Friday, September 11, 2026
2 changes · saas-19.4
Security fixes and vulnerability patches
This update prevents full authentication tokens from being written to logs in the Peppol accounting integration. It reduces the risk of sensitive access information being exposed while keeping logging useful for troubleshooting.
Original PR description
don't log full token Description of the issue/feature this PR addresses: Current behavior before PR: Desired behavior after PR is merged: --- I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr Forward-Port-Of: odoo/odoo#287738 Forward-Port-Of: odoo/odoo#287262
Discuss call channels now use keys that are unique to each channel instead of relying directly on a shared database secret. This helps better protect real-time call sessions and reduces the risk of one channel's access details affecting another.
Original PR description
derive channel-specific key from db secret and the channel id. Forward-Port-Of: odoo/odoo#287646 Forward-Port-Of: odoo/odoo#286304