Monday, September 21, 2026
1 change · master
Security fixes and vulnerability patches
The website configurator preview now validates its inputs more carefully and is limited to website designers. This helps prevent unintended access or misuse of the preview page, improving protection for website setup workflows.
Original PR description
bug: The configurator preview used the parameters it is given without checking them enough. fix: Check them, keep the configurator to website designers, and give the preview page a stricter policy. Forward-Port-Of: odoo/odoo#289273 Forward-Port-Of: odoo/odoo#288584