Commit Graph
38 Commits
Author SHA1 Message Date
simonev 2857980a6c [FIX] auth_totp: add missing model decorator on change_password method override
Declared as an api.model in all the other modules except auth_totp

closes odoo/odoo#79726

X-original-commit: 61b319ea2b5ffc70e0fd80eb62b8a3f700be0f1f
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-11-12 18:07:15 +00:00
std-odooandnounoubensebia cd8e0e9f46 [IMP] base, *: hide non-relevant fields for portal users
Purpose
=======
Hide non-relevant fields for a portal user. E.G. we want to hide the
notification type,  the menu customization... Because those fields
make no sense for a portal user.

Force the non-internal user to receive notifications by emails since
they can not open Discuss.

Task-2508521

Part-of: odoo/odoo#77766
Co-authored-by: nounoubensebia <neb@odoo.com>
2021-11-09 14:45:49 +00:00
Romeo Fragomeli 0cecf918a6 [FIX] auth_totp,mail,web: TOTP authentication with JSON-RPC
Since [1] and [2], the mobile app gets this error when trying to login
on v15, while it was working fine in v14 with TOTP enabled.

The 'authenticate' JSON-RPC route tries to authenticate the user and
then call `session_info()`. As no UID is defined, some methods in
`session_info()` raise an exception and an unexpected error is sent:
* `_is_public()` -> "Expected singleton: res.users()"
* `get_web_translations_hash()` -> "lang"

In this fix, this exception is avoided and the proper result is sent,
allowing the authentication process to continue.

Steps to reproduce:
* Try to connect to an account with TOTP on the mobile app (v15+) => BUG

Refs:
[1] odoo/odoo@80d74e7ee0
[2] odoo/odoo@401fc7efe9

X-original-commit: 65dca67ecdcc2228d90781a9f5ccd99f290ada6c
Part-of: odoo/odoo#79182
2021-10-29 11:54:21 +00:00
b63ee52552 [FIX] *: remove scss 'extend' from dropdown components
This commit removes all the 'extend' initially introduced to avoid code
repetition and ensure visual consistency across Bootstrap and Owl dropdowns.

Despite achieving the desired results, using 'extend' in this context
was seriously impacting the bundle generation time, probably due to an
underestimated amount of Apps' legacy-code applied on these elements.

In order to achieve the same results, the chosen strategy is to add
Bootstrap default classes directly into Owl dropdowns.
Also, it moves code related to bootstrap dropdown in 'webclient.scss',
leaving 'core/dropdown/dropdown.scss' for Owl code only.

Due to the discrepancies between Bootstrap and Owl html
structure, the '.dropdown-item' class could not have been added
directly to Owl's '.o_dropdown_item' itself, without refactoring
the Dropdown component structure.

// ==== Bootstrap 4.6 default Structure ================================
<div class="dropdown-menu">
  <button class="dropdown-item" type="button">Action</button>
  <a class="dropdown-item" href="#">Another action</a>
</div>

// ==== OWL default Structure before this commit =======================
<ul class="o_dropdown_menu">
  <li class="o_dropdown_item">
     <span>Action</span>
  </li>
  <li class="o_dropdown_item">
     <a href="#">Another action</a>
  </li>
</ul>

// ==== OWL Structure after this commit ================================
<div class="o-dropdown--menu dropdown-menu">
  <span class="dropdown-item">Action</span>
  <a class="dropdown-item" href="#">Another action</a>
</div>

// ==== web.assets_backend.css Bundle Generation Comparison ============
With all modules installed (enterprise edition over runbot):
Before this commit, bundle took ~2.5s and ~4s to generate and weighted ~322kB (~2.5MB uncompressed)
After this commit, it takes between ~1.2s and ~1.6s and weights ~257kB (~1.6MB uncompressed)

closes odoo/odoo#77649

X-original-commit: 84715436d87bb05b421bc9ccaacda67d07571690
Related: odoo/enterprise#21370
Signed-off-by: Géry Debongnie (ged) <ged@openerp.com>
Co-authored-by: Stefano Rigano <sri@odoo.com>
Co-authored-by: François Georis <fge@odoo.com>
Co-authored-by: Bruno Boi <boi@odoo.com>
2021-10-04 07:57:00 +00:00
Martin Trigaux ef8ad324b0 [I18N] *: export 15.0 source terms
closes odoo/odoo#76542

