-sudo | XenditController.xendit_return — Endpoint 'XenditController.xendit_return' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| point_of_sale | route-public-sudo | /pos/ticket — Endpoint 'PosController.invoice_request_screen' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| point_of_sale | route-public-sudo | /pos/ticket/validate — Endpoint 'PosController.show_ticket_validation_screen' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| point_of_sale | route-public-sudo | /pos_customer_display/<id_>/<identifier> — Endpoint 'PosCustomerDisplay.pos_customer_display' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| point_of_sale | route-public-sudo | /pos_customer_display/register-device — Endpoint 'PosCustomerDisplay.register_device' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| portal | route-public-sudo | /my/address/country_info/<model("res.country"):country> — Endpoint 'CustomerPortal.portal_address_country_info' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| portal | route-public-sudo | /my/address/state_info/ — Endpoint 'CustomerPortal.portal_address_state_info' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_adyen | route-public-sudo | /pos_adyen/notification — Endpoint 'PosAdyenController.notification' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_bancontact_pay | route-public-csrf-off | /bancontact_pay/webhook — Public HTTP endpoint 'BancontactPayController.bancontact_pay_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| pos_mercado_pago | route-public-csrf-off | /pos_mercado_pago/notification — Public HTTP endpoint 'PosMercadoPagoWebhook.notification' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| pos_mercado_pago | route-public-sudo | /pos_mercado_pago/notification — Endpoint 'PosMercadoPagoWebhook.notification' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_mollie | route-public-csrf-off | /pos_mollie/webhook — Public HTTP endpoint 'PosMollie.mollie_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| pos_mollie | route-public-sudo | /pos_mollie/webhook — Endpoint 'PosMollie.mollie_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_online_payment | route-public-sudo | /pos/pay/<int:pos_order_id> — Endpoint 'PaymentPortal.pos_order_pay' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_online_payment | route-public-sudo | /pos/pay/transaction/<int:pos_order_id> — Endpoint 'PaymentPortal.pos_order_pay_transaction' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_online_payment | route-public-sudo | /pos/pay/confirmation/<int:pos_order_id> — Endpoint 'PaymentPortal.pos_order_pay_confirmation' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_qfpay | route-public-csrf-off | /qfpay/notify — Public HTTP endpoint 'QFPayNotificationController.qfpay_notify' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| pos_qfpay | route-public-sudo | /qfpay/notify — Endpoint 'QFPayNotificationController.qfpay_notify' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_safaricom | route-public-csrf-off | /pos_safaricom/callback — Public HTTP endpoint 'SafaricomController.safaricom_callback' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| pos_safaricom | route-public-sudo | /pos_safaricom/callback — Endpoint 'SafaricomController.safaricom_callback' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_safaricom | route-public-csrf-off | /c2b/validation/callback — Public HTTP endpoint 'SafaricomController.c2b_validation_callback' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| pos_safaricom | route-public-sudo | /c2b/validation/callback — Endpoint 'SafaricomController.c2b_validation_callback' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_safaricom | route-public-csrf-off | /c2b/confirmation/callback — Public HTTP endpoint 'SafaricomController.c2b_confirmation_callback' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| pos_safaricom | route-public-sudo | /c2b/confirmation/callback — Endpoint 'SafaricomController.c2b_confirmation_callback' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_self_order | route-public-sudo | /pos-self-order/process-order/<device_type>/ — Endpoint 'PosSelfOrderController.process_order' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_self_order | route-public-sudo | /pos-self-order/validate-partner — Endpoint 'PosSelfOrderController.validate_partner' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_self_order | route-public-sudo | /pos-self-order/receipt/<int:order_id> — Endpoint 'PosSelfOrderController.pos_self_order_receipt' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_self_order | route-public-sudo | /pos-self/autocomplete/address — Endpoint 'PosSelfOrderController.pos_self_order_autocomplete_address' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_self_order | route-public-sudo | /pos-self/autocomplete/address_full — Endpoint 'PosSelfOrderController.pos_self_order_autocomplete_address_full' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_self_order_bancontact_pay | route-public-sudo | /pos-self-order/create-bancontact-pay-payment — Endpoint 'PosSelfOrderControllerBancontactPay.bancontact_pay_create_payment_from_kiosk' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_viva_com | route-public-csrf-off | /pos_viva_com/notification — Public HTTP endpoint 'PosVivaComController.notification' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| pos_viva_com | route-public-sudo | /pos_viva_com/notification — Endpoint 'PosVivaComController.notification' (auth="none") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| pos_viva_com | route-public-sudo | /pos_viva_com/<int:config_id>/payment/<string:order_uuid> — Endpoint 'PosVivaComController.viva_payment_callback' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| project | route-public-sudo | /my/projects/<int:project_id>/task/<int:task_id> — Endpoint 'ProjectCustomerPortal.portal_my_project_task' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. _document_check_access is present, but its coverage is not verified. · |
| rpc | route-public-csrf-off | /xmlrpc/<service> — Public HTTP endpoint 'XMLRPC.xmlrpc_1' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| rpc | route-public-csrf-off | /xmlrpc/2/<service> — Public HTTP endpoint 'XMLRPC.xmlrpc_2' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| sale | route-public-sudo | /my/orders/<int:order_id>/accept — Endpoint 'CustomerPortal.portal_quote_accept' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. _document_check_access is present, but its coverage is not verified. · |
| sale | route-public-sudo | /my/orders/<int:order_id>/document/<int:document_id> — Endpoint 'CustomerPortal.portal_quote_document' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. _document_check_access is present, but its coverage is not verified. · |
| sale_gelato | route-public-csrf-off | GelatoController.gelato_webhook — Public HTTP endpoint 'GelatoController.gelato_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| sale_gelato | route-public-sudo | GelatoController.gelato_webhook — Endpoint 'GelatoController.gelato_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| sale_loyalty | route-public-sudo | /gift_card/send — Endpoint 'GiftCard.send_gift_card' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| sale_management | route-public-sudo | /my/orders/<int:order_id>/update_line_dict — Endpoint 'CustomerPortal.portal_quote_option_update' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. _document_check_access is present, but its coverage is not verified. · |
| sale_stock | route-public-sudo | /my/orders/<int:order_id>/download_return_label — Endpoint 'CustomerPortal.order_return_label' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. _document_check_access is present, but its coverage is not verified. · |
| sale_stock | route-public-sudo | /my/picking/pdf/<int:picking_id> — Endpoint 'CustomerPortal.portal_my_picking_report' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| sms | route-public-sudo | /sms/status — Endpoint 'SmsController.update_sms_status' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| sms_twilio | route-public-csrf-off | /sms_twilio/status/<string:uuid> — Public HTTP endpoint 'SmsTwilioController.update_sms_status' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| sms_twilio | route-public-sudo | /sms_twilio/status/<string:uuid> — Endpoint 'SmsTwilioController.update_sms_status' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| snailmail | route-public-csrf-off | /webhook/snailmail/1/<string:event_type> — Public HTTP endpoint 'SnailmailWebhookController.snailmail_webhook' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| snailmail | route-public-sudo | /webhook/snailmail/1/<string:event_type> — Endpoint 'SnailmailWebhookController.snailmail_webhook' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| survey | route-public-sudo | /survey/start/<string:survey_token> — Endpoint 'Survey.survey_start' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| survey | route-public-sudo | /survey/get_question_image/<string:survey_token>/<string:answer_token>/<int:question_id>/<int:suggested_answer_id> — Endpoint 'Survey.survey_get_question_image' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| survey | route-public-sudo | /survey/submit/<string:survey_token>/<string:answer_token> — Endpoint 'Survey.survey_submit' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| test_http | route-public-csrf-off | /test_http/echo-http-post — Public HTTP endpoint 'TestHttp.echo_http_post' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| test_http | route-public-csrf-off | /test_http/echo-json-over-http — Public HTTP endpoint 'TestHttp.echo_json_over_http' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| test_http | route-public-csrf-off | /test_http/upload_file — Public HTTP endpoint 'TestHttp.upload_file_retry' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| test_website | route-public-sudo | /test_website/model_item_sudo/<int:record_id> — Endpoint 'WebsiteTest.test_model_item_sudo' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| web | route-public-csrf-off | /web/database/create — Public HTTP endpoint 'Database.create' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| web | route-public-csrf-off | /web/database/duplicate — Public HTTP endpoint 'Database.duplicate' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| web | route-public-csrf-off | /web/database/drop — Public HTTP endpoint 'Database.drop' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| web | route-public-csrf-off | /web/database/rename — Public HTTP endpoint 'Database.rename' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| web | route-public-csrf-off | /web/database/backup — Public HTTP endpoint 'Database.backup' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| web | route-public-csrf-off | /web/database/restore — Public HTTP endpoint 'Database.restore' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| web | route-public-csrf-off | /web/database/change_password — Public HTTP endpoint 'Database.change_password' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| web | route-public-sudo | /web/assets/<string:unique>/<string:filename> — Endpoint 'Binary.content_assets' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| web | route-public-sudo | /web/image, /web/image/<string:xmlid>, /web/image/<string:xmlid>/<string:filename>, /web/image/<string:xmlid>/<int:width>x<int:height>, /web/image/<string:xmlid>/<int:width>x<int:height>/<string:filename>, /web/image/<string:model>/<int:id>/<string:field>, /web/image/<string:model>/<int:id>/<string:field>/<string:filename>, /web/image/<string:model>/<int:id>/<string:field>/<int:width>x<int:height>, /web/image/<string:model>/<int:id>/<string:field>/<int:width>x<int:height>/<string:filename>, /web/image/<int:id>, /web/image/<int:id>/<string:filename>, /web/image/<int:id>/<int:width>x<int:height>, /web/image/<int:id>/<int:width>x<int:height>/<string:filename>, /web/image/<int:id>-<string:unique>, /web/image/<int:id>-<string:unique>/<string:filename>, /web/image/<int:id>-<string:unique>/<int:width>x<int:height>, /web/image/<int:id>-<string:unique>/<int:width>x<int:height>/<string:filename> — Endpoint 'Binary.content_image' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| web | route-public-sudo | /web/webclient/translations — Endpoint 'WebClient.translations' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website | route-public-sudo | /website/odoo_track — Endpoint 'Website.track' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website | route-public-sudo | /sitemap.xml — Endpoint 'Website.sitemap_xml_index' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website | route-public-sudo | /website/info — Endpoint 'Website.website_info' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website | route-public-sudo | /website/cookie-policy — Endpoint 'Website.cookie_policy_redirect' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website | route-public-sudo | /website/snippet/filters — Endpoint 'Website.get_dynamic_filter' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website | route-public-sudo | /website/snippet/filter_templates — Endpoint 'Website.get_dynamic_snippet_templates' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website | route-public-sudo | /google<string(length=16):key>.html — Endpoint 'Website.google_console_search' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website | route-public-sudo | /website/action/<path_or_xml_id_or_id>, /website/action/<path_or_xml_id_or_id>/<path:path> — Endpoint 'Website.actions_server' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website | route-public-sudo | /model/<string:page_name_slugified>, /model/<string:page_name_slugified>/page/<int:page_number>, /model/<string:page_name_slugified>/<string:record_slug> — Endpoint 'ModelPageController.generic_model' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website | route-public-csrf-off | /website/form/<string:model_name> — Public HTTP endpoint 'WebsiteForm.website_form' disables CSRF protection (fine for webhooks/callbacks, worth a review otherwise) · |
| website_blog | route-public-sudo | /blog/<model("blog.blog"):blog>/<model("blog.post", "[('blog_id','=',blog.id)]"):blog_post> — Endpoint 'WebsiteBlog.blog_post' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_customer | route-public-sudo | /customers, /customers/page/<int:page>, /customers/country/<model("res.country"):country>, /customers/country/<model("res.country"):country>/page/<int:page>, /customers/industry/<model("res.partner.industry"):industry>, /customers/industry/<model("res.partner.industry"):industry>/page/<int:page>, /customers/industry/<model("res.partner.industry"):industry>/country/<model("res.country"):country>, /customers/industry/<model("res.partner.industry"):industry>/country/<model("res.country"):country>/page/<int:page> — Endpoint 'WebsiteCustomer.customers' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_customer | route-public-sudo | /customers/<partner_id> — Endpoint 'WebsiteCustomer.customers_detail' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event | route-public-sudo | WebsiteEventController.events — Endpoint 'WebsiteEventController.events' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event | route-public-sudo | /event/<model("event.event"):event>/page/<path:page> — Endpoint 'WebsiteEventController.event_page' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event | route-public-sudo | /event/<model("event.event"):event>/registration/success — Endpoint 