Commit Graph
32 Commits
Author SHA1 Message Date
MANALIMALPANI 8a0dd29899 [FIX] auth_ldap: fix LDAP error handling
In order to ensure consistent results of all error conditions returned
    by the LDAP server, the _authenticate() method should return `False`
    for every kind of exception, not just for INVALID_CREDENTIALS.

    This is not actually relevant in 12.0 as the result is exactly the
    same, due to the way the `entry` variable is being initialized, but it
    will make the code path "visibly consistent" across all supported
    versions

closes odoo/odoo#72484

X-original-commit: 24a3f669e5199c35849dabbf7b0d37f43b684538
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2021-06-21 17:50:25 +00:00
Éloi Rivard 72917b4a82 [IMP] auth_ldap: allow multiple '%s' in the filter.
Before this commit, the ldap filter can only contain a single
placeholder, and thus the `login` can only be matched against a single
LDAP attribute.

This change allows matching the `login` against multiple LDAP
attributes e.g. checking against either an email or a uid:

   (|(mail=%s)(uid=%s))

closes odoo/odoo#62134

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2021-01-28 08:12:30 +00:00
Olivier Dony 7cf64c2173 [IMP] auth*: adapt auth_* modules for totp
Prevent non-interactive RPC access when TOTP is enabled, also via
external auth services.
2020-08-14 23:06:25 +00:00
Xavier Morel 950d962d95 [IMP] core: add env to various auth methods
Allows accessing various keys, especially whether this is an
interactive login or not.

Also have the xml-rpc `login` delegate to `authenticate` instead of
having its own half-assed implementation.

And remove some dead code: as far as I can tell, Session.authenticate
is never called with a uid.
2020-08-14 21:20:47 +00:00
Denis Ledoux e050d9150c [ADD] auth_ldap: give possibility to users to change their ldap password
- A user using ldap to sign in can now changes his password,
   providing hid old password.
 - When the ldap password is changed, empty the possible
   value for the password set in database so
   it can no longer be used.
 - Usually, in all res.users methods auth_ldap replaces,
   we first try to call `super` before fallbacking to
   ldap if the call to super fails.
   e.g. when authenticating,
   we first check the regular (super) credentials,
   before fallbacking to ldap if it fails.
   In this case, we do the opposite on purpose,
   to give the priority to ldap in case a user changes of password.
   e.g. a user has the same password in ldap and in database,
   when he changes, we rather like changing the ldap password
   and then empty the internal password.

closes odoo/odoo#50144

X-original-commit: 8bff93feee0c40dd9ee73ed8217cfdd6abb7de3b
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
2020-04-24 11:32:59 +00:00
Holger Brunn 67848457d0 [FIX] auth_ldap: encode python ldap's output as utf8
Non-ascii characters in LDAP don't cause a python unicode string in
returned ldap entries, this commit fixes this.

Before this commit, further string operations on ldap values with
non-ascii characters fail.

closes odoo/odoo#40761

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2019-11-25 08:50:09 +00:00
Christophe Simonis f351dd8cab [MERGE] forward port branch 12.0 up to 047e2b28de 2018-12-12 11:38:25 +01:00
Christophe Simonis 069278b652 [MERGE] forward port branch saas-11.3 up to 55dafc20f6 2018-12-11 18:51:05 +01:00
Christophe Simonis 7e5d5045bf [MERGE] forward port branch saas-15 up to 1ace2ed88b 2018-12-11 16:20:34 +01:00
Christophe Simonis 5a147acf1b [MERGE] forward port branch 10.0 up to f69c004795 2018-12-11 14:33:39 +01:00
Jairo Llopis 81c26383b0 [FIX] auth_ldap: Avoid sending email for newly created user
If installed along with `auth_signup`, it sends an email when creating a missing user authenticated through LDAP.

It is a confusing message that makes no sense, because the user is, from his POV, not actually creating a new user, but just authenticating with a new app with his known company-wide credentials.

Besides, that invitation leads the user to change his password in Odoo, although he probably doesn't want to do that and have a password for Odoo and another in the LDAP server.

