[IMP] auth_oauth: prevent portal users to land on /web after login

Before this commit, a portal user would land on /web after login in with oauth.
He would then just see the "Website" app.
He should then click on it to land on website instead of landing directly on it
after login in, which is not convenient, especially since theses users doesn't
know Odoo (in case of sale customers manually created for instance).

Now, if users has no 'base.group_user' right, it will be redirected to the
website directly instead of /web.
This commit is contained in:
rde
2017-10-20 15:25:28 +02:00
parent c6a9bab074
commit 31c1be1fac
+5 -1
View File
@@ -151,7 +151,11 @@ class OAuthController(http.Controller):
url = '/web#action=%s' % action
elif menu:
url = '/web#menu_id=%s' % menu
return login_and_redirect(*credentials, redirect_url=url)
resp = login_and_redirect(*credentials, redirect_url=url)
#Since /web is hardcoded, verify user has right to land on it
if urlparse.urlparse(resp.location).path == '/web' and not request.registry['res.users'].has_group(request.cr, request.uid, 'base.group_user'):
resp.location = '/'
return resp
except AttributeError:
# auth_signup is not installed
_logger.error("auth_signup not installed on database %s: oauth sign up cancelled." % (dbname,))