Files
odoo_source/addons/mail/controllers/home.py
T
Xavier Morel 5a6d4c4932 [FIX] mail: when warning about password user, fetch partner as su
The superuser is already used to check whether modules are installed
with demo data and create the notification.

It was not used for accessing the admin partner though, so in the case
where a user is logging in with the password "admin" and with no
access to `partner_admin` it's going to blow up the login process
despite no reason to.

Admittedly this is somewhat difficult to achieve in "standard" odoo,
it was only discovered because 2FA (odoo/odoo#33928) can reach this
point without having a "proper" session set up as that set up is
delayed until after the MFA step has succeeded while
`_admin_password_warn` is part of the redirection flow from the
initial login (user/password input).

closes odoo/odoo#53244

X-original-commit: d18d226084a8b47f2858d8a271886115b29d7b2f
Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-06-18 12:17:15 +00:00

43 lines
1.6 KiB
Python

# -*- coding: utf-8 -*-
import ipaddress
from odoo import _, SUPERUSER_ID
from odoo.http import request
from odoo.addons.web.controllers import main as web
def _admin_password_warn(uid):
""" Admin still has `admin` password, flash a message via chatter.
Uses a private mail.channel from the system (/ odoobot) to the user, as
using a more generic mail.thread could send an email which is undesirable
Uses mail.channel directly because using mail.thread might send an email instead.
"""
if request.params['password'] != 'admin':
return
if ipaddress.ip_address(request.httprequest.remote_addr).is_private:
return
env = request.env(user=SUPERUSER_ID, su=True)
admin = env.ref('base.partner_admin')
if uid not in admin.user_ids.ids:
return
has_demo = bool(env['ir.module.module'].search_count([('demo', '=', True)]))
if has_demo:
return
user = request.env(user=uid)['res.users']
MailChannel = env(context=user.context_get())['mail.channel']
MailChannel.browse(MailChannel.channel_get([admin.id])['id'])\
.message_post(
body=_("Your password is the default (admin)! If this system is exposed to untrusted users it is important to change it immediately for security reasons. I will keep nagging you about it!"),
message_type='comment',
subtype_xmlid='mail.mt_comment'
)
class Home(web.Home):
def _login_redirect(self, uid, redirect=None):
if request.params.get('login_success'):
_admin_password_warn(uid)
return super()._login_redirect(uid, redirect)