[IMP] http/db: change behaviour of list_dbs() when --db-filter is not provided (Closed #18526)

In case `--db-filter` is not provided and `--database` is passed,
Odoo will not fetch the list of databases available in the postgres
server anymore because it does not have anything to match against this
list. Instead, `list_dbs()` will use the value of `--database` as a
comma separated list of exposed databases.

This allows better security hardening in postgres access rights.

Basically, that means that those commands

    $ odoo-bin -d foobar
    $ odoo-bin -d foo,bar,baz

are now respectively equivalent to those commands

    $ odoo-bin -d foobar --db-filter='^foobar$'
    $ odoo-bin -d foo,bar,baz --db-filter='^(foo|bar|baz)$'

The old behaviour can still be used with this command:

    $ odoo-bin -d foobar --db-filter='.*'
This commit is contained in:
Fabien Meghazi
2017-08-03 13:49:51 +02:00
parent 5658e337c3
commit b34e00540e
3 changed files with 17 additions and 3 deletions
+8 -2
View File
@@ -1488,8 +1488,14 @@ def db_filter(dbs, httprequest=None):
d, _, r = h.partition('.')
if d == "www" and r:
d = r.partition('.')[0]
r = odoo.tools.config['dbfilter'].replace('%h', h).replace('%d', d)
dbs = [i for i in dbs if re.match(r, i)]
if odoo.tools.config['dbfilter']:
r = odoo.tools.config['dbfilter'].replace('%h', h).replace('%d', d)
dbs = [i for i in dbs if re.match(r, i)]
else:
# In case --db-filter is not provided and --database is passed, Odoo will
# use the value of --database as a comma seperated list of exposed databases.
exposed_dbs = set(db.strip() for db in odoo.tools.config['db_name'].split(','))
dbs = sorted(exposed_dbs.intersection(dbs))
return dbs
def db_monodb(httprequest=None):
+8
View File
@@ -326,6 +326,14 @@ def exp_db_exist(db_name):
def list_dbs(force=False):
if not odoo.tools.config['list_db'] and not force:
raise odoo.exceptions.AccessDenied()
if not odoo.tools.config['dbfilter'] and odoo.tools.config['db_name']:
# In case --db-filter is not provided and --database is passed, Odoo will not
# fetch the list of databases available on the postgres server and instead will
# use the value of --database as comma seperated list of exposed databases.
res = sorted(db.strip() for db in odoo.tools.config['db_name'].split(','))
return res
chosen_template = odoo.tools.config['db_template']
templates_list = tuple(set(['postgres', chosen_template]))
db = odoo.sql_db.db_connect('postgres')
+1 -1
View File
@@ -138,7 +138,7 @@ class configmanager(object):
# WEB
group = optparse.OptionGroup(parser, "Web interface Configuration")
group.add_option("--db-filter", dest="dbfilter", my_default='.*',
group.add_option("--db-filter", dest="dbfilter", my_default='',
help="Filter listed database", metavar="REGEXP")
parser.add_option_group(group)