'WebsiteEventController.event_registration_success' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event_booth | route-public-sudo | /event/booth/check_availability — Endpoint 'WebsiteEventBoothController.check_booths_availability' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event_booth | route-public-sudo | /event/booth_category/get_available_booths — Endpoint 'WebsiteEventBoothController.get_booth_category_available_booths' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event_exhibitor | route-public-sudo | /event/<model("event.event", "[('exhibitor_menu', '=', True)]"):event>/exhibitor/<model("event.sponsor", "[('event_id', '=', event.id)]"):sponsor> — Endpoint 'ExhibitorController.event_exhibitor' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event_exhibitor | route-public-sudo | /event_sponsor/<int:sponsor_id>/read — Endpoint 'ExhibitorController.event_sponsor_read' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event_track | route-public-sudo | /event/<model("event.event", "[('website_track', '=', True)]"):event>/track/<model("event.track", "[('event_id', '=', event.id)]"):track> — Endpoint 'EventTrackController.event_track_page' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event_track | route-public-sudo | /event/track/send_email_reminder — Endpoint 'EventTrackController.send_email_reminder' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event_track | route-public-sudo | /event/<model("event.event"):event>/track_proposal/post — Endpoint 'EventTrackController.event_track_proposal_post' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event_track_live | route-public-sudo | /event_track/get_track_suggestion — Endpoint 'EventTrackLiveController.get_next_track_suggestion' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event_track_quiz | route-public-sudo | /event_track/quiz/submit — Endpoint 'WebsiteEventTrackQuiz.event_track_quiz_submit' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_event_track_quiz | route-public-sudo | /event_track/quiz/reset — Endpoint 'WebsiteEventTrackQuiz.quiz_reset' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_forum | route-public-sudo | /forum/<model("forum.forum"):forum>/partner/<int:partner_id> — Endpoint 'WebsiteForum.open_partner' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_google_map | route-public-sudo | /google_map — Endpoint 'GoogleMap.google_map' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_hr_recruitment | route-public-sudo | /jobs, /jobs/page/<int:page> — Endpoint 'WebsiteHrRecruitment.jobs' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_mail | route-public-sudo | /website_mail/follow — Endpoint 'WebsiteMail.website_message_subscribe' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_mail | route-public-sudo | /website_mail/is_follower — Endpoint 'WebsiteMail.is_follower' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_mail_group | route-public-sudo | /group/is_member — Endpoint 'WebsiteMailGroup.group_is_member' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_mass_mailing | route-public-sudo | /website_mass_mailing/is_subscriber — Endpoint 'MassMailController.is_subscriber' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_partner | route-public-sudo | /partners/<partner_id> — Endpoint 'WebsitePartnerPage.partners_detail' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_payment | route-public-sudo | /website_payment/snippet/supported_payment_methods — Endpoint 'PaymentPortal.get_supported_payment_methods' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_profile | route-public-sudo | /profile/avatar/<int:user_id> — Endpoint 'WebsiteProfile.get_user_profile_avatar' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_profile | route-public-sudo | /profile/users, /profile/users/page/<int:page> — Endpoint 'WebsiteProfile.view_all_users_page' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_profile | route-public-sudo | /profile/validate_email — Endpoint 'WebsiteProfile.validate_email' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | WebsiteSale.shop — Endpoint 'WebsiteSale.shop' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/<model("product.template"):product_template>/document/<int:document_id> — Endpoint 'WebsiteSale.product_document' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/product/is_add_to_cart_allowed — Endpoint 'WebsiteSale.is_add_to_cart_allowed' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/pricelist — Endpoint 'WebsiteSale.pricelist' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/update_address — Endpoint 'WebsiteSale.shop_update_address' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/payment/validate — Endpoint 'WebsiteSale.shop_payment_validate' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/confirmation — Endpoint 'WebsiteSale.shop_payment_confirmation' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/print — Endpoint 'WebsiteSale.print_saleorder' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/print/invoice — Endpoint 'WebsiteSale.print_invoice' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/products/recently_viewed_delete — Endpoint 'WebsiteSale.products_recently_viewed_delete' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/donation/info — Endpoint 'WebsiteSaleDonation.donation_info' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/set_delivery_method — Endpoint 'Delivery.shop_set_delivery_method' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/get_delivery_rate — Endpoint 'Delivery.shop_get_delivery_rate' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/wishlist/add — Endpoint 'ProductWishlist.add_to_wishlist' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/wishlist/remove/<int:wish_id> — Endpoint 'ProductWishlist.remove_from_wishlist' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /shop/add/stock_notification — Endpoint 'ProductWishlist.add_stock_email_notification' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | Cart.cart — Endpoint 'Cart.cart' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | Cart.add_to_cart — Endpoint 'Cart.add_to_cart' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /website/form/shop.sale.order — Endpoint 'WebsiteSaleForm.website_form_saleorder' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale | route-public-sudo | /my/orders/reorder — Endpoint 'CustomerPortal.my_orders_reorder' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. _document_check_access is present, but its coverage is not verified. · |
| website_sale_collect | route-public-sudo | /shop/set_click_and_collect_location — Endpoint 'InStoreDelivery.shop_set_click_and_collect_location' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale_loyalty | route-public-sudo | /shop/claimreward — Endpoint 'WebsiteSale.claim_reward' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_sale_stock | route-public-sudo | /website_sale_stock/get_pickup_locations — Endpoint 'LocationSelector.website_sale_get_pickup_locations' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_slides | route-public-sudo | /slides/<int:channel_id>, /slides/<int:channel_id>/category/<int:category_id>, /slides/<int:channel_id>/category/<int:category_id>/page/<int:page>, /slides/<model("slide.channel"):channel>, /slides/<model("slide.channel"):channel>/page/<int:page>, /slides/<model("slide.channel"):channel>/tag/<model("slide.tag"):tag>, /slides/<model("slide.channel"):channel>/tag/<model("slide.tag"):tag>/page/<int:page>, /slides/<model("slide.channel"):channel>/category/<model("slide.slide"):category>, /slides/<model("slide.channel"):channel>/category/<model("slide.slide"):category>/page/<int:page> — Endpoint 'WebsiteSlides.channel' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_slides | route-public-sudo | /slides/channel/join — Endpoint 'WebsiteSlides.slide_channel_join' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_slides | route-public-sudo | /slides/slide/<model("slide.slide"):slide> — Endpoint 'WebsiteSlides.slide_view' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_slides | route-public-sudo | /slides/slide/like — Endpoint 'WebsiteSlides.slide_like' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
| website_slides | route-public-sudo | /slides/slide/quiz/submit — Endpoint 'WebsiteSlides.slide_quiz_submit' (auth="public") calls .sudo(). Check authorization before each privileged operation and validate user-controlled record IDs. · |
Migration Considerations
Found by automated static analysis: patterns worth a look before/after upgrading a module to a newer Odoo version, not a guarantee.
Warnings 0
No findings that likely need a code change.
Info 59
| Module | Code | Message |
|---|---|---|
| account | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `update ir_model_data set noupdate = TRUE where id in %s` - re-check the table/column names still match after upgrading. · |
| account | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_attachment SET res_id = NULL WHERE id IN %s` - re-check the table/column names still match after upgrading. · |
| account | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE res_partner SET invoice_edi_format_store = invoice_edi_format_store - res_company.id::char FROM res_company WHERE res_partner.invoice_edi_format_store ->> res_company.id::char IN %s` - re-check the table/column names still match after upgrading. · |
| account_peppol | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_attachment SET res_id = NULL WHERE id IN %s` - re-check the table/column names still match after upgrading. · |
| account_update_tax_tags | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `-- 1.a) Handle base line: relation aml <-> tag, if no relation, tag is NULL WITH base_aml_id_rep_tag_to_insert AS ( SELECT aml.id AS aml_id, rep_tags.account_account_tag_id AS tag_id FROM account_move_line aml JOIN account_move move ON aml.move_id = move.id AND move.company_id = %(company_id)s AND aml.date >= %(date_from)s LEFT JOIN account_move caba_origin_move ON move.tax_cash_basis_origin_move_id = caba_origin_move.id JOIN account_move_line_account_tax_rel aml_to_tax ON aml_to_tax.account_move_line_id = aml.id -- Handle possible children_tax_ids LEFT JOIN account_tax_filiation_rel taxes_filiation ON taxes_filiation.parent_tax = aml_to_tax.account_tax_id JOIN account_tax tax ON tax.id = COALESCE(taxes_filiation.child_tax, aml_to_tax.account_tax_id) JOIN account_tax parent_tax ON