Tuesday, September 1, 2026
2 changes · saas-19.2
Security fixes and vulnerability patches
This update ensures portal access tokens are only accepted when they match the expected value exactly, while still supporting standard list-based checks. This helps prevent incorrect token matches and keeps portal access validation reliable.
Original PR description
Access tokens can only be matched by exact value. Accept `in` and `not in` operators. Task-6481193 Forward-Port-Of: odoo/odoo#285388 Forward-Port-Of: odoo/odoo#285218
Resolved issues and error corrections
Customer invoice portal pages no longer show the salesperson's city or phone number. This keeps invoice views consistent with sales order views and reduces the risk of exposing personal employee information, such as home-office location details.
Original PR description
This change aligns the salesperson's information shown to customers on the invoice view with those shown on the sales order view. Now city and phone number are not shown and both views are consistent. This information can be personal information not supposed to be leaked to customers especially the salesperson's city in case of home office. --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr Forward-Port-Of: odoo/odoo#278497