Files
odoo_source/odoo/addons/test_auth_custom/__init__.py
T
Xavier Morel 9e27956aa9 [FIX] core: handle cors preflight with custom auth
Odoo provides basic handling of CORS preflight requests: if an
endpoint is marked as `cors=<truthy value>` then it'll automatically
reply allowing the request.

*However* this is performed in `HttpRequest.dispatch` (likely in order
to correctly handle the nodb case), which means it's executed after
the auth handler has run... which means custom auth handlers will be
called on preflight requests.

This is a problem because they are missing relevant
information (e.g. which endpoint they're invoked for), plus having to
deal with preflight requests in every custom auth handler is annoying,
and simply allowing preflights could cause issues if the decision
diverges between the auth handler and the automatic
handling.

To fix this issue, extract the preflight *decision* into a separate
method so we get the same decision-making process everywhere, and in
case of CORS preflight set the auth to none to limit the eventual
capacity for nuisance in the span between the bypassed auth and the
automated preflight handling.

Also change the signature of IrHttp._authenticate so it's clearer if a
callsite was forgotten somehow (and this makes for less changes and
duplication at the callsites).

closes odoo/odoo#56029

Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
2020-08-19 13:41:24 +00:00

23 lines
691 B
Python

from odoo import models
from odoo.exceptions import AccessDenied
from odoo.http import Controller, route
class IrHttp(models.AbstractModel):
_inherit = 'ir.http'
@classmethod
def _auth_method_thing(cls):
raise AccessDenied()
class TestController(Controller):
# for HTTP endpoints, must allow OPTIONS or werkzeug won't match the route
# when dispatching the CORS preflight
@route('/test_auth_custom/http', type="http", auth="thing", cors="*", methods=['GET', 'OPTIONS'])
def _http(self):
raise NotImplementedError
@route('/test_auth_custom/json', type="json", auth="thing", cors="*")
def _json(self):
raise NotImplementedError