From d3cc71db72f48c715dfeeb314f64e2cbb56ebe2a Mon Sep 17 00:00:00 2001 From: Martin Trigaux Date: Thu, 23 Jun 2022 10:10:13 +0000 Subject: [PATCH] [FIX] auth_totp: remove outdated trusted devices The trusted devices are valid for maximum 90 days (TRUSTED_DEVICE_AGE). No need to keep them in the list of trusted device, it may even be confusing. closes odoo/odoo#95796 X-original-commit: 49130e60a3c43fa3df0adddbd3359e437f5bc0b2 Signed-off-by: Martin Trigaux (mat) --- addons/auth_totp/models/auth_totp.py | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/addons/auth_totp/models/auth_totp.py b/addons/auth_totp/models/auth_totp.py index ac97cd2f5bc..8b7489e6e96 100644 --- a/addons/auth_totp/models/auth_totp.py +++ b/addons/auth_totp/models/auth_totp.py @@ -1,5 +1,9 @@ # -*- coding: utf-8 -*- -from odoo import models +from odoo import api, models +from odoo.addons.auth_totp.controllers.home import TRUSTED_DEVICE_AGE + +import logging +_logger = logging.getLogger(__name__) class AuthTotpDevice(models.Model): @@ -17,3 +21,11 @@ class AuthTotpDevice(models.Model): """Return True if device key matches given `scope` for user ID `uid`""" assert uid, "uid is required" return self._check_credentials(scope=scope, key=key) == uid + + @api.autovacuum + def _gc_device(self): + self._cr.execute(""" + DELETE FROM auth_totp_device + WHERE create_date < (NOW() AT TIME ZONE 'UTC' - INTERVAL '%s SECONDS') + """, [TRUSTED_DEVICE_AGE]) + _logger.info("GC'd %d totp devices entries", self._cr.rowcount)