Friday, September 25, 2026
1 change · 19.0
Enhancements to existing features
Odoo’s Xendit payment integration now uses Xendit’s newer hosted payment flow because older payment endpoints are being retired. Customers will be redirected to Xendit to complete all payments, while existing saved card tokens remain supported and administrators are notified about required webhook changes.
Original PR description
Xendit is deprecating the v2/invoices and credit_card_charges endpoints for new payments. This switches checkout and card sessions to the Payment Sessions API (/sessions) and charges v3 tokens…
Xendit is deprecating the v2/invoices and credit_card_charges endpoints for
new payments. This switches checkout and card sessions to the Payment
Sessions API (/sessions) and charges v3 tokens through /v3/payment_requests,
while still charging pre-existing v2 tokens through the legacy
credit_card_charges endpoint, as there is no migration path for them.
- the inline card form, its direct flow, and the Xendit SDK are removed; all
payment methods now redirect to the Xendit-hosted payment link
- a v3 token charge that unexpectedly still requires 3DS exposes the
authentication URL as a processing value; the frontend navigates the top
window to it directly, since Xendit's challenge page must be top-level and
only accepts GET
- a customer returning from checkout, or from a 3DS challenge, is checked
directly against Xendit before falling back to pending, in case the
webhook is delayed or dropped
- webhook payloads are unwrapped from their {event, data} envelope, and
transactions are looked up by reference_id, falling back to external_id
for legacy charges and to a suffix-stripped reference_id otherwise
Upgrade / stable-version compatibility:
- the inline_form view is emptied rather than removed (it's noupdate, and
ondelete='restrict' would abort the module update otherwise); it is never
rendered
- xendit_public_key is kept but unused, and several touched methods keep
their old name or signature (_xendit_create_charge, _get_rounded_amount,
_xendit_prepare_invoice_request_payload, _extract_token_values,
_get_redirect_form_view, the /payment/xendit/payment route), since
partners may override them and a stable version can't drop or break an
override
- bump the module version so partners upgrading notice the change
Webhook migration notice:
Xendit replaced the single webhook field with separate v3 event groups, so
already-configured databases silently stop receiving updates. Remind admins
once via the daily autovacuum cron (works without an upgrade or a new
ir.cron record), tracked through the payment_xendit.v3_notification_sent
system parameter so it's only sent once.
Forward-port to 19.0: requests go through the generic _send_api_request
framework (the api-version header via _build_request_headers, the URL via
odoo.tools.urls.urljoin), notifications through _process/_apply_updates,
and card tokens are created through _tokenize/_extract_token_values.
Task-6373405
Forward-Port-Of: odoo/odoo#277626