Commit Graph
21 Commits
Author SHA1 Message Date
Thomas (thbe) 922d8efe79 [ADD] auth_{signup,totp}: New connection to user mail alert
Prior to this, there was no way of knowing when a new device logged
into your personnal account.

Adding the new version of the authenticate function, user's will now
automaticly receive a mail containing informations on a new connection
made to their account.  This system uses a mail template sent
automaticly on a new connection if the user has activated 2FA and if
his device his not in the trusted devices of his account.

task-3191567

closes odoo/odoo#115362

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2023-10-25 11:37:09 +00:00
Florian Vranckx 4ac35f1170 [IMP] auth_signup, auth_totp: isolate signup_token and auth_totp
This commit is a security reinforcement.

It applies the same logic as for the password of the user to the totp_secret and signup_token

closes odoo/odoo#113753

Signed-off-by: Vranckx Florian (flvr) <flvr@odoo.com>
2023-02-28 18:08:12 +01:00
Martin Trigaux d3cc71db72 [FIX] auth_totp: remove outdated trusted devices
The trusted devices are valid for maximum 90 days (TRUSTED_DEVICE_AGE).
No need to keep them in the list of trusted device, it may even be
confusing.

closes odoo/odoo#95796

X-original-commit: 49130e60a3c43fa3df0adddbd3359e437f5bc0b2
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2022-07-12 06:21:03 +02:00
Olivier Dony 038cdc66b9 [IMP] auth_totp: add trusted device method to validate user
Adds a variant `_check_credentials_for_uid()` for auth_totp.device's
`_check_credentials()`. The new method will directly verify the device
key matches the given uid.

This spares the redundant uid comparison on the caller side, and
allows extension modules to customise the user/device matching logic.

closes odoo/odoo#94365

X-original-commit: 0e266eb3c73409950d1eb160c41eb6668d439856
Signed-off-by: Olivier Dony <odo@odoo.com>
2022-06-23 02:05:42 +02:00
Raphael Collet 6cf8db906f [REF] *: adapt code to new flush API
closes odoo/odoo#87527

Related: odoo/upgrade#3497
Related: odoo/enterprise#26939
Signed-off-by: Raphael Collet <rco@odoo.com>
2022-05-25 18:00:47 +02:00
Denis Ledoux a08a0b6454 [ADD] auth_totp_mail: 2FA using code sent by email
Add the possibility to force the two-factor authentication for all users,
using a two-factor authentication by email
when the 2FA using an Authenticator app is not configured for the user.

Two possibilities:
 - Force the 2FA only for employee users using the system parameter `auth_totp.policy=employee_required`
 - Force the 2FA for all users, employees and portals, using the system parameter `auth_totp.policy=all_required`

closes odoo/odoo#83750

Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
2022-02-01 17:15:30 +00:00
simonev 2857980a6c [FIX] auth_totp: add missing model decorator on change_password method override
Declared as an api.model in all the other modules except auth_totp

closes odoo/odoo#79726

X-original-commit: 61b319ea2b5ffc70e0fd80eb62b8a3f700be0f1f
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-11-12 18:07:15 +00:00
David Beguin eb2e328275 [FIX-MOV] auth_totp, auth_totp_invite: move 2FA invite mail to new bridge module
Since 29db699e9b, auth_top depends of mail module, which lead to delay auth_totp
installation - not during DB creation anymore. As mail module is not installed
during DB creation, once an app that depends on mail is installed after DB
creation, auth_top module is finally installed and the session token now depends
auth_top module. As a result, the user is automatically logged out.

This commit moves the invite mail (and the dependance to 'mail' module) to a
new bridge module. Auth_totp module will now be reinstalled during DB creation
automatically.

Task-2638538
Parent Task-2487630
COM PR: odoo/odoo#76022
UPG PR: odoo/upgrade#2808

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-09-06 15:47:23 +00:00
Arnaud GonyandMartin Trigaux 2dee29a7dc [IMP] auth_totp: 2FA Trusted Devices
+ Added the 'Trusted Devices' feature
+ Added 'Remember this Device' checkbox on /web/login/totp
+ Added trusted device's OS / browser on Profile > Account Security

Added '2FA Trusted Devices' feature to allow users to remember their
device to bypass the 2FA for the next connections. The trusted devices
are displayed in a 'Trusted Devices' One2Many under the 'Developer API
Keys'. It is possible to revoke all the trusted devices at once with a
special button. It is also possible to revoke one at a time on the
desired one.

Task-id 2523092

closes odoo/odoo#75535

Related: odoo/upgrade#2800
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Co-authored-by: Martin Trigaux <mat@odoo.com>
2021-09-06 13:17:48 +00:00
David Beguin 09f6ae5b95 [MOV] auth_top: reorganise module to set content in proper place
This commit juste moves the different part of code (class, views, data) in the
correct file where they belong.

Task-2487630

Part-of: odoo/odoo#71142
2021-08-30 21:05:12 +00:00
David Beguin 29db699e9b [IMP] auth_top, *: revamp Two-factor authentication flow
Purpose
=======

Review the UX of the 2-factor authentication flow in order to make it more clear
and easy to use.

Specifications
==============

This commit applies multiple rewording of instructions, button, etc. Tests have
been adapted accordingly.

It also adds an 'invite to use two-factor authentication' flow that will
send an email to the selected used to redirect them their account security
settings.
- If portal is not installed yet, the user is redirected to his account security
settings in backend.
- If portal is installed, the user is redirected to /my/profile if them are
portal user. Otherwise, the redirection is still done at backend side.

As the backend view of auth_totp wizard is used at frontend side, copyclipboard
widget has to be rebuilt at frontend side (click event, style etc..).

As API key section is now displayed only on debug mode, test urls have been
adapted accordingly.

Task-2487630

Part-of: odoo/odoo#71142
2021-08-30 21:05:12 +00:00
Raphael Collet 35a9f6c27a [FIX] core: SELF_READABLE_FIELDS and SELF_WRITEABLE_FIELDS on res.users
Avoid setting up those lists with method __init__() on the model, since
the model's class no longer has the expected parent classes.
2021-05-06 07:30:24 +00:00
Xavier Morel 6f4f8f0265 [IMP] auth_totp: notify user on activation and deactivation of OTP
Was not super visible, especially without HR as the dialog immediately
closes (limitation of the web client), or when an administrator user
massively disables totp.

Show a toast notification indicating the success of the action.

Also fix the logging of `totp_disable` so it correctly handles being
called on more than one record, and change the logging data to
<browse_record> (<logins>) across the board.

Also add a way to provide an action to execute after a notification:
by default nothing happens, which leads to dialogs not closing and
forms not reloading, and there is no good way to show a notification
and/then do some other thing, which is inconvenient.
2020-09-10 12:49:00 +00:00
Xavier Morel eac225e3ea [IMP] auth_totp: label of totp_enabled field & show status in form
Use same look in form as in preferences dialog, just without the
buttons to enable / disable it (technically could have the button to
disable with the correct group I guess?)
2020-09-10 12:49:00 +00:00
Xavier Morel ba03154d63 [IMP] auth_totp: better issuer label
The "issuer" being the user's company is not necessarily helpful as
e.g. the company might have multiple services which all use 2FA.

Use the domain name instead (fallback on the company if for some
reason we're in a situation where this is computed without a request).
2020-09-10 12:47:42 +00:00
Xavier Morel 70b6ac5009 [IMP] auth_totp: allow spaces in totp code input
TOTP programs generally group the code into two groups of 3 digits,
but we'd only allow a single group of 6 digits.

Allow spaces in the value for a bit of flexibility, and fix
placeholders to look like codes (also turns out @placeholder on a
field doesn't do anything, not sure where I got this idea).

Also improve the label slightly in the login flow:

* add information to the label itself
* properly link the label & input via an `id`
2020-09-10 12:47:15 +00:00
Xavier Morel 011d55d3e1 [FIX] auth_totp: session update after enabling or disabling totp
bfcc7dee8f tried to fix the session
disconnection issue, but the fix only worked in single-process (either
threaded or workers=1): because the cache was cleared but the update
not flushed, since `_compute_session_token` uses SQL directly it would
recompute the old session_token which it would cache, and thus the
process would carry-on with the old token just re-set in the session
and cache.

Meanwhile in multi-process, odds are good that the next request will
be on a different worker which *will* see the change, and will
immediately complain & destroy the session.

Add the missing flush calls right before recomputing the session token
so the SQL "sees" the correct state.
2020-09-10 12:46:10 +00:00
Xavier Morel f3574caf7c [IMP] auth_totp: import qrcode lazily
fp request

closes odoo/odoo#57377

X-original-commit: e10cbc792f8f6432f8ee5d8065cd4a123f2a4754
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-09-09 15:23:01 +00:00
Xavier Morel bfa00919cd [IMP] core: clarify making fields inaccessible
* add a constant to `fields` for that purpose
* add a test to ensure that it works as expected
* fix the formatter so it handles the pattern correctly
2020-08-17 09:30:53 +00:00
Olivier Dony bfcc7dee8f [FIX] auth_totp: add totp secret to session-relevant fields
Setting the totp secret is a significant change to the user's
auth-ability, and as such should be taken in account for the session's
validity.

For convenience, update the user's session in-place to avoid logging
them out.
2020-08-17 09:30:41 +00:00
Xavier MorelandOlivier Dony a9a6509713 [ADD] auth_totp
New module for supporting two-factor authentication via time-base
one-time-password (TOTP).

Users (including portal users) can choose to enable two-factor auth in
their user account settings, by scanning a QR code and adding it to an
authenticator app, such as Google Auth, 1Password, etc.

When two-factor is enabled, password-based non-interactive RPC is only
possible by using API keys.

Co-authored-by: Olivier Dony <odo@odoo.com>
2020-08-14 23:06:24 +00:00