Friday, September 11, 2026
2 changes · 18.0
Security fixes and vulnerability patches
This update prevents unauthenticated users from changing customer or partner information in point-of-sale related flows. It helps protect sensitive business and customer data by ensuring only signed-in users can make these changes.
Original PR description
This also ensures that only authenticated users can modify partner data.
This fix prevents self-order checkouts from relying on customer details that the frontend does not provide. It reduces validation errors and helps ensure only authenticated users can change customer information.
Original PR description
The partner is never added by the frontend, so we can safely ignore it. --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr