[FIX] base: make check_credentials more consistent with alternatives

The other methods do test password length before verifying it, so even
if check_credentials() is not meant to be called directly, it's better
to keep it consistent with the alternatives.

Closes #29023
This commit is contained in:
Denis Roussel
2018-11-27 10:14:43 +01:00
parent 3b85900faf
commit 6639630de1
+2
View File
@@ -444,6 +444,8 @@ class Users(models.Model):
@api.model
def check_credentials(self, password):
""" Override this method to plug additional authentication methods"""
if not password:
raise AccessDenied()
user = self.sudo().search([('id', '=', self._uid), ('password', '=', password)])
if not user:
raise AccessDenied()