Files
odoo_source/odoo/service/security.py
T
Xavier Morel aac21e4125 [CHG] Change login/auth internal protocol
* Make Users._login and session.authenticate always raise AccessDenied
  on authentication failure instead of only sometimes (cf
  Session.authenticate calling security.check() which raises and not
  catching the exception)
* Alter AccessDenied such that it's possible to add a custom access
  message, for use with login rate limiting instead of smuggling the
  information via the session
* Alter the RPC endpoints to catch and convert AccessDenied back to
  a boolean sentinel
2018-07-26 15:53:26 +02:00

29 lines
891 B
Python

# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
import odoo
import odoo.exceptions
def login(db, login, password):
res_users = odoo.registry(db)['res.users']
try:
return res_users._login(db, login, password)
except odoo.exceptions.AccessDenied:
return False
def check(db, uid, passwd):
res_users = odoo.registry(db)['res.users']
return res_users.check(db, uid, passwd)
def compute_session_token(session, env):
self = env['res.users'].browse(session.uid)
return self._compute_session_token(session.sid)
def check_session(session, env):
self = env['res.users'].browse(session.uid)
expected = self._compute_session_token(session.sid)
if expected and odoo.tools.misc.consteq(expected, session.session_token):
return True
self._invalidate_session_cache()
return False