Wednesday, September 9, 2026
1 change · saas-19.1
Security fixes and vulnerability patches
This update prevents unauthorized changes to customer details during point-of-sale self-invoicing. It ensures invoices are only created after required customer information is validated and only allows edits by users linked to the customer record.
Original PR description
Before this commit: ------------------- - During self-invoicing, a public user could create a new customer or update the current order's customer data by submitting the self-invoicing form, without any access rights validation. - For logged-in users (portal or internal), invoice generation could proceed even when the user or the selected customer lacked the required invoicing information. After this commit: ------------------- - During self-invoicing, a public user can create a new customer for the order, but cannot modify the existing customer linked to the order. - For logged-in users (portal or internal), required customer information is validated before generating an invoice. Customer data can only be updated when the customer is the logged-in user's partner or a child contact of that partner. Task-6272660 Forward-Port-Of: odoo/odoo#286827 Forward-Port-Of: odoo/odoo#270112