Allows accessing various keys, especially whether this is an
interactive login or not.
Also have the xml-rpc `login` delegate to `authenticate` instead of
having its own half-assed implementation.
And remove some dead code: as far as I can tell, Session.authenticate
is never called with a uid.
- A user using ldap to sign in can now changes his password,
providing hid old password.
- When the ldap password is changed, empty the possible
value for the password set in database so
it can no longer be used.
- Usually, in all res.users methods auth_ldap replaces,
we first try to call `super` before fallbacking to
ldap if the call to super fails.
e.g. when authenticating,
we first check the regular (super) credentials,
before fallbacking to ldap if it fails.
In this case, we do the opposite on purpose,
to give the priority to ldap in case a user changes of password.
e.g. a user has the same password in ldap and in database,
when he changes, we rather like changing the ldap password
and then empty the internal password.
closesodoo/odoo#50144
X-original-commit: 8bff93feee0c40dd9ee73ed8217cfdd6abb7de3b
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
* Make Users._login and session.authenticate always raise AccessDenied
on authentication failure instead of only sometimes (cf
Session.authenticate calling security.check() which raises and not
catching the exception)
* Alter AccessDenied such that it's possible to add a custom access
message, for use with login rate limiting instead of smuggling the
information via the session
* Alter the RPC endpoints to catch and convert AccessDenied back to
a boolean sentinel
Task 31122 section 4.
Implement per-IP rate limiting of login attempts after some number
of failures.
* check_credentials has no reason to be public, make it private
* add hooks to check for login cooldown on a source IP (remote_addr:
http://werkzeug.pocoo.org/docs/0.14/wrappers/#werkzeug.wrappers.BaseRequest.remote_addr)
basis
* add baseline/default configuration of 60s cooldown
* add baseline threshold of 10 login failures, after checking odoo.com
logs it looks like we have short runs of up to 7 failures (assumed
to be legitimate) before the user either gets it right or goes and
looks it up
Depends on #24187