TIP: You can type at any time to perform a new search.

Security findings

Repository
OCA/server-auth · module folder · Try on Runboat
Module version
1.0.2
Category
Uncategorized
Folder size
0.11 MB
License
LGPL-3
Application
No
Auto-installable
No
Website
https://github.com/OCA/server-auth
Last tracking update
2026-10-03 23:57:03
Authors
ACSONE SA/NV, Odoo Community Association (OCA)
Maintainers
ACSONE SA/NV, Odoo Community Association (OCA)
Committers
Stefan Rijnhart, Stéphane Bidoul, kobros-tech, OCA-git-bot, oca-ci
Odoo dependencies
None
Python dependencies
cryptography, pyjwt
System dependencies
None
Required by
auth_jwt_demo, fastapi_auth_jwt
Description
JWT bearer token authentication.

Code Analysis info_outline

Views touched (2)
XML IDNameModelTypeStatus
view_auth_jwt_validator_form auth.jwt.validator.form auth.jwt.validator form New
view_auth_jwt_validator_tree auth.jwt.validator.tree auth.jwt.validator list New
HTTP endpoints (0)

No HTTP endpoints found for this module.

Models touched (2)

New fields (18)
  • audience Char
    help='Comma separated list of audiences, to validate aud.' required=True
  • cookie_enabled Boolean
    help='Convert the JWT token into an HttpOnly Secure cookie. When both an Authorization header and the cookie are present in the request, the cookie is ignored.'
  • cookie_max_age Integer
    default=<expr> help='Number of seconds until the cookie expires (Max-Age).'
  • cookie_name Char
    default='authorization'
  • cookie_path Char
    default='/'
  • cookie_secure Boolean
    default=True help='Set to false only for development without https.'
  • issuer Char
    help='To validate iss.' required=True
  • name Char
    required=True
  • next_validator_id Many2one → auth.jwt.validator
    domain="[('id', '!=', id)]" help='Next validator to try if this one fails' args: 'auth.jwt.validator'
  • partner_id_required Boolean
  • partner_id_strategy Selection
    args: [('email', 'From email claim')]
  • public_key_algorithm Selection
    default='RS256' args: [('ES256', 'ES256 - ECDSA using SHA-256'), ('ES256K', 'ES256K - ECDSA with secp256k1 curve using SHA-256'), ('ES384', 'ES384 - ECDSA using SHA-384'), ('ES512', 'ES512 - ECDSA using SHA-512'), ('RS256', 'RS256 - RSASSA-PKCS1-v1_5 using SHA-256'), ('RS384', 'RS384 - RSASSA-PKCS1-v1_5 using SHA-384'), ('RS512', 'RS512 - RSASSA-PKCS1-v1_5 using SHA-512'), ('PS256', 'PS256 - RSASSA-PSS using SHA-256 and MGF1 padding with SHA-256'), ('PS384', 'PS384 - RSASSA-PSS using SHA-384 and MGF1 padding with SHA-384'), ('PS512', 'PS512 - RSASSA-PSS using SHA-512 and MGF1 padding with SHA-512')]
  • public_key_jwk_uri Char
  • secret_algorithm Selection
    default='HS256' args: [('HS256', 'HS256 - HMAC using SHA-256 hash algorithm'), ('HS384', 'HS384 - HMAC using SHA-384 hash algorithm'), ('HS512', 'HS512 - HMAC using SHA-512 hash algorithm')]
  • secret_key Char
  • signature_type Selection
    required=True args: [('secret', 'Secret'), ('public_key', 'Public key')]
  • static_user_id Many2one → res.users
    default=1 args: 'res.users'
  • user_id_strategy Selection
    default='static' required=True args: [('static', 'Static')]
Public methods (3)
  • create(self, vals)
    @api.model_create_multi
  • unlink(self)
  • write(self, vals)

New fields (0)

No new fields.

Public methods (0)

No public methods.

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…

Status
Open migration PR — not merged yet for this version
CI status
green — ready to merge
Open since
366 days ago
Last activity
33 days ago
Repository
OCA/server-auth
Pull request
[19.0][MIG] auth_jwt: Migration to 19.0 (#844)