Monday, September 28, 2026
1 change · saas-19.1
Security fixes and vulnerability patches
AI-powered document sorting no longer shows disruptive on-screen errors when API credentials are missing, while still recording the issue on the document for follow-up. The update also prevents invalid AI API key details from appearing in user-facing messages, reducing the risk of exposing sensitive information.
Original PR description
Prior to this PR, any users who have enabled the ai_document sort without any API key enable will have a error notification when adding the document in a folder where ai_sort is enabled. We'd like to remove this notification if the API key is not set in the configuration, and instead have the error log in the chatter of the document only. How to reproduce: - Disable AI Keys from the environment - On any record, add an attachment (ex: in HR app) - Click on the "Add to Documents" - Move it to the Inbox folder (where ai_sort is enabled) Current behavior: - A notification error is shown on top right for each time it attempts to sort the document - The error message is stored in the chatter of the document. (keep this behavior) Expected behavior: - If no credits (API key) is set, no error should be shown on screen. - The error message is stored in the chatter of the document. (keep this behavior) task: 5499622 Forward-Port-Of: odoo/enterprise#125521