Odoo provides basic handling of CORS preflight requests: if an endpoint is marked as `cors=<truthy value>` then it'll automatically reply allowing the request. *However* this is performed in `HttpRequest.dispatch` (likely in order to correctly handle the nodb case), which means it's executed after the auth handler has run... which means custom auth handlers will be called on preflight requests. This is a problem because they are missing relevant information (e.g. which endpoint they're invoked for), plus having to deal with preflight requests in every custom auth handler is annoying, and simply allowing preflights could cause issues if the decision diverges between the auth handler and the automatic handling. To fix this issue, extract the preflight *decision* into a separate method so we get the same decision-making process everywhere, and in case of CORS preflight set the auth to none to limit the eventual capacity for nuisance in the span between the bypassed auth and the automated preflight handling. Also change the signature of IrHttp._authenticate so it's clearer if a callsite was forgotten somehow (and this makes for less changes and duplication at the callsites). closes odoo/odoo#56029 Signed-off-by: Xavier Morel (xmo) <xmo@odoo.com>
23 lines
691 B
Python
23 lines
691 B
Python
from odoo import models
|
|
from odoo.exceptions import AccessDenied
|
|
from odoo.http import Controller, route
|
|
|
|
|
|
class IrHttp(models.AbstractModel):
|
|
_inherit = 'ir.http'
|
|
|
|
@classmethod
|
|
def _auth_method_thing(cls):
|
|
raise AccessDenied()
|
|
|
|
class TestController(Controller):
|
|
# for HTTP endpoints, must allow OPTIONS or werkzeug won't match the route
|
|
# when dispatching the CORS preflight
|
|
@route('/test_auth_custom/http', type="http", auth="thing", cors="*", methods=['GET', 'OPTIONS'])
|
|
def _http(self):
|
|
raise NotImplementedError
|
|
|
|
@route('/test_auth_custom/json', type="json", auth="thing", cors="*")
|
|
def _json(self):
|
|
raise NotImplementedError
|