Commit Graph
87 Commits
Author SHA1 Message Date
Florian Charlier dae28c4b46 [IMP] base: add _is_internal method to res.users
No method was readily available to know if a user is `internal` (has
group `base.group_user`), which was inconsistent with other base groups.

_is_internal is now used in the codebase where it is clear that
`.has_group('base.group_user')` is called on a single record.

Part-of: odoo/odoo#85703
2022-06-14 09:35:57 +02:00
Xavier Morel e0345512d9 [FIX] auth_oauth: google rejects nonce if response_type=token
I apparently missed this case in #88871: Google's legacy
flow (response_type=token) explicitly rejects a `nonce` parameter
being passed in the authentication request. The nonce parameter is
only accepted for an OIDC-conformant implicit flow request (aka
`response_type=token id_token`).

The specific endpoint doesn't seem to have any bearing on this, v1 and
v2 authentication endpoints result in the same behavior.

Drawback: Okta isn't supported anymore, as it requires the nonce, no
if, no but, even on "legacy" auth requests, possibly others. However
since these already weren't supported that's considered less of an
issue than possibly breaking compatibility with existing IDP.

Rejected alternative: adding `id_token` to the `response_type` to come
closer to OIDC-conformant request, however that was considered too
risky: Odoo clients could be using legacy IDP which also reject the
nonce parameter but don't have a magic "OIDC conformant" trigger.

closes odoo/odoo#91500

X-original-commit: 1fd738d9826f9bdfe8deddd5ef81dcb9757e8988
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
Signed-off-by: Olivier Dony <odo@odoo.com>
2022-05-16 20:18:24 +02:00
Xavier Morel c5964f84d9 [FIX] auth_oauth: improve implicit flow implementation / compat
The current implementation is rather non-standard and largely an
ad-hoc pre-RFC implementation, with a number of incompatibilities with
the standard & actual real-world identity providers (IDP).

Tested with the following IDP:

- google oauth v1
- google oauth v3
- auth0
- okta

Add support to bearer Authorization
===================================

Sending the access token via "Authorization: Bearer $TOK" is strongly
recommended by the RFC, and required for all IDP to support. The query
parameter method is a legacy compatibility method and should be
avoided.

Query parameter access tokens are supported by Google (both v1 and
v3), and auth0, but not okta. All three support bearer tokens. However
making this the default is complicated by compatibility issues with
current behavior.

Use standard `sub`ject for identity
===================================

The specification defines `sub` as the userinfo key providing the user
identifier at the IDP.

- auth0, okta, and google v3 use `sub`
- google v1 uses `id`
- google v1's `tokeninfo` (possibly v3 as well, not tested) uses
  `user_id`
- odoo replicates the google v1 tokeninfo behavior, using `user_id`

All the code is now standardised on `sub`, with `_auth_oauth_validate`
performing unification under that key.

Support non-json error bodies and WWW-Authenticate
==================================================

Per-spec, there is no requirement for error (userinfo) responses to
return any body, and all error information can be returned via
`WWW-Authenticate`.

Both auth0 and okta return empty bodies on error, though only okta
returns a useful www-authenticate, or relevant 40x statuses (auth0
seems to always return 400, okta has been observed to return both 400
and 401 depending on client error).

Error handling in `_auth_oauth_rpc` has been updated to only parse the
body as json on success (200), and fallback on a generic error payload
if `WWW-Authenticate` doesn't contain relevant information.

Nonce
=====

Okta requires a nonce to be provided.

