Files
odoo_source/odoo/service/security.py
T
Martin Trigaux 96f01c08f8 [FIX] service: properly invalidate session of deteled users
If a user A deletes the res.users record of user B while B is connected,
the verification of the session token fails with a comparison of a boolean and
bytes values.
While the check should obviously fail, this patch gracefully inform the user B
its session has expired and redirect him to the login page.

Without the patch, the session is never invalidated in the user browser,
redirecting to a forbidden error page as long as the session has not been manually
cleared from the browser.

Fixes #25530
Closes #25654
Closes #25682
2018-07-10 13:49:41 +02:00

26 lines
816 B
Python

# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
import odoo
import odoo.exceptions
def login(db, login, password):
res_users = odoo.registry(db)['res.users']
return res_users._login(db, login, password)
def check(db, uid, passwd):
res_users = odoo.registry(db)['res.users']
return res_users.check(db, uid, passwd)
def compute_session_token(session, env):
self = env['res.users'].browse(session.uid)
return self._compute_session_token(session.sid)
def check_session(session, env):
self = env['res.users'].browse(session.uid)
expected = self._compute_session_token(session.sid)
if expected and odoo.tools.misc.consteq(expected, session.session_token):
return True
self._invalidate_session_cache()
return False