Tuesday, September 22, 2026
2 changes · master
Security fixes and vulnerability patches
This update keeps an internal Colombian electronic invoicing status calculation from being accessed through external integration channels. It reduces unintended exposure while preserving the same invoice status behavior for users.
Original PR description
- Make the EDI states compute method private to avoid exposing it through XML-RPC. - Rename `compute_l10n_co_edi_states` to `_compute_l10n_co_edi_states` and update its field references accordingly. Commit cherry-picked from https://github.com/odoo/enterprise/pull/131963 to continue that part of the fw-port. Forward-Port-Of: odoo/enterprise#132381
This update restores user validation for IoT websocket requests, matching the previous expected behavior. It helps ensure IoT communications are only handled for appropriate users, reducing the risk of unauthorized access or incorrect device interactions.
Original PR description
Restore to pre 19.0 behaviour by checking user. Forward-Port-Of: odoo/enterprise#132399 Forward-Port-Of: odoo/enterprise#132098