From 31c8741420b6ee2944762609dc5dd2dc925e19d8 Mon Sep 17 00:00:00 2001 From: Maxime Franco Date: Thu, 9 Feb 2023 16:58:13 +0100 Subject: [PATCH 1/3] [ADD] auth_device - Allows to connect with an external device whose the value is stored on the user --- auth_device/README.rst | 105 +++++ auth_device/__init__.py | 1 + auth_device/__manifest__.py | 20 + auth_device/controllers/__init__.py | 1 + auth_device/controllers/main.py | 81 ++++ auth_device/models/__init__.py | 1 + auth_device/models/res_users.py | 41 ++ auth_device/readme/CONTRIBUTORS.rst | 1 + auth_device/readme/DESCRIPTION.rst | 5 + auth_device/readme/USAGE.rst | 15 + auth_device/static/description/icon.png | Bin 0 -> 9455 bytes auth_device/static/description/index.html | 442 +++++++++++++++++++ auth_device/static/img/scan.jpg | Bin 0 -> 3425 bytes auth_device/static/js/device_connection.js | 9 + auth_device/tests/__init__.py | 2 + auth_device/tests/test_auth_device.py | 74 ++++ auth_device/tests/test_ui.py | 121 +++++ auth_device/views/assets_frontend.xml | 14 + auth_device/views/auth_device_connection.xml | 96 ++++ auth_device/views/res_users_views.xml | 22 + 20 files changed, 1051 insertions(+) create mode 100644 auth_device/README.rst create mode 100644 auth_device/__init__.py create mode 100644 auth_device/__manifest__.py create mode 100644 auth_device/controllers/__init__.py create mode 100644 auth_device/controllers/main.py create mode 100644 auth_device/models/__init__.py create mode 100644 auth_device/models/res_users.py create mode 100644 auth_device/readme/CONTRIBUTORS.rst create mode 100644 auth_device/readme/DESCRIPTION.rst create mode 100644 auth_device/readme/USAGE.rst create mode 100644 auth_device/static/description/icon.png create mode 100644 auth_device/static/description/index.html create mode 100644 auth_device/static/img/scan.jpg create mode 100644 auth_device/static/js/device_connection.js create mode 100644 auth_device/tests/__init__.py create mode 100644 auth_device/tests/test_auth_device.py create mode 100644 auth_device/tests/test_ui.py create mode 100644 auth_device/views/assets_frontend.xml create mode 100644 auth_device/views/auth_device_connection.xml create mode 100644 auth_device/views/res_users_views.xml diff --git a/auth_device/README.rst b/auth_device/README.rst new file mode 100644 index 0000000000..d20c1b9945 --- /dev/null +++ b/auth_device/README.rst @@ -0,0 +1,105 @@ +=========== +Auth Device +=========== + +.. !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! + !! This file is generated by oca-gen-addon-readme !! + !! changes will be overwritten. !! + !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! + +.. |badge1| image:: https://img.shields.io/badge/maturity-Beta-yellow.png + :target: https://odoo-community.org/page/development-status + :alt: Beta +.. |badge2| image:: https://img.shields.io/badge/licence-AGPL--3-blue.png + :target: http://www.gnu.org/licenses/agpl-3.0-standalone.html + :alt: License: AGPL-3 +.. |badge3| image:: https://img.shields.io/badge/github-OCA%2Fserver--auth-lightgray.png?logo=github + :target: https://github.com/OCA/server-auth/tree/14.0/auth_device + :alt: OCA/server-auth +.. |badge4| image:: https://img.shields.io/badge/weblate-Translate%20me-F47D42.png + :target: https://translation.odoo-community.org/projects/server-auth-14-0/server-auth-14-0-auth_device + :alt: Translate me on Weblate +.. |badge5| image:: https://img.shields.io/badge/runboat-Try%20me-875A7B.png + :target: https://runboat.odoo-community.org/webui/builds.html?repo=OCA/server-auth&target_branch=14.0 + :alt: Try me on Runboat + +|badge1| |badge2| |badge3| |badge4| |badge5| + +Allows to authenticate with an external device like and RFID card, badge, barcode, yubikey,... + +That needs an external device reader connected to the computer (like a RFID reader if you want to connect with a RFID card) + +**Take care while using this module, the route /auth_device/login should not be exposed outside your infrastructure.