TIP: You can type at any time to perform a new search.

Security findings

Repository
OCA/server-auth · module folder · Try on Runboat
Module version
1.0.0
Category
Tools
Folder size
0.22 MB
License
AGPL-3
Application
No
Auto-installable
No
Website
https://github.com/OCA/server-auth
Last tracking update
2026-10-04 00:16:48
Authors
Odoo Community Association (OCA), XCG Consulting
Maintainers
Odoo Community Association (OCA), XCG Consulting
Committers
Weblate, OCA-git-bot, oca-ci, Vincent Hatakeyama
Odoo dependencies
odoo/odoo:
- web
Python dependencies
pysaml2, responses
System dependencies
xmlsec1
Required by
None
Description
Let users log into Odoo via an SAML2 identity provider.

This module allows to deport the management of users and passwords in an
external authentication system to provide SSO functionality (Single Sign
On) between Odoo and other applications of your ecosystem.

**Benefits**:

- Reducing the time spent typing different passwords for different
  accounts.
- Reducing the time spent in IT support for password oversights.
- Centralizing authentication systems.
- Securing all input levels / exit / access to multiple systems without
  prompting users.
- The centralization of access control information for compliance
  testing to different standards.

Code Analysis info_outline

Views touched (6)
XML IDNameModelTypeStatus
auth_saml.providers Auth SAML Providers ir.ui.view qweb Inherits web.login_oauth
auth_saml_base_settings_form auth_saml_base_settings_form res.config.settings form Inherits base.res_config_settings_view_form
auth_saml_provider_view_search auth.saml.provider.search auth.saml.provider search New
view_saml_provider_form auth.saml.provider.form auth.saml.provider form New
view_saml_provider_list auth.saml.provider.list auth.saml.provider list New
view_users_form res.users.form res.users form Inherits base.view_users_form
HTTP endpoints (5)
Route(s)HandlerAuthTypeMethodsFlags
/auth_saml/get_auth_request AuthSAMLController.get_auth_request none http ALL sudo
/auth_saml/metadata AuthSAMLController.saml_metadata none http ALL csrf off sudo
/auth_saml/signin AuthSAMLController.signin none http ALL csrf off
(inherited route override) SAMLLogin.web_client inherited http ALL
(inherited route override) SAMLLogin.web_login inherited http ALL
Models touched (7)

New fields (3)
  • attribute_name Char
    required=True string='IDP Response Attribute'
  • field_name Selection
    required=True selection='_field_name_selection' string='Odoo Field'
  • provider_id Many2one → auth.saml.provider
    index=True ondelete='cascade' required=True args: 'auth.saml.provider'
Public methods (0)

No public methods.

