TIP: You can type at any time to perform a new search.

Security findings

Repository
OCA/server-auth · module folder · Try on Runboat
Module version
1.0.2
Category
Vault
Folder size
0.09 MB
License
AGPL-3
Application
No
Auto-installable
No
Website
https://github.com/OCA/server-auth
Last tracking update
2026-10-03 23:57:03
Authors
Odoo Community Association (OCA), initOS GmbH
Maintainers
Odoo Community Association (OCA), initOS GmbH
Committers
CarlosRoca13, Jan Suhr, OCA-git-bot, oca-ci
Odoo dependencies
OCA/server-auth:
odoo/odoo:
- web
Python dependencies
None
System dependencies
None
Required by
None
Description
This module implements possibilities to share specific secrets with
external users. This bases on the vault implementation and the generated
RSA key pair.

## Share

This allows an user to share a secret with external users. A share can
be generated from a vault entry or directly created by an user. The
secret is symmetrically encrypted by a key derived from a pin. To grant
access the user has to transmit the link and pin with the external. If
either the access counter reaches 0 or the share expires it will be
deleted automatically. Due to the usage of a numeric pin and the browser
side decryption a share is vulnerable to brute-force attacks and
shouldn't be used as a permanent storage for secrets. For long time uses
the user should create an account and a vault should be used.

Code Analysis info_outline

Views touched (4)
XML IDNameModelTypeStatus
res_config_settings_view_form res.config.settings.view.form res.config.settings form Inherits vault.res_config_settings_view_form
share share ir.ui.view qweb New
view_vault_share_form vault.share form New
view_vault_share_tree vault.share list New
HTTP endpoints (1)
Route(s)HandlerAuthTypeMethodsFlags
/vault/share/<string:token> Controller.vault_share public http ALL sudo website
Models touched (4)

New fields (1)
  • vault_share_delay Integer
    default=0
Public methods (0)

No public methods.

New fields (1)
  • vault_share_delay Integer
    help='Delays the deletion of a share. After the expiration date it continues to stay inaccessible' readonly=False related='company_id.vault_share_delay' string='Delayed Deletion'
Public methods (0)

No public methods.

New fields (14)
  • accesses Integer
    default=5 help='Specifies how often a share can be accessed before deletion.' args: 'Access counter'
  • expiration Datetime
    default=<expr> help='Specifies how long a share can be accessed until deletion.'
  • filename Char
  • iterations Integer
  • iv Char
    required=True
  • log_ids One2many → vault.share.log
    readonly=True args: 'vault.share.log', 'share_id', 'Log'
  • name Char
    required=True
  • pin Char
    help='The pin needed to decrypt the share.' required=True
  • salt Char
    required=True
  • secret Char
  • secret_file Char
  • share_link Char
    compute='_compute_url' help='Using this link and pin people can access the secret.' store=False args: 'Share URL'
  • token Char
    copy=False default=<expr> readonly=True required=True
  • user_id Many2one → res.users
    default=<expr> args: 'res.users'
Public methods (3)
  • clean(self)
    @api.model
  • create(self, vals_list)
    @api.model_create_multi
  • get(self, token, ip=None)
    @api.model

New fields (2)
  • name Char
    readonly=True
  • share_id Many2one → vault.share
    ondelete='cascade' readonly=True required=True args: 'vault.share'
Public methods (0)

No public methods.

Loading…

Loading…

Loading…

Loading…