Commit Graph
15 Commits
Author SHA1 Message Date
Olivier Dony 7cf64c2173 [IMP] auth*: adapt auth_* modules for totp
Prevent non-interactive RPC access when TOTP is enabled, also via
external auth services.
2020-08-14 23:06:25 +00:00
Xavier Morel 950d962d95 [IMP] core: add env to various auth methods
Allows accessing various keys, especially whether this is an
interactive login or not.

Also have the xml-rpc `login` delegate to `authenticate` instead of
having its own half-assed implementation.

And remove some dead code: as far as I can tell, Session.authenticate
is never called with a uid.
2020-08-14 21:20:47 +00:00
Xavier Morel a8d868e287 [ADD] Rate limiting to (failed) login attempts
Task 31122 section 4.

Implement per-IP rate limiting of login attempts after some number
of failures.

* check_credentials has no reason to be public, make it private
* add hooks to check for login cooldown on a source IP (remote_addr:
  http://werkzeug.pocoo.org/docs/0.14/wrappers/#werkzeug.wrappers.BaseRequest.remote_addr)
  basis
* add baseline/default configuration of 60s cooldown
* add baseline threshold of 10 login failures, after checking odoo.com
  logs it looks like we have short runs of up to 7 failures (assumed
  to be legitimate) before the user either gets it right or goes and
  looks it up

Depends on #24187
2018-07-26 15:53:26 +02:00
Christophe Simonis e0345a4a3f [MERGE] forward port branch 11.0 up to 2835d29979 2018-03-20 11:45:11 +01:00
Christophe Simonis 672a275c7f [MERGE] forward port branch saas-15 up to 3d9a2340d9 2018-03-19 21:26:01 +01:00
tbe-odoo da1f153d61 [IMP] http: Sessions implicit deactivation
- Store a token inside sessions to allow implicit session deactivation when needed.
2018-03-19 18:11:12 +01:00
Thibault Delavallée c129b91b6d [MOV] base: move res_* models into models/ 2017-11-27 11:15:00 +01:00
Denis Vermylen 676022e3af [IMP] auth_signup: display meaningfull and translated error messages
Since 5425316eff errors when signing up will only display two
messages:

 * "Another user is already registered using this email address." or
 * "Could not create a new account."

While Odoo creates a multitude of other comprehensible error messages
such as

 * "Passwords do not match; please retype them."
 * "Signup token '%s' is no longer valid"

This commit now separate UserError and AssertionError from SignupErrors.
Those are still hidden in a general message (see 5425316eff for reasons) while
the other ones are fully displayed.

This commit also improves translations of messages.
2017-07-06 12:53:39 +02:00
Christophe Simonis ed2ddeccdf [MERGE] forward port branch saas-16 up to 1b50c829ef 2017-06-15 18:46:47 +02:00
Christophe Simonis 1b50c829ef [MERGE] forward port branch saas-15 up to 9713dc2e1f 2017-06-15 18:44:16 +02:00
Olivier Dony 16714a7e71 [FIX] auth_oauth: correctly register token field 2017-06-15 16:23:44 +02:00
Xavier Morel 01e3514147 [FIX] P3: urllib, urllib2 and urlparse
In Python 3, all of these were "consolidated" under urllib(.request,
.parse, .errors) which is inconvenient.

Since we already have hard dependencies on requests and
werkzeug(.urls, which is a backport of Python 3's unicode-aware
urllib.parse) migrate *everything* to that.

A sticking point is urllib2.URLError, those were (mostly) replaced by
the slightly more general IOError which URLError extends.
2017-05-15 12:26:30 +02:00
Xavier Morel 3979f6802e [#8530] convert exception handlers to except..as syntax
Futurize fixers:
* lib2to3.fixes.fix_except
2017-04-11 14:53:29 +02:00
Kinjal Mehta 3f201066f0 [MIG]auth_oauth: Migrate to new api. 2016-08-02 16:02:29 +02:00
Kinjal Mehta 914b2be967 [MOVE]auth_oauth: Moved files in related models and views directory. 2016-08-02 16:02:29 +02:00