X-original-commit: 63e6807437295519a0f4705fb88644d6d557ca3a
Related: odoo/enterprise#20882
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-09-16 07:17:40 +00:00
Xavier Morel 499b1621ba [FIX] *: non-accessible buttons
closes odoo/odoo#76581

Related: odoo/enterprise#20897
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2021-09-15 15:22:58 +00:00
David Beguin 97ed053b31 [FIX] auth_totp, auth_totp_mail: fix misplaced test of 2FA invite button
Since mail dependancy has been extracted into a bridge module auth_totp_mail,
the test about "Invite to use 2FA" is misplaced in the wrong module.

This commit moves the test on 2FA invite button to the bridge module and fixes
the test on auth_totp module to use another indicator that 2FA has been disabled
for the currently tested user (see test file).

Task-2645206
Parent Task-2638538
COM PR: odoo/odoo#76381

closes odoo/odoo#76579

X-original-commit: 305f94bf1b7ac7c106e05e60601640feca934005
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-09-15 15:22:44 +00:00
Martin Trigaux e8fd353cfa [IMP] auth_totp: add test
Original commit was adding the feature in stable but was replaced by
2dee29a7dc in 15.0

This is the forward port of 4736344a57e176 keeping only the test

closes odoo/odoo#76476

X-original-commit: f707d5887c168604b7b7571ae4adc47d64b4a55a
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-09-14 13:32:14 +00:00
David Beguin eb2e328275 [FIX-MOV] auth_totp, auth_totp_invite: move 2FA invite mail to new bridge module
Since 29db699e9b, auth_top depends of mail module, which lead to delay auth_totp
installation - not during DB creation anymore. As mail module is not installed
during DB creation, once an app that depends on mail is installed after DB
creation, auth_top module is finally installed and the session token now depends
auth_top module. As a result, the user is automatically logged out.

This commit moves the invite mail (and the dependance to 'mail' module) to a
new bridge module. Auth_totp module will now be reinstalled during DB creation
automatically.

Task-2638538
Parent Task-2487630
COM PR: odoo/odoo#76022
UPG PR: odoo/upgrade#2808

Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2021-09-06 15:47:23 +00:00
Arnaud GonyandMartin Trigaux 2dee29a7dc [IMP] auth_totp: 2FA Trusted Devices
+ Added the 'Trusted Devices' feature
+ Added 'Remember this Device' checkbox on /web/login/totp
+ Added trusted device's OS / browser on Profile > Account Security

Added '2FA Trusted Devices' feature to allow users to remember their
device to bypass the 2FA for the next connections. The trusted devices
are displayed in a 'Trusted Devices' One2Many under the 'Developer API
Keys'. It is possible to revoke all the trusted devices at once with a
special button. It is also possible to revoke one at a time on the
desired one.

Task-id 2523092

closes odoo/odoo#75535

Related: odoo/upgrade#2800
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
Co-authored-by: Martin Trigaux <mat@odoo.com>
2021-09-06 13:17:48 +00:00
Thibault Delavallée bd1eeababa [FIX] auth_totp: fix file name for mail template
Zairisse too much esse.

Part-of: odoo/odoo#75895
2021-09-03 09:26:11 +00:00
David Beguin 09f6ae5b95 [MOV] auth_top: reorganise module to set content in proper place
This commit juste moves the different part of code (class, views, data) in the
correct file where they belong.

Task-2487630

Part-of: odoo/odoo#71142
2021-08-30 21:05:12 +00:00
David Beguin 29db699e9b [IMP] auth_top, *: revamp Two-factor authentication flow
Purpose
=======

Review the UX of the 2-factor authentication flow in order to make it more clear
and easy to use.

Specifications
==============

This commit applies multiple rewording of instructions, button, etc. Tests have
been adapted accordingly.

It also adds an 'invite to use two-factor authentication' flow that will
send an email to the selected used to redirect them their account security
settings.
- If portal is not installed yet, the user is redirected to his account security
settings in backend.
- If portal is installed, the user is redirected to /my/profile if them are
portal user. Otherwise, the redirection is still done at backend side.

As the backend view of auth_totp wizard is used at frontend side, copyclipboard
widget has to be rebuilt at frontend side (click event, style etc..).

As API key section is now displayed only on debug mode, test urls have been
adapted accordingly.

Task-2487630

Part-of: odoo/odoo#71142
2021-08-30 21:05:12 +00:00
Xavier-Do 288595f558 [FIX] *: add explicit license to all manifest
The license is missing in most enterprise manifest so
the decision was taken to make it explicit in all cases.
When not defined, a warning will be triggered starting from
14.0 when falling back on the default LGPL-3.

closes odoo/odoo#74245

Related: odoo/design-themes#48
Related: odoo/enterprise#19862
Signed-off-by: Xavier Dollé (xdo) <xdo@odoo.com>
2021-07-26 13:09:57 +00:00
Kevin Baptiste 86aa7b78aa [IMP] *: introduce data-hotkey on form and modal views
Define `data-hotkey` on most used action buttons.

For the modals, the following keys are dedicated for "special"
actions:
 - Alt+G: add
 - Alt+V: save
 - Alt+Z: cancel

closes odoo/odoo#73275

Taskid: 2588233
Related: odoo/enterprise#19464
Signed-off-by: Kevin Baptiste <kba@odoo.com>
2021-07-15 08:39:49 +00:00
Martin Trigaux 6758868731 [I18N] *: export saas-14.4 source terms
Without demo data

closes odoo/odoo#73560

X-original-commit: 802e46541117573e028b711ea33dad9df9075a39
Related: odoo/enterprise#19602
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-07-12 10:57:37 +00:00
Jeremy Kersten 478068c829 [IMP] *: always use Odoo Response
This branch adds request.redirect on all requests.
In case of a front end request, we do an url_for to the location.

We removed redirect_with_hash that was only for retro compatibility

local_redirect has been renamed to redirect_query, and param keep_hash has been
removed and moved.

Default code for redirect is 303 now instead of 302.

Now redirect and redirect_query make local redirect by default, you need to
pass local=False to make external redirect.

All werkeug.utils.redirect has been replaced by request.redirect.

Http.redirect now use an http.Response type, and it become easy to add an
override like 'set_cookies' e.g.

Dispatch of a website.page return an http.response too, so we first need to
check if it is a cached version before to check if it is an Odoo Response.

Migrate your code:

http.redirect -> request.redirect(location, code, local)
http.local_redirect -> request.redirect_query(location, query, code, local)
http.redirect_with_hash -> request.redirect

Courtesy of odony for help and review ;)

closes odoo/odoo#72599

Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
2021-07-08 07:00:06 +00:00
stefanorigano (SRI) 1fb2cd9af7 [FIX] web, *: drop o_dropdown_toggler_btnclasses
Drop `o_dropdown_toggler_btn` class in favor of `o_dropdown_toggler`.
o_dropdown_toggler_btn was initially introduced in ~13.3, but it's now
obsolete.
2021-06-18 21:31:32 +02:00
Victor Feyens 0348b95aee [FIX] *: update documentation links
Following the recent reorganisation of the documentation in 12.0+,
the majority of the documents have been moved and their old links are no longer valid.
Some redirection rules will soon be deployed, but those rules might be dropped in some years
and we want the links to still work, which is why we still replace the links to the new ones.

FW-Port of odoo/odoo#70675 (13.0)

closes odoo/odoo#70920

X-original-commit: bc9c1eef538ba6095e74c19d5d9ed9e01625ec7c
Related: odoo/enterprise#18361
Signed-off-by: Victor Feyens (vfe) <vfe@odoo.com>
2021-05-17 19:26:27 +00:00
Raphael Collet 35a9f6c27a [FIX] core: SELF_READABLE_FIELDS and SELF_WRITEABLE_FIELDS on res.users
Avoid setting up those lists with method __init__() on the model, since
the model's class no longer has the expected parent classes.
2021-05-06 07:30:24 +00:00
Julien MougenotandSimon Genin 03641610c2 [REF] *: convert all modules to new asset system
Conversion of all modules to the new manifest assets declaration.

