TIP: You can type at any time to perform a new search.

Security findings

Repository
OCA/server-auth · module folder · Try on Runboat
Module version
1.1.0
Category
Tools
Folder size
0.72 MB
License
LGPL-3
Application
No
Auto-installable
No
Website
https://github.com/OCA/server-auth
Last tracking update
2026-10-03 22:39:58
Authors
Odoo Community Association (OCA), LasLabs
Maintainers
Odoo Community Association (OCA), LasLabs
Committers
GitHub, Patrick Tombez, Weblate, OCA Transbot, OCA-git-bot, oca-travis
Odoo dependencies
odoo/odoo:
- web
Python dependencies
pyotp
System dependencies
None
Required by
auth_totp_password_security
Description

Code Analysis info_outline

Views touched (4)
XML IDNameModelTypeStatus
mfa_login MFA Login Page ir.ui.view qweb New
res_users_authenticator_create_view_form MFA App/Device Creation Wizard res.users.authenticator.create form New
view_users_form User Form - MFA Settings res.users form Inherits base.view_users_form
view_users_form_simple_modif Change My Preferences - MFA Settings res.users form Inherits base.view_users_form_simple_modif
HTTP endpoints (3)
Route(s)HandlerAuthTypeMethodsFlags
/auth_totp/login AuthTotp.mfa_login_get public http GET website
/auth_totp/login AuthTotp.mfa_login_post none http POST sudo
(inherited route override) AuthTotp.web_login inherited http ALL
Models touched (3)

New fields (3)
  • authenticator_ids One2many → res.users.authenticator
    comodel_name='res.users.authenticator' help='To delete an authentication app, remove it from this list. To add a new authentication app, please use the button to the right. If the button is not present, you do not have the permissions to do this.' inverse_name='user_id' string='Authentication Apps/Devices'
  • mfa_enabled Boolean
    string='MFA Enabled?'
  • trusted_device_cookie_key Char
    compute='_compute_trusted_device_cookie_key' store=True
Public methods (2)
  • check(cls, db, uid, password)
    @classmethod
    Prevent auth caching for MFA users without active MFA session
  • validate_mfa_confirmation_code(self, confirmation_code)
    @api.multi

New fields (3)
  • name Char
    readonly=True required=True
  • secret_key Char
    readonly=True required=True
  • user_id Many2one → res.users
    comodel_name='res.users' ondelete='cascade'
Public methods (1)
  • validate_conf_code(self, confirmation_code)
    @api.multi

New fields (6)
  • confirmation_code Char
    help='Enter the latest six digit code generated by your authentication app' required=True string='Confirmation Code'
  • name Char
    help='A name that will help you remember this authentication app/device' required=True string='Authentication App/Device Name'
  • qr_code_tag Html
    compute='_compute_qr_code_tag' help='Scan this image with your authentication app to add your account' string='QR Code'
  • secret_key Char
    default=<expr> required=True string='Secret Code'
  • secret_key_display Char
    compute='_compute_secret_key_display' readonly=True store=False string='Secret Code'
  • user_id Many2one → res.users
    comodel_name='res.users' default=<expr> help='This is the user whose account the new authentication app/device will be tied to' ondelete='cascade' readonly=True required=True string='Associated User'
Public methods (1)
  • action_create(self)
    @api.multi

Loading…

Loading…

Loading…

Loading…