From 00a55f4428bf72f5e9e2ff4b4028090b6321cf4a Mon Sep 17 00:00:00 2001 From: Martin Trigaux Date: Mon, 9 Jul 2018 14:59:11 +0200 Subject: [PATCH] [FIX] service: properly invalidate session of deteled users If a user A deletes the res.users record of user B while B is connected, the verification of the session token fails with a comparison of a boolean and bytes values. While the check should obviously fail, this patch gracefully inform the user B its session has expired and redirect him to the login page. Without the patch, the session is never invalidated in the user browser, redirecting to a forbidden error page as long as the session has not been manually cleared from the browser. Fixes #25530 Closes #25654 Closes #25682 Cherry-Pick of 96f01c08f8cd15cd572333fafed4456e4f6ef88a --- openerp/service/security.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/openerp/service/security.py b/openerp/service/security.py index 28c85788a0a..babdd88f30e 100644 --- a/openerp/service/security.py +++ b/openerp/service/security.py @@ -18,7 +18,8 @@ def compute_session_token(session, env): def check_session(session, env): self = env['res.users'].browse(session.uid) - if openerp.tools.misc.consteq(self._compute_session_token(session.sid), session.session_token): + expected = self._compute_session_token(session.sid) + if expected and openerp.tools.misc.consteq(expected, session.session_token): return True self._invalidate_session_cache() return False