Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[17.0][MIG] auth_jwt: Migration to 17.0 #751

Merged
merged 43 commits into from
Jan 18, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
43 commits
Select commit Hold shift + click to select a range
a0ca0a0
[ADD] auth_jwt
sbidoul Apr 28, 2021
da4dfd0
auth_jwt: use PyJWT instead of python-jose
sbidoul Apr 28, 2021
22e8c80
auth_jwt: add signature algorithms
sbidoul Apr 28, 2021
910a716
auth_jwt: support multiple audiences
sbidoul Apr 28, 2021
40aedcc
auth_jwt: add nbf validation test
sbidoul Apr 28, 2021
06897a4
auth_jwt: docs clarification and fixes
sbidoul Apr 29, 2021
05a10d5
auth_jwt: fix jwks URI support
sbidoul Jun 25, 2021
89dd810
auth_jwt: mock instead of committing in tests
sbidoul Jul 25, 2021
16bc96b
auth_jwt: more precise precondition check
sbidoul Jul 26, 2021
030164b
Rename auth_jwt_test to auth_jwt_demo
sbidoul Jul 26, 2021
e6c93e2
[MIG] auth_jwt
sbidoul Jun 27, 2021
2d167fd
[UPD] Update auth_jwt.pot
oca-travis Jul 28, 2021
6bc609b
[UPD] README.rst
OCA-git-bot Jul 28, 2021
b430a28
auth_jwt 14.0.1.0.1
OCA-git-bot Jul 28, 2021
3c074d6
[IMP] auth_jwt: add public_or_jwt auth method
sbidoul Oct 5, 2021
51365a8
[UPD] README.rst
OCA-git-bot Oct 6, 2021
8dd53c6
auth_jwt 14.0.1.1.0
OCA-git-bot Oct 6, 2021
e8c12c3
auth_jwt: Relicence under LGPL
yankinmax Dec 29, 2021
d00e0a7
auth_jwt 14.0.1.2.0
OCA-git-bot Dec 29, 2021
6b17cc6
[IMP] auth_jwt: Add validator.next_validator_id to allow validator ch…
paradoxxxzero Feb 17, 2022
f486b8a
[UPD] Update auth_jwt.pot
Jun 14, 2022
e82d36f
auth_jwt 14.0.2.0.0
OCA-git-bot Jun 14, 2022
e884ba2
[MIG] auth_jwt from 14 to 16
sbidoul Jun 6, 2023
cda5566
[MIG] auth_jwt: convert unit tests to integration tests
sbidoul Jun 6, 2023
9a78860
[UPD] Update auth_jwt.pot
Jun 7, 2023
7c33f97
[UPD] README.rst
OCA-git-bot Jun 7, 2023
d8017fb
auth_jwt: add cookie mode
sbidoul Jun 7, 2023
621b490
auth_jwt: clarify exceptions
sbidoul Jun 8, 2023
91333a6
auth_jwt: minor refactoring
sbidoul Jun 8, 2023
2353a46
[IMP] auth_jwt: refactor
sbidoul Jun 8, 2023
8aeef4a
[FIX] auth_jwt: don't use public mode if a cookie is present
sbidoul Jun 8, 2023
e003ebd
[IMP] auth_jwt: check cookie_name is present in cookie mode
sbidoul Jun 16, 2023
6131bff
[UPD] Update auth_jwt.pot
Jun 23, 2023
9942618
[UPD] README.rst
OCA-git-bot Jun 23, 2023
b2001ad
auth_jwt 16.0.1.1.0
OCA-git-bot Jun 23, 2023
b3db3c4
Added translation using Weblate (Spanish)
Ivorra78 Aug 25, 2023
6c6a6fb
Translated using Weblate (Spanish)
Ivorra78 Aug 25, 2023
80cd757
[UPD] README.rst
OCA-git-bot Sep 3, 2023
5165407
Added translation using Weblate (Italian)
rbellanova Dec 15, 2023
d5135a4
Translated using Weblate (Italian)
rbellanova Dec 15, 2023
290f8c1
Translated using Weblate (Italian)
mymage Jan 3, 2024
5856039
Translated using Weblate (Italian)
francesco-ooops Jan 29, 2024
559b3fe
[MIG] auth_jwt: Migration to 17.0
MikeAelbrecht May 30, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
164 changes: 164 additions & 0 deletions auth_jwt/README.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,164 @@
========
Auth JWT
========