aml_to_tax.account_tax_id = parent_tax.id JOIN account_tax_repartition_line tax_to_rep_line -- the repartition line to join depends of the move_type -- also, as this is the base line query, we only join for the base repartition type ON tax_to_rep_line.repartition_type = 'base' AND ( -- invoice type doc ( COALESCE(caba_origin_move.move_type, move.move_type) IN ('in_invoice','out_invoice', 'in_receipt', 'out_receipt') AND tax_to_rep_line.document_type = 'invoice' AND tax_to_rep_line.tax_id = tax.id ) OR -- refund type doc ( COALESCE(caba_origin_move.move_type, move.move_type) IN ('in_refund','out_refund') AND tax_to_rep_line.document_type = 'refund' AND tax_to_rep_line.tax_id = tax.id ) OR -- entry type doc: depends on the tax type -- for base line: -- balance < 0 and sale tax --> invoice -- balance > 0 and sale tax --> refund -- balance > 0 and purchase tax --> invoice -- balance < 0 and purchase tax --> refund -- impossible to decide for balance at 0 --> invoice by default ( COALESCE(caba_origin_move.move_type, move.move_type) = 'entry' AND ( ( COALESCE(parent_tax.type_tax_use, tax.type_tax_use) = 'sale' AND ( aml.balance <= 0 AND tax_to_rep_line.document_type = 'invoice' AND tax_to_rep_line.tax_id = tax.id OR aml.balance > 0 AND tax_to_rep_line.document_type = 'refund' AND tax_to_rep_line.tax_id = tax.id ) ) OR ( COALESCE(parent_tax.type_tax_use, tax.type_tax_use) = 'purchase' AND ( aml.balance >= 0 AND tax_to_rep_line.document_type = 'invoice' AND tax_to_rep_line.tax_id = tax.id OR aml.balance < 0 AND tax_to_rep_line.document_type = 'refund' AND tax_to_rep_line.tax_id = tax.id ) ) ) ) ...` - re-check the table/column names still match after upgrading. · |
| auth_ldap | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE res_users SET password=NULL WHERE id=%s` - re-check the table/column names still match after upgrading. · |
| auth_totp | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE res_users SET totp_secret = %s WHERE id=%s` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE res_partner SET parent_id = NULL WHERE parent_id = id` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `INSERT INTO ir_model_fields_group_rel(field_id, group_id) SELECT * FROM UNNEST(%s, %s)` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `DELETE FROM ir_model_fields_group_rel rel WHERE EXISTS ( SELECT FROM UNNEST(%s, %s) AS rm(field_id, group_id) WHERE rm.field_id = rel.field_id AND rm.group_id = rel.group_id )` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_cron SET failure_count = %s, first_failure_date = %s, active = %s WHERE id = %s` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `DELETE FROM ir_cron_trigger WHERE cron_id = %s AND call_at <= %s` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_cron SET nextcall = %s, lastcall = %s WHERE id = %s` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `INSERT INTO ir_cron_trigger(call_at, cron_id) VALUES (%s, %s)` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_cron_progress SET timed_out_counter = 0 WHERE id = %s` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `DELETE FROM res_users_log log1 WHERE EXISTS ( SELECT 1 FROM res_users_log log2 WHERE log1.create_uid = log2.create_uid AND log1.create_date < log2.create_date )` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE res_users SET password=%s WHERE id=%s` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `WITH _share AS ( SELECT u.id, any_value(r.gid) is null as share FROM res_users u LEFT JOIN res_groups_users_rel r ON r.uid = u.id AND r.gid = ANY(%s) GROUP BY u.id ) UPDATE res_users u SET share = s.share FROM _share s WHERE s.id = u.id AND s.share IS DISTINCT FROM u.share` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `WITH _share AS ( SELECT p.id, any_value(u.id) IS NULL as partner_share FROM res_partner p LEFT JOIN res_users u ON u.partner_id = p.id AND u.share IS NOT TRUE GROUP BY p.id ) UPDATE res_partner p SET partner_share = s.partner_share FROM _share s WHERE s.id = p.id AND s.partner_share IS DISTINCT FROM p.partner_share` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `SELECT FROM ir_cron FOR UPDATE` - re-check the table/column names still match after upgrading. · |
| base | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `INSERT INTO ir_logging(create_date, create_uid, type, dbname, name, level, message, path, line, func) VALUES (NOW() at time zone 'UTC', %s, %s, %s, %s, %s, %s, %s, %s, %s)` - re-check the table/column names still match after upgrading. · |
| bus | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `DELETE FROM bus_bus WHERE create_date < %s` - re-check the table/column names still match after upgrading. · |
| cloud_storage_migration | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_config_parameter SET value = %s WHERE key = 'cloud_storage_migration_min_attachment_id'` - re-check the table/column names still match after upgrading. · |
| fs_attachment | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `SELECT id FROM ir_attachment WHERE id = %s FOR UPDATE NOWAIT` - re-check the table/column names still match after upgrading. · |
| fs_attachment | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `DELETE FROM fs_file_gc WHERE fs_storage_code IN %s` - re-check the table/column names still match after upgrading. · |
