steps to reproduce: - install the module "2FA by mail" (auth_totp_mail_enforce) - open settings (this should bring the settings of the settings app) - activate "Two-factor authentification enforcing policy" to "Employees only" (or "All users") and save - try to (re)connect with a user (demo/demo or admin/admin) before this commit: - internal server error after this commit: - error is passed to the user, allowing him (or the admin) to debug without contacting odoo support opw-3624816 closes odoo/odoo#147196 X-original-commit: a449210cc18f64460096cb43b3633d4861120d0e Signed-off-by: Denis Ledoux (dle) <dle@odoo.com>
32 lines
1.2 KiB
Python
32 lines
1.2 KiB
Python
# -*- coding: utf-8 -*-
|
|
import logging
|
|
import odoo.addons.auth_totp.controllers.home
|
|
|
|
from odoo import http
|
|
from odoo.exceptions import AccessDenied, UserError
|
|
from odoo.http import request
|
|
|
|
_logger = logging.getLogger(__name__)
|
|
|
|
|
|
class Home(odoo.addons.auth_totp.controllers.home.Home):
|
|
@http.route()
|
|
def web_totp(self, redirect=None, **kwargs):
|
|
response = super().web_totp(redirect=redirect, **kwargs)
|
|
if response.status_code != 200 or response.qcontext['user']._mfa_type() != 'totp_mail':
|
|
# In case the response from the super is a redirection
|
|
# or the user has another TOTP method, we return the response from the call to super.
|
|
return response
|
|
assert request.session.pre_uid and not request.session.uid, \
|
|
"The user must still be in the pre-authentication phase"
|
|
|
|
# Send the email containing the code to the user inbox
|
|
try:
|
|
response.qcontext['user']._send_totp_mail_code()
|
|
except (AccessDenied, UserError) as e:
|
|
response.qcontext['error'] = str(e)
|
|
except Exception as e:
|
|
_logger.exception('Unable to send TOTP email')
|
|
response.qcontext['error'] = str(e)
|
|
return response
|