In order to ensure consistent results of all error conditions returned
by the LDAP server, the _authenticate() method should return `False`
for every kind of exception, not just for INVALID_CREDENTIALS.
This is not actually relevant in 12.0 as the result is exactly the
same, due to the way the `entry` variable is being initialized, but it
will make the code path "visibly consistent" across all supported
versions
closesodoo/odoo#72484
X-original-commit: 24a3f669e5199c35849dabbf7b0d37f43b684538
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Before this commit, the ldap filter can only contain a single
placeholder, and thus the `login` can only be matched against a single
LDAP attribute.
This change allows matching the `login` against multiple LDAP
attributes e.g. checking against either an email or a uid:
(|(mail=%s)(uid=%s))
closesodoo/odoo#62134
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Allows accessing various keys, especially whether this is an
interactive login or not.
Also have the xml-rpc `login` delegate to `authenticate` instead of
having its own half-assed implementation.
And remove some dead code: as far as I can tell, Session.authenticate
is never called with a uid.
- A user using ldap to sign in can now changes his password,
providing hid old password.
- When the ldap password is changed, empty the possible
value for the password set in database so
it can no longer be used.
- Usually, in all res.users methods auth_ldap replaces,
we first try to call `super` before fallbacking to
ldap if the call to super fails.
e.g. when authenticating,
we first check the regular (super) credentials,
before fallbacking to ldap if it fails.
In this case, we do the opposite on purpose,
to give the priority to ldap in case a user changes of password.
e.g. a user has the same password in ldap and in database,
when he changes, we rather like changing the ldap password
and then empty the internal password.
closesodoo/odoo#50144
X-original-commit: 8bff93feee0c40dd9ee73ed8217cfdd6abb7de3b
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
Non-ascii characters in LDAP don't cause a python unicode string in
returned ldap entries, this commit fixes this.
Before this commit, further string operations on ldap values with
non-ascii characters fail.
closesodoo/odoo#40761
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
If installed along with `auth_signup`, it sends an email when creating a missing user authenticated through LDAP.
It is a confusing message that makes no sense, because the user is, from his POV, not actually creating a new user, but just authenticating with a new app with his known company-wide credentials.
Besides, that invitation leads the user to change his password in Odoo, although he probably doesn't want to do that and have a password for Odoo and another in the LDAP server.
The best option is to disable that email completely, which is what this commit does.
closesodoo/odoo#29243
This commit replaces calls to pycompat helpers that were intended for
python 2 <-> python 3 interoperability for python 3 builtins, as python
2 is no longer officially supported by Odoo.
This includes:
* calls to imap/izip/ifilter replaced by map/zip/filter
* uses of text_type replaced by str
* uses of unichr replaced by chr
* calls to implements_to_string, implements_iterator removed
* string_types and integer_types replaced by str, int respectively
* calls to to_native replaced by calls to to_text
This is done in preparation to the removal of these deprecated helpers
in the following commit.
This commit adapts the business code to changes introduced by
the parent commit in order to keep the same behaviour as before.
All readonly=False fields will have to be checked afterwards to confirm
that the business case requires write access to the source field.
* Make Users._login and session.authenticate always raise AccessDenied
on authentication failure instead of only sometimes (cf
Session.authenticate calling security.check() which raises and not
catching the exception)
* Alter AccessDenied such that it's possible to add a custom access
message, for use with login rate limiting instead of smuggling the
information via the session
* Alter the RPC endpoints to catch and convert AccessDenied back to
a boolean sentinel
Task 31122 section 4.
Implement per-IP rate limiting of login attempts after some number
of failures.
* check_credentials has no reason to be public, make it private
* add hooks to check for login cooldown on a source IP (remote_addr:
http://werkzeug.pocoo.org/docs/0.14/wrappers/#werkzeug.wrappers.BaseRequest.remote_addr)
basis
* add baseline/default configuration of 60s cooldown
* add baseline threshold of 10 login failures, after checking odoo.com
logs it looks like we have short runs of up to 7 failures (assumed
to be legitimate) before the user either gets it right or goes and
looks it up
Depends on #24187
=======
Purpose
=======
The company form should be heavily simplified. It's complex to have some settings on the company form, and others on the Settings menu of the related app. It would be much easier to have all settings in Settings menu (res.config) and nothing on the company, even if some of the Settings are multi company. (Stored on the company but set from the Settings menu).