** + + +**Table of contents** + +.. contents:: + :local: + +Usage +===== + +To apply this authentication system to your user, you must set: + +- 'device_code' with the code stored in your external id (the code of the rfid, barcode,...) +- 'is_allowed_to_connect_with_device' must be set to True + +To connect with this authentication system: + +- go to the odoo web site +- click on 'Sign in' +- Below the login button, click on 'Log in with your Device' +- A modal will appear and insert your device code in the field +- click on 'Log in' + +If the device_code is correct and the user allowed to connect with it, you should be connected. +else your are redirected to the login page with an error giving information about what happened + +Bug Tracker +=========== + +Bugs are tracked on `GitHub Issues `_. +In case of trouble, please check there if your issue has already been reported. +If you spotted it first, help us smashing it by providing a detailed and welcomed +`feedback `_. + +Do not contact contributors directly about support or help with technical issues. + +Credits +======= + +Authors +~~~~~~~ + +* ACSONE SA/NV + +Contributors +~~~~~~~~~~~~ + +* Maxime Franco + +Maintainers +~~~~~~~~~~~ + +This module is maintained by the OCA. + +.. image:: https://odoo-community.org/logo.png + :alt: Odoo Community Association + :target: https://odoo-community.org + +OCA, or the Odoo Community Association, is a nonprofit organization whose +mission is to support the collaborative development of Odoo features and +promote its widespread use. + +.. |maintainer-FrancoMaxime| image:: https://github.com/FrancoMaxime.png?size=40px + :target: https://github.com/FrancoMaxime + :alt: FrancoMaxime + +Current `maintainer `__: + +|maintainer-FrancoMaxime| + +This module is part of the `OCA/server-auth `_ project on GitHub. + +You are welcome to contribute. To learn how please visit https://odoo-community.org/page/Contribute. diff --git a/auth_device/__init__.py b/auth_device/__init__.py new file mode 100644 index 0000000000..72d3ea60a8 --- /dev/null +++ b/auth_device/__init__.py @@ -0,0 +1 @@ +from . import controllers, models diff --git a/auth_device/__manifest__.py b/auth_device/__manifest__.py new file mode 100644 index 0000000000..065a824e29 --- /dev/null +++ b/auth_device/__manifest__.py @@ -0,0 +1,20 @@ +# Copyright 2023 ACSONE SA/NV +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl). + +{ + "name": "Auth Device", + "summary": "Allows users to log in through an external device.", + "version": "14.0.1.0.0", + "license": "AGPL-3", + "author": "ACSONE SA/NV,Odoo Community Association (OCA)", + "maintainers": ["FrancoMaxime"], + "website": "https://github.com/OCA/server-auth", + "depends": [ + "web", + ], + "data": [ + "views/assets_frontend.xml", + "views/auth_device_connection.xml", + "views/res_users_views.xml", + ], +} diff --git a/auth_device/controllers/__init__.py b/auth_device/controllers/__init__.py new file mode 100644 index 0000000000..12a7e529b6 --- /dev/null +++ b/auth_device/controllers/__init__.py @@ -0,0 +1 @@ +from . import main diff --git a/auth_device/controllers/main.py b/auth_device/controllers/main.py new file mode 100644 index 0000000000..07e977f098 --- /dev/null +++ b/auth_device/controllers/main.py @@ -0,0 +1,81 @@ +# Copyright 2023 ACSONE SA/NV +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl). + + +import werkzeug.utils + +from odoo import _, http +from odoo.exceptions import AccessDenied +from odoo.http import request + +from odoo.addons.portal.controllers.web import Home +from odoo.addons.web.controllers.main import ensure_db, login_and_redirect + + +class DeviceController(Home): + @http.route() + def web_login(self, *args, **kw): + ensure_db() + if ( + request.httprequest.method == "GET" + and request.session.uid + and request.params.get("redirect") + ): + # Redirect if already logged in and redirect param is present + return http.redirect_with_hash(request.params.get("redirect")) + + response = super().web_login(*args, **kw) + if response.is_qweb: + error = request.params.get("auth_device_error") + if error == "1": + error = _("Access Denied") + elif error == "2": + error = _("Missing Device Code") + elif error == "3": + error = _("Internal Error") + else: + error = None + if error: + response.qcontext["error"] = error + + return response + + +class AuthDeviceController(http.Controller): + @http.route("/auth_device/login", type="http", auth="none") + def device_login(self, redirect="/web", **kw): + ensure_db() + if request.httprequest.method == "GET" or request.session.uid: + return werkzeug.utils.redirect(redirect) + # By default redirect to Access denied Error + url = "/web/login?auth_device_error=1" + # If no Device Code redirect to Missing Device Code Error + if not request.params.get("device_code", None): + return werkzeug.utils.redirect("/web/login?auth_device_error=2", 303) + user = ( + request.env["res.users"] + .sudo() + .search( + [ + ("device_code", "=", request.params["device_code"]), + ("is_allowed_to_connect_with_device", "=", True), + ] + ) + ) + if not user: + # If no user found redirect to Access Denied + url = "/web/login?auth_device_error=1" + elif len(user) > 1: + # Elif more than one user found redirect to Internal Error + url = "/web/login?auth_device_error=3" + elif user and request.httprequest.method == "POST": + try: + return login_and_redirect( + db=request.session.db, + login=user.login, + key=request.params["device_code"], + redirect_url=redirect, + ) + except AccessDenied: + url = "/web/login?auth_device_error=1" + return werkzeug.utils.redirect(url, 303) diff --git a/auth_device/models/__init__.py b/auth_device/models/__init__.py new file mode 100644 index 0000000000..8835165330 --- /dev/null +++ b/auth_device/models/__init__.py @@ -0,0 +1 @@ +from . import res_users diff --git a/auth_device/models/res_users.py b/auth_device/models/res_users.py new file mode 100644 index 0000000000..48f6435b9c --- /dev/null +++ b/auth_device/models/res_users.py @@ -0,0 +1,41 @@ +# Copyright 2023 ACSONE SA/NV +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl). + +from odoo import exceptions, fields, models + + +class ResUsers(models.Model): + _inherit = "res.users" + _sql_constraints = [ + ( + "device_code_uniq", + "UNIQUE(device_code)", + "The device code should be unique.", + ) + ] + + device_code = fields.Char("Device Code", copy=False) + + is_allowed_to_connect_with_device = fields.Boolean( + string="Is allowed to connect with the external device?" + ) + + # pylint: disable=missing-return + def _check_credentials(self, password, env): + try: + super()._check_credentials(password, env) + + except exceptions.AccessDenied: + # Just be sure that parent methods aren't wrong + user = ( + self.env["res.users"] + .sudo() + .search( + [ + ("device_code", "=", password), + ("is_allowed_to_connect_with_device", "=", True), + ] + ) + ) + if not user or len(user) > 1: + raise diff --git a/auth_device/readme/CONTRIBUTORS.rst b/auth_device/readme/CONTRIBUTORS.rst new file mode 100644 index 0000000000..efc4eee124 --- /dev/null +++ b/auth_device/readme/CONTRIBUTORS.rst @@ -0,0 +1 @@ +* Maxime Franco diff --git a/auth_device/readme/DESCRIPTION.rst b/auth_device/readme/DESCRIPTION.rst new file mode 100644 index 0000000000..9300852723 --- /dev/null +++ b/auth_device/readme/DESCRIPTION.rst @@ -0,0 +1,5 @@ +Allows to authenticate with an external device like and RFID card, badge, barcode, yubikey,... + +That needs an external device reader connected to the computer (like a RFID reader if you want to connect with a RFID card) + +**Take care while using this module, the route /auth_device/login should not be exposed outside your infrastructure.