[FIX] auth_totp_mail

1. sudo permission for _totp_check
env.user is still public user which doesn't have access rights for self.login
in Odoo 15 it was not a problem since self.login was in cache
but in Odoo 16 it is not and as a result, returns an access error

2. format_timedelta
the lang was used for `granularity` as the second argument not for `locale`

closes odoo/odoo#138532

X-original-commit: d439fae7a27874ceeaab99cc4db5d28fcbe587c2
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
Signed-off-by: Chong Wang (cwg) <cwg@odoo.com>
This commit is contained in:
Chong Wang (cwg)
2023-10-16 07:58:42 +00:00
parent 3044b67372
commit fc587dc61b
@@ -49,12 +49,12 @@ class Users(models.Model):
if user._mfa_type() != 'totp_mail':
return super()._totp_check(code)
key = self._get_totp_mail_key()
key = user._get_totp_mail_key()
match = TOTP(key).match(code, window=3600, timestep=3600)
if match is None:
_logger.info("2FA check (mail): FAIL for %s %r", self, self.login)
_logger.info("2FA check (mail): FAIL for %s %r", user, user.login)
raise AccessDenied(_("Verification failed, please double-check the 6-digit code"))
_logger.info("2FA check(mail): SUCCESS for %s %r", self, self.login)
_logger.info("2FA check(mail): SUCCESS for %s %r", user, user.login)
self._totp_rate_limit_purge('code_check')
self._totp_rate_limit_purge('send_email')
return True
@@ -74,7 +74,7 @@ class Users(models.Model):
code = hotp(key, counter)
expiration = timedelta(seconds=3600)
lang = babel_locale_parse(self.env.context.get('lang') or self.lang)
expiration = babel.dates.format_timedelta(expiration, lang)
expiration = babel.dates.format_timedelta(expiration, locale=lang)
return str(code).zfill(6), expiration