Allows accessing various keys, especially whether this is an
interactive login or not.
Also have the xml-rpc `login` delegate to `authenticate` instead of
having its own half-assed implementation.
And remove some dead code: as far as I can tell, Session.authenticate
is never called with a uid.
A sequence field is present in the model but was not used.
After this commit, the field is used as sorting criteria. This allows to sort providers on the login page.
closesodoo/odoo#43968
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
If the record with the external id 'auth_oauth.provider_google' does
not exist in the database, 'google_provider' variable will contains
None.
Before this commit, calling get and set methods produced an error.
After this commit, trying to set a token for Google Authentication
will do nothing.
While this is not ideal, one can assume somebody that deleted an OAuth
provider rarely wants to configure it and can still upgrade the module
to get it back.
closesodoo/odoo#45566
X-original-commit: eca90a31d0d3667cf63994d34c5d2bb81bfd45c4
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Task 31122 section 4.
Implement per-IP rate limiting of login attempts after some number
of failures.
* check_credentials has no reason to be public, make it private
* add hooks to check for login cooldown on a source IP (remote_addr:
http://werkzeug.pocoo.org/docs/0.14/wrappers/#werkzeug.wrappers.BaseRequest.remote_addr)
basis
* add baseline/default configuration of 60s cooldown
* add baseline threshold of 10 login failures, after checking odoo.com
logs it looks like we have short runs of up to 7 failures (assumed
to be legitimate) before the user either gets it right or goes and
looks it up
Depends on #24187
Since 5425316eff errors when signing up will only display two
messages:
* "Another user is already registered using this email address." or
* "Could not create a new account."
While Odoo creates a multitude of other comprehensible error messages
such as
* "Passwords do not match; please retype them."
* "Signup token '%s' is no longer valid"
This commit now separate UserError and AssertionError from SignupErrors.
Those are still hidden in a general message (see 5425316eff for reasons) while
the other ones are fully displayed.
This commit also improves translations of messages.
Currently, all the methods that start with `get_default_` and `set_` are called on a res.config.settings loading or saving.
This commit purpose is to replace all the occurences of `get_default_foo` and `set_foo`. As these methods won't be called anymore, a warning is logged to notice its deprecation.
The generic method `get_default_fields` and `set_fields` could be improved too. The method names and API are not so good:
Why "default" fields? What you ask for is the current value of the stuff, shown as fields in the model. The values are fed as default values in the wizard, but that's an implementation trick.
Why "fields"? What you ask for are configuration parameters, and such things.
Why passing a list of fields? Its value is never used.
We should further simplify the API of both methods to something like
def get_values(self):
return {}
def set_values(self):
pass
In Python 3, all of these were "consolidated" under urllib(.request,
.parse, .errors) which is inconvenient.
Since we already have hard dependencies on requests and
werkzeug(.urls, which is a backport of Python 3's unicode-aware
urllib.parse) migrate *everything* to that.
A sticking point is urllib2.URLError, those were (mostly) replaced by
the slightly more general IOError which URLError extends.