TIP: You can type at any time to perform a new search.

Security findings

Repository
OCA/server-auth · module folder · Try on Runboat
Module version
1.0.0
Category
Uncategorized
Folder size
0.28 MB
License
AGPL-3
Application
No
Auto-installable
No
Website
https://github.com/OCA/server-auth
Last tracking update
2026-10-04 00:16:48
Authors
ACSONE SA/NV, Odoo Community Association (OCA), ICTSTUDIO, André Schenkels
Maintainers
ACSONE SA/NV, Odoo Community Association (OCA), ICTSTUDIO, André Schenkels
Committers
Andreas Perhab, Weblate, OCA-git-bot, oca-ci
Odoo dependencies
Python dependencies
python-jose
System dependencies
None
Required by
None
Description
This module allows users to login through an OpenID Connect provider
using the authorization code flow or implicit flow.

Note the implicit flow is not recommended because it exposes access
tokens to the browser and in http logs.

Code Analysis info_outline

Views touched (1)
XML IDNameModelTypeStatus
view_oidc_provider_form auth.oidc.provider.form auth.oauth.provider form Inherits auth_oauth.view_oauth_provider_form
HTTP endpoints (0)

No HTTP endpoints found for this module.

Models touched (2)

New fields (7)
  • client_secret Char
    help='Used in OpenID Connect authorization code flow for confidential clients.'
  • code_verifier Char
    default=<expr> help='Used for PKCE.'
  • flow Selection
    default='access_token' required=True string='Auth Flow' args: [('access_token', 'OAuth2'), ('id_token_code', 'OpenID Connect (authorization code flow)'), ('id_token', 'OpenID Connect (implicit flow, not recommended)')]
  • jwks_uri Char
    help='Required for OpenID Connect.' string='JWKS URL'
  • token_endpoint Char
    help='Required for OpenID Connect authorization code flow.' string='Token URL'
  • token_map Char
    help="Some Oauth providers don't map keys in their responses exactly as required. It is important to ensure user_id and email at least are mapped. For OpenID Connect user_id is the sub key in the standard."
  • validation_endpoint Char
    required=False
Public methods (0)

No public methods.

New fields (0)

No new fields.

Public methods (1)
  • auth_oauth(self, provider, params)
    @api.model

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…