Commit Graph
9 Commits
Author SHA1 Message Date
Olivier Dony 7cf64c2173 [IMP] auth*: adapt auth_* modules for totp
Prevent non-interactive RPC access when TOTP is enabled, also via
external auth services.
2020-08-14 23:06:25 +00:00
Xavier Morel 950d962d95 [IMP] core: add env to various auth methods
Allows accessing various keys, especially whether this is an
interactive login or not.

Also have the xml-rpc `login` delegate to `authenticate` instead of
having its own half-assed implementation.

And remove some dead code: as far as I can tell, Session.authenticate
is never called with a uid.
2020-08-14 21:20:47 +00:00
Denis Ledoux e050d9150c [ADD] auth_ldap: give possibility to users to change their ldap password
- A user using ldap to sign in can now changes his password,
   providing hid old password.
 - When the ldap password is changed, empty the possible
   value for the password set in database so
   it can no longer be used.
 - Usually, in all res.users methods auth_ldap replaces,
   we first try to call `super` before fallbacking to
   ldap if the call to super fails.
   e.g. when authenticating,
   we first check the regular (super) credentials,
   before fallbacking to ldap if it fails.
   In this case, we do the opposite on purpose,
   to give the priority to ldap in case a user changes of password.
   e.g. a user has the same password in ldap and in database,
   when he changes, we rather like changing the ldap password
   and then empty the internal password.

closes odoo/odoo#50144

X-original-commit: 8bff93feee0c40dd9ee73ed8217cfdd6abb7de3b
Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
2020-04-24 11:32:59 +00:00
Xavier Morel d5dc1536dd [IMP] auth_ldap: make methods non-RPC-accessible
There really is no reason for these methods to be called over RPC.
2018-07-26 15:53:26 +02:00
Xavier Morel aac21e4125 [CHG] Change login/auth internal protocol
* Make Users._login and session.authenticate always raise AccessDenied
  on authentication failure instead of only sometimes (cf
  Session.authenticate calling security.check() which raises and not
  catching the exception)
* Alter AccessDenied such that it's possible to add a custom access
  message, for use with login rate limiting instead of smuggling the
  information via the session
* Alter the RPC endpoints to catch and convert AccessDenied back to
  a boolean sentinel
2018-07-26 15:53:26 +02:00
Xavier Morel a8d868e287 [ADD] Rate limiting to (failed) login attempts
Task 31122 section 4.

Implement per-IP rate limiting of login attempts after some number
of failures.

* check_credentials has no reason to be public, make it private
* add hooks to check for login cooldown on a source IP (remote_addr:
  http://werkzeug.pocoo.org/docs/0.14/wrappers/#werkzeug.wrappers.BaseRequest.remote_addr)
  basis
* add baseline/default configuration of 60s cooldown
* add baseline threshold of 10 login failures, after checking odoo.com
  logs it looks like we have short runs of up to 7 failures (assumed
  to be legitimate) before the user either gets it right or goes and
  looks it up

Depends on #24187
2018-07-26 15:53:26 +02:00
Raphael Collet 70dec2d896 [REF] registry: now mapping model name to model class 2016-08-31 17:21:59 +02:00
Kinjal Mehta c4c716579a [MIG] auth_ldap: Migrate into new api. 2016-07-29 15:15:47 +02:00
Kinjal Mehta a7d276727f [SPLIT] auth_ldap: split files according to new API. 2016-07-29 15:15:47 +02:00