..
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!! This file is generated by oca-gen-addon-readme !!
!! changes will be overwritten. !!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!! source digest: sha256:d22309ac82ef1eb8879974683b10d4be288eb330fd7e250927f1a8d602dc3988
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

.. |badge1| image:: https://img.shields.io/badge/maturity-Beta-yellow.png
:target: https://odoo-community.org/page/development-status
:alt: Beta
.. |badge2| image:: https://img.shields.io/badge/licence-LGPL--3-blue.png
:target: http://www.gnu.org/licenses/lgpl-3.0-standalone.html
:alt: License: LGPL-3
.. |badge3| image:: https://img.shields.io/badge/github-OCA%2Fserver--auth-lightgray.png?logo=github
:target: https://github.com/OCA/server-auth/tree/17.0/auth_jwt
:alt: OCA/server-auth
.. |badge4| image:: https://img.shields.io/badge/weblate-Translate%20me-F47D42.png
:target: https://translation.odoo-community.org/projects/server-auth-17-0/server-auth-17-0-auth_jwt
:alt: Translate me on Weblate
.. |badge5| image:: https://img.shields.io/badge/runboat-Try%20me-875A7B.png
:target: https://runboat.odoo-community.org/builds?repo=OCA/server-auth&target_branch=17.0
:alt: Try me on Runboat

|badge1| |badge2| |badge3| |badge4| |badge5|

JWT bearer token authentication.

**Table of contents**

.. contents::
:local:

Installation
============

This module requires the ``pyjwt`` library to be installed.

Usage
=====

This module lets developpers add a new ``jwt`` authentication method on
Odoo controller routes.

To use it, you must:

- Create an ``auth.jwt.validator`` record to configure how the JWT token
will be validated.
- Add an ``auth="jwt_{validator-name}"`` or
``auth="public_or_jwt_{validator-name}"`` attribute to the routes you
want to protect where ``{validator-name}`` corresponds to the name
attribute of the JWT validator record.

The ``auth_jwt_demo`` module provides examples.

The JWT validator can be configured with the following properties:

- ``name``: the validator name, to match the
``auth="jwt_{validator-name}"`` route property.
- ``audience``: a comma-separated list of allowed audiences, used to
validate the ``aud`` claim.
- ``issuer``: used to validate the ``iss`` claim.
- Signature type (secret or public key), algorithm, secret and JWK URI
are used to validate the token signature.

In addition, the ``exp`` claim is validated to reject expired tokens.

If the ``Authorization`` HTTP header is missing, malformed, or contains
an invalid token, the request is rejected with a 401 (Unauthorized)
code, unless the cookie mode is enabled (see below).

If the token is valid, the request executes with the configured user id.
By default the user id selection strategy is ``static`` (i.e. the same
for all requests) and the selected user is configured on the JWT
validator. Additional strategies can be provided by overriding the
``_get_uid()`` method and extending the ``user_id_strategy`` selection
field.

The selected user is *not* stored in the session. It is only available
in ``request.uid`` (and thus it is the one used in ``request.env``). To
avoid any confusion and mismatches between the bearer token and the
session, this module rejects requests made with an authenticated user
session.

Additionally, if a ``partner_id_strategy`` is configured, a partner is
searched and if found, its id is stored in the
``request.jwt_partner_id`` attribute. If ``partner_id_required`` is set,
a 401 (Unauthorized) is returned if no partner was found. Otherwise
``request.jwt_partner_id`` is left falsy. Additional strategies can be
provided by overriding the ``_get_partner_id()`` method and extending
the ``partner_id_strategy`` selection field.

The decoded JWT payload is stored in ``request.jwt_payload``.

The ``public_auth_jwt`` method delegates authentication to the standard
Odoo ``public`` method when the Authorization header is not set. If it
is set, the regular JWT authentication is performed as described above.
This method is useful for public endpoints that need to work for
anonymous users, but can be enhanced when an authenticated user is know.
A typical use case is a "add to cart" endpoint that can work for
anonymous users, but can be enhanced by binding the cart to a known
customer when the authenticated user is known.

