[IMP] base_crypt: encrypting all passwords at the first check.

bzr revid: vmt@openerp.com-20101223163100-ib3qf9i4kiqkpn77
This commit is contained in:
Vo Minh Thu
2010-12-23 17:31:00 +01:00
parent a0640060f5
commit e9c8d9ce77
2 changed files with 18 additions and 42 deletions
-31
View File
@@ -1,31 +0,0 @@
<?xml version="1.0"?>
<openerp>
<data>
<!-- TODO not needed anymore, delete this file -->
<record model="ir.ui.view" id="view_users_form_simple_modif_inherit">
<field name="name">res.users.form.modif.inherit</field>
<field name="model">res.users</field>
<field name="type">form</field>
<field name="inherit_id" ref="base.view_users_form_simple_modif"/>
<field name="priority" eval="10"/>
<field name="arch" type="xml">
<field name="password" position="replace">
<field name="password" password="True"/>
</field>
</field>
</record>
<record model="ir.ui.view" id="view_users_form_inherit1">
<field name="name">res.users.form.inherit1</field>
<field name="model">res.users</field>
<field name="type">form</field>
<field name="inherit_id" ref="base.view_users_form"/>
<field name="arch" type="xml">
<field name="password" position="replace">
<field name="password" password="True"/>
</field>
</field>
</record>
</data>
</openerp>
+18 -11
View File
@@ -160,7 +160,7 @@ class users(osv.osv):
# Return early if no such id.
return False
stored_pw = self.maybe_encrypt_and_store(cr, stored_pw, id)
stored_pw = self.maybe_encrypt(cr, stored_pw, id)
res = {}
res[id] = stored_pw
@@ -202,7 +202,7 @@ class users(osv.osv):
# Return early if there is no such login.
return False
stored_pw = self.maybe_encrypt_and_store(cr, stored_pw, id)
stored_pw = self.maybe_encrypt(cr, stored_pw, id)
# Calculate an encrypted password from the user-provided
# password.
@@ -222,7 +222,7 @@ class users(osv.osv):
def check(self, db, uid, passwd):
print ">>>>>> check"
# TODO cannot use the cache as it would prevent the update by
# maybe_encrypt_and_store.
# maybe_encrypt.
#cached_pass = self._uid_cache.get(db, {}).get(uid)
#if (cached_pass is not None) and cached_pass == passwd:
# return True
@@ -254,17 +254,24 @@ class users(osv.osv):
# self._uid_cache[db] = {uid: passwd}
return bool(res)
def maybe_encrypt_and_store(self, cr, pw, id):
# Calculate a new password 'encrypted' from 'pw' if the
# latter isn't encrypted yet. Use it to update the database entry
# and return it, or simply return 'pw'.
def maybe_encrypt(self, cr, pw, id):
# If the password 'pw' is not encrypted, then encrypt all passwords
# in the db. Returns the (possibly newly) encrypted password for 'id'.
if pw[0:len(magic_md5)] != magic_md5:
encrypted = encrypt_md5(pw, gen_salt())
cr.execute('update res_users set password=%s where id=%s',
(encrypted.encode('utf-8'), id))
cr.execute('select id, password from res_users')
res = cr.fetchall()
for i, p in res:
encrypted = p
if p[0:len(magic_md5)] != magic_md5:
encrypted = encrypt_md5(p, gen_salt())
print ">>>>>> changing %s to %s" % (p, encrypted)
cr.execute('update res_users set password=%s where id=%s',
(encrypted.encode('utf-8'), i))
if i == id:
encrypted_res = encrypted
cr.commit()
return encrypted
return encrypted_res
return pw
users()