Misc
====

A few improvements which are in no way required but should make things
simpler / clearer:

- update the default scope to match the standard for the implicit
  flow's values (intersected with our requirements)
- update the default google configuration to use the v3 endpoints and
  drop the tokeninfo request, remove the explicit scopes
- update the label of `validation_endpoint` to match the official
  terminology, same with `auth_endpoint`
- add a label to `body` in order to explain what it's for (as that's
  really confusing when the form just says `body` until you hover the
  field)

Expected future updates
=======================

These issues were left out and may lead to degraded security, but were
considered too large changes fora stable compatibility-oriented
update:

* store and validate the nonce
* request and properly validate the id token, as well as validate the
  access token (implicit guide sections 2.2.1, 2.2.2)
* implement "basic" flow[^basic], and / or "hybrid" flow, the implicit
  flow[^implicit] is intended for purely client-side applications
  (SPAs), the "authorization code" flow is intended as the primary
  flow for normal web applications involving a server component,
  the main advantage of the hybrid flow is that the id token *can*
  contain the claims selected by `scope`, avoiding the need for the
  userinfo request[^idtoken]
* remove support for query parameter requests
* remove support for Google's v1 oauth and subject identifiers other
  than `sub`, facebook has not been tested but looks to support that
  key as well in the OpenGraph API[^fb], this will require migrating
  existing google providers to v3 implicitly (but would allow
  simplifying their configuration)

References: RFC 6749, RFC 6750, Implicit Client Implementer's Guide
1.0 draft 23[^implicit]

Closes #88618, closes #64348, fixes #63963, closes #63970,
closes #69568

[^implicit]: https://openid.net/specs/openid-connect-implicit-1_0.html
[^basic]: https://openid.net/specs/openid-connect-basic-1_0.html also
          known as "authorization code" flow
[^fb]: https://www.facebook.com/.well-known/openid-configuration
[^idtoken]: during testing, only auth0 returned the additional claims
            as part of the id token, but this may be a configuration
            issue

closes odoo/odoo#91262

X-original-commit: fb3c4845b1549bc2e1378620a5f01e52aa4dbbdb
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-05-13 07:44:52 +02:00
Julien Castiaux 1dd3865208 [IMP] *: odoo.addons.web.controllers.main splitted
The odoo.addons.web.controllers.main python module have been splitted
over multiple files on the basis 1 controller = 1 file. In this work we
adapt all modules to use the new imports.

A non-exhaustive list of where stuff have been moved:

* main.Home		--> home.Home
* main.Session		--> session.Session
* main.WebClient	--> webclient.WebClient
* main.clean_action	--> action.clean_action
* main.ensure_db	--> home.ensure_db

The complete list is accessible in odoo.addons.web.controllers.main.

closes odoo/odoo#87571

Related: odoo/enterprise#25746
Signed-off-by: Raphael Collet <rco@odoo.com>
2022-03-31 02:10:53 +02:00
Julien Castiaux f04b90b6e8 [REF] core: HTTPocalypse (12) web ir.http & login
This commit is the 12th commit of a comprehensive refactor of our HTTP
framework. See odoo/odoo#78857 for complete historic, discussions and
rationnals.

The web module is twofold, on one side there are many controllers: /,
/web, /web/login, /web/database/selector, /web/dataset/call_kw, etc, on
the other side there is `session_info`: the method responsible to create
the web client's environ.

This module is kinda an exception as it is (with base) a server wide
module. In the case of the HTTP framework, it means that the controllers
of web are always accessible, i.e. going to / or /web/login will never
return a 404 Not Found even if the user is not connected to a database.

This is both a blessing and a curse. It is a blessing because the
controllers are always accessible it means that a new users can freely
access those routes. It is a curse because *any* user can access them,
even user who don't have a session yet thus who are not connected to a
database yet. From a developer standpoint, we have to put extra care to
correct serve users with and without a database. An example is the
/web/login route, the login/password pair is stored in a database,
without database it is impossible to validate a user login but users can
still access this route without db.

To solve this problem, there is the `ensure_db` function. This function
attempts to find a database using various sources (?db= query-string,
session db, mono db) and to save it on the user session. In case no db
is found, the user is redirected to the database selector. In a way,
this function grants a database to the user in a seamingly experience.
In a way, this function brings a welcome differentiation between
`auth='none'` with a database and `auth='none'` without a database. Such
differentiation only matters for the server wide modules as "regular"
module controllers are only accessible via the ir.http routing map, i.e.
it is not possible to declare a nodb controller outside of server wide
modules.

