Wednesday, September 2, 2026
3 changes · master
Security fixes and vulnerability patches
Email marketing building blocks have been converted to a newer template system, making them easier to update, extend, and maintain across versions. This also reduces security risk from how snippets were previously rendered, adds an easier way to insert unsubscribe links, and prevents product emails from showing internal cost prices.
Original PR description
also modified: html_builder, website Currently, all mailing snippets are "backend" views, instantiated and stored in-database on spin-up, just like website snippets. This has several drawbacks: - mailing snippets cannot be easily updated and/or fixed if they are flawed - new snippets cannot be easily added to older versions - as the snippets are rendered with qweb, they have an elevated level of permission making them an attack vector - "placeholders" for fragments that are editable via plugin (e.g. filling in social links with a company's social info) exist separate from their "filling" This PR intends to fix these issues by turning all backend snippets into frontend Owl templates. To ensure compatibility with the current HTMLBuilder snippet service & existing custom snippets, builtin snippets are seamlessy added to the snippet document when mailing snippets are loaded. task-5477951
Resolved issues and error corrections
Customer-facing invoice pages no longer show the salesperson's city or phone number. This keeps invoice and sales order views consistent while reducing the risk of exposing personal employee information, such as home-office location details.
Original PR description
This change aligns the salesperson's information shown to customers on the invoice view with those shown on the sales order view. Now city and phone number are not shown and both views are consistent. This information can be personal information not supposed to be leaked to customers especially the salesperson's city in case of home office. --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr Forward-Port-Of: odoo/odoo#285845 Forward-Port-Of: odoo/odoo#278497
Self-order payment notifications no longer include full order details when sent through live updates. This reduces unnecessary data sharing while keeping order status updates working for customers and staff.
Original PR description
Remove the order data from the websocket notification. Forward-Port-Of: odoo/odoo#285517 Forward-Port-Of: odoo/odoo#284631