The best option is to disable that email completely, which is what this commit does.

closes odoo/odoo#29243
2018-12-04 12:13:39 +00:00
Adrian Torres 52f5528cfb [REF] *: replace deprecated pycompat helpers for builtins
This commit replaces calls to pycompat helpers that were intended for
python 2 <-> python 3 interoperability for python 3 builtins, as python
2 is no longer officially supported by Odoo.

This includes:
    * calls to imap/izip/ifilter replaced by map/zip/filter
    * uses of text_type replaced by str
    * uses of unichr replaced by chr
    * calls to implements_to_string, implements_iterator removed
    * string_types and integer_types replaced by str, int respectively
    * calls to to_native replaced by calls to to_text

This is done in preparation to the removal of these deprecated helpers
in the following commit.
2018-11-29 09:28:17 +00:00
Alexey Pelykh e658cb8c32 [FIX] auth_ldap: missing _description on res.company.ldap
Produces a warning when installed
2018-10-23 10:32:29 +00:00
Adrian Torres 3f4f77fd9d [REF] *: adapt code to new related default behaviour
This commit adapts the business code to changes introduced by
the parent commit in order to keep the same behaviour as before.

All readonly=False fields will have to be checked afterwards to confirm
that the business case requires write access to the source field.
2018-09-27 12:10:23 +02:00
Xavier Morel d5dc1536dd [IMP] auth_ldap: make methods non-RPC-accessible
There really is no reason for these methods to be called over RPC.
2018-07-26 15:53:26 +02:00
Xavier Morel aac21e4125 [CHG] Change login/auth internal protocol
* Make Users._login and session.authenticate always raise AccessDenied
  on authentication failure instead of only sometimes (cf
  Session.authenticate calling security.check() which raises and not
  catching the exception)
* Alter AccessDenied such that it's possible to add a custom access
  message, for use with login rate limiting instead of smuggling the
  information via the session
* Alter the RPC endpoints to catch and convert AccessDenied back to
  a boolean sentinel
2018-07-26 15:53:26 +02:00
Xavier Morel a8d868e287 [ADD] Rate limiting to (failed) login attempts
Task 31122 section 4.

Implement per-IP rate limiting of login attempts after some number
of failures.

* check_credentials has no reason to be public, make it private
* add hooks to check for login cooldown on a source IP (remote_addr:
  http://werkzeug.pocoo.org/docs/0.14/wrappers/#werkzeug.wrappers.BaseRequest.remote_addr)
  basis
* add baseline/default configuration of 60s cooldown
* add baseline threshold of 10 login failures, after checking odoo.com
  logs it looks like we have short runs of up to 7 failures (assumed
  to be legitimate) before the user either gets it right or goes and
  looks it up

Depends on #24187
2018-07-26 15:53:26 +02:00
Christophe Simonis 5c51a0ad4d [MERGE] forward port branch saas-17 up to bf4ccb21f6 2017-09-21 18:14:55 +02:00
Christophe Simonis e0ad21dbdd [FIX] auth_ldap: P3 compatibility 2017-09-20 16:25:41 +02:00
Yannick Tivisse 781a03b2bc [IMP] res_config: Update file names, xmlids, class names according to guidelines
Now that we only have one model (res.config.settings). Uniformize everything according to the guidelines.
2017-09-01 13:03:18 +02:00
Deep Patel 898224f110 [IMP] web,account,...: Regroup settings, add a nav and search bar
Purpose
=======

Settings are often way too long and hard to scan and sometimes you don't know where to find the settings you're looking for.
By adding a left navigation, you can already have an overview of the settings, and switch easily between them.

