From 2cffcfd860a8c035074ca123e01d8bf5f47ecc4e Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Sat, 25 Feb 2017 02:10:30 +0100 Subject: [PATCH] [FIX] website_mail: disable sha_in based message_post The _message_post_helper() method historically allowed passing a `sha_in` signature to let an unauthenticated user post a message on a record. This option is unused and an alternative is preferred: passing a `token` value that matches the value of a given field of the record. In light of the increasingly grim future of SHA-1 as a cryptographic hash function, we consider it better to entirely remove this specific option. It has been unused for a while, and a simple alternative exists. The `object_shasign` method itself will be dropped in master. --- addons/website_mail/controllers/main.py | 25 +++++++++---------------- 1 file changed, 9 insertions(+), 16 deletions(-) diff --git a/addons/website_mail/controllers/main.py b/addons/website_mail/controllers/main.py index c966b2bede7..57fb68e1330 100644 --- a/addons/website_mail/controllers/main.py +++ b/addons/website_mail/controllers/main.py @@ -11,7 +11,12 @@ from odoo.http import request def object_shasign(record=False, res_model='', res_id=None, **kw): """ Generate a sha signature using the current time, database secret and the record object or the res_model and res_id parameters - Return the sha signature and the time of generation in a tuple""" + Return the sha signature and the time of generation in a tuple + + :deprecated: Support for this SHA1-based signature was discontinued + in `_message_post_helper()`, use the `token` parameter + to allow posting from public sessions instead. + """ secret = request.env['ir.config_parameter'].sudo().get_param('database.secret') shasign = False timestamp = int(time()) @@ -24,7 +29,7 @@ def object_shasign(record=False, res_model='', res_id=None, **kw): def _message_post_helper(res_model='', res_id=None, message='', token='', token_field='token', sha_in='', sha_time=None, nosubscribe=True, **kw): """ Generic chatter function, allowing to write on *any* object that inherits mail.thread. - If a token or a shasign is specified, all logged in users will be able to write a message regardless + If a token is specified, all logged in users will be able to write a message regardless of access rights; if the user is the public user, the message will be posted under the name of the partner_id of the object (or the public user if there is no partner_id on the object). @@ -36,12 +41,8 @@ def _message_post_helper(res_model='', res_id=None, message='', token='', token_ :param string token: access token if the object's model uses some kind of public access using tokens (usually a uuid4) to bypass access rules :param string token_field: name of the field that contains the token on the object (defaults to 'token') - :param string sha_in: sha1 hash of the string composed of res_model, res_id and the dabase secret in ir.config_parameter - if you wish to allow public users to write on the object with some security but you don't want - to add a token field on the object, the sha-sign prevents public users from writing to any other - object that the one specified by res_model and res_id - to generate the shasign, you can import the function object_shasign from this file in your controller - :param str sha_time: timestamp of sha signature generation (signatures are valid for 24h) + :param string sha_in: Deprecated, use `token` and `token_field` instead + :param str sha_time: Deprecated, use `token` and `token_field` instead :param bool nosubscribe: set False if you want the partner to be set as follower of the object when posting (default to True) The rest of the kwargs are passed on to message_post() @@ -55,14 +56,6 @@ def _message_post_helper(res_model='', res_id=None, message='', token='', token_ else: if not author_id: raise NotFound() - elif sha_in: - timestamp = int(sha_time) - secret_sudo = request.env['ir.config_parameter'].sudo().get_param('database.secret') - shasign = sha1('%s%s%s%s' % (res_model, res_id, secret_sudo, timestamp)) - if sha_in == shasign.hexdigest() and int(time()) < timestamp + 3600 * 24: - record = record.sudo() - else: - raise NotFound() return record.with_context(mail_create_nosubscribe=nosubscribe).message_post(body=message, message_type=kw.pop('message_type', "comment"), subtype=kw.pop('subtype', "mt_comment"),