Files
odoo_source/addons/project/controllers
Thomas Lefebvre (thle) 86ffeb2e5d [FIX] project: update token even if False
Steps to reproduce:
- take a project;
- change the visibility to allow sharing;
- click on "SHARE EDITABLE";
- share the project with a portal user;
- login as portal;
- try to open a project task.
Remark: the problem does not occur for all tasks.

Issue:
A traceback appears.

Cause:
Error occurs because: `return (token and record and consteq(record[token_field], token))`
compare two values with different type.
- `token` is equal to `'null'`
- `record[token_field]` is equal to `False`

In the code: `consteq = hmac_lib.compare_digest`

> `hmac.compare_digest(a, b)`
Return `a == b`.
This function uses an approach designed to prevent timing analysis
by avoiding content-based short circuiting behaviour, making it appropriate for cryptography.
a and b must both be of the same type:
either str (ASCII only, as e.g. returned by HMAC.hexdigest()), or a bytes-like object.
[source](https://docs.python.org/3/library/hmac.html#hmac.compare_digest)

The source of the problem is upstream to this comparison.
Indeed, we first test if we have a token.
As the value of the token is `'null'`, we pass the condition.

Solution:
It is necessary to have a token equal to `False` if the task has not token.
Therefore, whatever the value of the token (token value or `False`), we have to update the token.

opw-3217490

closes odoo/odoo#115947

X-original-commit: dd3a59fa28c5644be93cc2778e0c6854a4481d51
Signed-off-by: Xavier Bol (xbo) <xbo@odoo.com>
2023-03-20 23:49:09 +01:00
..
…