Tuesday, September 1, 2026
1 change · 18.0
Resolved issues and error corrections
This fix prevents website pages from failing when a visitor's cookie consent data is malformed or empty. Instead of showing a server error across the site, Odoo clears the invalid cookie and lets the visitor choose cookie preferences again.
Original PR description
Steps to reproduce: =================== 1. Enable the cookies bar on a website. 2. Set a malformed `website_cookies_bar` cookie in the browser (e.g. an empty value). 3. Open any frontend page. =>…
Steps to reproduce:
===================
1. Enable the cookies bar on a website.
2. Set a malformed `website_cookies_bar` cookie in the browser (e.g. an empty value).
3. Open any frontend page.
=> Every frontend page returns a bare 500; the error page cannot
render either, since it goes through the same code path.
Root cause:
===========
`_is_allowed_cookie('optional')` parses the `website_cookies_bar` cookie with `json_scriptsafe.loads` without guarding against invalid JSON. An empty or unparsable value raises `JSONDecodeError`.
The unguarded `loads` has existed since 16.0, but it was only reached in a few situational spots, so a bad cookie was harmless. It became reachable on every page render when [1] added an unconditional `_is_allowed_cookie('optional')` call to
`IrQWeb._prepare_frontend_environment` (run for every frontend QWeb render) and put its result in `_get_template_cache_keys`, so the value must be computed on every render. This is why 17.0 is unaffected and 18.0+ crash.
Fix:
====
Wrap the `loads` in a try/except on `ValueError` (superclass of `JSONDecodeError`) and fall back to `None`. A `None`/non-dict value already flows into the existing pre-16.0 compatibility branch, which resets the cookie (`max_age=0`) and lets the visitor choose again.
[1]: https://github.com/odoo/odoo/commit/958b41c4acec7e1700ca4d6e0b25ee0ad2aac9f1
opw-6380116
---
I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr