[18.0][FIX] vault: inbox share form token handling and optional file - #987
Open
jans23 wants to merge 1 commit into
Open
[18.0][FIX] vault: inbox share form token handling and optional file#987jans23 wants to merge 1 commit into
jans23 wants to merge 1 commit into
Conversation
jans23
force-pushed
the
18.0-fix-vault-invalid-token
branch
from
August 24, 2026 12:42
c53cc4b to
1acf60a
Compare
fkantelberg
suggested changes
Sep 2, 2026
| placeholder="Secret" | ||
| id="secret_file" | ||
| name="secret_file" | ||
| required="required" |
Member
There was a problem hiding this comment.
True this shouldn't be required here but neither should secret be required. It should be made sure that either one of those must be present. Without the required here it's not visually obvious what is missing except for the error message on submit.
- Entering secret but not secret_file => allowed
- Entering secret_file but not secret => allowed
- Entering secret and secret_file => allowed
- Entering neither secret nor secret_file => denied
Contributor
Author
There was a problem hiding this comment.
I added an appropriate error message shown to the user.
| inbox = request.env["vault.inbox"].sudo().find_inbox(token) | ||
| user = request.env["res.users"].sudo().find_user_of_inbox(token) | ||
| if len(inbox) == 1 and inbox.accesses > 0: | ||
| if len(inbox) == 1: |
Member
There was a problem hiding this comment.
I don't know about this change here. I think without access it should look like the link is invalid. To we want to be verbose here?
Contributor
Author
There was a problem hiding this comment.
restored as suggested.
The frontend inbox share form showed 'Invalid token' for valid links and wrongly required a file even when a name and secret were provided. - Resolve the recipient public key for any valid token instead of only when the inbox still has accesses left, so a valid link no longer reports 'Invalid token'. Distinguish an unknown token from a recipient without a key pair with clearer messages. - Drop the hardcoded 'required' on the file input so name + secret are sufficient; the file remains optional (the JS still toggles the requirements and the server/model already accept secret or file).
jans23
force-pushed
the
18.0-fix-vault-invalid-token
branch
from
September 2, 2026 11:50
1acf60a to
bebdc50
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The frontend inbox share form showed 'Invalid token' for valid links and wrongly required a file even when a name and secret were provided.