Commit Graph
196 Commits
Author SHA1 Message Date
Louis (wil) 3f6f949fa5 [I18N] export sources
closes odoo/odoo#140002

Related: odoo/enterprise#49687
Signed-off-by: Louis Wicket (wil) <wil@odoo.com>
2023-10-27 08:36:16 +00:00
Martin Trigaux 2afdda2576 [I18N] *: export saas-16.3 source terms
closes odoo/odoo#123046

X-original-commit: 137f5ca0cb703ee953cb01db525362f7a778e6bd
Related: odoo/enterprise#41703
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-06-01 11:43:51 +02:00
Louis Wicket (wil) 04189318cc [I18N] *: update master translations
Currently, only stable releases see their translations updated. This has
resulted in master accumulating outdated stuff for years, which can be
confusing for users testing master on runbot.

This one-shot commit resynchronizes master translations based on the
content from 16.0 and removes empty PO files (i.e. no longer containing
translations).

closes odoo/odoo#121629

Related: odoo/enterprise#41171
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-05-22 17:52:07 +02:00
Martin Trigaux 077bbd0b0b [I18N] *: export master source terms
closes odoo/odoo#121563

Related: odoo/enterprise#41140
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-05-17 10:34:00 +02:00
Martin Trigaux 1be5eae8ef [I18N] *: remove nl_BE files
They dates from < 2027 and are quite outdated. Favour the nl
translation instead.
n_BE is not on Transifex so it was not possible to correct bad
translations.

closes odoo/odoo#115845

X-original-commit: d04c8b7e484db8306d858c891a7a2b11885fdcd9
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-03-20 16:51:30 +01:00
Martin Trigaux 1a8772769e [I18N] *: export 16.0 source terms
closes odoo/odoo#100573

Related: odoo/enterprise#31507
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2022-09-20 13:48:49 +02:00
Martin Trigaux 5acb6db891 [I18N] *: export saas-15.4 source terms
closes odoo/odoo#93246

X-original-commit: 5ff6d185f70650c26c28a6aef7dd37c859ab58d2
Related: odoo/enterprise#28218
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2022-06-10 07:27:26 +02:00
Xavier Morel c5964f84d9 [FIX] auth_oauth: improve implicit flow implementation / compat
The current implementation is rather non-standard and largely an
ad-hoc pre-RFC implementation, with a number of incompatibilities with
the standard & actual real-world identity providers (IDP).

Tested with the following IDP:

- google oauth v1
- google oauth v3
- auth0
- okta

Add support to bearer Authorization
===================================

Sending the access token via "Authorization: Bearer $TOK" is strongly
recommended by the RFC, and required for all IDP to support. The query
parameter method is a legacy compatibility method and should be
avoided.

Query parameter access tokens are supported by Google (both v1 and
v3), and auth0, but not okta. All three support bearer tokens. However
making this the default is complicated by compatibility issues with
current behavior.

Use standard `sub`ject for identity
===================================

The specification defines `sub` as the userinfo key providing the user
identifier at the IDP.

- auth0, okta, and google v3 use `sub`
- google v1 uses `id`
- google v1's `tokeninfo` (possibly v3 as well, not tested) uses
  `user_id`
- odoo replicates the google v1 tokeninfo behavior, using `user_id`

All the code is now standardised on `sub`, with `_auth_oauth_validate`
performing unification under that key.

Support non-json error bodies and WWW-Authenticate
==================================================

Per-spec, there is no requirement for error (userinfo) responses to
return any body, and all error information can be returned via
`WWW-Authenticate`.

Both auth0 and okta return empty bodies on error, though only okta
returns a useful www-authenticate, or relevant 40x statuses (auth0
seems to always return 400, okta has been observed to return both 400
and 401 depending on client error).

Error handling in `_auth_oauth_rpc` has been updated to only parse the
body as json on success (200), and fallback on a generic error payload
if `WWW-Authenticate` doesn't contain relevant information.

Nonce
=====

Okta requires a nonce to be provided.