Specification
=============

- Add a search bar on all the apps that have settings which can search results from all the installed apps.
  (If i'm on sales settings,and I search anything then it shows results from sales settings and also shows
  all the other matching results from all the other apps such as, Inventory...etc) with app name.
- Able to activate feature from the current page results (no matter if the searched result is from another apps).
- Highlight searched word in results
- Delete the sheet, have a full white background
- Add left navigation bar on setting
- Left navigation bar fixed
- List displayed based on installed apps
- On right panel, by default display current app setting and change accordingly
- [Mobile] Left navigation bar displayed on top
- Add Breadcrumb on top of the page: have the name "Settings" + Save / discard CTA + Search
- Add General Settings on the nav bar
- remove "save this page..." notif in all settings
- Delete all recommanded apps section + all checkbox that install app should disappear:
	payroll: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrSkMzWVpuZ0ZoaFE/view?usp=drivesdk
	Events: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrYXlHMHd2NTM2blE/view?usp=drivesdk
	Manufacturing: Delete Repair - Quality Control - Maintenance - Product Lifecycle Management [LAP][ok]
	Timesheets: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrdFg5XzNydkd2TlU/view?usp=drivesdk
	project: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrraWo3NE04TktwcTQ/view?usp=drivesdk
	inventory: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrQkRaVUR5ekFQYTQ/view?usp=drivesdk
	recruitment: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrbDdqLWQweF80UkE/view?usp=drivesdk
	purchase: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrRlAyUDBnb0trQWs/view?usp=drivesdk
	email marketing: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrOUZONjhvX2k3Y2s/view?usp=drivesdk
	expenses: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrR0JpN1ZpQmtxU3M/view?usp=drivesdk
	attendances: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrralpjZ1VJclNpMWs/view?usp=drivesdk
- About duplicate settings:
	Docsaway: Delete from Sales + delete Default Print Provider
	Attributs & Variants: Delete from Purchases - Manufacturing
	Multi-currencies: delete from Sales
	Unit Of Measures: Delete from Purchase & Expenses
- Add a scroll bar on the left bar when there's too many apps
- Keep the navbar visible even when you search
- Move General Settings to the bottom of the list
- Update on Settings:
    - Accounting:
        - rename automatic rates
        - Anglo Saxon Account: Should be in technical feature
        - Place Accounting Reports section before Taxes section
    - CRM:
        - Phone Validation: Enforce international format becomes
        - Local Numbers: (2 radio buttons proposals) Add international prefix / No prefix
    - Fleet: typo " ... a new car if ..." + text is too long <br>
    - project: fix tooltip for colab pads
2017-09-01 13:02:54 +02:00
xmo-odoo b4429c2a91 [FIX] Various P3-related import changes
* LDAP import: python-ldap is not python3-compatible, pyldap is

  Warning: only supported from debian Stretch (current testing)?
  https://packages.debian.org/search?searchon=names&keywords=pyldap

* implicitly relative imports
* imports of moved or removed stdlib modules

issue #8530
2017-04-28 09:06:53 +02:00
Xavier Morel 3979f6802e [#8530] convert exception handlers to except..as syntax
Futurize fixers:
* lib2to3.fixes.fix_except
2017-04-11 14:53:29 +02:00
Olivier Dony 087ce98928 [MERGE] Forward-port 10.0 up to 2cffcfd860 2017-02-25 02:32:17 +01:00
Stéphane Bidoul (ACSONE) 6f1c291982 [FIX] auth_ldap: allow non-ascii ldap base
For installations with accents in the name

Closes #15597
2017-02-24 15:18:51 +01:00
Akash Bhavsar 79fd51b2a5 [IMP] base_setup: Improve the General Settings form view 2017-01-03 17:07:02 +01:00
Christophe Simonis c813dbf068 [MERGE] forward port branch saas-12 up to 84429ab 2016-09-30 17:21:34 +02:00
Yannick Tivisse 665781d5a8 [IMP] various: Move all configuration fields from res_company form to the related modules
=======
Purpose
=======

The company form should be heavily simplified. It's complex to have some settings on the company form, and others on the Settings menu of the related app. It would be much easier to have all settings in Settings menu (res.config) and nothing on the company, even if some of the Settings are multi company. (Stored on the company but set from the Settings menu).
2016-09-02 13:44:15 +02:00
Raphael Collet 70dec2d896 [REF] registry: now mapping model name to model class 2016-08-31 17:21:59 +02:00
Kinjal Mehta c4c716579a [MIG] auth_ldap: Migrate into new api. 2016-07-29 15:15:47 +02:00
Kinjal Mehta a7d276727f [SPLIT] auth_ldap: split files according to new API. 2016-07-29 15:15:47 +02:00
Kinjal Mehta 64ac8caa06 [MOVE] auth_ldap: Move files in related models and views directory 2016-07-29 15:15:47 +02:00