# Copyright 2026 Criptomart # License AGPL-3.0 or later (https://www.gnu.org/licenses/agpl) import logging from odoo import http from odoo.http import request from odoo.addons.website_sale.controllers.main import WebsiteSale _logger = logging.getLogger(__name__) DEFAULT_REDIRECT_URL = "/shop" REDIRECT_URL_PARAM = "website_sale_disable_cart.redirect_url" class WebsiteSaleDisableCart(WebsiteSale): """Neutralize the standard ``website_sale`` cart endpoints. The shop keeps working as a plain catalog (listing, search and product pages are untouched); only the cart itself becomes unreachable. HTTP routes redirect to the configured URL, JSON routes answer with an inert payload so any leftover frontend call is a no-op instead of an error. """ def _get_cart_redirect_url(self): """Return the internal path the disabled cart routes redirect to.""" url = ( request.env["ir.config_parameter"] .sudo() .get_param(REDIRECT_URL_PARAM, DEFAULT_REDIRECT_URL) ) url = (url or "").strip() # Only site-internal paths are accepted: an absolute or protocol # relative URL would turn the shop into an open redirect, and a path # back under /shop/cart would loop through the disabled routes. if ( not url.startswith("/") or url.startswith("//") or url.startswith("/shop/cart") ): _logger.warning( "[DISABLE_CART] Invalid redirect URL %r, falling back to %s", url, DEFAULT_REDIRECT_URL, ) return DEFAULT_REDIRECT_URL return url def _redirect_disabled_cart(self, route): """Redirect a disabled cart route to the configured URL.""" url = self._get_cart_redirect_url() _logger.info("[DISABLE_CART] %s → %s", route, url) return request.redirect(url) @http.route() def cart(self, access_token=None, revive="", **post): """Cart page is disabled: send the visitor to the configured URL.""" return self._redirect_disabled_cart("/shop/cart") @http.route() def cart_update( self, product_id=None, add_qty=1, set_qty=0, product_custom_attribute_values=None, no_variant_attribute_value_ids=None, **kwargs, ): """Adding to cart is disabled: nothing is written, just redirect.""" return self._redirect_disabled_cart("/shop/cart/update") @http.route() def cart_update_json( self, product_id=None, line_id=None, add_qty=None, set_qty=None, display=True, product_custom_attribute_values=None, no_variant_attribute_value_ids=None, **kwargs, ): """Adding to cart is disabled. An empty dict is the response ``website_sale`` already returns when the order cannot be updated, so callers handle it without breaking. """ _logger.info("[DISABLE_CART] /shop/cart/update_json ignored") return {} @http.route() def cart_quantity(self): """The cart is always empty while this module is installed.""" return 0 @http.route() def clear_cart(self): """Nothing to clear: the cart is never fed through the standard shop.""" return None