Misc
====

A few improvements which are in no way required but should make things
simpler / clearer:

- update the default scope to match the standard for the implicit
  flow's values (intersected with our requirements)
- update the default google configuration to use the v3 endpoints and
  drop the tokeninfo request, remove the explicit scopes
- update the label of `validation_endpoint` to match the official
  terminology, same with `auth_endpoint`
- add a label to `body` in order to explain what it's for (as that's
  really confusing when the form just says `body` until you hover the
  field)

Expected future updates
=======================

These issues were left out and may lead to degraded security, but were
considered too large changes fora stable compatibility-oriented
update:

* store and validate the nonce
* request and properly validate the id token, as well as validate the
  access token (implicit guide sections 2.2.1, 2.2.2)
* implement "basic" flow[^basic], and / or "hybrid" flow, the implicit
  flow[^implicit] is intended for purely client-side applications
  (SPAs), the "authorization code" flow is intended as the primary
  flow for normal web applications involving a server component,
  the main advantage of the hybrid flow is that the id token *can*
  contain the claims selected by `scope`, avoiding the need for the
  userinfo request[^idtoken]
* remove support for query parameter requests
* remove support for Google's v1 oauth and subject identifiers other
  than `sub`, facebook has not been tested but looks to support that
  key as well in the OpenGraph API[^fb], this will require migrating
  existing google providers to v3 implicitly (but would allow
  simplifying their configuration)

References: RFC 6749, RFC 6750, Implicit Client Implementer's Guide
1.0 draft 23[^implicit]

Closes #88618, closes #64348, fixes #63963, closes #63970,
closes #69568

[^implicit]: https://openid.net/specs/openid-connect-implicit-1_0.html
[^basic]: https://openid.net/specs/openid-connect-basic-1_0.html also
          known as "authorization code" flow
[^fb]: https://www.facebook.com/.well-known/openid-configuration
[^idtoken]: during testing, only auth0 returned the additional claims
            as part of the id token, but this may be a configuration
            issue

closes odoo/odoo#91262

X-original-commit: fb3c4845b1549bc2e1378620a5f01e52aa4dbbdb
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2022-05-13 07:44:52 +02:00
Martin Trigaux 2d00263127 [I18N] *: export saas-13.3 translations
closes odoo/odoo#50031

X-original-commit: 15a7a9f9d71a0b9c46d7caf2f4fbf09a5a4c63fe
Related: odoo/enterprise#10140
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-04-23 07:13:48 +00:00
Martin Trigaux b7d91ba25b [I18N] *: remove es_AR translations
Followup of a425695e
The terms were back in 12.0
Courtesy of Juan José Scarafía

closes odoo/odoo#41624

X-original-commit: 85d0c7001a997748d7691205bbb8d066597591a5
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2019-12-10 10:00:18 +00:00
Martin Trigaux 3a7bb6aefd [I18N] *: export 13.0 source terms
closes odoo/odoo#39118

X-original-commit: cfc887dc2032aac4f5894ade017dadab7a413557
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2019-10-21 12:12:48 +00:00
Andreas Perhab fd51030c43 [FIX] auth_oauth: enable translation of link text for oauth providers
closes odoo/odoo#38494

X-original-commit: 1e012dda76601437659b640b389fe2b73b6cbb3b
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
2019-10-11 11:38:20 +00:00
Odoo Translation Bot b6e7ed6c7b [I18N] Update translation terms from Transifex 2019-10-07 09:11:11 +02:00
Odoo Translation Bot 40deff7cbe [I18N] Update translation terms from Transifex 2019-10-01 21:21:46 +02:00
Odoo Translation Bot d7b8831ea8 [I18N] Update translation terms from Transifex 2019-09-29 01:22:33 +02:00
Odoo Translation Bot e80b81dca1 [I18N] Update translation terms from Transifex 2019-09-15 01:30:37 +02:00
Odoo Translation Bot 86809804f9 [I18N] Update translation terms from Transifex 2019-09-01 01:28:13 +02:00
Martin Trigaux b247aa3252 [I18N] *: export saas-12.5 source terms
That will be used a the basis for the future 13.0 version
Without demo data

