TIP: You can type at any time to perform a new search.
LDAP groups assignment
users_ldap_groups · OCA/server-auth
Security findings
- Repository
- OCA/server-auth · module folder · Try on Runboat
- Module version
- 1.0.0
- Category
- Authentication
- Folder size
- 0.09 MB
- License
- AGPL-3
- Application
- No
- Auto-installable
- No
- Website
- https://github.com/OCA/server-auth
- Last tracking update
- 2026-10-03 23:38:44
- Authors
- Odoo Community Association (OCA), Therp BV
- Maintainers
- Odoo Community Association (OCA), Therp BV
- Committers
- OCA-git-bot, oca-ci, Ryan Cole
- Odoo dependencies
- Python dependencies
- python-ldap
- System dependencies
- None
- Required by
- None
- Description
[](https://www.gnu.org/licenses/agpl) Adds user accounts to groups based on rules defined by the administrator.
Code Analysis
Views touched (1)
| XML ID | Name | Model | Type | Status |
|---|---|---|---|---|
view_ldap_installer_form |
res.company.ldap.form | res.company.ldap | form | Inherits auth_ldap.view_ldap_installer_form |
HTTP endpoints (0)
No HTTP endpoints found for this module.
Models touched (4)
New fields (2)
-
group_mapping_idsOne2many → res.company.ldap.group_mappinghelp='Define how Odoo groups are assigned to LDAP users' args: 'res.company.ldap.group_mapping', 'ldap_id', 'Group mappings' -
only_ldap_groupsBooleandefault=Falsehelp='If this is checked, manual changes to group membership are undone on every login (so Odoo groups are always synchronous with LDAP groups). If not, manually added groups are preserved.' args: 'Only LDAP groups'
No public methods.
New fields (5)
-
group_idMany2one → res.groupshelp='The Odoo group to assign'required=True args: 'res.groups', 'Odoo group' -
ldap_attributeCharhelp='The LDAP attribute to check.\nFor active directory, use memberOf.' args: 'LDAP attribute' -
ldap_idMany2one → res.company.ldapondelete='cascade'required=True args: 'res.company.ldap', 'LDAP server' -
operatorSelectionhelp="The operator to check the attribute against the value\nFor active directory, use 'contains'"required=True args: <expr> -
valueCharhelp='The value to check the attribute against.\nFor active directory, use the dn of the desired group'required=True
No public methods.
New fields (0)
No new fields.
Public methods (2)-
operators(self)@api.modelReturn names (without '_') of function to call on this model as operator -
safe_ldap_decode(self, attr)Safe LDAP decode; Base64 encode attributes containing binary data. Binary data can be stored in Active Directory, e.g., thumbnailPhoto is stored as binary. As Str.decoce() cannot handle binary, this method Base64 encodes the data in the attribute, instead, if decode fails. Using Base64 should be a suitable fallback, because the use cases of users_ldap_groups do not really require comparing binary attributes.
New fields (0)
No new fields.
Public methods (0)No public methods.
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
- Status
- Open migration PR — not merged yet for this version
- CI status
- checks failing
- Open since
- 259 days ago
- Last activity
- 63 days ago
- Repository
- OCA/server-auth
- Pull request
- [18.0][MIG] users_ldap_groups : Migration to v18 (#889)
- Status
- Open migration PR — not merged yet for this version
- CI status
- green — ready to merge
- Open since
- 28 days ago
- Last activity
- 28 days ago
- Repository
- OCA/server-auth
- Pull request
- [19.0][MIG] users_ldap_groups: Migration to 19.0 (#1000)