TIP: You can type at any time to perform a new search.

Security findings

Repository
OCA/server-auth · module folder · Try on Runboat
Module version
1.0.0
Category
Authentication
Folder size
0.09 MB
License
AGPL-3
Application
No
Auto-installable
No
Website
https://github.com/OCA/server-auth
Last tracking update
2026-10-03 23:38:44
Authors
Odoo Community Association (OCA), Therp BV
Maintainers
Odoo Community Association (OCA), Therp BV
Committers
OCA-git-bot, oca-ci, Ryan Cole
Odoo dependencies
odoo/odoo:
- web
Python dependencies
python-ldap
System dependencies
None
Required by
None
Description
[![License: AGPL-3](https://img.shields.io/badge/license-AGPL--3-blue.png)](https://www.gnu.org/licenses/agpl)

Adds user accounts to groups based on rules defined by the
administrator.

Code Analysis info_outline

Views touched (1)
XML IDNameModelTypeStatus
view_ldap_installer_form res.company.ldap.form res.company.ldap form Inherits auth_ldap.view_ldap_installer_form
HTTP endpoints (0)

No HTTP endpoints found for this module.

Models touched (4)

New fields (2)
  • group_mapping_ids One2many → res.company.ldap.group_mapping
    help='Define how Odoo groups are assigned to LDAP users' args: 'res.company.ldap.group_mapping', 'ldap_id', 'Group mappings'
  • only_ldap_groups Boolean
    default=False help='If this is checked, manual changes to group membership are undone on every login (so Odoo groups are always synchronous with LDAP groups). If not, manually added groups are preserved.' args: 'Only LDAP groups'
Public methods (0)

No public methods.

New fields (5)
  • group_id Many2one → res.groups
    help='The Odoo group to assign' required=True args: 'res.groups', 'Odoo group'
  • ldap_attribute Char
    help='The LDAP attribute to check.\nFor active directory, use memberOf.' args: 'LDAP attribute'
  • ldap_id Many2one → res.company.ldap
    ondelete='cascade' required=True args: 'res.company.ldap', 'LDAP server'
  • operator Selection
    help="The operator to check the attribute against the value\nFor active directory, use 'contains'" required=True args: <expr>
  • value Char
    help='The value to check the attribute against.\nFor active directory, use the dn of the desired group' required=True
Public methods (0)

No public methods.

New fields (0)

No new fields.

Public methods (2)
  • operators(self)
    @api.model
    Return names (without '_') of function to call on this model as operator
  • safe_ldap_decode(self, attr)
    Safe LDAP decode; Base64 encode attributes containing binary data. Binary data can be stored in Active Directory, e.g., thumbnailPhoto is stored as binary. As Str.decoce() cannot handle binary, this method Base64 encodes the data in the attribute, instead, if decode fails. Using Base64 should be a suitable fallback, because the use cases of users_ldap_groups do not really require comparing binary attributes.

New fields (0)

No new fields.

Public methods (0)

No public methods.

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…

Loading…

Status
Open migration PR — not merged yet for this version
CI status
checks failing
Open since
259 days ago
Last activity
63 days ago
Repository
OCA/server-auth
Pull request
[18.0][MIG] users_ldap_groups : Migration to v18 (#889)
Status
Open migration PR — not merged yet for this version
CI status
green — ready to merge
Open since
28 days ago
Last activity
28 days ago
Repository
OCA/server-auth
Pull request
[19.0][MIG] users_ldap_groups: Migration to 19.0 (#1000)