Thursday, September 10, 2026
1 change · saas-19.4
Security fixes and vulnerability patches
Self-invoicing in Point of Sale now prevents public users from changing existing customer details and checks that logged-in users have complete, valid customer information before invoices are created. This reduces the risk of incorrect customer data being changed or invoices being issued with missing required details.
Original PR description
Before this commit: ------------------- - During self-invoicing, a public user could create a new customer or update the current order's customer data by submitting the self-invoicing form, without any access rights validation. - For logged-in users (portal or internal), invoice generation could proceed even when the user or the selected customer lacked the required invoicing information. After this commit: ------------------- - During self-invoicing, a public user can create a new customer for the order, but cannot modify the existing customer linked to the order. - For logged-in users (portal or internal), required customer information is validated before generating an invoice. Customer data can only be updated when the customer is the logged-in user's partner or a child contact of that partner. Task-6272660 Forward-Port-Of: odoo/odoo#287007 Forward-Port-Of: odoo/odoo#270112