** diff --git a/auth_device/readme/USAGE.rst b/auth_device/readme/USAGE.rst new file mode 100644 index 0000000000..057ebe1fad --- /dev/null +++ b/auth_device/readme/USAGE.rst @@ -0,0 +1,15 @@ +To apply this authentication system to your user, you must set: + +- 'device_code' with the code stored in your external id (the code of the rfid, barcode,...) +- 'is_allowed_to_connect_with_device' must be set to True + +To connect with this authentication system: + +- go to the odoo web site +- click on 'Sign in' +- Below the login button, click on 'Log in with your Device' +- A modal will appear and insert your device code in the field +- click on 'Log in' + +If the device_code is correct and the user allowed to connect with it, you should be connected. +else your are redirected to the login page with an error giving information about what happened diff --git a/auth_device/static/description/icon.png b/auth_device/static/description/icon.png new file mode 100644 index 0000000000000000000000000000000000000000..3a0328b516c4980e8e44cdb63fd945757ddd132d GIT binary patch literal 9455 zcmW++2RxMjAAjx~&dlBk9S+%}OXg)AGE&Cb*&}d0jUxM@u(PQx^-s)697TX`ehR4?GS^qbkof1cslKgkU)h65qZ9Oc=ml_0temigYLJfnz{IDzUf>bGs4N!v3=Z3jMq&A#7%rM5eQ#dc?k~! zVpnB`o+K7|Al`Q_U;eD$B zfJtP*jH`siUq~{KE)`jP2|#TUEFGRryE2`i0**z#*^6~AI|YzIWy$Cu#CSLW3q=GA z6`?GZymC;dCPk~rBS%eCb`5OLr;RUZ;D`}um=H)BfVIq%7VhiMr)_#G0N#zrNH|__ zc+blN2UAB0=617@>_u;MPHN;P;N#YoE=)R#i$k_`UAA>WWCcEVMh~L_ zj--gtp&|K1#58Yz*AHCTMziU1Jzt_jG0I@qAOHsk$2}yTmVkBp_eHuY$A9)>P6o~I z%aQ?!(GqeQ-Y+b0I(m9pwgi(IIZZzsbMv+9w{PFtd_<_(LA~0H(xz{=FhLB@(1&qHA5EJw1>>=%q2f&^X>IQ{!GJ4e9U z&KlB)z(84HmNgm2hg2C0>WM{E(DdPr+EeU_N@57;PC2&DmGFW_9kP&%?X4}+xWi)( z;)z%wI5>D4a*5XwD)P--sPkoY(a~WBw;E~AW`Yue4kFa^LM3X`8x|}ZUeMnqr}>kH zG%WWW>3ml$Yez?i%)2pbKPI7?5o?hydokgQyZsNEr{a|mLdt;X2TX(#B1j35xPnPW z*bMSSOauW>o;*=kO8ojw91VX!qoOQb)zHJ!odWB}d+*K?#sY_jqPdg{Sm2HdYzdEx zOGVPhVRTGPtv0o}RfVP;Nd(|CB)I;*t&QO8h zFfekr30S!-LHmV_Su-W+rEwYXJ^;6&3|L$mMC8*bQptyOo9;>Qb9Q9`ySe3%V$A*9 zeKEe+b0{#KWGp$F+tga)0RtI)nhMa-K@JS}2krK~n8vJ=Ngm?R!9G<~RyuU0d?nz# z-5EK$o(!F?hmX*2Yt6+coY`6jGbb7tF#6nHA zuKk=GGJ;ZwON1iAfG$E#Y7MnZVmrY|j0eVI(DN_MNFJmyZ|;w4tf@=CCDZ#5N_0K= z$;R~bbk?}TpfDjfB&aiQ$VA}s?P}xPERJG{kxk5~R`iRS(SK5d+Xs9swCozZISbnS zk!)I0>t=A<-^z(cmSFz3=jZ23u13X><0b)P)^1T_))Kr`e!-pb#q&J*Q`p+B6la%C zuVl&0duN<;uOsB3%T9Fp8t{ED108<+W(nOZd?gDnfNBC3>M8WE61$So|P zVvqH0SNtDTcsUdzaMDpT=Ty0pDHHNL@Z0w$Y`XO z2M-_r1S+GaH%pz#Uy0*w$Vdl=X=rQXEzO}d6J^R6zjM1u&c9vYLvLp?W7w(?np9x1 zE_0JSAJCPB%i7p*Wvg)pn5T`8k3-uR?*NT|J`eS#_#54p>!p(mLDvmc-3o0mX*mp_ zN*AeS<>#^-{S%W<*mz^!X$w_2dHWpcJ6^j64qFBft-o}o_Vx80o0>}Du;>kLts;$8 zC`7q$QI(dKYG`Wa8#wl@V4jVWBRGQ@1dr-hstpQL)Tl+aqVpGpbSfN>5i&QMXfiZ> zaA?T1VGe?rpQ@;+pkrVdd{klI&jVS@I5_iz!=UMpTsa~mBga?1r}aRBm1WS;TT*s0f0lY=JBl66Upy)-k4J}lh=P^8(SXk~0xW=T9v*B|gzIhN z>qsO7dFd~mgxAy4V?&)=5ieYq?zi?ZEoj)&2o)RLy=@hbCRcfT5jigwtQGE{L*8<@Yd{zg;CsL5mvzfDY}P-wos_6PfprFVaeqNE%h zKZhLtcQld;ZD+>=nqN~>GvROfueSzJD&BE*}XfU|H&(FssBqY=hPCt`d zH?@s2>I(|;fcW&YM6#V#!kUIP8$Nkdh0A(bEVj``-AAyYgwY~jB zT|I7Bf@%;7aL7Wf4dZ%VqF$eiaC38OV6oy3Z#TER2G+fOCd9Iaoy6aLYbPTN{XRPz z;U!V|vBf%H!}52L2gH_+j;`bTcQRXB+y9onc^wLm5wi3-Be}U>k_u>2Eg$=k!(l@I zcCg+flakT2Nej3i0yn+g+}%NYb?ta;R?(g5SnwsQ49U8Wng8d|{B+lyRcEDvR3+`O{zfmrmvFrL6acVP%yG98X zo&+VBg@px@i)%o?dG(`T;n*$S5*rnyiR#=wW}}GsAcfyQpE|>a{=$Hjg=-*_K;UtD z#z-)AXwSRY?OPefw^iI+ z)AXz#PfEjlwTes|_{sB?4(O@fg0AJ^g8gP}ex9Ucf*@_^J(s_5jJV}c)s$`Myn|Kd z$6>}#q^n{4vN@+Os$m7KV+`}c%4)4pv@06af4-x5#wj!KKb%caK{A&Y#Rfs z-po?Dcb1({W=6FKIUirH&(yg=*6aLCekcKwyfK^JN5{wcA3nhO(o}SK#!CINhI`-I z1)6&n7O&ZmyFMuNwvEic#IiOAwNkR=u5it{B9n2sAJV5pNhar=j5`*N!Na;c7g!l$ z3aYBqUkqqTJ=Re-;)s!EOeij=7SQZ3Hq}ZRds%IM*PtM$wV z@;rlc*NRK7i3y5BETSKuumEN`Xu_8GP1Ri=OKQ$@I^ko8>H6)4rjiG5{VBM>B|%`&&s^)jS|-_95&yc=GqjNo{zFkw%%HHhS~e=s zD#sfS+-?*t|J!+ozP6KvtOl!R)@@-z24}`9{QaVLD^9VCSR2b`b!KC#o;Ki<+wXB6 zx3&O0LOWcg4&rv4QG0)4yb}7BFSEg~=IR5#ZRj8kg}dS7_V&^%#Do==#`u zpy6{ox?jWuR(;pg+f@mT>#HGWHAJRRDDDv~@(IDw&R>9643kK#HN`!1vBJHnC+RM&yIh8{gG2q zA%e*U3|N0XSRa~oX-3EAneep)@{h2vvd3Xvy$7og(sayr@95+e6~Xvi1tUqnIxoIH zVWo*OwYElb#uyW{Imam6f2rGbjR!Y3`#gPqkv57dB6K^wRGxc9B(t|aYDGS=m$&S!NmCtrMMaUg(c zc2qC=2Z`EEFMW-me5B)24AqF*bV5Dr-M5ig(l-WPS%CgaPzs6p_gnCIvTJ=Y<6!gT zVt@AfYCzjjsMEGi=rDQHo0yc;HqoRNnNFeWZgcm?f;cp(6CNylj36DoL(?TS7eU#+ z7&mfr#y))+CJOXQKUMZ7QIdS9@#-}7y2K1{8)cCt0~-X0O!O?Qx#E4Og+;A2SjalQ zs7r?qn0H044=sDN$SRG$arw~n=+T_DNdSrarmu)V6@|?1-ZB#hRn`uilTGPJ@fqEy zGt(f0B+^JDP&f=r{#Y_wi#AVDf-y!RIXU^0jXsFpf>=Ji*TeqSY!H~AMbJdCGLhC) zn7Rx+sXw6uYj;WRYrLd^5IZq@6JI1C^YkgnedZEYy<&4(z%Q$5yv#Boo{AH8n$a zhb4Y3PWdr269&?V%uI$xMcUrMzl=;w<_nm*qr=c3Rl@i5wWB;e-`t7D&c-mcQl7x! zZWB`UGcw=Y2=}~wzrfLx=uet<;m3~=8I~ZRuzvMQUQdr+yTV|ATf1Uuomr__nDf=X zZ3WYJtHp_ri(}SQAPjv+Y+0=fH4krOP@S&=zZ-t1jW1o@}z;xk8 z(Nz1co&El^HK^NrhVHa-_;&88vTU>_J33=%{if;BEY*J#1n59=07jrGQ#IP>@u#3A z;!q+E1Rj3ZJ+!4bq9F8PXJ@yMgZL;>&gYA0%_Kbi8?S=XGM~dnQZQ!yBSgcZhY96H zrWnU;k)qy`rX&&xlDyA%(a1Hhi5CWkmg(`Gb%m(HKi-7Z!LKGRP_B8@`7&hdDy5n= z`OIxqxiVfX@OX1p(mQu>0Ai*v_cTMiw4qRt3~NBvr9oBy0)r>w3p~V0SCm=An6@3n)>@z!