| fs_attachment | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `INSERT INTO fs_file_gc ( store_fname, fs_storage_code, create_date, write_date, create_uid, write_uid ) VALUES ( %s, %s, now() at time zone 'UTC', now() at time zone 'UTC', %s, %s ) ON CONFLICT DO NOTHING` - re-check the table/column names still match after upgrading. · |
| fs_storage | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE fs_storage SET server_env_defaults = (('{"x_check_connection_method_env_default": "' || check_connection_method || '"}')::jsonb || server_env_defaults::jsonb)::text ;` - re-check the table/column names still match after upgrading. · |
| google_calendar | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE calendar_user SET google_sync_enabled = TRUE WHERE is_primary = TRUE` - re-check the table/column names still match after upgrading. · |
| hr_holidays | migration-sql-view | hr.leave.employee.type.report — Model 'hr.leave.employee.type.report' has `_auto = False` and its init() (re)creates a SQL VIEW: the standard reporting-model pattern, but its raw SQL isn't checked by the ORM - verify it against renamed/removed tables and columns in the target version. |
| hr_holidays | migration-sql-view | hr.leave.report — Model 'hr.leave.report' has `_auto = False` and its init() (re)creates a SQL VIEW: the standard reporting-model pattern, but its raw SQL isn't checked by the ORM - verify it against renamed/removed tables and columns in the target version. |
| hr_holidays | migration-sql-view | hr.leave.report.calendar — Model 'hr.leave.report.calendar' has `_auto = False` and its init() (re)creates a SQL VIEW: the standard reporting-model pattern, but its raw SQL isn't checked by the ORM - verify it against renamed/removed tables and columns in the target version. |
| hr_holidays | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_rule r SET domain_force = '["|", ("employee_id", "=", False), ("employee_id.company_id", "in", company_ids)]' FROM ir_model_data d WHERE d.res_id = r.id AND d.model = 'ir.rule' AND d.module = 'hr_holidays' AND d.name = 'hr_leave_allocation_rule_multicompany'` - re-check the table/column names still match after upgrading. · |
| hr_timesheet_attendance | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_rule r SET domain_force = '[(1, "=", 1)]' FROM ir_model_data d WHERE d.res_id = r.id AND d.model = 'ir.rule' AND d.module = 'hr_timesheet_attendance' AND d.name = 'hr_timesheet_attendance_report_rule_approver'` - re-check the table/column names still match after upgrading. · |
| l10n_es | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE account_account_tag_account_tax_repartition_line_rel tax_rep_tag SET account_account_tag_id = %s FROM account_account_tag new_tag, account_tax_repartition_line repln WHERE tax_rep_tag.account_account_tag_id = %s AND repln.id = tax_rep_tag.account_tax_repartition_line_id AND COALESCE(repln.invoice_tax_id, repln.refund_tax_id) IN %s` - re-check the table/column names still match after upgrading. · |
| l10n_es | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE account_account_tag_account_move_line_rel aml_tag SET account_account_tag_id = %s FROM account_move_line aml, account_move_line_account_tax_rel aml_tax WHERE aml_tag.account_move_line_id = aml.id AND aml_tax.account_move_line_id = aml.id AND aml.date >= '2021-07-01' AND aml_tax.account_tax_id IN %s AND aml_tag.account_account_tag_id = %s` - re-check the table/column names still match after upgrading. · |
| l10n_es | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE account_move_line aml SET tax_audit = REPLACE(tax_audit, %s, %s) FROM account_account_tag_account_move_line_rel aml_tag WHERE aml_tag.account_move_line_id = aml.id AND aml_tag.account_account_tag_id = %s` - re-check the table/column names still match after upgrading. · |
| l10n_eu_oss | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `DELETE FROM ir_model_data WHERE module = 'l10n_eu_oss' and model in ('account.tax.group', 'account.account');` - re-check the table/column names still match after upgrading. · |
| migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE mail_canned_response SET last_used=%(last_used)s WHERE id IN ( SELECT id from mail_canned_response WHERE id IN %(ids)s FOR NO KEY UPDATE SKIP LOCKED )` - re-check the table/column names still match after upgrading. · | |
| migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE mail_message SET pinned_at=%(pinned_at)s WHERE id=%(id)s` - re-check the table/column names still match after upgrading. · | |
| mrp | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE stock_move SET unit_factor = 1 WHERE unit_factor IS NULL` - re-check the table/column names still match after upgrading. · |
| pos_online_payment | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `SELECT id FROM pos_order WHERE id = %s FOR UPDATE` - re-check the table/column names still match after upgrading. · |
| project | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_model_access a SET perm_read = true FROM ir_model_data d WHERE d.res_id = a.id AND d.model = 'ir.model.access' AND d.module = 'project' AND d.name = 'access_project_milestone_portal'` - re-check the table/column names still match after upgrading. · |
