From 7df7ecae9b81ea6d9ce8cd12f1385cf69bed5c0b Mon Sep 17 00:00:00 2001 From: Pierre Paridans Date: Fri, 25 Feb 2022 13:10:20 +0000 Subject: [PATCH] [FIX] auth_totp,web: TOTP login from mobile apps Since PR odoo/odoo#78857 , the TOTP authentication support is broken when used inside either Android or iOS mobile apps. Due to our inability to update the iOS app (following review from Apple), this commit aims at restoring the bare minimum requirements to make the current mobile apps (specially iOS but also Android) authentication workflow works. As extended explanation: - Set-Cookie header is expected to be sent even when session_id hasn't changed (iOS specific). - Successful credentials check on `/web/session/authenticate` expect a successful response with a result containing `uid` set to `null` to mark the need of an additional totp handshake (both platforms). closes odoo/odoo#85463 Signed-off-by: Julien Castiaux --- addons/auth_totp/controllers/home.py | 4 ++++ addons/auth_totp/tests/test_totp.py | 2 +- addons/web/controllers/main.py | 6 +++++- 3 files changed, 10 insertions(+), 2 deletions(-) diff --git a/addons/auth_totp/controllers/home.py b/addons/auth_totp/controllers/home.py index fecd2359c2c..ebef4a1266e 100644 --- a/addons/auth_totp/controllers/home.py +++ b/addons/auth_totp/controllers/home.py @@ -65,8 +65,12 @@ class Home(odoo.addons.web.controllers.main.Home): httponly=True, samesite='Lax' ) + # Crapy workaround for unupdatable Odoo Mobile App iOS (Thanks Apple :@) + request.session.should_touch = True return response + # Crapy workaround for unupdatable Odoo Mobile App iOS (Thanks Apple :@) + request.session.should_touch = True return request.render('auth_totp.auth_totp_form', { 'user': user, 'error': error, diff --git a/addons/auth_totp/tests/test_totp.py b/addons/auth_totp/tests/test_totp.py index 4a52e1773a2..7f9791b732d 100644 --- a/addons/auth_totp/tests/test_totp.py +++ b/addons/auth_totp/tests/test_totp.py @@ -114,4 +114,4 @@ class TestTOTP(HttpCase): } response = self.url_open("/web/session/authenticate", data=json.dumps(payload), headers=headers) data = response.json() - self.assertEqual(data['error']['data']['message'], "Reniewing an expired session for user that has multi-factor-authentication is not supported. Please use /web/login instead.") + self.assertEqual(data['result']['uid'], None) diff --git a/addons/web/controllers/main.py b/addons/web/controllers/main.py index 620047813bb..6a418b54661 100644 --- a/addons/web/controllers/main.py +++ b/addons/web/controllers/main.py @@ -1191,6 +1191,8 @@ class Session(http.Controller): @http.route('/web/session/get_session_info', type='json', auth="user") def get_session_info(self): + # Crapy workaround for unupdatable Odoo Mobile App iOS (Thanks Apple :@) + request.session.should_touch = True return request.env['ir.http'].session_info() @http.route('/web/session/authenticate', type='json', auth="none") @@ -1199,7 +1201,9 @@ class Session(http.Controller): raise AccessError("Database not found.") pre_uid = request.session.authenticate(db, login, password) if pre_uid != request.session.uid: - raise AccessError("Reniewing an expired session for user that has multi-factor-authentication is not supported. Please use /web/login instead.") + # Crapy workaround for unupdatable Odoo Mobile App iOS (Thanks Apple :@) and Android + # Correct behavior should be to raise AccessError("Renewing an expired session for user that has multi-factor-authentication is not supported. Please use /web/login instead.") + return {'uid': None} request.session.db = db registry = odoo.modules.registry.Registry(db)