|o-$HvDK z|3D2ZMJkLE5loMKl6R^ez@Zz%S$&mbeoqH5`Bb){Ei21q&VP)hWS2tjShfFtGE+$z zzCR$P#uktu+#!w)cX!lWN1XU%K-r=s{|j?)Akf@q#3b#{6cZCuJ~gCxuMXRmI$nGtnH+-h z+GEi!*X=AP<|fG`1>MBdTb?28JYc=fGvAi2I<$B(rs$;eoJCyR6_bc~p!XR@O-+sD z=eH`-ye})I5ic1eL~TDmtfJ|8`0VJ*Yr=hNCd)G1p2MMz4C3^Mj?7;!w|Ly%JqmuW zlIEW^Ft%z?*|fpXda>Jr^1noFZEwFgVV%|*XhH@acv8rdGxeEX{M$(vG{Zw+x(ei@ zmfXb22}8-?Fi`vo-YVrTH*C?a8%M=Hv9MqVH7H^J$KsD?>!SFZ;ZsvnHr_gn=7acz z#W?0eCdVhVMWN12VV^$>WlQ?f;P^{(&pYTops|btm6aj>_Uz+hqpGwB)vWp0Cf5y< zft8-je~nn?W11plq}N)4A{l8I7$!ks_x$PXW-2XaRFswX_BnF{R#6YIwMhAgd5F9X zGmwdadS6(a^fjHtXg8=l?Rc0Sm%hk6E9!5cLVloEy4eh(=FwgP`)~I^5~pBEWo+F6 zSf2ncyMurJN91#cJTy_u8Y}@%!bq1RkGC~-bV@SXRd4F{R-*V`bS+6;W5vZ(&+I<9$;-V|eNfLa5n-6% z2(}&uGRF;p92eS*sE*oR$@pexaqr*meB)VhmIg@h{uzkk$9~qh#cHhw#>O%)b@+(| z^IQgqzuj~Sk(J;swEM-3TrJAPCq9k^^^`q{IItKBRXYe}e0Tdr=Huf7da3$l4PdpwWDop%^}n;dD#K4s#DYA8SHZ z&1!riV4W4R7R#C))JH1~axJ)RYnM$$lIR%6fIVA@zV{XVyx}C+a-Dt8Y9M)^KU0+H zR4IUb2CJ{Hg>CuaXtD50jB(_Tcx=Z$^WYu2u5kubqmwp%drJ6 z?Fo40g!Qd<-l=TQxqHEOuPX0;^z7iX?Ke^a%XT<13TA^5`4Xcw6D@Ur&VT&CUe0d} z1GjOVF1^L@>O)l@?bD~$wzgf(nxX1OGD8fEV?TdJcZc2KoUe|oP1#=$$7ee|xbY)A zDZq+cuTpc(fFdj^=!;{k03C69lMQ(|>uhRfRu%+!k&YOi-3|1QKB z z?n?eq1XP>p-IM$Z^C;2L3itnbJZAip*Zo0aw2bs8@(s^~*8T9go!%dHcAz2lM;`yp zD=7&xjFV$S&5uDaiScyD?B-i1ze`+CoRtz`Wn+Zl&#s4&}MO{@N!ufrzjG$B79)Y2d3tBk&)TxUTw@QS0TEL_?njX|@vq?Uz(nBFK5Pq7*xj#u*R&i|?7+6# z+|r_n#SW&LXhtheZdah{ZVoqwyT{D>MC3nkFF#N)xLi{p7J1jXlmVeb;cP5?e(=f# zuT7fvjSbjS781v?7{)-X3*?>tq?)Yd)~|1{BDS(pqC zC}~H#WXlkUW*H5CDOo<)#x7%RY)A;ShGhI5s*#cRDA8YgqG(HeKDx+#(ZQ?386dv! zlXCO)w91~Vw4AmOcATuV653fa9R$fyK8ul%rG z-wfS zihugoZyr38Im?Zuh6@RcF~t1anQu7>#lPpb#}4cOA!EM11`%f*07RqOVkmX{p~KJ9 z^zP;K#|)$`^Rb{rnHGH{~>1(fawV0*Z#)}M`m8-?ZJV<+e}s9wE# z)l&az?w^5{)`S(%MRzxdNqrs1n*-=jS^_jqE*5XDrA0+VE`5^*p3CuM<&dZEeCjoz zR;uu_H9ZPZV|fQq`Cyw4nscrVwi!fE6ciMmX$!_hN7uF;jjKG)d2@aC4ropY)8etW=xJvni)8eHi`H$%#zn^WJ5NLc-rqk|u&&4Z6fD_m&JfSI1Bvb?b<*n&sfl0^t z=HnmRl`XrFvMKB%9}>PaA`m-fK6a0(8=qPkWS5bb4=v?XcWi&hRY?O5HdulRi4?fN zlsJ*N-0Qw+Yic@s0(2uy%F@ib;GjXt01Fmx5XbRo6+n|pP(&nodMoap^z{~q ziEeaUT@Mxe3vJSfI6?uLND(CNr=#^W<1b}jzW58bIfyWTDle$mmS(|x-0|2UlX+9k zQ^EX7Nw}?EzVoBfT(-LT|=9N@^hcn-_p&sqG z&*oVs2JSU+N4ZD`FhCAWaS;>|wH2G*Id|?pa#@>tyxX`+4HyIArWDvVrX)2WAOQff z0qyHu&-S@i^MS-+j--!pr4fPBj~_8({~e1bfcl0wI1kaoN>mJL6KUPQm5N7lB(ui1 zE-o%kq)&djzWJ}ob<-GfDlkB;F31j-VHKvQUGQ3sp`CwyGJk_i!y^sD0fqC@$9|jO zOqN!r!8-p==F@ZVP=U$qSpY(gQ0)59P1&t@y?5rvg<}E+GB}26NYPp4f2YFQrQtot5mn3wu_qprZ=>Ig-$ zbW26Ws~IgY>}^5w`vTB(G`PTZaDiGBo5o(tp)qli|NeV( z@H_=R8V39rt5J5YB2Ky?4eJJ#b`_iBe2ot~6%7mLt5t8Vwi^Jy7|jWXqa3amOIoRb zOr}WVFP--DsS`1WpN%~)t3R!arKF^Q$e12KEqU36AWwnCBICpH4XCsfnyrHr>$I$4 z!DpKX$OKLWarN7nv@!uIA+~RNO)l$$w}p(;b>mx8pwYvu;dD_unryX_NhT8*Tj>BTrTTL&!?O+%Rv;b?B??gSzdp?6Uug9{ zd@V08Z$BdI?fpoCS$)t4mg4rT8Q_I}h`0d-vYZ^|dOB*Q^S|xqTV*vIg?@fVFSmMpaw0qtTRbx} z({Pg?#{2`sc9)M5N$*N|4;^t$+QP?#mov zGVC@I*lBVrOU-%2y!7%)fAKjpEFsgQc4{amtiHb95KQEwvf<(3T<9-Zm$xIew#P22 zc2Ix|App^>v6(3L_MCU0d3W##AB0M~3D00EWoKZqsJYT(#@w$Y_H7G22M~ApVFTRHMI_3be)Lkn#0F*V8Pq zc}`Cjy$bE;FJ6H7p=0y#R>`}-m4(0F>%@P|?7fx{=R^uFdISRnZ2W_xQhD{YuR3t< z{6yxu=4~JkeA;|(J6_nv#>Nvs&FuLA&PW^he@t(UwFFE8)|a!R{`E`K`i^ZnyE4$k z;(749Ix|oi$c3QbEJ3b~D_kQsPz~fIUKym($a_7dJ?o+40*OLl^{=&oq$<#Q(yyrp z{J-FAniyAw9tPbe&IhQ|a`DqFTVQGQ&Gq3!C2==4x{6EJwiPZ8zub-iXoUtkJiG{} zPaR&}_fn8_z~(=;5lD-aPWD3z8PZS@AaUiomF!G8I}Mf>e~0g#BelA-5#`cj;O5>N Xviia!U7SGha1wx#SCgwmn*{w2TRX*I literal 0 HcmV?d00001 diff --git a/auth_device/static/description/index.html b/auth_device/static/description/index.html new file mode 100644 index 0000000000..9ff327860b --- /dev/null +++ b/auth_device/static/description/index.html @@ -0,0 +1,442 @@ + + + + + + +Auth Device + + + +
+

