From 31c1be1fac29cb0298827e1d686d956b0339df24 Mon Sep 17 00:00:00 2001 From: rde Date: Tue, 17 Oct 2017 11:27:20 +0200 Subject: [PATCH] [IMP] auth_oauth: prevent portal users to land on /web after login Before this commit, a portal user would land on /web after login in with oauth. He would then just see the "Website" app. He should then click on it to land on website instead of landing directly on it after login in, which is not convenient, especially since theses users doesn't know Odoo (in case of sale customers manually created for instance). Now, if users has no 'base.group_user' right, it will be redirected to the website directly instead of /web. --- addons/auth_oauth/controllers/main.py | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/addons/auth_oauth/controllers/main.py b/addons/auth_oauth/controllers/main.py index b7c1f13cf6b..3c3ddf84559 100644 --- a/addons/auth_oauth/controllers/main.py +++ b/addons/auth_oauth/controllers/main.py @@ -151,7 +151,11 @@ class OAuthController(http.Controller): url = '/web#action=%s' % action elif menu: url = '/web#menu_id=%s' % menu - return login_and_redirect(*credentials, redirect_url=url) + resp = login_and_redirect(*credentials, redirect_url=url) + #Since /web is hardcoded, verify user has right to land on it + if urlparse.urlparse(resp.location).path == '/web' and not request.registry['res.users'].has_group(request.cr, request.uid, 'base.group_user'): + resp.location = '/' + return resp except AttributeError: # auth_signup is not installed _logger.error("auth_signup not installed on database %s: oauth sign up cancelled." % (dbname,))