Tuesday, September 1, 2026
2 changes · saas-19.1
Security fixes and vulnerability patches
Customer invoice pages no longer show the salesperson's city or phone number, matching what customers already see on sales orders. This reduces exposure of personal employee information while keeping portal views consistent.
Original PR description
This change aligns the salesperson's information shown to customers on the invoice view with those shown on the sales order view. Now city and phone number are not shown and both views are consistent. This information can be personal information not supposed to be leaked to customers especially the salesperson's city in case of home office. --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr Forward-Port-Of: odoo/odoo#278497
Portal access tokens are now only accepted when they match exactly, reducing the risk of unintended access from partial or loose matches. The update keeps expected list-based checks working while making token validation safer and more predictable.
Original PR description
Access tokens can only be matched by exact value. Accept `in` and `not in` operators. Task-6481193 Forward-Port-Of: odoo/odoo#285388 Forward-Port-Of: odoo/odoo#285218