Part of task: 2352566

Co-authored-by: Julien Mougenot <jum@odoo.com>
Co-authored-by: Simon Genin <ges@odoo.com>
2021-03-31 13:57:18 +02:00
Martin Trigaux e79531c136 [I18N] *: export 14.0 source terms
Including demo data this time

closes odoo/odoo#58862

X-original-commit: 575abde110acb3d12b25f177a863374becef0894
Related: odoo/enterprise#13705
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-09-29 17:52:02 +00:00
Olivier Dony 3f3c7b507a [IMP] base, totp: simplify form layout and improve responsiveness
Some of the TOTP-related forms contained an attempt at making a centered
modal pop-up, using a bootstrap `card` that would also serve to
emphasize that the interaction was sensitive and security-related.
Some of the "footer buttons" were moved inside the form to make it
more obvious that they were part of the interaction flow.

However some of this caused breakages of responsiveness and did not yield
a really satisfactory result anyway.

This commit switches back to using regular non-centered forms. It looks
quite ugly because the content is better suited for a narrow modal, but
it means less surprises in terms of layout and less responsiveness
issues.

closes odoo/odoo#58541

closes odoo/odoo#58544

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
2020-09-26 09:45:17 +00:00
Xavier Morel 7e06e39c50 [FIX] auth_totp: tour not working on a base install
This is a followup to #57826: turns out discuss isn't necessarily
installed (who knew?), so the tour would break if mail was not
explicitly installed alongside base, which is not great.

So instead of opening discuss to try and fix the profile race
condition, reload the *entire web client* by navigating to `/web`.

Further discovery: async run functions don't actually do anything in
tours, not sure where I got that, maybe used one for the convenience
of `await` then the next time around having decided to wipe any
knowledge of tours I had, I figured it wasn't possible that tours were
so stupid as to not support promises.

So yeah, can't just return a "pending" promise in order to force the
tour manager to wait until the page has reloaded to carry on, that
doesn't work. Instead use marker classes. Also remove the `async run`
I had in the rest of the file to avoid being misleading, use a marker
class for the one step where it probably matters.

closes odoo/odoo#58128

X-original-commit: d252b0c6311fd389295e980e6f9725673ce8b650
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-09-21 12:29:28 +00:00
Xavier Morel 152ff868b7 [IMP] auth_totp: reliability of tour
On runbot the tour shows transient failures related to race
conditions.

The issue here is that when a user updates their own TOTP status, if
hr is not installed this will close the Preferences dialog requiring
reopening the dialog in order to check that everything worked.

However if hr is installed there is no dialog ("My Profile" opens as a
full action, which will not disappear on TOTP updates).

We still reopen the My Profile action, but if the server is a bit too
slow the tour may see the "old" version of "My Profile" which has not
been unloaded, click the tab to go to the next step, but because it's
already there the action has no effect, the next step is triggered
when "My Profile" finally (re)loads at which point we're back on the
first tab while the tour believes it should be on the second, and the
tour breaks.

Fix this by forcing a full reload of the action: between updating TOTP
status and checking for the status change, navigate to the Discuss
application then back to the preferences / profile screen.

closes odoo/odoo#57843

X-original-commit: 7a1dc71186d00ece21cede205a045fa93cd6dcfb
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-09-16 12:35:32 +00:00
Xavier Morel 9c58c51179 [IMP] auth_totp: totp screen layout when website is installed
Apparently website's login layout removes the "card" around the login
form, and only the inner login form remains and is centered.

Put the card-title inside the login form, it doesn't seem to affect
the web layout in noticeable ways, just fixes the layout when website
is installed.

closes odoo/odoo#56144

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-09-10 12:49:00 +00:00
Xavier Morel 6f4f8f0265 [IMP] auth_totp: notify user on activation and deactivation of OTP
Was not super visible, especially without HR as the dialog immediately
closes (limitation of the web client), or when an administrator user
massively disables totp.

Show a toast notification indicating the success of the action.

Also fix the logging of `totp_disable` so it correctly handles being
called on more than one record, and change the logging data to
<browse_record> (<logins>) across the board.