An important changement is the `session.authenticate` method, before it
was possible to call the method when the cursor was not yet initialized,
authenticate would open a cursor against the given database, setup a
registry and an environment and ultimately save everything on the
current request. Because the cursor is now greedily created, it is no
more possible to update the request environment when authenticating on
another database.

PR: odoo#78857
Task: 2571224
2022-02-24 13:30:50 +00:00
Jeremy Kersten 478068c829 [IMP] *: always use Odoo Response
This branch adds request.redirect on all requests.
In case of a front end request, we do an url_for to the location.

We removed redirect_with_hash that was only for retro compatibility

local_redirect has been renamed to redirect_query, and param keep_hash has been
removed and moved.

Default code for redirect is 303 now instead of 302.

Now redirect and redirect_query make local redirect by default, you need to
pass local=False to make external redirect.

All werkeug.utils.redirect has been replaced by request.redirect.

Http.redirect now use an http.Response type, and it become easy to add an
override like 'set_cookies' e.g.

Dispatch of a website.page return an http.response too, so we first need to
check if it is a cached version before to check if it is an Odoo Response.

Migrate your code:

http.redirect -> request.redirect(location, code, local)
http.local_redirect -> request.redirect_query(location, query, code, local)
http.redirect_with_hash -> request.redirect

Courtesy of odony for help and review ;)

closes odoo/odoo#72599

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-08 07:00:06 +00:00
Xavier Morel de590816d8 [FIX] *: deprecated access to url_ utilities through werkzeug root
In 0.15 accessing werkzeug.urls functions directly through werkzeug
is deprecated, the shortcut will be removed in the eventual werkzeug
1.0.

Fix existing uses of these shortcuts. Also cleanup some imports when
they're not far from a werkzeug* import being altered.
2020-02-04 12:42:35 +00:00
Christophe Simonis d61873ac4a [MERGE] forward port branch saas-15 up to 10d88083a0 2019-08-29 13:37:39 +02:00
Jairo Llopis 7c99310b23 [FIX] auth_oauth: Override qcontext in the right place
Before this patch, if some module was based on top of `auth_signup`, and `auth_oauth` was also installed in the same database, the only way to get the proper qcontext would be to call `super()` inside `web_auth_signup_qcontext`, which would produce a login, which is most likely not desired because such addon would try to add some logic on top of it that maybe prevents login based on some circumstances.

After this patch, any submodules can work properly without workarounds.

closes odoo/odoo#34690

Signed-off-by: Christophe Simonis <chs@odoo.com>
2019-07-09 11:31:25 +00:00
Christophe Simonis e354142ce7 [MERGE] forward port branch saas-15 up to c22e479246 2018-07-10 13:21:06 +02:00
Christophe Simonis 5e682451cb [MERGE] forward port branch 9.0 up to 8b25099aea 2018-07-10 11:25:27 +02:00
Andreas Perhab 8b25099aea [FIX] auth_oauth: validate db against db_filter 2018-07-09 18:55:11 +02:00
Christophe Simonis 5ea0f55d65 [MERGE] forward port branch saas-15 up to bee0c11ef7 2017-10-20 17:57:21 +02:00
Christophe Simonis e2532f855f [MERGE] forward port branch 9.0 up to 31c1be1fac 2017-10-20 16:02:12 +02:00
rde 31c1be1fac [IMP] auth_oauth: prevent portal users to land on /web after login
Before this commit, a portal user would land on /web after login in with oauth.
He would then just see the "Website" app.
He should then click on it to land on website instead of landing directly on it
after login in, which is not convenient, especially since theses users doesn't
know Odoo (in case of sale customers manually created for instance).

