* Make Users._login and session.authenticate always raise AccessDenied on authentication failure instead of only sometimes (cf Session.authenticate calling security.check() which raises and not catching the exception) * Alter AccessDenied such that it's possible to add a custom access message, for use with login rate limiting instead of smuggling the information via the session * Alter the RPC endpoints to catch and convert AccessDenied back to a boolean sentinel
29 lines
891 B
Python
29 lines
891 B
Python
# -*- coding: utf-8 -*-
|
|
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
|
|
|
import odoo
|
|
import odoo.exceptions
|
|
|
|
def login(db, login, password):
|
|
res_users = odoo.registry(db)['res.users']
|
|
try:
|
|
return res_users._login(db, login, password)
|
|
except odoo.exceptions.AccessDenied:
|
|
return False
|
|
|
|
def check(db, uid, passwd):
|
|
res_users = odoo.registry(db)['res.users']
|
|
return res_users.check(db, uid, passwd)
|
|
|
|
def compute_session_token(session, env):
|
|
self = env['res.users'].browse(session.uid)
|
|
return self._compute_session_token(session.sid)
|
|
|
|
def check_session(session, env):
|
|
self = env['res.users'].browse(session.uid)
|
|
expected = self._compute_session_token(session.sid)
|
|
if expected and odoo.tools.misc.consteq(expected, session.session_token):
|
|
return True
|
|
self._invalidate_session_cache()
|
|
return False
|