From b34e00540e20b4aa8ca5a04d5f8097fb1d8b74fe Mon Sep 17 00:00:00 2001 From: Fabien Meghazi Date: Fri, 28 Jul 2017 15:55:50 +0200 Subject: [PATCH] [IMP] http/db: change behaviour of list_dbs() when `--db-filter` is not provided (Closed #18526) In case `--db-filter` is not provided and `--database` is passed, Odoo will not fetch the list of databases available in the postgres server anymore because it does not have anything to match against this list. Instead, `list_dbs()` will use the value of `--database` as a comma separated list of exposed databases. This allows better security hardening in postgres access rights. Basically, that means that those commands $ odoo-bin -d foobar $ odoo-bin -d foo,bar,baz are now respectively equivalent to those commands $ odoo-bin -d foobar --db-filter='^foobar$' $ odoo-bin -d foo,bar,baz --db-filter='^(foo|bar|baz)$' The old behaviour can still be used with this command: $ odoo-bin -d foobar --db-filter='.*' --- odoo/http.py | 10 ++++++++-- odoo/service/db.py | 8 ++++++++ odoo/tools/config.py | 2 +- 3 files changed, 17 insertions(+), 3 deletions(-) diff --git a/odoo/http.py b/odoo/http.py index 1ea60b9194d..e66497ccdba 100644 --- a/odoo/http.py +++ b/odoo/http.py @@ -1488,8 +1488,14 @@ def db_filter(dbs, httprequest=None): d, _, r = h.partition('.') if d == "www" and r: d = r.partition('.')[0] - r = odoo.tools.config['dbfilter'].replace('%h', h).replace('%d', d) - dbs = [i for i in dbs if re.match(r, i)] + if odoo.tools.config['dbfilter']: + r = odoo.tools.config['dbfilter'].replace('%h', h).replace('%d', d) + dbs = [i for i in dbs if re.match(r, i)] + else: + # In case --db-filter is not provided and --database is passed, Odoo will + # use the value of --database as a comma seperated list of exposed databases. + exposed_dbs = set(db.strip() for db in odoo.tools.config['db_name'].split(',')) + dbs = sorted(exposed_dbs.intersection(dbs)) return dbs def db_monodb(httprequest=None): diff --git a/odoo/service/db.py b/odoo/service/db.py index e335e5b685d..bdcf0e404d9 100644 --- a/odoo/service/db.py +++ b/odoo/service/db.py @@ -326,6 +326,14 @@ def exp_db_exist(db_name): def list_dbs(force=False): if not odoo.tools.config['list_db'] and not force: raise odoo.exceptions.AccessDenied() + + if not odoo.tools.config['dbfilter'] and odoo.tools.config['db_name']: + # In case --db-filter is not provided and --database is passed, Odoo will not + # fetch the list of databases available on the postgres server and instead will + # use the value of --database as comma seperated list of exposed databases. + res = sorted(db.strip() for db in odoo.tools.config['db_name'].split(',')) + return res + chosen_template = odoo.tools.config['db_template'] templates_list = tuple(set(['postgres', chosen_template])) db = odoo.sql_db.db_connect('postgres') diff --git a/odoo/tools/config.py b/odoo/tools/config.py index 97c0d2f3d09..375f55b4714 100644 --- a/odoo/tools/config.py +++ b/odoo/tools/config.py @@ -138,7 +138,7 @@ class configmanager(object): # WEB group = optparse.OptionGroup(parser, "Web interface Configuration") - group.add_option("--db-filter", dest="dbfilter", my_default='.*', + group.add_option("--db-filter", dest="dbfilter", my_default='', help="Filter listed database", metavar="REGEXP") parser.add_option_group(group)