Since [1] and [2], the mobile app gets this error when trying to login
on v15, while it was working fine in v14 with TOTP enabled.
The 'authenticate' JSON-RPC route tries to authenticate the user and
then call `session_info()`. As no UID is defined, some methods in
`session_info()` raise an exception and an unexpected error is sent:
* `_is_public()` -> "Expected singleton: res.users()"
* `get_web_translations_hash()` -> "lang"
In this fix, this exception is avoided and the proper result is sent,
allowing the authentication process to continue.
Steps to reproduce:
* Try to connect to an account with TOTP on the mobile app (v15+) => BUG
Refs:
[1] odoo/odoo@80d74e7ee0
[2] odoo/odoo@401fc7efe9
X-original-commit: 65dca67ecdcc2228d90781a9f5ccd99f290ada6c
Part-of: odoo/odoo#79182
Original commit was adding the feature in stable but was replaced by
2dee29a7dc in 15.0
This is the forward port of 4736344a57e176 keeping only the test
closesodoo/odoo#76476
X-original-commit: f707d5887c168604b7b7571ae4adc47d64b4a55a
Signed-off-by: Martin Trigaux (mat) <mat@odoo.com>
* Not sure how the tour passed during merge as it would not be looking
for the button in the right tab, it would fail locally, fix this
issue by properly switching to the Account Security tab
* add the missing test of RPC (which should not work on an account
with totp enabled)
* also reorder ops & fix comments: turns out `totp_login_enabled`
checks that totp is enabled *then disables it*
closesodoo/odoo#55979
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
New module for supporting two-factor authentication via time-base
one-time-password (TOTP).
Users (including portal users) can choose to enable two-factor auth in
their user account settings, by scanning a QR code and adding it to an
authenticator app, such as Google Auth, 1Password, etc.
When two-factor is enabled, password-based non-interactive RPC is only
possible by using API keys.
Co-authored-by: Olivier Dony <odo@odoo.com>