TIP: You can type at any time to perform a new search.
SAML2 Authentication
auth_saml · OCA/server-auth
Security findings
Migration considerations
- Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `SELECT id FROM auth_saml_provider WHERE id in %s FOR UPDATE` - re-check the table/column names still match after upgrading. migration-raw-sql-write · source
- Raw `cr.execute()` INSERT/UPDATE/DELETE bypasses the ORM (no compute/constrains/tracking/mail): `UPDATE res_users SET password = NULL WHERE id IN %s` - re-check the table/column names still match after upgrading. migration-raw-sql-write · source
Migration review checklist, not a compatibility verdict. No target version is selected: apply version-specific advice only when migrating to that version or later.
- Repository
- OCA/server-auth · module folder · Try on Runboat
- Module version
- 1.0.0
- Category
- Tools
- Folder size
- 0.22 MB
- License
- AGPL-3
- Application
- No
- Auto-installable
- No
- Website
- https://github.com/OCA/server-auth
- Last tracking update
- 2026-10-04 00:16:48
- Authors
- Odoo Community Association (OCA), XCG Consulting
- Maintainers
- Odoo Community Association (OCA), XCG Consulting
- Committers
- Weblate, OCA-git-bot, oca-ci, Vincent Hatakeyama
- Odoo dependencies
- Python dependencies
- pysaml2, responses
- System dependencies
- xmlsec1
- Required by
- None
- Description
Let users log into Odoo via an SAML2 identity provider. This module allows to deport the management of users and passwords in an external authentication system to provide SSO functionality (Single Sign On) between Odoo and other applications of your ecosystem. **Benefits**: - Reducing the time spent typing different passwords for different accounts. - Reducing the time spent in IT support for password oversights. - Centralizing authentication systems. - Securing all input levels / exit / access to multiple systems without prompting users. - The centralization of access control information for compliance testing to different standards.
Code Analysis
Views touched (6)
| XML ID | Name | Model | Type | Status |
|---|---|---|---|---|
auth_saml.providers |
Auth SAML Providers | ir.ui.view | qweb | Inherits web.login_oauth |
auth_saml_base_settings_form |
auth_saml_base_settings_form | res.config.settings | form | Inherits base.res_config_settings_view_form |
auth_saml_provider_view_search |
auth.saml.provider.search | auth.saml.provider | search | New |
view_saml_provider_form |
auth.saml.provider.form | auth.saml.provider | form | New |
view_saml_provider_list |
auth.saml.provider.list | auth.saml.provider | list | New |
view_users_form |
res.users.form | res.users | form | Inherits base.view_users_form |
HTTP endpoints (5)
| Route(s) | Handler | Auth | Type | Methods | Flags |
|---|---|---|---|---|---|
/auth_saml/get_auth_request |
AuthSAMLController.get_auth_request |
none | http | ALL | sudo |
/auth_saml/metadata |
AuthSAMLController.saml_metadata |
none | http | ALL | csrf off sudo |
/auth_saml/signin |
AuthSAMLController.signin |
none | http | ALL | csrf off |
| (inherited route override) | SAMLLogin.web_client |
inherited | http | ALL | |
| (inherited route override) | SAMLLogin.web_login |
inherited | http | ALL |
Models touched (7)
New fields (3)
-
attribute_nameCharrequired=Truestring='IDP Response Attribute' -
field_nameSelectionrequired=Trueselection='_field_name_selection'string='Odoo Field' -
provider_idMany2one → auth.saml.providerindex=Trueondelete='cascade'required=True args: 'auth.saml.provider'
No public methods.
