From 7d1959febc4146276328f454f089f0f23eea43eb Mon Sep 17 00:00:00 2001 From: Julien Castiaux Date: Tue, 13 Jun 2023 12:15:07 +0000 Subject: [PATCH] [FIX] core: reset current_thread.dbname/uid between requests In [HTTPocalypse] the `odoo/service/wsgi_server.py` file has been removed and its features has been spread to other files. One of the feature was reseting those few thread-local variables[^1] before processing any new request: if hasattr(threading.current_thread(), 'uid'): del threading.current_thread().uid if hasattr(threading.current_thread(), 'dbname'): del threading.current_thread().dbname if hasattr(threading.current_thread(), 'url'): del threading.current_thread().url In [HTTPocalypse] the `url`[^2] is correctly set at its definitive value at the beginning of the request so there is no need to delete it before processing. On the other hand, `dbname`[^3][^4] and `uid`[^5] are only set when the request is processed by `_serve_db`, i.e. that the user is connected to a database already. Those values weren't reset at the begining of the next request so in case that next request was processed by `_serve_nodb` or `_serve_static`, the dbname and uid of the previous request would still be present. This commit restores both `del uid` and `del dbname` at the beginning of the http stack, before the request is processed. [HTTPocalypse]: odoo/odoo#78857 [^1]: https://github.com/odoo/odoo/blob/a1361d6629a829fd622f2a1a1b3e5b025050eaf9/odoo/service/wsgi_server.py#L80-L85 [^2]: https://github.com/odoo/odoo/blob/0e629cd2a1fc3623b579a38ae534fbdfae9b38a3/odoo/http.py#L1987 [^3]: https://github.com/odoo/odoo/blob/0e629cd2a1fc3623b579a38ae534fbdfae9b38a3/odoo/http.py#L1563 [^4]: https://github.com/odoo/odoo/blob/0e629cd2a1fc3623b579a38ae534fbdfae9b38a3/odoo/modules/registry.py#L70 [^5]: https://github.com/odoo/odoo/blob/0e629cd2a1fc3623b579a38ae534fbdfae9b38a3/odoo/http.py#L1582 closes odoo/odoo#125205 X-original-commit: c327c4586243430751100c8980169ae067383b1c Signed-off-by: Julien Castiaux (juc) --- odoo/http.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/odoo/http.py b/odoo/http.py index 9d6d3808962..5e54e00ae05 100644 --- a/odoo/http.py +++ b/odoo/http.py @@ -2102,6 +2102,10 @@ class Application: current_thread.query_count = 0 current_thread.query_time = 0 current_thread.perf_t0 = time.time() + if hasattr(current_thread, 'dbname'): + del current_thread.dbname + if hasattr(current_thread, 'uid'): + del current_thread.uid if odoo.tools.config['proxy_mode'] and environ.get("HTTP_X_FORWARDED_HOST"): # The ProxyFix middleware has a side effect of updating the