[FIX] auth_totp: remove outdated trusted devices
The trusted devices are valid for maximum 90 days (TRUSTED_DEVICE_AGE). No need to keep them in the list of trusted device, it may even be confusing. closes odoo/odoo#95796 X-original-commit: 49130e60a3c43fa3df0adddbd3359e437f5bc0b2 Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
This commit is contained in:
@@ -1,5 +1,9 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
from odoo import models
|
||||
from odoo import api, models
|
||||
from odoo.addons.auth_totp.controllers.home import TRUSTED_DEVICE_AGE
|
||||
|
||||
import logging
|
||||
_logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
class AuthTotpDevice(models.Model):
|
||||
@@ -17,3 +21,11 @@ class AuthTotpDevice(models.Model):
|
||||
"""Return True if device key matches given `scope` for user ID `uid`"""
|
||||
assert uid, "uid is required"
|
||||
return self._check_credentials(scope=scope, key=key) == uid
|
||||
|
||||
@api.autovacuum
|
||||
def _gc_device(self):
|
||||
self._cr.execute("""
|
||||
DELETE FROM auth_totp_device
|
||||
WHERE create_date < (NOW() AT TIME ZONE 'UTC' - INTERVAL '%s SECONDS')
|
||||
""", [TRUSTED_DEVICE_AGE])
|
||||
_logger.info("GC'd %d totp devices entries", self._cr.rowcount)
|
||||
|
||||
Reference in New Issue
Block a user