Auth Device

+ + +

Beta License: AGPL-3 OCA/server-auth Translate me on Weblate Try me on Runboat

+

Allows to authenticate with an external device like and RFID card, badge, barcode, yubikey,…

+

That needs an external device reader connected to the computer (like a RFID reader if you want to connect with a RFID card)

+

Take care while using this module, the route /auth_device/login should not be exposed outside your infrastructure.

+

Table of contents

+ +
+

Usage

+

To apply this authentication system to your user, you must set:

+
    +
  • ‘device_code’ with the code stored in your external id (the code of the rfid, barcode,…)
  • +
  • ‘is_allowed_to_connect_with_device’ must be set to True
  • +
+

To connect with this authentication system:

+
    +
  • go to the odoo web site
  • +
  • click on ‘Sign in’
  • +
  • Below the login button, click on ‘Log in with your Device’
  • +
  • A modal will appear and insert your device code in the field
  • +
  • click on ‘Log in’
  • +
+

If the device_code is correct and the user allowed to connect with it, you should be connected. +else your are redirected to the login page with an error giving information about what happened

+
+
+

Bug Tracker

+

Bugs are tracked on GitHub Issues. +In case of trouble, please check there if your issue has already been reported. +If you spotted it first, help us smashing it by providing a detailed and welcomed +feedback.

+

Do not contact contributors directly about support or help with technical issues.

+
+
+

Credits

+
+

Authors

+
    +
  • ACSONE SA/NV
  • +
+
+
+

Contributors

+ +
+
+

Maintainers

+

This module is maintained by the OCA.

+Odoo Community Association +

OCA, or the Odoo Community Association, is a nonprofit organization whose +mission is to support the collaborative development of Odoo features and +promote its widespread use.

+

Current maintainer:

+

FrancoMaxime

+

This module is part of the OCA/server-auth project on GitHub.

+

You are welcome to contribute. To learn how please visit https://odoo-community.org/page/Contribute.