| project_sms | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_rule r SET domain_force = '[(''model'', ''in'', (''project.task'', ''project.project''))]' FROM ir_model_data d WHERE d.res_id = r.id AND r.domain_force = '[(''model_id.model'', ''in'', (''project.task.type'', ''project.project.stage''))]' AND d.model = 'ir.rule' AND d.module = 'project_sms' AND d.name = 'ir_rule_sms_template_project_manager'` - re-check the table/column names still match after upgrading. · |
| purchase_stock | migration-sql-view | vendor.delay.report — Model 'vendor.delay.report' has `_auto = False` and its init() (re)creates a SQL VIEW: the standard reporting-model pattern, but its raw SQL isn't checked by the ORM - verify it against renamed/removed tables and columns in the target version. |
| queue_job | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `DROP TRIGGER IF EXISTS queue_job_notify ON queue_job; CREATE OR REPLACE FUNCTION queue_job_notify() RETURNS trigger AS $$ BEGIN IF TG_OP = 'DELETE' THEN IF OLD.state != 'done' THEN PERFORM pg_notify('queue_job', OLD.uuid); END IF; ELSE PERFORM pg_notify('queue_job', NEW.uuid); END IF; RETURN NULL; END; $$ LANGUAGE plpgsql; CREATE TRIGGER queue_job_notify AFTER INSERT OR UPDATE OR DELETE ON queue_job FOR EACH ROW EXECUTE PROCEDURE queue_job_notify();` - re-check the table/column names still match after upgrading. · |
| queue_job | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `INSERT INTO queue_job_lock (id, queue_job_id) SELECT id, id FROM queue_job WHERE uuid = %s ON CONFLICT(id) DO NOTHING;` - re-check the table/column names still match after upgrading. · |
| queue_job | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `SELECT * FROM queue_job_lock WHERE queue_job_id in ( SELECT id FROM queue_job WHERE uuid = %s AND state = %s ) FOR NO KEY UPDATE SKIP LOCKED;` - re-check the table/column names still match after upgrading. · |
| queue_job | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE queue_job SET state=%s, date_enqueued=date_trunc('seconds', now() at time zone 'utc') WHERE uuid=%s` - re-check the table/column names still match after upgrading. · |
| queue_job | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `SELECT uuid FROM queue_job WHERE uuid=%s AND state=%s FOR NO KEY UPDATE SKIP LOCKED` - re-check the table/column names still match after upgrading. · |
| queue_job_cron_jobrunner | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `SELECT id FROM queue_job WHERE state = 'pending' AND (eta IS NULL OR eta <= (now() AT TIME ZONE 'UTC')) ORDER BY priority, date_created LIMIT 1 FOR NO KEY UPDATE SKIP LOCKED` - re-check the table/column names still match after upgrading. · |
| resource | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `SELECT id FROM resource_calendar WHERE id IN %s ORDER BY id FOR NO KEY UPDATE` - re-check the table/column names still match after upgrading. · |
| rest_log | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `INSERT INTO rest_log ( request_url, request_method, params, headers, result, error, exception_name, exception_message, state, severity, create_uid, create_date, write_uid, write_date ) SELECT request_url, request_method, params, headers, result, error, exception_name, exception_message, state, severity, create_uid, create_date, write_uid, write_date FROM shopfloor_log;` - re-check the table/column names still match after upgrading. · |
| rest_log | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `DELETE FROM shopfloor_log` - re-check the table/column names still match after upgrading. · |
| sale_service | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE sale_order_line line SET is_service = (pt.type = 'service') FROM product_product pp LEFT JOIN product_template pt ON pt.id = pp.product_tmpl_id WHERE pp.id = line.product_id AND is_service IS NULL` - re-check the table/column names still match after upgrading. · |
| stock_delivery | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE stock_move move SET weight = move.product_qty * product.weight FROM product_product product WHERE move.product_id = product.id AND move.state != 'cancel'` - re-check the table/column names still match after upgrading. · |
| website | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE website SET default_lang_id=%s` - re-check the table/column names still match after upgrading. · |
| website | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_model_fields SET website_form_blacklisted=true WHERE website_form_blacklisted IS NULL` - re-check the table/column names still match after upgrading. · |
| website | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE ir_model_fields SET website_form_blacklisted=false WHERE model=%s AND name in %s` - re-check the table/column names still match after upgrading. · |
| website | migration-raw-sql-write | Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE website_visitor SET access_token = partner_id WHERE partner_id::int != access_token::int AND partner_id = %s;` - re-check the table/column names still match after upgrading. · |
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…