Friday, September 11, 2026
2 changes · saas-19.3
Security fixes and vulnerability patches
This change prevents full authentication tokens from being written to logs in the Peppol accounting integration. It helps reduce the risk of sensitive access information being exposed through internal log files while keeping troubleshooting possible.
Original PR description
don't log full token Description of the issue/feature this PR addresses: Current behavior before PR: Desired behavior after PR is merged: --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr Forward-Port-Of: odoo/odoo#287262
Discuss now uses a separate protected key for each call channel instead of sharing one general secret. This helps keep real-time communication access better isolated and reduces the risk of one channel affecting another.
Original PR description
derive channel-specific key from db secret and the channel id. Forward-Port-Of: odoo/odoo#287561 Forward-Port-Of: odoo/odoo#286304