From 2041f55c8585469c6038ed262f562fde902f5ad0 Mon Sep 17 00:00:00 2001 From: Xavier Morel Date: Fri, 20 May 2022 13:15:16 +0000 Subject: [PATCH] [FIX] auth_oauth: restore fetching uid from user_id In discussing 56fe16bd I was reminded to re-set the `user_id` from `sub` in case an override / other client would be using it, but we didn't think that an override might also be *setting* this work key, which apparently is the case. Therefore restore the old behavior of *getting* the user_id from the response object, migration to using `sub` (and removal of compat with `user_id` and `id`) will be done when the module is reworked and the flow compatibility, nonce, etc... are all fixed. closes odoo/odoo#91996 X-original-commit: a787a2f644e9e83dc6320eaf372e657718fd2e22 Signed-off-by: Xavier Morel (xmo) --- addons/auth_oauth/models/res_users.py | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/addons/auth_oauth/models/res_users.py b/addons/auth_oauth/models/res_users.py index ecaa68d0530..223cc1fac4f 100644 --- a/addons/auth_oauth/models/res_users.py +++ b/addons/auth_oauth/models/res_users.py @@ -50,7 +50,9 @@ class ResUsers(models.Model): if oauth_provider.data_endpoint: data = self._auth_oauth_rpc(oauth_provider.data_endpoint, access_token) validation.update(data) - # unify subject key under standard (sub), pop all possible and get most sensible + # unify subject key, pop all possible and get most sensible. When this + # is reworked, BC should be dropped and only the `sub` key should be + # used (here, in _generate_signup_values, and in _auth_oauth_signin) subject = next(filter(None, [ validation.pop(key, None) for key in [ @@ -61,15 +63,13 @@ class ResUsers(models.Model): ]), None) if not subject: raise AccessDenied('Missing subject identity') - # also set on user_id for BC reasons, remove in master when the entire - # thing gets reworked - validation['sub'] = validation['user_id'] = subject + validation['user_id'] = subject return validation @api.model def _generate_signup_values(self, provider, validation, params): - oauth_uid = validation['sub'] + oauth_uid = validation['user_id'] email = validation.get('email', 'provider_%s_user_%s' % (provider, oauth_uid)) name = validation.get('name', email) return { @@ -93,7 +93,7 @@ class ResUsers(models.Model): This method can be overridden to add alternative signin methods. """ - oauth_uid = validation['sub'] + oauth_uid = validation['user_id'] try: oauth_user = self.search([("oauth_uid", "=", oauth_uid), ('oauth_provider_id', '=', provider)]) if not oauth_user: