Commit Graph
26 Commits
Author SHA1 Message Date
Gorash 774a3fad0e [REF] base,all: Update modifier syntax: view migration
Apply of the migration script to update all view modifiers.

Part-of: odoo/odoo#104741
2023-08-18 09:49:13 +02:00
Florian Vranckx 4ac35f1170 [IMP] auth_signup, auth_totp: isolate signup_token and auth_totp
This commit is a security reinforcement.

It applies the same logic as for the password of the user to the totp_secret and signup_token

closes odoo/odoo#113753

Signed-off-by: Vranckx Florian (flvr) <flvr@odoo.com>
2023-02-28 18:08:12 +01:00
amdi-odoo 2a015600b2 [FIX] web,auth_totp,base: fix 2FA views
Web:

Adding a css rule constraint to avoid the rule
from overwriting the o_field_highlight css class
applied on a field in a form view.

Base, auth_totp:

Adding the o_field_highlight class on the 2FA
form fields to display the input bottom border and
thereby more easily identify the fields.

Adding a placeholder to the 2FA password field.

Modifying the 2FA title and toggle font to keep
a consistency between the different page titles.

Task-3083540

closes odoo/odoo#108611

X-original-commit: c128a01490bbbcbf824781f5e8716aa30e65ba5b
Signed-off-by: Warnon Aurélien (awa) <awa@odoo.com>
2022-12-26 11:39:47 +01:00
Damien Bouvy e647a2de09 [IMP] *: adapt to grid form views
The recent switch from tables to css grids for form views `group` nodes
has introduced several inconsistencies/issues with several views accross
modules - these will not be the last fixes.

closes odoo/odoo#102174

X-original-commit: 836568dfd59886a6d52f15e0e2109709903b6803
Related: odoo/enterprise#32295
Signed-off-by: Bouvy Damien (dbo) <dbo@odoo.com>
2022-10-11 13:15:12 +02:00
Romain Estievenart 98a97d0fea [IMP] *: removes .form-group
this commit removes the usage of .form-group class which is deprecated
since BS5.

Here is the css rules that was used:

a) https://github.com/twbs/bootstrap/blob/8fa0d3010112dca5dd6dd501173415856001ba8b/dist/css/bootstrap.css#L1997
As we can see, it simply adds a `margin-bottom` of `1rem` which
corresponds to the `.mb-3` BS class.

b) https://github.com/twbs/bootstrap/blob/8fa0d3010112dca5dd6dd501173415856001ba8b/dist/css/bootstrap.css#L2326
As we already checked all `form-inline` in [1] and [2], we don't have to
do anything about these rules.

'''Breaking change: Dropped form-specific layout classes for our grid
system.
Use our grid and utilities instead of .form-group, .form-row, or
.form-inline.'''

https://getbootstrap.com/docs/5.0/migration/#forms

Notes:
- `position: relative` is already on `#new-password-group`.
- `.field-db`, `#editor-media-image`, `.unsplash_img_container` and
`#url-form-group` seems unused.
- Sometimes margins are unnecessary because of blocks overlapping.
  (e.g. `margin-bottom` is not needed if margin-top is set on the
  following node)
- CSS rules applied on `.s_website_form_rows > .form-group` are now in
the XML by adding `mb-0 py-2` BS classes.

Follow-up of:
[1] https://github.com/odoo/odoo/pull/97967
[2] https://github.com/odoo/enterprise/pull/30343

closes odoo/odoo#100052

Related: odoo/enterprise#31261
Signed-off-by: Adrien Dieudonné (adr) <adr@odoo.com>
2022-09-16 20:51:56 +02:00
Paul Morelle 972b54f918 [FIX] auth_totp,auth_totp_portal: fix typo in login verb
Login is a noun and not a verb. The corresponding verb is Log in.
And indeed the translation in French was "Identifiant" instead of
"Se connecter".

closes odoo/odoo#99478

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2022-09-06 10:58:13 +02:00
Romain Estievenart 36628c9b1c [FIX] *: removes .form-inline
this commit removes the usage of .form-inline class which is deprecated
since BS5.

here is the css rules that was used:
https://github.com/twbs/bootstrap/blob/8fa0d3010112dca5dd6dd501173415856001ba8b/dist/css/bootstrap.css#L2303

'''Breaking change: Dropped form-specific layout classes for our grid
system.
Use our grid and utilities instead of .form-group, .form-row, or
.form-inline.'''

https://getbootstrap.com/docs/5.0/migration/#forms

We also took the opportunity to remove some .input-group-append and
.form-group. We are currently working to remove all of them.

Part-of: odoo/odoo#97967
2022-08-16 09:19:08 +02:00
Romeo Fragomeli 1fcd098af5 [REF] *: BS5: migration
Automated change made by a lot of RegEx to change all think that is
possible to automate.

https://getbootstrap.com/docs/5.1/migration

Task ID: 2766483

Part-of: odoo/odoo#95450
2022-07-07 13:30:24 +02:00
Romeo Fragomeli eee625bbb0 [REF] *: BS5: Migrate btn-block
Due to the removal of btn-block we need to change the display to grid

> Dropped .btn-block for utilities. Instead of using .btn-block on the
> .btn, wrap your buttons with .d-grid and a .gap-* utility to space
> them as needed

https://getbootstrap.com/docs/5.1/migration/#buttons

Task ID: 2766483

Part-of: odoo/odoo#95450
2022-07-07 13:30:23 +02:00
Olivier Dony 6b23d8a2ca [FIX] auth_totp: show trusted devices in user prefs
PR #75535 introduced trusted devices, but only made them visible in the
main user form (for admins) and in the portal.

It's quite useful for users to be able to view and manage their trusted
devices in their own user preferences as well.

This commit add them in the "Account Security" of the user profile.

In addition:
- improve the layout of the trusted devices by wrapping them in a
  <group> to have them stand out from the surrounding prefs
- move the "Account is protected" label about the trusted devices, and
  under main the 2FA toggle button, where it's supposed to be.
- removed the custom form view for trusted devices inside the one2many.
  The point was to hide the extra `scope` field, but it's not worth it,
  and the Cancel button wasn't even working, the default form view is
  better.
- improve the confirmation message of the "Revoke All" button when it's
  located on the user management form (for admins) to clarify that it's
  not the admin's devices that will be revoked.
- change the 2FA label from "Your Account is protected" to "This account is
  protected" when located on the user management form for admins.

Note: this is a manual partial fwd-port of #94111, as this part was
mistakenly dropped in the fwd-port chain at #94193

closes odoo/odoo#94869

X-original-commit: d3a7910788ceff856fc6a843876579d379ce9caf
Signed-off-by: Olivier Dony <odo@odoo.com>
2022-06-29 17:11:39 +02:00
Antoine Vandevenne (anv) adf70bf9dc [FIX] *: retarget documentation links to master
closes odoo/odoo#84990

X-original-commit: 39bdf46
Related: odoo/enterprise#24582
Signed-off-by: Antoine Vandevenne (anv) <anv@odoo.com>
2022-02-21 17:01:02 +00:00
std-odooandnounoubensebia cd8e0e9f46 [IMP] base, *: hide non-relevant fields for portal users
Purpose
=======
Hide non-relevant fields for a portal user. E.G. we want to hide the
notification type,  the menu customization... Because those fields
make no sense for a portal user.

Force the non-internal user to receive notifications by emails since
they can not open Discuss.

Task-2508521

Part-of: odoo/odoo#77766
Co-authored-by: nounoubensebia <neb@odoo.com>
2021-11-09 14:45:49 +00:00
Xavier Morel 499b1621ba [FIX] *: non-accessible buttons
closes odoo/odoo#76581

Related: odoo/enterprise#20897
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2021-09-15 15:22:58 +00:00
David Beguin eb2e328275 [FIX-MOV] auth_totp, auth_totp_invite: move 2FA invite mail to new bridge module
Since 29db699e9b, auth_top depends of mail module, which lead to delay auth_totp
installation - not during DB creation anymore. As mail module is not installed
during DB creation, once an app that depends on mail is installed after DB
creation, auth_top module is finally installed and the session token now depends
auth_top module. As a result, the user is automatically logged out.

This commit moves the invite mail (and the dependance to 'mail' module) to a
new bridge module. Auth_totp module will now be reinstalled during DB creation
automatically.

Task-2638538
Parent Task-2487630
COM PR: odoo/odoo#76022
UPG PR: odoo/upgrade#2808

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-09-06 15:47:23 +00:00
Arnaud GonyandMartin Trigaux 2dee29a7dc [IMP] auth_totp: 2FA Trusted Devices
+ Added the 'Trusted Devices' feature
+ Added 'Remember this Device' checkbox on /web/login/totp
+ Added trusted device's OS / browser on Profile > Account Security

Added '2FA Trusted Devices' feature to allow users to remember their
device to bypass the 2FA for the next connections. The trusted devices
are displayed in a 'Trusted Devices' One2Many under the 'Developer API
Keys'. It is possible to revoke all the trusted devices at once with a
special button. It is also possible to revoke one at a time on the
desired one.

Task-id 2523092

closes odoo/odoo#75535

Related: odoo/upgrade#2800
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Co-authored-by: Martin Trigaux <mat@odoo.com>
2021-09-06 13:17:48 +00:00
David Beguin 09f6ae5b95 [MOV] auth_top: reorganise module to set content in proper place
This commit juste moves the different part of code (class, views, data) in the
correct file where they belong.

Task-2487630

Part-of: odoo/odoo#71142
2021-08-30 21:05:12 +00:00
David Beguin 29db699e9b [IMP] auth_top, *: revamp Two-factor authentication flow
Purpose
=======

Review the UX of the 2-factor authentication flow in order to make it more clear
and easy to use.

Specifications
==============

This commit applies multiple rewording of instructions, button, etc. Tests have
been adapted accordingly.

It also adds an 'invite to use two-factor authentication' flow that will
send an email to the selected used to redirect them their account security
settings.
- If portal is not installed yet, the user is redirected to his account security
settings in backend.
- If portal is installed, the user is redirected to /my/profile if them are
portal user. Otherwise, the redirection is still done at backend side.

As the backend view of auth_totp wizard is used at frontend side, copyclipboard
widget has to be rebuilt at frontend side (click event, style etc..).

As API key section is now displayed only on debug mode, test urls have been
adapted accordingly.

Task-2487630

Part-of: odoo/odoo#71142
2021-08-30 21:05:12 +00:00
Kevin Baptiste 86aa7b78aa [IMP] *: introduce data-hotkey on form and modal views
Define `data-hotkey` on most used action buttons.

For the modals, the following keys are dedicated for "special"
actions:
 - Alt+G: add
 - Alt+V: save
 - Alt+Z: cancel

closes odoo/odoo#73275

Taskid: 2588233
Related: odoo/enterprise#19464
Signed-off-by: Kevin Baptiste <kba@odoo.com>
2021-07-15 08:39:49 +00:00
Victor Feyens 0348b95aee [FIX] *: update documentation links
Following the recent reorganisation of the documentation in 12.0+,
the majority of the documents have been moved and their old links are no longer valid.
Some redirection rules will soon be deployed, but those rules might be dropped in some years
and we want the links to still work, which is why we still replace the links to the new ones.

FW-Port of odoo/odoo#70675 (13.0)

closes odoo/odoo#70920

X-original-commit: bc9c1eef538ba6095e74c19d5d9ed9e01625ec7c
Related: odoo/enterprise#18361
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2021-05-17 19:26:27 +00:00
Julien MougenotandSimon Genin 03641610c2 [REF] *: convert all modules to new asset system
Conversion of all modules to the new manifest assets declaration.

Part of task: 2352566

Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Simon Genin <ges@odoo.com>
2021-03-31 13:57:18 +02:00
Olivier Dony 3f3c7b507a [IMP] base, totp: simplify form layout and improve responsiveness
Some of the TOTP-related forms contained an attempt at making a centered
modal pop-up, using a bootstrap `card` that would also serve to
emphasize that the interaction was sensitive and security-related.
Some of the "footer buttons" were moved inside the form to make it
more obvious that they were part of the interaction flow.

However some of this caused breakages of responsiveness and did not yield
a really satisfactory result anyway.

This commit switches back to using regular non-centered forms. It looks
quite ugly because the content is better suited for a narrow modal, but
it means less surprises in terms of layout and less responsiveness
issues.

closes odoo/odoo#58541

closes odoo/odoo#58544

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2020-09-26 09:45:17 +00:00
Xavier Morel 9c58c51179 [IMP] auth_totp: totp screen layout when website is installed
Apparently website's login layout removes the "card" around the login
form, and only the inner login form remains and is centered.

Put the card-title inside the login form, it doesn't seem to affect
the web layout in noticeable ways, just fixes the layout when website
is installed.

closes odoo/odoo#56144

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-09-10 12:49:00 +00:00
Xavier Morel 3e7d096f32 [WIP] base, auth_totp: add doc links for 2FA & API keys 2020-09-10 12:49:00 +00:00
Xavier Morel eac225e3ea [IMP] auth_totp: label of totp_enabled field & show status in form
Use same look in form as in preferences dialog, just without the
buttons to enable / disable it (technically could have the button to
disable with the correct group I guess?)
2020-09-10 12:49:00 +00:00
Xavier Morel 70b6ac5009 [IMP] auth_totp: allow spaces in totp code input
TOTP programs generally group the code into two groups of 3 digits,
but we'd only allow a single group of 6 digits.

Allow spaces in the value for a bit of flexibility, and fix
placeholders to look like codes (also turns out @placeholder on a
field doesn't do anything, not sure where I got this idea).

Also improve the label slightly in the login flow:

* add information to the label itself
* properly link the label & input via an `id`
2020-09-10 12:47:15 +00:00
Xavier MorelandOlivier Dony a9a6509713 [ADD] auth_totp
New module for supporting two-factor authentication via time-base
one-time-password (TOTP).

Users (including portal users) can choose to enable two-factor auth in
their user account settings, by scanning a QR code and adding it to an
authenticator app, such as Google Auth, 1Password, etc.

When two-factor is enabled, password-based non-interactive RPC is only
possible by using API keys.

Co-authored-by: Olivier Dony <odo@odoo.com>
2020-08-14 23:06:24 +00:00