+
+
+
+ + diff --git a/auth_device/static/img/scan.jpg b/auth_device/static/img/scan.jpg new file mode 100644 index 0000000000000000000000000000000000000000..f6d55a92c7ded2eb28401564719d2891b5b32903 GIT binary patch literal 3425 zcmb7HcTm&Yw*Dmn0*Df-f}w*bAW}mOks^>FEr6k)0|bEp9*`=cNE1OpBPG&nXn})5 zC{jEiA{|6}ks?h3C{m?g^t}7-oq2EW%>DjYGkdKydw*-KnKj=&9yy){U>IGrE&u`n zU`wzi034445db3t1C)WD5ekJeF)=c;aGqv4b&7?Dor9H=k5_=7j~5OX6qObi6qXW! z!!Igbl9G{CP*4yMS3xSvsY}Z%$bp!cm{?A+oI8E`oSYC`NbbMJ@mqk65oiO}ARu7? z%m#w6fsWq+vOj4;KqmnH2`Gr3fer#@{OSCc_h%Fgf*g+lERd7JU=Y}e>OQjsqX=O%wLrN9HCBHJTjj8>R`YY#L4-=RFHM_#z z(-WTw2J6ep@DpP;G>?Eu`Ov^_qkEmTi79%f0HJ_m0P0h+tlCrY z%WT=@#gyU*zLG(F1ZS0GQ=j_g7?4CqyO`jUG|@9bYnon%(*t$z!|p)An)_=6ySV!c z^)OphprUju%Ez8jTA-enr=q?wkVh83x;N1`?}TGle0CJ4 z!)ErIiu_gfQ~q_K<*LP(^Nz{44F2pYk{J-LJeyQH$PUX2Kr4#`9$u#{e-Eofu^_)j z2~BvvQy5G0Mr*M%VH3OnK2h51suVgVU9Jo2DP1MAY!6|^M9Yo_VEJt%O)tc#_d>8h zhSyi`UDUYwy(&|&PS~;uxevbxone~1x{(IX)PMitUXfJxf~|I}6up?MiHQkPFwUtC z@*Z1si278$B~K}P&)k0?vr`L?@^MAP-duwT>QIEaB!iQ?r@tvHJDr>MZVheh{l;r}7|=(&n8hU24nr8e@`e5G2Zd~yEW8f;P2i{`a76bIf1Z?_n3#Ihie*)nkan zXI#g?mDSP-sm9Xw{G60A8_%JH9FP%5-Gl5Wl;AxD*Sq#vnO_y# z68)n@H8f2RrUeGen5r8%jvQZ2nz>EeKdy&nuCm$})%j583zcLH3tn%BcYOmbp*6bA zu1MZ`6$-AVpXb+S1(Uh!}m_f3{JiR4foYdmc zzH4SG5K+<3vk}*VcU^h-m!8_t;4(rPo^m%(d^7ESdcbPA$^BFrNsnBz8d)buiHoLM zg~&B6vNK(+{X{)fy*vFZpof9o;&~$AayyRWXXzn8d-2 zpfI1jRo#s=wJjx=^XHU}IQxU{R6M*!spl9EjEbui_b=7x}JHxSdECdWHaR= zDoNrO=PloM(WQ=GkIa@YE{IuBPkR;=0NNAj?AlEC`uKswj-^J5ZqVWR%sn1EQsNPj zpca02mIz9vvTET9qA!WFuqc_nx7_M(AY{S*UTuLb*J{Ghc+SK(HI1p@&r%0m+^q%T z5HehUK~9m^Kwd;iSgp{H#LgWBDWK?ALy!aU4(f{VzYE7zT6r^{+ASHMsd0^SHT-gstJueq@5kpsY zl`LAh2deW1=fkLSfVP{mwA30#FKyd<;Ous_UyC7uWyHKDF2s#r?s>wuf~;w>PWVuc z{2=8{z)&~YJP$)1Hq}|wF6Vc4b`cQ|)%B9g35>;6wc3@Mn=+sJQY|cyQVmCY_YIkA zq51Iz{e|p*-28B1e0cLz=)3RcVhtO^bBsQ8dyJ~o?MfqxK4fjiDb z;&c2QE-M|(Dm{NY3Oqwb8Wzcra#fYXyT!B7NIG9Wt#qrAK{o{&(f?l2rRGTi{dRmt zARqIxu}GJ9+W=2ru}O0B={Xe7Tx1pP3^prBZ=(#|cVYG8r)W6?DV_W(QkqRClfKoY zC6BtCSFEg1@@42bzcX3uSWZsXyx{cmKJt)%@Sa1qkqXxw+RTkdLQ9jmajEgfJ>HjP zwPKxmQT*yj$%Tjx*qmbeU>GsHR^wx!5AR}eB6FgpM-JI2`m(6g{!MHSQq;x5E_!r} z9mf~VxueSBV)O+ye?zarq9J^UJ75|&p2D6c#(~W%JX1PTk4&jxqju_2&JZ<{R`#^x z#L9DMwk)C<5}2koz`JQ?FmClmB6Fo-P^L*-G@HEsT3>n~-{E-0w;7|LiC_%6b|f{-R56nT=yr z5t{@R6(gj?U5ZV>l3yi+w}{;J^@85fe$=#>Z8OH-edJ8I@|~UsD!}aVoGRW?f)6QV zn;$Ht8u+hjnSu#6NxIkd)}r)Y+{UGGlq}Ah3tlVM4B{Mu9k@Kl&Kj{qp2kF5jdZ)2 z2|)?mY1Pnst`rG;M#YCe$+vMLt-Luy)3%&d1cgzi`|`P$Ocq%6MY7_E2L}Z5tva&aU~-^=K9B*Pcz>(b)6@fZgQgD>7H%Iy$e04>qVuBuo^45t*}{kPtdF;7Ox1M>Bv*Ur(~5%feB z&uQ2Ndr}Qk)5l6eKJyBrXfRAt#I8l`%u$ve>BgJB)y`5Tol8XoE4ZWnTll80FSWKnH&Hnh>JhZTNk z`QT2h?YLOgEyX{tI+*Vk&rZ$Es2~Z(eH!T!PDb4j5$&qUO(O*zSq$ez!HeguSr=3nKLl>E)&uLz@P41JM8#G;!A_NPdw-(s30m*4Oo1C2R8yttK9ob5_U151PM<@;euvEK z39GS^Zq$!&57#)_B(@n@EIp-or#!xc3o^D&98lG&+2T0jI|fd~ogfzMBCmOLor>C*JrT09;AjMFLAAWrPgTgN@=Ksul1M0ZO0#Q zo9vdAVqc`)ZcKK|zO%w5f5qQwYMrIKEU7my(H^^YR~oo4!{52#y<_UgVw6^kiI67o@fbt2ds) KE5T2XNB;qvp!VDV literal 0 HcmV?d00001 diff --git a/auth_device/static/js/device_connection.js b/auth_device/static/js/device_connection.js new file mode 100644 index 0000000000..3407584832 --- /dev/null +++ b/auth_device/static/js/device_connection.js @@ -0,0 +1,9 @@ +odoo.define("auth_device.connection_device", function () { + "use strict"; + + $(document).ready(function () { + $("#loginDevice").on("shown.bs.modal", function () { + $(this).find("#device_code_input").focus(); + }); + }); +}); diff --git a/auth_device/tests/__init__.py b/auth_device/tests/__init__.py new file mode 100644 index 0000000000..cae5faed9d --- /dev/null +++ b/auth_device/tests/__init__.py @@ -0,0 +1,2 @@ +from . import test_auth_device +from . import test_ui diff --git a/auth_device/tests/test_auth_device.py b/auth_device/tests/test_auth_device.py new file mode 100644 index 0000000000..64990d9819 --- /dev/null +++ b/auth_device/tests/test_auth_device.py @@ -0,0 +1,74 @@ +# Copyright 2023 ACSONE SA/NV +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl). +import logging + +from psycopg2.errors import UniqueViolation + +from odoo import exceptions +from odoo.tests import tagged +from odoo.tests.common import SavepointCase + + +@tagged("post_install", "-at_install") +class TestAuthDevice(SavepointCase): + @classmethod + def setUpClass(cls): + super().setUpClass() + cls.env = cls.env(context=dict(cls.env.context, tracking_disable=True)) + cls.ResUsers = cls.env["res.users"] + cls.ResPartner = cls.env["res.partner"] + cls.user_device_code = "123456789012" + cls.bad_device_code = "345678098765" + cls.partner_user = cls.ResPartner.create( + { + "name": "User Device Code", + "email": "user.device@example.com", + } + ) + cls.user = cls.ResUsers.create( + { + "name": "User Device Code", + "login": "user_device", + "email": "device@user.login", + "partner_id": cls.partner_user.id, + "device_code": cls.user_device_code, + "is_allowed_to_connect_with_device": True, + } + ) + cls.user = cls.user.with_user(cls.user) + + def test_01_normal_login_succeed(self): + self.user._check_credentials(self.user_device_code, {"interactive": True}) + + def test_02_normal_login_fail(self): + with self.assertRaises(exceptions.AccessDenied): + self.user._check_credentials(self.bad_device_code, {"interactive": True}) + + def test_03_missing_device_code(self): + with