From fc587dc61b35da03448da77745d5ec5acd62740f Mon Sep 17 00:00:00 2001 From: "Chong Wang (cwg)" Date: Wed, 11 Oct 2023 23:16:45 +0200 Subject: [PATCH] [FIX] auth_totp_mail 1. sudo permission for _totp_check env.user is still public user which doesn't have access rights for self.login in Odoo 15 it was not a problem since self.login was in cache but in Odoo 16 it is not and as a result, returns an access error 2. format_timedelta the lang was used for `granularity` as the second argument not for `locale` closes odoo/odoo#138532 X-original-commit: d439fae7a27874ceeaab99cc4db5d28fcbe587c2 Signed-off-by: Denis Ledoux (dle) Signed-off-by: Chong Wang (cwg) --- addons/auth_totp_mail_enforce/models/res_users.py | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/addons/auth_totp_mail_enforce/models/res_users.py b/addons/auth_totp_mail_enforce/models/res_users.py index b730af1d007..063e193dc37 100644 --- a/addons/auth_totp_mail_enforce/models/res_users.py +++ b/addons/auth_totp_mail_enforce/models/res_users.py @@ -49,12 +49,12 @@ class Users(models.Model): if user._mfa_type() != 'totp_mail': return super()._totp_check(code) - key = self._get_totp_mail_key() + key = user._get_totp_mail_key() match = TOTP(key).match(code, window=3600, timestep=3600) if match is None: - _logger.info("2FA check (mail): FAIL for %s %r", self, self.login) + _logger.info("2FA check (mail): FAIL for %s %r", user, user.login) raise AccessDenied(_("Verification failed, please double-check the 6-digit code")) - _logger.info("2FA check(mail): SUCCESS for %s %r", self, self.login) + _logger.info("2FA check(mail): SUCCESS for %s %r", user, user.login) self._totp_rate_limit_purge('code_check') self._totp_rate_limit_purge('send_email') return True @@ -74,7 +74,7 @@ class Users(models.Model): code = hotp(key, counter) expiration = timedelta(seconds=3600) lang = babel_locale_parse(self.env.context.get('lang') or self.lang) - expiration = babel.dates.format_timedelta(expiration, lang) + expiration = babel.dates.format_timedelta(expiration, locale=lang) return str(code).zfill(6), expiration