Commit Graph
4 Commits
Author SHA1 Message Date
Romeo Fragomeli 0cecf918a6 [FIX] auth_totp,mail,web: TOTP authentication with JSON-RPC
Since [1] and [2], the mobile app gets this error when trying to login
on v15, while it was working fine in v14 with TOTP enabled.

The 'authenticate' JSON-RPC route tries to authenticate the user and
then call `session_info()`. As no UID is defined, some methods in
`session_info()` raise an exception and an unexpected error is sent:
* `_is_public()` -> "Expected singleton: res.users()"
* `get_web_translations_hash()` -> "lang"

In this fix, this exception is avoided and the proper result is sent,
allowing the authentication process to continue.

Steps to reproduce:
* Try to connect to an account with TOTP on the mobile app (v15+) => BUG

Refs:
[1] odoo/odoo@80d74e7ee0
[2] odoo/odoo@401fc7efe9

X-original-commit: 65dca67ecdcc2228d90781a9f5ccd99f290ada6c
Part-of: odoo/odoo#79182
2021-10-29 11:54:21 +00:00
Martin Trigaux e8fd353cfa [IMP] auth_totp: add test
Original commit was adding the feature in stable but was replaced by
2dee29a7dc in 15.0

This is the forward port of 4736344a57e176 keeping only the test

closes odoo/odoo#76476

X-original-commit: f707d5887c168604b7b7571ae4adc47d64b4a55a
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
2021-09-14 13:32:14 +00:00
Xavier Morel 17ae856cc1 [FIX] auto_totp: tour & check RPC w/ token
* Not sure how the tour passed during merge as it would not be looking
  for the button in the right tab, it would fail locally, fix this
  issue by properly switching to the Account Security tab
* add the missing test of RPC (which should not work on an account
  with totp enabled)
* also reorder ops & fix comments: turns out `totp_login_enabled`
  checks that totp is enabled *then disables it*

closes odoo/odoo#55979

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-08-17 09:30:53 +00:00
Xavier MorelandOlivier Dony a9a6509713 [ADD] auth_totp
New module for supporting two-factor authentication via time-base
one-time-password (TOTP).

Users (including portal users) can choose to enable two-factor auth in
their user account settings, by scanning a QR code and adding it to an
authenticator app, such as Google Auth, 1Password, etc.

When two-factor is enabled, password-based non-interactive RPC is only
possible by using API keys.

Co-authored-by: Olivier Dony <odo@odoo.com>
2020-08-14 23:06:24 +00:00