closes odoo/odoo#36057

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2019-08-26 09:38:09 +00:00
Martin Trigaux 8be6470a82 [I18N] *: export saas-12.4 source terms 2019-08-13 11:53:38 +02:00
Odoo Translation Bot ec4ee14c89 [I18N] Update translation terms from Transifex 2018-12-09 01:16:26 +01:00
Odoo Translation Bot 1208ac6ce3 [I18N] Update translation terms from Transifex 2018-12-02 01:25:05 +01:00
Odoo Translation Bot 07f6b8ef57 [I18N] Update translation terms from Transifex 2018-11-25 01:26:32 +01:00
Odoo Translation Bot b60f9bb739 [I18N] Update translation terms from Transifex 2018-11-18 01:28:38 +01:00
Odoo Translation Bot dcc077afc5 [I18N] Update translation terms from Transifex 2018-11-11 01:26:46 +01:00
Odoo Translation Bot 790bd62f14 [I18N] Update translation terms from Transifex 2018-11-04 01:27:12 +01:00
Odoo Translation Bot 29dc21ae4b [I18N] Update translation terms from Transifex 2018-10-28 01:25:21 +02:00
Odoo Translation Bot de265ce63e [I18N] Update translation terms from Transifex 2018-10-21 01:25:56 +02:00
Odoo Translation Bot e774b2cb1c [I18N] Update translation terms from Transifex 2018-10-14 01:23:43 +02:00
Martin Trigaux 57884ccdc8 [I18N] all: convert remaining model: translation entries
It should be model_terms:

Fixes odoo/docker#219

closes odoo/odoo#27664
2018-10-11 09:49:01 +00:00
Odoo Translation Bot b6c8919444 [I18N] Update translation terms from Transifex 2018-10-07 02:27:57 +02:00
Odoo Translation Bot a01c1bf5bf [I18N] Update translation terms from Transifex 2018-09-30 02:25:45 +02:00
Odoo Translation Bot 5a439a85ef [I18N] Update translation terms from Transifex 2018-09-25 15:32:59 +02:00
Odoo Translation Bot 1d79bf0273 [I18N] Update translation terms from Transifex 2018-09-23 02:29:29 +02:00
Martin Trigaux ae1fed50d5 [I18N] export saas-11.5 source terms 2018-09-21 16:32:59 +02:00
Odoo Translation Bot 53908da50c [I18N] Update translation terms from Transifex 2018-09-18 18:08:33 +02:00
Martin trigaux 710f67ad4b [I18N] export saas-11.5 source terms
To match new model_terms syntax
2018-09-18 14:30:04 +02:00
Odoo Translation Bot e9111f46a6 [I18N] Update translation terms from Transifex 2018-09-16 02:21:25 +02:00
Odoo Translation Bot 0b2349ee41 [I18N] Update translation terms from Transifex 2018-09-14 11:30:58 +02:00
Odoo Translation Bot 55a5aca6d9 [I18N] Update translation terms from Transifex 2018-09-05 11:24:24 +02:00
Odoo Translation Bot e8606ce00b [I18N] Update translation terms from Transifex 2018-09-02 02:24:05 +02:00
Odoo Translation Bot f22e61dc74 [I18N] Update translation terms from Transifex 2018-08-29 14:19:27 +02:00
Odoo Translation Bot 0da9da4c44 [I18N] Update translation terms from Transifex 2018-08-26 02:17:37 +02:00
Odoo Translation Bot 935bac15df [I18N] Update translation terms from Transifex 2018-08-03 10:55:14 +02:00
Odoo Translation Bot 8aed99b0bd [I18N] Update translation terms from Transifex 2018-08-02 14:39:54 +02:00
Odoo Translation Bot 0b927cf590 [I18N] Update translation terms from Transifex 2018-04-01 07:07:32 +02:00
Martin Trigaux 7d86bdca21 [I18N] *: export source terms of saas-11.2 2018-03-22 15:19:07 +01:00
Odoo Translation Bot 09923c7bf6 [I18N] Update translation terms from Transifex 2018-02-11 07:05:39 +01:00
Odoo Translation Bot ed1740a6b7 [I18N] Update translation terms from Transifex 2018-02-04 07:05:04 +01:00
Odoo Translation Bot 770ebf19ac [I18N] Update translation terms from Transifex 2017-12-17 07:10:06 +01:00
Odoo Translation Bot 1a43e2e66f [I18N] Update translation terms from Transifex 2017-12-10 04:25:30 +01:00