[FIX] service: properly invalidate session of deteled users
If a user A deletes the res.users record of user B while B is connected,
the verification of the session token fails with a comparison of a boolean and
bytes values.
While the check should obviously fail, this patch gracefully inform the user B
its session has expired and redirect him to the login page.
Without the patch, the session is never invalidated in the user browser,
redirecting to a forbidden error page as long as the session has not been manually
cleared from the browser.
Fixes #25530
Closes #25654
Closes #25682
Cherry-Pick of 96f01c08f8
This commit is contained in:
committed by
Christophe Simonis
parent
8b25099aea
commit
00a55f4428
@@ -18,7 +18,8 @@ def compute_session_token(session, env):
|
||||
|
||||
def check_session(session, env):
|
||||
self = env['res.users'].browse(session.uid)
|
||||
if openerp.tools.misc.consteq(self._compute_session_token(session.sid), session.session_token):
|
||||
expected = self._compute_session_token(session.sid)
|
||||
if expected and openerp.tools.misc.consteq(expected, session.session_token):
|
||||
return True
|
||||
self._invalidate_session_cache()
|
||||
return False
|
||||
|
||||
Reference in New Issue
Block a user