[FIX] auth_totp_mail
1. sudo permission for _totp_check env.user is still public user which doesn't have access rights for self.login in Odoo 15 it was not a problem since self.login was in cache but in Odoo 16 it is not and as a result, returns an access error 2. format_timedelta the lang was used for `granularity` as the second argument not for `locale` closes odoo/odoo#138532 X-original-commit: d439fae7a27874ceeaab99cc4db5d28fcbe587c2 Signed-off-by: Denis Ledoux (dle) <dle@odoo.com> Signed-off-by: Chong Wang (cwg) <cwg@odoo.com>
This commit is contained in:
@@ -49,12 +49,12 @@ class Users(models.Model):
|
||||
if user._mfa_type() != 'totp_mail':
|
||||
return super()._totp_check(code)
|
||||
|
||||
key = self._get_totp_mail_key()
|
||||
key = user._get_totp_mail_key()
|
||||
match = TOTP(key).match(code, window=3600, timestep=3600)
|
||||
if match is None:
|
||||
_logger.info("2FA check (mail): FAIL for %s %r", self, self.login)
|
||||
_logger.info("2FA check (mail): FAIL for %s %r", user, user.login)
|
||||
raise AccessDenied(_("Verification failed, please double-check the 6-digit code"))
|
||||
_logger.info("2FA check(mail): SUCCESS for %s %r", self, self.login)
|
||||
_logger.info("2FA check(mail): SUCCESS for %s %r", user, user.login)
|
||||
self._totp_rate_limit_purge('code_check')
|
||||
self._totp_rate_limit_purge('send_email')
|
||||
return True
|
||||
@@ -74,7 +74,7 @@ class Users(models.Model):
|
||||
code = hotp(key, counter)
|
||||
expiration = timedelta(seconds=3600)
|
||||
lang = babel_locale_parse(self.env.context.get('lang') or self.lang)
|
||||
expiration = babel.dates.format_timedelta(expiration, lang)
|
||||
expiration = babel.dates.format_timedelta(expiration, locale=lang)
|
||||
|
||||
return str(code).zfill(6), expiration
|
||||
|
||||
|
||||
Reference in New Issue
Block a user