Monday, September 7, 2026
1 change · saas-18.4
Security fixes and vulnerability patches
Point of Sale self-invoicing now prevents unauthorized changes to existing customer records and checks that required invoicing details are present before creating invoices. This protects customer data while still allowing legitimate users to complete invoices for themselves or related contacts.
Original PR description
Before this commit: ------------------- - During self-invoicing, a public user could create a new customer or update the current order's customer data by submitting the self-invoicing form, without any access rights validation. - For logged-in users (portal or internal), invoice generation could proceed even when the user or the selected customer lacked the required invoicing information. After this commit: ------------------- - During self-invoicing, a public user can create a new customer for the order, but cannot modify the existing customer linked to the order. - For logged-in users (portal or internal), required customer information is validated before generating an invoice. Customer data can only be updated when the customer is the logged-in user's partner or a child contact of that partner. Task-6272660 Forward-Port-Of: odoo/odoo#283470 Forward-Port-Of: odoo/odoo#270112