details: https://code.tryton.org/tryton/commit/1487498d59d6
branch: default
user: Cédric Krier <[email protected]>
date: Wed Sep 02 12:19:42 2026 +0200
description:
Enforce the type of login parameters
As they are received from a non authenticated entrypoint, we must
ensure their
types.
diffstat:
modules/authentication_sms/res.py | 2 +-
modules/ldap_authentication/res.py | 2 +-
trytond/trytond/res/user.py | 33 +++++++++++++++++----------------
3 files changed, 19 insertions(+), 18 deletions(-)
diffs (74 lines):
diff -r c7e33ba0f7c2 -r 1487498d59d6 modules/authentication_sms/res.py
--- a/modules/authentication_sms/res.py Wed Sep 02 12:18:08 2026 +0200
+++ b/modules/authentication_sms/res.py Wed Sep 02 12:19:42 2026 +0200
@@ -40,7 +40,7 @@
if user_id:
SMSCode.send(user_id)
if 'sms_code' in parameters:
- code = parameters['sms_code']
+ code = str(parameters['sms_code'])
if not code:
return
if SMSCode.check(user_id, code):
diff -r c7e33ba0f7c2 -r 1487498d59d6 modules/ldap_authentication/res.py
--- a/modules/ldap_authentication/res.py Wed Sep 02 12:18:08 2026 +0200
+++ b/modules/ldap_authentication/res.py Wed Sep 02 12:19:42 2026 +0200
@@ -135,7 +135,7 @@
if 'password' not in parameters:
msg = gettext('res.msg_user_password', login=login)
raise LoginException('password', msg, type='password')
- password = parameters['password']
+ password = str(parameters['password'])
try:
server = ldap_server()
if server:
diff -r c7e33ba0f7c2 -r 1487498d59d6 trytond/trytond/res/user.py
--- a/trytond/trytond/res/user.py Wed Sep 02 12:18:08 2026 +0200
+++ b/trytond/trytond/res/user.py Wed Sep 02 12:19:42 2026 +0200
@@ -775,21 +775,22 @@
msg = gettext('res.msg_user_password', login=login)
raise LoginException('password', msg, type='password')
user_id, password_hash, password_reset = cls._get_login(login)
- if user_id and password_hash:
- password = parameters['password']
- valid, new_hash = cls.check_password(password, password_hash)
- if valid:
- if new_hash:
- logger.info("Update password hash for %s", user_id)
- with Transaction().new_transaction():
- with without_check_access():
- cls.write([cls(user_id)], {
- 'password_hash': new_hash,
- })
- return user_id
- if user_id and password_reset:
- if compare_digest(password_reset, parameters['password']):
- return user_id
+ if user_id:
+ password = str(parameters['password'])
+ if password_hash:
+ valid, new_hash = cls.check_password(password, password_hash)
+ if valid:
+ if new_hash:
+ logger.info("Update password hash for %s", user_id)
+ with Transaction().new_transaction():
+ with without_check_access():
+ cls.write([cls(user_id)], {
+ 'password_hash': new_hash,
+ })
+ return user_id
+ if password_reset:
+ if compare_digest(password_reset, password):
+ return user_id
@classmethod
def hash_password(cls, password):
@@ -894,7 +895,7 @@
try:
device, = cls.search([
('login', '=', login),
- ('cookie', '=', cookie),
+ ('cookie', '=', str(cookie)),
], limit=1)
except ValueError:
return None