TIP: You can type at any time to perform a new search.
Vault - Share
vault_share · OCA/server-auth
Security findings
- Repository
- OCA/server-auth · module folder · Try on Runboat
- Module version
- 1.0.2
- Category
- Vault
- Folder size
- 0.09 MB
- License
- AGPL-3
- Application
- No
- Auto-installable
- No
- Website
- https://github.com/OCA/server-auth
- Last tracking update
- 2026-10-03 23:57:03
- Authors
- Odoo Community Association (OCA), initOS GmbH
- Maintainers
- Odoo Community Association (OCA), initOS GmbH
- Committers
- CarlosRoca13, Jan Suhr, OCA-git-bot, oca-ci
- Odoo dependencies
- Python dependencies
- None
- System dependencies
- None
- Required by
- None
- Description
This module implements possibilities to share specific secrets with external users. This bases on the vault implementation and the generated RSA key pair. ## Share This allows an user to share a secret with external users. A share can be generated from a vault entry or directly created by an user. The secret is symmetrically encrypted by a key derived from a pin. To grant access the user has to transmit the link and pin with the external. If either the access counter reaches 0 or the share expires it will be deleted automatically. Due to the usage of a numeric pin and the browser side decryption a share is vulnerable to brute-force attacks and shouldn't be used as a permanent storage for secrets. For long time uses the user should create an account and a vault should be used.
Code Analysis
Views touched (4)
| XML ID | Name | Model | Type | Status |
|---|---|---|---|---|
res_config_settings_view_form |
res.config.settings.view.form | res.config.settings | form | Inherits vault.res_config_settings_view_form |
share |
share | ir.ui.view | qweb | New |
view_vault_share_form |
vault.share | form | New | |
view_vault_share_tree |
vault.share | list | New |
HTTP endpoints (1)
| Route(s) | Handler | Auth | Type | Methods | Flags |
|---|---|---|---|---|---|
/vault/share/<string:token> |
Controller.vault_share |
public | http | ALL | sudo website |
Models touched (4)
New fields (1)
-
vault_share_delayIntegerdefault=0
No public methods.
New fields (1)
-
vault_share_delayIntegerhelp='Delays the deletion of a share. After the expiration date it continues to stay inaccessible'readonly=Falserelated='company_id.vault_share_delay'string='Delayed Deletion'
No public methods.
New fields (14)
-
accessesIntegerdefault=5help='Specifies how often a share can be accessed before deletion.' args: 'Access counter' -
expirationDatetimedefault=<expr>help='Specifies how long a share can be accessed until deletion.' -
filenameChar -
iterationsInteger -
ivCharrequired=True -
log_idsOne2many → vault.share.logreadonly=True args: 'vault.share.log', 'share_id', 'Log' -
nameCharrequired=True -
pinCharhelp='The pin needed to decrypt the share.'required=True -
saltCharrequired=True -
secretChar -
secret_fileChar -
share_linkCharcompute='_compute_url'help='Using this link and pin people can access the secret.'store=False args: 'Share URL' -
tokenCharcopy=Falsedefault=<expr>readonly=Truerequired=True -
user_idMany2one → res.usersdefault=<expr> args: 'res.users'
-
clean(self)@api.model -
create(self, vals_list)@api.model_create_multi -
get(self, token, ip=None)@api.model
New fields (2)
-
nameCharreadonly=True -
share_idMany2one → vault.shareondelete='cascade'readonly=Truerequired=True args: 'vault.share'
No public methods.
Loading…
Loading…
Loading…
Loading…