Commit Graph
34 Commits
Author SHA1 Message Date
Olivier Dony 7cf64c2173 [IMP] auth*: adapt auth_* modules for totp
Prevent non-interactive RPC access when TOTP is enabled, also via
external auth services.
2020-08-14 23:06:25 +00:00
Xavier Morel 950d962d95 [IMP] core: add env to various auth methods
Allows accessing various keys, especially whether this is an
interactive login or not.

Also have the xml-rpc `login` delegate to `authenticate` instead of
having its own half-assed implementation.

And remove some dead code: as far as I can tell, Session.authenticate
is never called with a uid.
2020-08-14 21:20:47 +00:00
Swapnesh Shah 36cec45f43 [IMP] auth_oauth: use sequence field for ordering
A sequence field is present in the model but was not used.
After this commit, the field is used as sorting criteria. This allows to sort providers on the login page.

closes odoo/odoo#43968

Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-03-02 17:13:33 +00:00
Swapnesh Shah 695a1c8ada [FIX] auth_oauth: set values when necessary
If the record with the external id 'auth_oauth.provider_google' does
not exist in the database, 'google_provider' variable will contains
None.
Before this commit, calling get and set methods produced an error.

After this commit, trying to set a token for Google Authentication
will do nothing.
While this is not ideal, one can assume somebody that deleted an OAuth
provider rarely wants to configure it and can still upgrade the module
to get it back.

closes odoo/odoo#45566

X-original-commit: eca90a31d0d3667cf63994d34c5d2bb81bfd45c4
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-02-17 20:24:25 +00:00
Kevin Baptiste 6cbe824871 [REV] web: reverts update to fontawesome 5.11.2
This reverts commit ff1c35513a.

closes odoo/odoo#41480

X-original-commit: 116057b26e71db4692280463669f3e80d813ddcc
Related: odoo/enterprise#7110
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-12-09 10:33:36 +00:00
Kevin Baptiste ff1c35513a [IMP] web: update to fontawesome 4.7.0 to 5.11.2
FontAwesome 5 introduced new names for some icons as described on
https://fontawesome.com/how-to-use/on-the-web/setup/upgrading-from-version-4#name-changes

This commit replaces the old names to the new ones.

closes odoo/odoo#35826

Taskid: 2050241
Related: odoo/enterprise#5180
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-11-28 10:05:12 +00:00
Andreas Perhab fd51030c43 [FIX] auth_oauth: enable translation of link text for oauth providers
closes odoo/odoo#38494

X-original-commit: 1e012dda76601437659b640b389fe2b73b6cbb3b
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
2019-10-11 11:38:20 +00:00
sri-odoo b78b9c87c9 [REF] web, *: redesign login screens
* auth_signup, auth_oauth
2018-09-17 12:04:23 +02:00
Xavier Morel a8d868e287 [ADD] Rate limiting to (failed) login attempts
Task 31122 section 4.

Implement per-IP rate limiting of login attempts after some number
of failures.

* check_credentials has no reason to be public, make it private
* add hooks to check for login cooldown on a source IP (remote_addr:
  http://werkzeug.pocoo.org/docs/0.14/wrappers/#werkzeug.wrappers.BaseRequest.remote_addr)
  basis
* add baseline/default configuration of 60s cooldown
* add baseline threshold of 10 login failures, after checking odoo.com
  logs it looks like we have short runs of up to 7 failures (assumed
  to be legitimate) before the user either gets it right or goes and
  looks it up