Now, if users has no 'base.group_user' right, it will be redirected to the
website directly instead of /web.
2017-10-20 15:25:28 +02:00
xmo-odoo b4429c2a91 [FIX] Various P3-related import changes
* LDAP import: python-ldap is not python3-compatible, pyldap is

  Warning: only supported from debian Stretch (current testing)?
  https://packages.debian.org/search?searchon=names&keywords=pyldap

* implicitly relative imports
* imports of moved or removed stdlib modules

issue #8530
2017-04-28 09:06:53 +02:00
Xavier Morel 3979f6802e [#8530] convert exception handlers to except..as syntax
Futurize fixers:
* lib2to3.fixes.fix_except
2017-04-11 14:53:29 +02:00
jaredkipe 4b500aa298 [FIX] auth_oauth: remove redirect if there is only 1 provider
Forcing the redirection for 1 provider but not for 2 makes no sense.
Was done at 311f041f for the reset password, applied to signup too.

Closes #15032
2017-01-16 13:49:59 +01:00
Christophe Simonis 1a77d9d02a [MERGE] forward port branch saas-12 up to 476cb5a0 2016-09-03 23:57:57 +02:00
Denis Ledoux 311f041f7f [FIX] auth_oauth: pass reset, remove auto redirect when only one provider
Even if there is only one provider,
you could still use the internal login rather than
this oauth provider to sign in,
and therefore you need to remain on the regular
login page if you would like to reset your internal password
2016-08-29 11:46:35 +02:00
Kinjal Mehta 3f201066f0 [MIG]auth_oauth: Migrate to new api. 2016-08-02 16:02:29 +02:00
Christophe Simonis 521b90a8da [MERGE] forward port of branch saas-6 up to 12d7996 2015-12-08 15:17:06 +01:00
Christophe Simonis 12d799623c [MERGE] forward port of branch 8.0 up to 83a4a58 2015-12-08 13:03:08 +01:00
Christophe Simonis 83a4a582fa [MERGE] forward port of branch saas-3 up to 513cea6 2015-12-08 12:28:41 +01:00
Christophe Simonis 513cea69c6 [FIX] auth_oauth: do not transfer debug flag to OAuth provider
This parameter is not part of the spec [1] and may not be supported by
all OAuth providers.

[1] http://tools.ietf.org/html/rfc6749#section-4.2.1
2015-12-08 12:16:42 +01:00
Leonardo Rochael Almeida 60af7cac02 [IMP] replace simplejson with stdlib json
The stdlib version of the json library is more recent than the 3.5.3
version we are pinning in `requirements.txt`

There is no reason to use it.

Closes #6940
2015-09-28 10:53:32 +02:00
Richard Mathot 03d71ad88c [REM] auth_oauth: remove legacy code
The forwardport has been done and these fields are required, so we can
safely shorten the domain.
2015-03-31 09:34:19 +02:00
Christophe Simonis 18e22be138 [MERGE] forward port of branch 8.0 up to 0aab81c 2015-01-19 17:15:56 +01:00
Denis Ledoux 36a6876980 [FIX] auth_oauth: avoid double slashed redirect urls 2015-01-12 12:02:06 +01:00
Christophe Simonis fab4d6d442 [MERGE] forward port of branch 8.0 up to ea54d4a 2015-01-06 11:49:04 +01:00
Leonardo Donelli 4a0b13ed92 [REF] remove vim modelines and resulting trailing blank lines
Let 2015 be a year without modelines!
cf #4174
2014-12-31 15:52:13 +01:00
Christophe Simonis 68134d38a3 [FIX] auth_oauth: ignore "debug" argument when converting fragment to query string 2014-12-12 15:11:08 +01:00
rlu-odoo 8b67a7202d [REF] OpenERP --> Odoo in various UI texts
Rebranding has been done in:
- data/demo files
- html templates
- help notices
- comments
- logger messages
- and other various messages

