Wednesday, September 9, 2026
1 change · master
Security fixes and vulnerability patches
Live chat visitor routes now use a dedicated guest access check instead of relying on each route to apply it manually. This reduces the risk of accidentally exposing live chat actions while preserving the expected visitor experience.
Original PR description
Before this commit, all 25 CORS routes of the live chat are declared auth="public" and call force_guest_env() as their first statement, to replace the request user by the public one and put the guest matching the guest_token parameter in the context. The problem is that auth="public" is wrong for these routes, so a route that forgets to call force_guest_env() is left public. This commit turns the helper into two ir.http auth methods, force_guest and force_guest_optional, the latter for the routes a visitor reaches before having a guest, so a route is safe by definition. The website tracking route keeps its own lookup, as it must not drop the session of a logged in visitor. Note that authentication runs before the dispatcher parses the parameters, so the token is read from the json body or from the http parameters, depending on the type of the route. task-6259734 https://github.com/odoo/enterprise/pull/118774