You can enable a cookie mode on JWT validators. In this case, the JWT
payload obtained from the ``Authorization`` header is returned as a
Http-Only cookie. This mode is sometimes simpler for front-end
applications which do not then need to store and protect the JWT token
across requests and can simply rely on the cookie management mechanisms
of browsers. When both the ``Authorization`` header and a cookie are
provided, the cookie is ignored in order to let clients authenticate
with a different user by providing a new JWT token.

Bug Tracker
===========

Bugs are tracked on `GitHub Issues <https://github.com/OCA/server-auth/issues>`_.
In case of trouble, please check there if your issue has already been reported.
If you spotted it first, help us to smash it by providing a detailed and welcomed
`feedback <https://github.com/OCA/server-auth/issues/new?body=module:%20auth_jwt%0Aversion:%2017.0%0A%0A**Steps%20to%20reproduce**%0A-%20...%0A%0A**Current%20behavior**%0A%0A**Expected%20behavior**>`_.

Do not contact contributors directly about support or help with technical issues.

Credits
=======

Authors
-------

* ACSONE SA/NV

Contributors
------------

- Stéphane Bidoul <[email protected]>
- Mohamed Alkobrosli <[email protected]>

Maintainers
-----------

This module is maintained by the OCA.

.. image:: https://odoo-community.org/logo.png
:alt: Odoo Community Association
:target: https://odoo-community.org

OCA, or the Odoo Community Association, is a nonprofit organization whose
mission is to support the collaborative development of Odoo features and
promote its widespread use.

.. |maintainer-sbidoul| image:: https://github.com/sbidoul.png?size=40px
:target: https://github.com/sbidoul
:alt: sbidoul

Current `maintainer <https://odoo-community.org/page/maintainer-role>`__:

|maintainer-sbidoul|

This module is part of the `OCA/server-auth <https://github.com/OCA/server-auth/tree/17.0/auth_jwt>`_ project on GitHub.

You are welcome to contribute. To learn how please visit https://odoo-community.org/page/Contribute.
1 change: 1 addition & 0 deletions auth_jwt/__init__.py
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
from . import models
20 changes: 20 additions & 0 deletions auth_jwt/__manifest__.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# Copyright 2021 ACSONE SA/NV
# License LGPL-3.0 or later (http://www.gnu.org/licenses/lgpl).

{
"name": "Auth JWT",
"summary": """
JWT bearer token authentication.""",
"version": "17.0.1.0.0",
"license": "LGPL-3",
"author": "ACSONE SA/NV,Odoo Community Association (OCA)",
"maintainers": ["sbidoul"],
"website": "https://github.com/OCA/server-auth",
"depends": [],
"external_dependencies": {"python": ["pyjwt", "cryptography"]},
"data": ["security/ir.model.access.csv", "views/auth_jwt_validator_views.xml"],
"demo": [],
"installable": True,
"application": False,
"auto_install": False,
}
54 changes: 54 additions & 0 deletions auth_jwt/exceptions.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
# Copyright 2021 ACSONE SA/NV
# License LGPL-3.0 or later (http://www.gnu.org/licenses/lgpl)

from werkzeug.exceptions import InternalServerError, Unauthorized


class UnauthorizedMissingAuthorizationHeader(Unauthorized):
pass


class UnauthorizedMissingCookie(Unauthorized):
pass


class UnauthorizedMalformedAuthorizationHeader(Unauthorized):
pass


class UnauthorizedSessionMismatch(Unauthorized):
pass


class AmbiguousJwtValidator(InternalServerError):
pass


class JwtValidatorNotFound(InternalServerError):
pass


class UnauthorizedInvalidToken(Unauthorized):
pass


class UnauthorizedPartnerNotFound(Unauthorized):
pass


class UnauthorizedCompositeJwtError(Unauthorized):
"""Indicate that multiple errors occurred during JWT chain validation."""

def __init__(self, errors):
self.errors = errors
super().__init__(
"Multiple errors occurred during JWT chain validation:\n"
+ "\n".join(
f"{validator_name}: {error}"
for validator_name, error in self.errors.items()
)
)


class ConfigurationError(InternalServerError):
pass
Loading
Loading