TIP: You can type at any time to perform a new search.

Security findings

Repository
OCA/server-auth · module folder · Try on Runboat
Module version
1.0.1
Category
Tools
Folder size
0.08 MB
License
AGPL-3
Application
No
Auto-installable
No
Website
https://github.com/OCA/server-auth
Last tracking update
2026-10-04 00:16:48
Authors
Akretion, Odoo Community Association (OCA)
Maintainers
Akretion, Odoo Community Association (OCA)
Committers
Moises Lopez, Weblate, OCA-git-bot, oca-ci, Melody Uffreduzzi, Milan Topuzov
Odoo dependencies
odoo/odoo:
- web
- bus
Python dependencies
None
System dependencies
None
Required by
None
Description
This module allows one user (for example, a member of the support team) to log in as another user.
The impersonation session can be exited by clicking on the button "Back to Original User".

To ensure that any abuse of this feature will not go unnoticed, the following measures are in place:

* In the chatter, it is displayed who is the user that is logged as another user.
* Mails and messages are sent from the original user.
* Impersonated logins are logged and can be consulted through the Settings -> Technical menu.
* You can optionally forbid impersonation of users with "Administration: Settings"
  rights by enabling the related option in the settings.
There is an alternative module to allow logins as another user (auth_admin_passkey),
but it does not support these security mechanisms.

Code Analysis info_outline

Views touched (3)
XML IDNameModelTypeStatus
impersonate_log_tree impersonate.log.tree impersonate.log list New
impersonate_res_users_tree res.users list Inherits base.view_users_tree
view_res_config_settings_impersonate res.config.settings.impersonate res.config.settings form Inherits base_setup.res_config_settings_view_form
HTTP endpoints (0)

No HTTP endpoints found for this module.

Models touched (7)

New fields (0)

No new fields.

Public methods (1)
  • write(self, vals)
    Overwrite the write_uid with the impersonating user

New fields (4)
  • date_end Datetime
    string='End Date'
  • date_start Datetime
    string='Start Date'
  • impersonated_partner_id Many2one → res.partner
    comodel_name='res.partner' string='Logged as'
  • user_id Many2one → res.users
    comodel_name='res.users'
Public methods (0)

No public methods.

New fields (0)

No new fields.

Public methods (1)
  • session_info(self)

New fields (2)
  • body Html
    compute='_compute_message_body' inverse='_inverse_message_body' readonly=False store=True
  • impersonated_author_id Many2one → res.partner
    comodel_name='res.partner' compute='_compute_impersonated_author_id' store=True
Public methods (0)

No public methods.

New fields (0)

No new fields.

Public methods (0)

No public methods.

New fields (1)
  • restrict_impersonate_admin_settings Boolean
    config_parameter='impersonate_login.restrict_impersonate_admin_settings' default=False help="If enabled, users with the 'Administration: Settings' access right cannot be impersonated." string="Restrict Impersonation of 'Administration: Settings' Users"
Public methods (0)

No public methods.

New fields (0)

No new fields.

Public methods (3)
  • action_impersonate_login(self)
    @api.model
  • back_to_origin_login(self)
    @api.model
  • impersonate_login(self)

Loading…

Loading…

Loading…

Loading…