New fields (29)
  • active Boolean
    default=True
  • attribute_mapping_ids One2many → auth.saml.attribute.mapping
    copy=True string='Attribute Mapping' args: 'auth.saml.attribute.mapping', 'provider_id'
  • authn_requests_signed Boolean
    default=True help='Indicates if the Authentication Requests sent by this SP should be signed by default.'
  • autoredirect Boolean
    default=False help='Only the provider with the higher priority will be automatically redirected' args: 'Automatic Redirection'
  • body Char
    help='Link text in Login Dialog' string='Login button label' translate=True
  • create_user Boolean
    default=False help='Create user if not found. The login and name will defaults to the SAML user matching attribute. Use the mapping attributes to change the value used. If a deactivated user has a matching saml uid, activate it rather thancreate a new one.'
  • create_user_reactivate Boolean
    default=False help='If a deactivated user has a matching SAML uid when trying to create the user, and this is checked, then the user is reactivated. Otherwise,access is denied.' args: 'Reactivate when Creating Users'
  • create_user_template_id Many2one → res.users
    comodel_name='res.users' domain="[('active', 'in', (True, False))]" help='When creating user, this user is used as a template'
  • css_class Char
    default='fa fa-fw fa-sign-in text-primary' help='Add a CSS class that serves you to style the login button.' string='Button Icon CSS class'
  • entity_id Char
    default='odoo' help='EntityID passed to IDP, used to identify the Odoo' required=True args: 'Entity ID'
  • idp_metadata Text
    help='Configuration for this Identity Provider. Supplied by the provider, in XML format.' required=True string='Identity Provider Metadata'
  • idp_metadata_url Char
    help='Some SAML providers, notably Office365 can have a metadata document which changes over time, and they provide a URL to the document instead. When this field is set, the metadata can be fetched from the provided URL.' string='Identity Provider Metadata URL'
  • logout_requests_signed Boolean
    default=True help='Indicates if this entity will sign the Logout Requests originated from it.'
  • matching_attribute Char
    default='subject.nameId' help='Attribute to look for in the returned IDP response to match against an Odoo user.' required=True string='Identity Provider matching attribute'
  • matching_attribute_to_lower Boolean
    help='Force matching_attribute to lower case before passing back to Odoo.' string='Lowercase IDP Matching Attribute'
  • name Char
    index='trigram' required=True args: 'Provider Name'
  • sequence Integer
    index=True
  • sig_alg Selection
    required=True selection=<expr> string='Signature Algorithm'
  • sign_authenticate_requests Boolean
    default=True help='Whether the request should be signed or not'
  • sign_metadata Boolean
    default=True help='Whether metadata should be signed or not'
  • sp_baseurl Text
    help='Base URL sent to Odoo with this, rather than automatically\n detecting from request or system parameter web.base.url' string='Override Base URL'
  • sp_metadata_url Char
    compute='_compute_sp_metadata_url' readonly=True string='Metadata URL'
  • sp_pem_private Binary
    attachment=True required=True string='Odoo Private Key'
  • sp_pem_private_filename Char
    args: 'Odoo Private Key File Name'
  • sp_pem_public Binary
    attachment=True required=True string='Odoo Public Certificate'
  • sp_pem_public_filename Char
    args: 'Odoo Public Certificate File Name'
  • want_assertions_or_response_signed Boolean
    default=True help='Indicates that either the Authentication Response or the assertions contained within the response to this SP must be signed.'
  • want_assertions_signed Boolean
    default=True help='Indicates if this SP wants the IdP to send the assertions signed.'
  • want_response_signed Boolean
    default=True help='Indicates that Authentication Responses to this SP must be signed.'
Public methods (1)
  • action_refresh_metadata_from_url(self)

New fields (2)
  • saml_provider_id Many2one → auth.saml.provider
    required=True string='SAML Provider that issued the token' args: 'auth.saml.provider'
  • saml_request_id Char
    required=True args: 'Current Request ID'
Public methods (0)

No public methods.

New fields (0)

No new fields.

Public methods (3)
  • create(self, vals_list)
    @api.model_create_multi
    Redefined to update users when our parameter is changed.
  • unlink(self)
    Redefined to update users when our parameter is deleted.
  • write(self, vals)
    Redefined to update users when our parameter is changed.

New fields (1)
  • allow_saml_uid_and_internal_password Boolean
    config_parameter=ALLOW_SAML_UID_AND_PASSWORD args: 'Allow SAML users to possess an Odoo password (warning: decreases security)'
Public methods (0)

No public methods.

New fields (1)
  • saml_ids One2many → res.users.saml
    args: 'res.users.saml', 'user_id'
Public methods (3)
  • allow_saml_and_password(self) -> bool
    @api.model
    Can both SAML and local password auth methods coexist.
  • allow_saml_and_password_changed(self)
    Called after the parameter is changed.
  • auth_saml(self, provider: int, saml_response: str, base_url: str=None)
    @api.model

New fields (4)
  • saml_access_token Char
    help='The current SAML token in use' required=False args: 'Current SAML token for this user'
  • saml_provider_id Many2one → auth.saml.provider
    index=True string='SAML Provider' args: 'auth.saml.provider'
  • saml_uid Char
    help='SAML Provider user_id' required=True args: 'SAML User ID'
  • user_id Many2one → res.users
    index=True ondelete='cascade' required=True args: 'res.users'
Public methods (1)
  • create(self, vals_list)
    @api.model_create_multi
    Creates new records for the res.users.saml model

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…