Tuesday, September 15, 2026
1 change · master
Security fixes and vulnerability patches
The Nilvera-based Turkish e-invoicing and e-dispatch integrations are now part of Odoo Enterprise as the officially supported solution. The move preserves existing module names and data, updates the license, and includes a security tightening to protect API keys from broader journal access.
Original PR description
Moves l10n_tr_nilvera{,_einvoice,_edispatch} from Community to Enterprise. - [MOV] adds the three modules byte-identical to their Community source, and registers their translations in .weblate.json.…
Moves l10n_tr_nilvera{,_einvoice,_edispatch} from Community to Enterprise.
- [MOV] adds the three modules byte-identical to their Community source, and registers their translations in .weblate.json.
- [IMP] switches their licence to OEEL-1.
- [REF] moves the ubl_tr EDI overrides (_get_edi_builder and _get_ubl_cii_formats_info) from l10n_tr_nilvera into l10n_tr_nilvera_einvoice, which owns the builder model and depends on account_edi_ubl_cii. l10n_tr_nilvera overrode both but did not depend on the module defining them; it worked only because l10n_tr_nilvera_einvoice auto-installs on it. The format selection, partner config, and _get_suggested_invoice_edi_format stay in l10n_tr_nilvera, since its views render the format and that method extends account, which is in its dependencies. Also drops an extra blank line (E303).
- [FIX] restricts l10n_tr_nilvera_api_key on account.journal with groups='base.group_system', matching the company field it is related to, so the key is not exposed to anyone able to read the journal (PY039); and uses urlsplit instead of urlparse to take a Nilvera endpoint path, avoiding urlparse's outdated RFC 1808 params behaviour.
Community pr: odoo/odoo#281446
Upgrade pr: odoo/upgrade#10977
task-6424221