(Commit taken from odoo-dev:8.0-improve-openerp-odoo-rlu at rev 7deaa08)

Closes #1260
2014-07-18 13:45:41 +02:00
Olivier Dony d9cda97cf4 [MERGE] Forward-port saas-4 up to 5ceded9 2014-07-05 01:28:19 +02:00
Olivier Dony 5ceded9d69 [MERGE] Forward-port saas-3 up to 4fa30f5 2014-07-05 01:04:19 +02:00
Richard Mathot 376cdf36b4 [FIX] auth_oauth: prevent crash on login screen
Empty URLs for OAuth providers do not crash anymore the login screen
2014-07-02 13:56:11 +02:00
Christophe Simonis adf07a9490 [MERGE] forward port of branch saas-4 up to 5087612 2014-06-19 16:13:35 +02:00
Christophe Simonis 5087612d1d [MERGE] forward port of branch saas-3 up to bf53aed 2014-06-19 15:44:07 +02:00
Denis Ledoux b587038570 [FIX] auth_oauth: url_unquote_plus does not handle boolean
If the redirect param 'r' is not in the state, do no try to unquote it
2014-06-17 09:26:20 +02:00
Denis Ledoux a3cfe1728d [FIX] auth_oauth: unquote redirect url from state
This is related to 2db6a0080f. Looks like Firefox auto unquote, but not Chrome
2014-06-16 22:52:50 +02:00
Denis Ledoux 2db6a0080f [FIX] auth_oauth: quote redirect url in state
Otherwise, Firefox is splitting the state at the first &, which can potentially be located in the redict param of the state
2014-06-16 22:40:31 +02:00
Denis Ledoux 0a537dae91 [FIX] auth_oauth: missing res_users.py diff from rev 33bfec2174
Most probably due to github migration
+  fix: directly redirect to login redirect paramas, instead of redirecting on the complete  web/login + redirect url
2014-06-02 18:47:41 +02:00
Christophe Simonis 8ac408f70e [FIX] auth_oauth: controller need to inherit from auth_signup controller 2014-06-02 15:17:58 +02:00
Christophe Simonis 3a7e003656 [MERGE] forward port of branch saas-3 up to revid 9394 chs@openerp.com-20140410103638-x7vajn70ewsfp0ck
bzr revid: chs@openerp.com-20140410110424-enhdg6pufhii56ni
2014-04-10 13:04:24 +02:00
Denis Ledoux ff76882701 [FIX] auth_oauth: avoid infinite loop while trying to sign in
bzr revid: dle@openerp.com-20140407155919-vm32q6nvcit59026
2014-04-07 17:59:19 +02:00
Denis Ledoux 6027657e3e [FIX] auth_oauth: redirect to url before sign in
bzr revid: dle@openerp.com-20140407150027-z46yxuh3a9uqoz26
2014-04-07 17:00:27 +02:00
Christophe Simonis d93b79e6f4 [MERGE] forward port of branch saas-3 up to revid 9345 dle@openerp.com-20140324110349-e82t1bmmtjqbl85k
bzr revid: chs@openerp.com-20140324133811-4az1kvbznd26seow
2014-03-24 14:38:11 +01:00
Fabien Meghazi a8f513f4f2 [MERGE] upstream
bzr revid: fme@openerp.com-20140312152942-egbzui0drs85wt7i
2014-03-12 16:29:42 +01:00
Fabien Meghazi 2ed053642a [IMP] oaut & signup, redirect if already logged in
bzr revid: fme@openerp.com-20140312112141-uvo89w4ovmzq5ozq
2014-03-12 12:21:41 +01:00
Christophe Simonis d504764eff [MERGE] forward port of branch saas-3 up to revid 9298 chm@openerp.com-20140311130852-3ft0v1mc9ht1any6
bzr revid: chs@openerp.com-20140311145205-s56fj113fsrnisc3
2014-03-11 15:52:05 +01:00