Depends on #24187
2018-07-26 15:53:26 +02:00
Christophe Simonis e0345a4a3f [MERGE] forward port branch 11.0 up to 2835d29979 2018-03-20 11:45:11 +01:00
Christophe Simonis 672a275c7f [MERGE] forward port branch saas-15 up to 3d9a2340d9 2018-03-19 21:26:01 +01:00
Christophe Simonis e098276644 [MERGE] forward port branch 10.0 up to da1f153d61 2018-03-19 19:32:55 +01:00
tbe-odoo da1f153d61 [IMP] http: Sessions implicit deactivation
- Store a token inside sessions to allow implicit session deactivation when needed.
2018-03-19 18:11:12 +01:00
Thibault Delavallée c129b91b6d [MOV] base: move res_* models into models/ 2017-11-27 11:15:00 +01:00
Yannick Tivisse 781a03b2bc [IMP] res_config: Update file names, xmlids, class names according to guidelines
Now that we only have one model (res.config.settings). Uniformize everything according to the guidelines.
2017-09-01 13:03:18 +02:00
Deep Patel 898224f110 [IMP] web,account,...: Regroup settings, add a nav and search bar
Purpose
=======

Settings are often way too long and hard to scan and sometimes you don't know where to find the settings you're looking for.
By adding a left navigation, you can already have an overview of the settings, and switch easily between them.

Specification
=============

- Add a search bar on all the apps that have settings which can search results from all the installed apps.
  (If i'm on sales settings,and I search anything then it shows results from sales settings and also shows
  all the other matching results from all the other apps such as, Inventory...etc) with app name.
- Able to activate feature from the current page results (no matter if the searched result is from another apps).
- Highlight searched word in results
- Delete the sheet, have a full white background
- Add left navigation bar on setting
- Left navigation bar fixed
- List displayed based on installed apps
- On right panel, by default display current app setting and change accordingly
- [Mobile] Left navigation bar displayed on top
- Add Breadcrumb on top of the page: have the name "Settings" + Save / discard CTA + Search
- Add General Settings on the nav bar
- remove "save this page..." notif in all settings
- Delete all recommanded apps section + all checkbox that install app should disappear:
	payroll: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrSkMzWVpuZ0ZoaFE/view?usp=drivesdk
	Events: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrYXlHMHd2NTM2blE/view?usp=drivesdk
	Manufacturing: Delete Repair - Quality Control - Maintenance - Product Lifecycle Management [LAP][ok]
	Timesheets: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrdFg5XzNydkd2TlU/view?usp=drivesdk
	project: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrraWo3NE04TktwcTQ/view?usp=drivesdk
	inventory: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrQkRaVUR5ekFQYTQ/view?usp=drivesdk
	recruitment: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrbDdqLWQweF80UkE/view?usp=drivesdk
	purchase: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrRlAyUDBnb0trQWs/view?usp=drivesdk
	email marketing: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrOUZONjhvX2k3Y2s/view?usp=drivesdk
	expenses: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrrR0JpN1ZpQmtxU3M/view?usp=drivesdk
	attendances: https://drive.google.com/a/odoo.com/file/d/0B1uIL9E_zXrralpjZ1VJclNpMWs/view?usp=drivesdk
- About duplicate settings:
	Docsaway: Delete from Sales + delete Default Print Provider
	Attributs & Variants: Delete from Purchases - Manufacturing
	Multi-currencies: delete from Sales
	Unit Of Measures: Delete from Purchase & Expenses
- Add a scroll bar on the left bar when there's too many apps
- Keep the navbar visible even when you search
- Move General Settings to the bottom of the list
- Update on Settings:
    - Accounting:
        - rename automatic rates
        - Anglo Saxon Account: Should be in technical feature
        - Place Accounting Reports section before Taxes section
    - CRM:
        - Phone Validation: Enforce international format becomes
        - Local Numbers: (2 radio buttons proposals) Add international prefix / No prefix
    - Fleet: typo " ... a new car if ..." + text is too long <br>
    - project: fix tooltip for colab pads
2017-09-01 13:02:54 +02:00
Denis Vermylen 676022e3af [IMP] auth_signup: display meaningfull and translated error messages
Since 5425316eff errors when signing up will only display two
messages:

 * "Another user is already registered using this email address." or
 * "Could not create a new account."

While Odoo creates a multitude of other comprehensible error messages
such as

 * "Passwords do not match; please retype them."
 * "Signup token '%s' is no longer valid"

This commit now separate UserError and AssertionError from SignupErrors.
Those are still hidden in a general message (see 5425316eff for reasons) while
the other ones are fully displayed.