Also add a way to provide an action to execute after a notification:
by default nothing happens, which leads to dialogs not closing and
forms not reloading, and there is no good way to show a notification
and/then do some other thing, which is inconvenient.
2020-09-10 12:49:00 +00:00
Xavier Morel 3e7d096f32 [WIP] base, auth_totp: add doc links for 2FA & API keys 2020-09-10 12:49:00 +00:00
Xavier Morel eac225e3ea [IMP] auth_totp: label of totp_enabled field & show status in form
Use same look in form as in preferences dialog, just without the
buttons to enable / disable it (technically could have the button to
disable with the correct group I guess?)
2020-09-10 12:49:00 +00:00
Xavier Morel ba03154d63 [IMP] auth_totp: better issuer label
The "issuer" being the user's company is not necessarily helpful as
e.g. the company might have multiple services which all use 2FA.

Use the domain name instead (fallback on the company if for some
reason we're in a situation where this is computed without a request).
2020-09-10 12:47:42 +00:00
Xavier Morel 70b6ac5009 [IMP] auth_totp: allow spaces in totp code input
TOTP programs generally group the code into two groups of 3 digits,
but we'd only allow a single group of 6 digits.

Allow spaces in the value for a bit of flexibility, and fix
placeholders to look like codes (also turns out @placeholder on a
field doesn't do anything, not sure where I got this idea).

Also improve the label slightly in the login flow:

* add information to the label itself
* properly link the label & input via an `id`
2020-09-10 12:47:15 +00:00
Xavier Morel 011d55d3e1 [FIX] auth_totp: session update after enabling or disabling totp
bfcc7dee8f tried to fix the session
disconnection issue, but the fix only worked in single-process (either
threaded or workers=1): because the cache was cleared but the update
not flushed, since `_compute_session_token` uses SQL directly it would
recompute the old session_token which it would cache, and thus the
process would carry-on with the old token just re-set in the session
and cache.

Meanwhile in multi-process, odds are good that the next request will
be on a different worker which *will* see the change, and will
immediately complain & destroy the session.

Add the missing flush calls right before recomputing the session token
so the SQL "sees" the correct state.
2020-09-10 12:46:10 +00:00
Xavier Morel f3574caf7c [IMP] auth_totp: import qrcode lazily
fp request

closes odoo/odoo#57377

X-original-commit: e10cbc792f8f6432f8ee5d8065cd4a123f2a4754
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-09-09 15:23:01 +00:00
Martin Trigaux 90d85eb9c5 [I18N] export saas-13.5 source terms
Without demo data

closes odoo/odoo#56869

X-original-commit: 33f251b6489455cd7221f2c62dee0400a69784b8
Related: odoo/enterprise#12836
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2020-09-01 11:18:00 +00:00
Xavier Morel 17ae856cc1 [FIX] auto_totp: tour & check RPC w/ token
* Not sure how the tour passed during merge as it would not be looking
  for the button in the right tab, it would fail locally, fix this
  issue by properly switching to the Account Security tab
* add the missing test of RPC (which should not work on an account
  with totp enabled)
* also reorder ops & fix comments: turns out `totp_login_enabled`
  checks that totp is enabled *then disables it*

closes odoo/odoo#55979

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-08-17 09:30:53 +00:00
Xavier Morel bfa00919cd [IMP] core: clarify making fields inaccessible
* add a constant to `fields` for that purpose
* add a test to ensure that it works as expected
* fix the formatter so it handles the pattern correctly
2020-08-17 09:30:53 +00:00
Olivier Dony bfcc7dee8f [FIX] auth_totp: add totp secret to session-relevant fields
Setting the totp secret is a significant change to the user's
auth-ability, and as such should be taken in account for the session's
validity.

For convenience, update the user's session in-place to avoid logging
them out.
2020-08-17 09:30:41 +00:00
Xavier MorelandOlivier Dony a9a6509713 [ADD] auth_totp
New module for supporting two-factor authentication via time-base
one-time-password (TOTP).

Users (including portal users) can choose to enable two-factor auth in
their user account settings, by scanning a QR code and adding it to an
authenticator app, such as Google Auth, 1Password, etc.

When two-factor is enabled, password-based non-interactive RPC is only
possible by using API keys.

Co-authored-by: Olivier Dony <odo@odoo.com>
2020-08-14 23:06:24 +00:00