TIP: You can type at any time to perform a new search.
Auth JWT
auth_jwt · OCA/server-auth
Security findings
- Repository
- OCA/server-auth · module folder · Try on Runboat
- Module version
- 1.0.2
- Category
- Uncategorized
- Folder size
- 0.11 MB
- License
- LGPL-3
- Application
- No
- Auto-installable
- No
- Website
- https://github.com/OCA/server-auth
- Last tracking update
- 2026-10-03 23:57:03
- Authors
- ACSONE SA/NV, Odoo Community Association (OCA)
- Maintainers
- ACSONE SA/NV, Odoo Community Association (OCA)
- Committers
- Stefan Rijnhart, Stéphane Bidoul, kobros-tech, OCA-git-bot, oca-ci
- Odoo dependencies
- None
- Python dependencies
- cryptography, pyjwt
- System dependencies
- None
- Required by
- auth_jwt_demo, fastapi_auth_jwt
- Description
JWT bearer token authentication.
Code Analysis
Views touched (2)
| XML ID | Name | Model | Type | Status |
|---|---|---|---|---|
view_auth_jwt_validator_form |
auth.jwt.validator.form | auth.jwt.validator | form | New |
view_auth_jwt_validator_tree |
auth.jwt.validator.tree | auth.jwt.validator | list | New |
HTTP endpoints (0)
No HTTP endpoints found for this module.
Models touched (2)
New fields (18)
-
audienceCharhelp='Comma separated list of audiences, to validate aud.'required=True -
cookie_enabledBooleanhelp='Convert the JWT token into an HttpOnly Secure cookie. When both an Authorization header and the cookie are present in the request, the cookie is ignored.' -
cookie_max_ageIntegerdefault=<expr>help='Number of seconds until the cookie expires (Max-Age).' -
cookie_nameChardefault='authorization' -
cookie_pathChardefault='/' -
cookie_secureBooleandefault=Truehelp='Set to false only for development without https.' -
issuerCharhelp='To validate iss.'required=True -
nameCharrequired=True -
next_validator_idMany2one → auth.jwt.validatordomain="[('id', '!=', id)]"help='Next validator to try if this one fails' args: 'auth.jwt.validator' -
partner_id_requiredBoolean -
partner_id_strategySelectionargs: [('email', 'From email claim')] -
public_key_algorithmSelectiondefault='RS256' args: [('ES256', 'ES256 - ECDSA using SHA-256'), ('ES256K', 'ES256K - ECDSA with secp256k1 curve using SHA-256'), ('ES384', 'ES384 - ECDSA using SHA-384'), ('ES512', 'ES512 - ECDSA using SHA-512'), ('RS256', 'RS256 - RSASSA-PKCS1-v1_5 using SHA-256'), ('RS384', 'RS384 - RSASSA-PKCS1-v1_5 using SHA-384'), ('RS512', 'RS512 - RSASSA-PKCS1-v1_5 using SHA-512'), ('PS256', 'PS256 - RSASSA-PSS using SHA-256 and MGF1 padding with SHA-256'), ('PS384', 'PS384 - RSASSA-PSS using SHA-384 and MGF1 padding with SHA-384'), ('PS512', 'PS512 - RSASSA-PSS using SHA-512 and MGF1 padding with SHA-512')] -
public_key_jwk_uriChar -
secret_algorithmSelectiondefault='HS256' args: [('HS256', 'HS256 - HMAC using SHA-256 hash algorithm'), ('HS384', 'HS384 - HMAC using SHA-384 hash algorithm'), ('HS512', 'HS512 - HMAC using SHA-512 hash algorithm')] -
secret_keyChar -
signature_typeSelectionrequired=True args: [('secret', 'Secret'), ('public_key', 'Public key')] -
static_user_idMany2one → res.usersdefault=1 args: 'res.users' -
user_id_strategySelectiondefault='static'required=True args: [('static', 'Static')]
-
create(self, vals)@api.model_create_multi -
unlink(self) -
write(self, vals)
New fields (0)
No new fields.
Public methods (0)No public methods.
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
- Status
- Open migration PR — not merged yet for this version
- CI status
- green — ready to merge
- Open since
- 366 days ago
- Last activity
- 33 days ago
- Repository
- OCA/server-auth
- Pull request
- [19.0][MIG] auth_jwt: Migration to 19.0 (#844)