5dd1efe3d8bfa4f9dfa1590e963659726bf177fa
Install auth_oauth and via the /web/login, click the "Log in using Odoo.com" button. You are redirected on odoo.com which ask you for your odoo.com login and password. When the login form on odoo.com is submited, you are redirected back on your local database. The problem is that, in case a new account was created on-the-fly, then the login fails with a cryptic error. The actual error is that `request.env.user._is_internal` fails because `user` is an empty recordset where it should had been the just-authenticated user. The problem is an inconsistent transaction state between the cursor of the request, the cursor used with `auth_oauth` (which created a new user) and the cursor used with `authenticate` (which authenticated the new user). Yes, there are 3 cursors. The newly created user just isn't present in the transaction of the request's cursor. Here is the lifetime of the 3 cursors: * request.env.cr, it begins when the http request enters Odoo, it is commited when a http response exits Odoo. * /auth_oauth/signin, it begins roughly at the beginning of the controller, it is commited once after the user is created (so before the authenticate transaction begins but AFTER the request transaction begun), it is commited again when the controller exits. * authenticate, begins when authenticate is called, is commited when it returns. Because the request transaction started before, it cannot access user created by /auth_oauth/signin. Because the route is `auth='none'`, if system administrators append the `auth_oauth` module via `--load` (cli) or `server_wide_modules` (odoorc) then the controller can be accessed without database. This is the reason for the explicit registry/cursor/environment inside this controller, we needed to make sure we are connected to a database, we cannot rely on request. The new approach used in this work is to benefit from `ensure_db()`, the function that is used by various web `auth='none'` controllers such as /web and /web/login. It makes sure that the database we want to connect to is already present on the request, otherwise it repeats the request but this time connecting it to the database. Using this approach we can have a `auth='none'` controller whose request.env is guaranteed to be connected on the right database. We can avoid to create explicit new registry/cursor/environment within the controller and just use request's ones. Because the /auth_oauth/signin controller now simply use the request transaction, the above point: > Because the request transaction started before, it cannot access user > created by /auth_oauth/signin. just doesn't stand anymore as the user is created within the same transaction. The extra `cr.commit()` must still be present for `authenticate` to see the newly created user. opw-3421701 closes odoo/odoo#138051 X-original-commit: e165568f9795af213c8467a7f17948ed781b0799 Signed-off-by: Olivier Dony (odo) <odo@odoo.com> Co-authored-by: Julien Castiaux <juc@odoo.com>
…
…
…
…
Odoo
Odoo is a suite of web based open source business apps.
The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...
Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.
Getting started with Odoo
For a standard installation please follow the Setup instructions from the documentation.
To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials
Languages
Python
49.6%
JavaScript
47.8%
SCSS
2%
CSS
0.3%
HTML
0.2%