From 9bae56acd4ebe2b169ef635892b2cd9b6664a9d0 Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Tue, 2 Oct 2018 01:00:37 +0200 Subject: [PATCH] [IMP] http: reinstate session rotation after login Session rotation was introduced a long time ago, but deactivated at login due to obscure side-effects related to #6949 (aka the "BBQ" PR). This commit reinstates the rotation, which is better from a security standpoint. In order to also prevent session ID reuse, we force the renewal of deleted sessions, at the SessionStore level (via `renew_missing`). --- odoo/http.py | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/odoo/http.py b/odoo/http.py index 3ae800cc71b..27d4d12fbca 100644 --- a/odoo/http.py +++ b/odoo/http.py @@ -1038,6 +1038,7 @@ class OpenERPSession(werkzeug.contrib.sessions.Session): uid = odoo.registry(db)['res.users'].authenticate(db, login, password, env) else: security.check(db, uid, password) + self.rotate = True self.db = db self.uid = uid self.login = login @@ -1299,7 +1300,8 @@ class Root(object): # Setup http sessions path = odoo.tools.config.session_dir _logger.debug('HTTP sessions stored in: %s', path) - return werkzeug.contrib.sessions.FilesystemSessionStore(path, session_class=OpenERPSession) + return werkzeug.contrib.sessions.FilesystemSessionStore( + path, session_class=OpenERPSession, renew_missing=True) @lazy_property def nodb_routing_map(self): @@ -1415,6 +1417,8 @@ class Root(object): if httprequest.session.rotate: self.session_store.delete(httprequest.session) httprequest.session.sid = self.session_store.generate_key() + if httprequest.session.uid: + httprequest.session.session_token = security.compute_session_token(httprequest.session, request.env) httprequest.session.modified = True self.session_store.save(httprequest.session) # We must not set the cookie if the session id was specified using a http header or a GET parameter.