self.assertRaises(AssertionError): + self.user._check_credentials("", {"interactive": True}) + + def test_04_duplicate_device_code(self): + partner_2 = self.partner_user = self.ResPartner.create( + { + "name": "Duplicate Device Code", + "email": "duplicate.device.code@example.com", + } + ) + with self.assertLogs(level=logging.ERROR): + with self.assertRaises(UniqueViolation): + self.ResUsers.create( + { + "name": "Duplicate Device Code", + "login": "duplicate_device_code", + "email": "device@duplicate.login", + "partner_id": partner_2.id, + "device_code": self.user_device_code, + "is_allowed_to_connect_with_device": True, + } + ) + + def test_05_not_allowed_to_connect(self): + self.user.sudo().is_allowed_to_connect_with_device = False + with self.assertRaises(exceptions.AccessDenied): + self.user._check_credentials(self.user_device_code, {"interactive": True}) diff --git a/auth_device/tests/test_ui.py b/auth_device/tests/test_ui.py new file mode 100644 index 0000000000..09d70584c7 --- /dev/null +++ b/auth_device/tests/test_ui.py @@ -0,0 +1,121 @@ +# Copyright 2023 ACSONE SA/NV +# License AGPL-3.0 or later (http://www.gnu.org/licenses/agpl). + +from lxml import html +from werkzeug.test import Client +from werkzeug.wrappers import BaseResponse + +from odoo.service import wsgi_server +from odoo.tests import common, tagged + + +@tagged("post_install", "-at_install") +class TestUI(common.HttpCase): + """ + This test was carried out in the same way as that the test_ui.py + in auth_admin_passkey. + Thanks to Sylvain Le Gal. + """ + + def setUp(self): + super(TestUI, self).setUp() + + with self.registry.cursor() as test_cursor: + env = self.env(test_cursor) + + self.ResUsers = self.env["res.users"] + self.ResPartner = self.env["res.partner"] + self.user_device_code = "123456789012" + self.bad_device_code = "345678098765" + self.partner_user = self.ResPartner.create( + { + "name": "User Device Code", + "email": "user.device@example.com", + } + ) + self.user = self.ResUsers.create( + { + "name": "User Device Code", + "login": "user_device", + "email": "device@user.login", + "partner_id": self.partner_user.id, + "device_code": self.user_device_code, + "is_allowed_to_connect_with_device": True, + } + ) + + self.dbname = env.cr.dbname + + self.werkzeug_environ = {"REMOTE_ADDR": "127.0.0.1"} + self.test_client = Client(wsgi_server.application, BaseResponse) + self.test_client.get("/web/session/logout") + + def html_doc(self, response): + """Get an HTML LXML document.""" + return html.fromstring(response.data) + + def get_request(self, url, data=None): + return self.test_client.get(url, query_string=data, follow_redirects=True) + + def csrf_token(self, response): + """Get a valid CSRF token.""" + doc = self.html_doc(response) + return doc.xpath("//input[@name='csrf_token']")[1].get("value") + + def post_request(self, url, data=None): + return self.test_client.post( + url, data=data, follow_redirects=True, environ_base=self.werkzeug_environ + ) + + def test_01_ui_normal_login_succeed(self): + # Our user wants to go to backoffice part of Odoo + response = self.get_request("/web/", data={"db": self.dbname}) + + # He notices that his redirected to login page as not authenticated + self.assertIn("oe_login_device_form", response.data.decode("utf8")) + + # He needs to enter his credentials and submit the form + data = { + "device_code": self.user.device_code, + "csrf_token": self.csrf_token(response), + "db": self.dbname, + } + response = self.post_request("/auth_device/login", data=data) + + # He notices that his redirected to backoffice + self.assertNotIn("oe_login_device_form", response.data.decode("utf8")) + + def test_02_normal_login_fail(self): + # Our user wants to go to backoffice part of Odoo + response = self.get_request("/web/", data={"db": self.dbname}) + + # He notices that he's redirected to login page as not authenticated + self.assertIn("oe_login_device_form", response.data.decode("utf8")) + + # He needs to enter his credentials and submit the form + data = { + "device_code": self.bad_device_code, + "csrf_token": self.csrf_token(response), + "db": self.dbname, + } + response = self.post_request("/auth_device/login", data=data) + + # He mistyped his password so he's redirected to login page again + self.assertIn("oe_login_device_form", response.data.decode("utf8")) + + def test_03_no_login(self): + # Our user wants to go to backoffice part of Odoo + response = self.get_request("/web/", data={"db": self.dbname}) + + # He notices that he's redirected to login page as not authenticated + self.assertIn("oe_login_device_form", response.data.decode("utf8")) + + # He forgot to enter his credentials and submit the form + data = { + "csrf_token": self.csrf_token(response), + "db": self.dbname, + } + response = self.post_request("/auth_device/login", data=data) + + # He forgot to complete the form so he's redirected to login page again + self.assertIn("oe_login_device_form", response.data.decode("utf8")) diff --git a/auth_device/views/assets_frontend.xml b/auth_device/views/assets_frontend.xml new file mode 100644 index 0000000000..354b0b48fb --- /dev/null +++ b/auth_device/views/assets_frontend.xml @@ -0,0 +1,14 @@ + + + +