This commit also improves translations of messages.
2017-07-06 12:53:39 +02:00
Yannick Tivisse 100f320217 [REF] base/res_config: Deprecate get_default_foo and set_foo
Currently, all the methods that start with `get_default_` and `set_` are called on a res.config.settings loading or saving.

This commit purpose is to replace all the occurences of `get_default_foo` and `set_foo`. As these methods won't be called anymore, a warning is logged to notice its deprecation.

The generic method `get_default_fields` and `set_fields` could be improved too. The method names and API are not so good:

    Why "default" fields? What you ask for is the current value of the stuff, shown as fields in the model. The values are fed as default values in the wizard, but that's an implementation trick.
    Why "fields"? What you ask for are configuration parameters, and such things.
    Why passing a list of fields? Its value is never used.

We should further simplify the API of both methods to something like

def get_values(self):
    return {}

def set_values(self):
    pass
2017-06-19 17:37:38 +02:00
Yannick Tivisse a38a3e93c2 [MOV] *: Reorganize configuration files according to guidelines 2017-06-19 17:37:38 +02:00
Christophe Simonis ed2ddeccdf [MERGE] forward port branch saas-16 up to 1b50c829ef 2017-06-15 18:46:47 +02:00
Christophe Simonis 1b50c829ef [MERGE] forward port branch saas-15 up to 9713dc2e1f 2017-06-15 18:44:16 +02:00
Christophe Simonis 96595772e0 [MERGE] forward port branch 10.0 up to dc8b473a03 2017-06-15 18:35:46 +02:00
Olivier Dony 16714a7e71 [FIX] auth_oauth: correctly register token field 2017-06-15 16:23:44 +02:00
Christophe Simonis a47a95cde0 [MERGE] forward port branch saas-16 up to 76262f2043 2017-06-12 20:41:44 +02:00
Christophe Simonis 50d8ea1d58 [MERGE] forward port branch saas-15 up to aae12c2bad 2017-06-12 19:37:28 +02:00
Christophe Simonis 62fec71568 [MERGE] forward port branch 10.0 up to fcc33f3e09 2017-06-12 18:55:24 +02:00
Christophe Simonis fcc33f3e09 [MERGE] forward port branch saas-11 up to 6ceecffcad 2017-06-12 18:52:53 +02:00
Xavier Morel 01e3514147 [FIX] P3: urllib, urllib2 and urlparse
In Python 3, all of these were "consolidated" under urllib(.request,
.parse, .errors) which is inconvenient.

Since we already have hard dependencies on requests and
werkzeug(.urls, which is a backport of Python 3's unicode-aware
urllib.parse) migrate *everything* to that.

A sticking point is urllib2.URLError, those were (mostly) replaced by
the slightly more general IOError which URLError extends.
2017-05-15 12:26:30 +02:00
xmo-odoo b4429c2a91 [FIX] Various P3-related import changes
* LDAP import: python-ldap is not python3-compatible, pyldap is

  Warning: only supported from debian Stretch (current testing)?
  https://packages.debian.org/search?searchon=names&keywords=pyldap

* implicitly relative imports
* imports of moved or removed stdlib modules

issue #8530
2017-04-28 09:06:53 +02:00
Xavier Morel 3979f6802e [#8530] convert exception handlers to except..as syntax
Futurize fixers:
* lib2to3.fixes.fix_except
2017-04-11 14:53:29 +02:00
Akash Bhavsar 79fd51b2a5 [IMP] base_setup: Improve the General Settings form view 2017-01-03 17:07:02 +01:00
Christophe Simonis 81f59cee2c [MERGE] forward port branch saas-11 up to b844d93889 2017-01-02 14:38:59 +01:00
Kinjal Mehta 3f201066f0 [MIG]auth_oauth: Migrate to new api. 2016-08-02 16:02:29 +02:00
Kinjal Mehta 914b2be967 [MOVE]auth_oauth: Moved files in related models and views directory. 2016-08-02 16:02:29 +02:00