New fields (29)
-
activeBooleandefault=True -
attribute_mapping_idsOne2many → auth.saml.attribute.mappingcopy=Truestring='Attribute Mapping' args: 'auth.saml.attribute.mapping', 'provider_id' -
authn_requests_signedBooleandefault=Truehelp='Indicates if the Authentication Requests sent by this SP should be signed by default.' -
autoredirectBooleandefault=Falsehelp='Only the provider with the higher priority will be automatically redirected' args: 'Automatic Redirection' -
bodyCharhelp='Link text in Login Dialog'string='Login button label'translate=True -
create_userBooleandefault=Falsehelp='Create user if not found. The login and name will defaults to the SAML user matching attribute. Use the mapping attributes to change the value used. If a deactivated user has a matching saml uid, activate it rather thancreate a new one.' -
create_user_reactivateBooleandefault=Falsehelp='If a deactivated user has a matching SAML uid when trying to create the user, and this is checked, then the user is reactivated. Otherwise,access is denied.' args: 'Reactivate when Creating Users' -
create_user_template_idMany2one → res.userscomodel_name='res.users'domain="[('active', 'in', (True, False))]"help='When creating user, this user is used as a template' -
css_classChardefault='fa fa-fw fa-sign-in text-primary'help='Add a CSS class that serves you to style the login button.'string='Button Icon CSS class' -
entity_idChardefault='odoo'help='EntityID passed to IDP, used to identify the Odoo'required=True args: 'Entity ID' -
idp_metadataTexthelp='Configuration for this Identity Provider. Supplied by the provider, in XML format.'required=Truestring='Identity Provider Metadata' -
idp_metadata_urlCharhelp='Some SAML providers, notably Office365 can have a metadata document which changes over time, and they provide a URL to the document instead. When this field is set, the metadata can be fetched from the provided URL.'string='Identity Provider Metadata URL' -
logout_requests_signedBooleandefault=Truehelp='Indicates if this entity will sign the Logout Requests originated from it.' -
matching_attributeChardefault='subject.nameId'help='Attribute to look for in the returned IDP response to match against an Odoo user.'required=Truestring='Identity Provider matching attribute' -
matching_attribute_to_lowerBooleanhelp='Force matching_attribute to lower case before passing back to Odoo.'string='Lowercase IDP Matching Attribute' -
nameCharindex='trigram'required=True args: 'Provider Name' -
sequenceIntegerindex=True -
sig_algSelectionrequired=Trueselection=<expr>string='Signature Algorithm' -
sign_authenticate_requestsBooleandefault=Truehelp='Whether the request should be signed or not' -
sign_metadataBooleandefault=Truehelp='Whether metadata should be signed or not' -
sp_baseurlTexthelp='Base URL sent to Odoo with this, rather than automatically\n detecting from request or system parameter web.base.url'string='Override Base URL' -
sp_metadata_urlCharcompute='_compute_sp_metadata_url'readonly=Truestring='Metadata URL' -
sp_pem_privateBinaryattachment=Truerequired=Truestring='Odoo Private Key' -
sp_pem_private_filenameCharargs: 'Odoo Private Key File Name' -
sp_pem_publicBinaryattachment=Truerequired=Truestring='Odoo Public Certificate' -
sp_pem_public_filenameCharargs: 'Odoo Public Certificate File Name' -
want_assertions_or_response_signedBooleandefault=Truehelp='Indicates that either the Authentication Response or the assertions contained within the response to this SP must be signed.' -
want_assertions_signedBooleandefault=Truehelp='Indicates if this SP wants the IdP to send the assertions signed.' -
want_response_signedBooleandefault=Truehelp='Indicates that Authentication Responses to this SP must be signed.'
-
action_refresh_metadata_from_url(self)
New fields (2)
-
saml_provider_idMany2one → auth.saml.providerrequired=Truestring='SAML Provider that issued the token' args: 'auth.saml.provider' -
saml_request_idCharrequired=True args: 'Current Request ID'
No public methods.
New fields (0)
No new fields.
Public methods (3)-
create(self, vals_list)@api.model_create_multiRedefined to update users when our parameter is changed. -
unlink(self)Redefined to update users when our parameter is deleted. -
write(self, vals)Redefined to update users when our parameter is changed.
New fields (1)
-
allow_saml_uid_and_internal_passwordBooleanconfig_parameter=ALLOW_SAML_UID_AND_PASSWORD args: 'Allow SAML users to possess an Odoo password (warning: decreases security)'
No public methods.
New fields (1)
-
saml_idsOne2many → res.users.samlargs: 'res.users.saml', 'user_id'
-
allow_saml_and_password(self) -> bool@api.modelCan both SAML and local password auth methods coexist. -
allow_saml_and_password_changed(self)Called after the parameter is changed. -
auth_saml(self, provider: int, saml_response: str, base_url: str=None)@api.model
New fields (4)
-
saml_access_tokenCharhelp='The current SAML token in use'required=False args: 'Current SAML token for this user' -
saml_provider_idMany2one → auth.saml.providerindex=Truestring='SAML Provider' args: 'auth.saml.provider' -
saml_uidCharhelp='SAML Provider user_id'required=True args: 'SAML User ID' -
user_idMany2one → res.usersindex=Trueondelete='cascade'required=True args: 'res.users'
-
create(self, vals_list)@api.model_create_multiCreates new records for the res.users.saml model
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…