Thursday, September 10, 2026
1 change · saas-19.3
Security fixes and vulnerability patches
Point of Sale self-invoicing now prevents public users from changing an existing customer on an order and checks that logged-in users have the required customer details and edit rights before invoicing. This reduces the risk of incorrect customer records and unauthorized changes while keeping invoice creation available when information is valid.
Original PR description
Before this commit: ------------------- - During self-invoicing, a public user could create a new customer or update the current order's customer data by submitting the self-invoicing form, without any access rights validation. - For logged-in users (portal or internal), invoice generation could proceed even when the user or the selected customer lacked the required invoicing information. After this commit: ------------------- - During self-invoicing, a public user can create a new customer for the order, but cannot modify the existing customer linked to the order. - For logged-in users (portal or internal), required customer information is validated before generating an invoice. Customer data can only be updated when the customer is the logged-in user's partner or a child contact of that partner. Task-6272660 Forward-Port-Of: odoo/odoo#287007 Forward-Port-Of: odoo/odoo#270112