Monday, September 7, 2026
1 change · 19.0
Security fixes and vulnerability patches
Point of Sale self-invoicing now prevents public users from changing an existing customer on an order and checks required customer details before invoice creation. This protects customer data and reduces failed or incomplete invoices by only allowing authorized users to update permitted customer records.
Original PR description
Before this commit: ------------------- - During self-invoicing, a public user could create a new customer or update the current order's customer data by submitting the self-invoicing form, without any access rights validation. - For logged-in users (portal or internal), invoice generation could proceed even when the user or the selected customer lacked the required invoicing information. After this commit: ------------------- - During self-invoicing, a public user can create a new customer for the order, but cannot modify the existing customer linked to the order. - For logged-in users (portal or internal), required customer information is validated before generating an invoice. Customer data can only be updated when the customer is the logged-in user's partner or a child contact of that partner. Task-6272660 Forward-Port-Of: odoo/odoo#283470 Forward-Port-Of: odoo/odoo#270112