[IMP] auth_oauth: prevent portal users to land on /web after login
Before this commit, a portal user would land on /web after login in with oauth. He would then just see the "Website" app. He should then click on it to land on website instead of landing directly on it after login in, which is not convenient, especially since theses users doesn't know Odoo (in case of sale customers manually created for instance). Now, if users has no 'base.group_user' right, it will be redirected to the website directly instead of /web.
This commit is contained in:
@@ -151,7 +151,11 @@ class OAuthController(http.Controller):
|
||||
url = '/web#action=%s' % action
|
||||
elif menu:
|
||||
url = '/web#menu_id=%s' % menu
|
||||
return login_and_redirect(*credentials, redirect_url=url)
|
||||
resp = login_and_redirect(*credentials, redirect_url=url)
|
||||
#Since /web is hardcoded, verify user has right to land on it
|
||||
if urlparse.urlparse(resp.location).path == '/web' and not request.registry['res.users'].has_group(request.cr, request.uid, 'base.group_user'):
|
||||
resp.location = '/'
|
||||
return resp
|
||||
except AttributeError:
|
||||
# auth_signup is not installed
|
||||
_logger.error("auth_signup not installed on database %s: oauth sign up cancelled." % (dbname,))
|
||||
|
||||
Reference in New Issue
Block a user