Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[18.0][MIG] auth_jwt: Migration to 18.0 #752

Open
wants to merge 48 commits into
base: 18.0
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
48 commits
Select commit Hold shift + click to select a range
9910dc7
[ADD] auth_jwt
sbidoul Apr 28, 2021
6f19851
auth_jwt: use PyJWT instead of python-jose
sbidoul Apr 28, 2021
56d9179
auth_jwt: add signature algorithms
sbidoul Apr 28, 2021
461ac34
auth_jwt: support multiple audiences
sbidoul Apr 28, 2021
179bf8c
auth_jwt: add nbf validation test
sbidoul Apr 28, 2021
05cf6fb
auth_jwt: docs clarification and fixes
sbidoul Apr 29, 2021
b44080e
auth_jwt: fix jwks URI support
sbidoul Jun 25, 2021
43ad29b
auth_jwt: mock instead of committing in tests
sbidoul Jul 25, 2021
8c78185
auth_jwt: more precise precondition check
sbidoul Jul 26, 2021
9e9ae3e
Rename auth_jwt_test to auth_jwt_demo
sbidoul Jul 26, 2021
560347b
[MIG] auth_jwt
sbidoul Jun 27, 2021
58e3595
[UPD] Update auth_jwt.pot
oca-travis Jul 28, 2021
eed83c5
[UPD] README.rst
OCA-git-bot Jul 28, 2021
587266f
auth_jwt 14.0.1.0.1
OCA-git-bot Jul 28, 2021
d916acc
[IMP] auth_jwt: add public_or_jwt auth method
sbidoul Oct 5, 2021
f025e45
[UPD] README.rst
OCA-git-bot Oct 6, 2021
e1dff5e
auth_jwt 14.0.1.1.0
OCA-git-bot Oct 6, 2021
caf5e00
auth_jwt: Relicence under LGPL
yankinmax Dec 29, 2021
1947663
auth_jwt 14.0.1.2.0
OCA-git-bot Dec 29, 2021
55d8ea1
[IMP] auth_jwt: Add validator.next_validator_id to allow validator ch…
paradoxxxzero Feb 17, 2022
b373e3f
[UPD] Update auth_jwt.pot
Jun 14, 2022
8514722
auth_jwt 14.0.2.0.0
OCA-git-bot Jun 14, 2022
71f3f2b
[MIG] auth_jwt from 14 to 16
sbidoul Jun 6, 2023
f86bee9
[MIG] auth_jwt: convert unit tests to integration tests
sbidoul Jun 6, 2023
ed78b30
[UPD] Update auth_jwt.pot
Jun 7, 2023
487b6e7
[UPD] README.rst
OCA-git-bot Jun 7, 2023
d24e127
auth_jwt: add cookie mode
sbidoul Jun 7, 2023
3e619e6
auth_jwt: clarify exceptions
sbidoul Jun 8, 2023
4d647f7
auth_jwt: minor refactoring
sbidoul Jun 8, 2023
0dbe315
[IMP] auth_jwt: refactor
sbidoul Jun 8, 2023
4475969
[FIX] auth_jwt: don't use public mode if a cookie is present
sbidoul Jun 8, 2023
b2a3d82
[IMP] auth_jwt: check cookie_name is present in cookie mode
sbidoul Jun 16, 2023
d2afabc
[UPD] Update auth_jwt.pot
Jun 23, 2023
c7958c1
[UPD] README.rst
OCA-git-bot Jun 23, 2023
6bdb431
auth_jwt 16.0.1.1.0
OCA-git-bot Jun 23, 2023
11899cc
Added translation using Weblate (Spanish)
Ivorra78 Aug 25, 2023
86a3df9
Translated using Weblate (Spanish)
Ivorra78 Aug 25, 2023
54589cf
[UPD] README.rst
OCA-git-bot Sep 3, 2023
9816ae5
Added translation using Weblate (Italian)
rbellanova Dec 15, 2023
031b44e
Translated using Weblate (Italian)
rbellanova Dec 15, 2023
9d2d030
Translated using Weblate (Italian)
mymage Jan 3, 2024
dd9d25b
Translated using Weblate (Italian)
francesco-ooops Jan 29, 2024
0337b9c
[MIG] auth_jwt: Migration to 17.0
MikeAelbrecht May 30, 2024
54cfe35
[UPD] Update auth_jwt.pot
Jan 18, 2025
2814bf7
[BOT] post-merge updates
OCA-git-bot Jan 18, 2025
ddd68c0
Update translation files
weblate Jan 18, 2025
b32ba29
[IMP] auth_jwt: pre-commit auto fixes
dnplkndll Jan 18, 2025
20c9df5
[MIG] auth_jwt: Migration to 18.0
dnplkndll Jan 16, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
164 changes: 164 additions & 0 deletions auth_jwt/README.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,164 @@
========
Auth JWT
========

..
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!! This file is generated by oca-gen-addon-readme !!
!! changes will be overwritten. !!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!! source digest: sha256:608e8780fabb7f7a32193245dd2a7e594810863dcc55aa1dc9e5b2bc3426d74c
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

.. |badge1| image:: https://img.shields.io/badge/maturity-Beta-yellow.png
:target: https://odoo-community.org/page/development-status
:alt: Beta
.. |badge2| image:: https://img.shields.io/badge/licence-LGPL--3-blue.png
:target: http://www.gnu.org/licenses/lgpl-3.0-standalone.html
:alt: License: LGPL-3
.. |badge3| image:: https://img.shields.io/badge/github-OCA%2Fserver--auth-lightgray.png?logo=github
:target: https://github.com/OCA/server-auth/tree/18.0/auth_jwt
:alt: OCA/server-auth
.. |badge4| image:: https://img.shields.io/badge/weblate-Translate%20me-F47D42.png
:target: https://translation.odoo-community.org/projects/server-auth-18-0/server-auth-18-0-auth_jwt
:alt: Translate me on Weblate
.. |badge5| image:: https://img.shields.io/badge/runboat-Try%20me-875A7B.png
:target: https://runboat.odoo-community.org/builds?repo=OCA/server-auth&target_branch=18.0
:alt: Try me on Runboat

|badge1| |badge2| |badge3| |badge4| |badge5|

JWT bearer token authentication.

**Table of contents**

.. contents::
:local:

Installation
============

This module requires the ``pyjwt`` library to be installed.

Usage
=====

This module lets developpers add a new ``jwt`` authentication method on
Odoo controller routes.

To use it, you must:

- Create an ``auth.jwt.validator`` record to configure how the JWT token
will be validated.
- Add an ``auth="jwt_{validator-name}"`` or
``auth="public_or_jwt_{validator-name}"`` attribute to the routes you
want to protect where ``{validator-name}`` corresponds to the name
attribute of the JWT validator record.

The ``auth_jwt_demo`` module provides examples.

The JWT validator can be configured with the following properties:

- ``name``: the validator name, to match the
``auth="jwt_{validator-name}"`` route property.
- ``audience``: a comma-separated list of allowed audiences, used to
validate the ``aud`` claim.
- ``issuer``: used to validate the ``iss`` claim.
- Signature type (secret or public key), algorithm, secret and JWK URI
are used to validate the token signature.

In addition, the ``exp`` claim is validated to reject expired tokens.

If the ``Authorization`` HTTP header is missing, malformed, or contains
an invalid token, the request is rejected with a 401 (Unauthorized)
code, unless the cookie mode is enabled (see below).

If the token is valid, the request executes with the configured user id.
By default the user id selection strategy is ``static`` (i.e. the same
for all requests) and the selected user is configured on the JWT
validator. Additional strategies can be provided by overriding the
``_get_uid()`` method and extending the ``user_id_strategy`` selection
field.

The selected user is *not* stored in the session. It is only available
in ``request.uid`` (and thus it is the one used in ``request.env``). To
avoid any confusion and mismatches between the bearer token and the
session, this module rejects requests made with an authenticated user
session.

Additionally, if a ``partner_id_strategy`` is configured, a partner is
searched and if found, its id is stored in the
``request.jwt_partner_id`` attribute. If ``partner_id_required`` is set,
a 401 (Unauthorized) is returned if no partner was found. Otherwise
``request.jwt_partner_id`` is left falsy. Additional strategies can be
provided by overriding the ``_get_partner_id()`` method and extending
the ``partner_id_strategy`` selection field.

The decoded JWT payload is stored in ``request.jwt_payload``.

The ``public_auth_jwt`` method delegates authentication to the standard
Odoo ``public`` method when the Authorization header is not set. If it
is set, the regular JWT authentication is performed as described above.
This method is useful for public endpoints that need to work for
anonymous users, but can be enhanced when an authenticated user is know.
A typical use case is a "add to cart" endpoint that can work for
anonymous users, but can be enhanced by binding the cart to a known
customer when the authenticated user is known.

You can enable a cookie mode on JWT validators. In this case, the JWT
payload obtained from the ``Authorization`` header is returned as a
Http-Only cookie. This mode is sometimes simpler for front-end
applications which do not then need to store and protect the JWT token
across requests and can simply rely on the cookie management mechanisms
of browsers. When both the ``Authorization`` header and a cookie are
provided, the cookie is ignored in order to let clients authenticate
with a different user by providing a new JWT token.

Bug Tracker
===========

Bugs are tracked on `GitHub Issues <https://github.com/OCA/server-auth/issues>`_.
In case of trouble, please check there if your issue has already been reported.
If you spotted it first, help us to smash it by providing a detailed and welcomed
`feedback <https://github.com/OCA/server-auth/issues/new?body=module:%20auth_jwt%0Aversion:%2018.0%0A%0A**Steps%20to%20reproduce**%0A-%20...%0A%0A**Current%20behavior**%0A%0A**Expected%20behavior**>`_.

Do not contact contributors directly about support or help with technical issues.

Credits
=======

Authors
-------

* ACSONE SA/NV

Contributors
------------

- Stéphane Bidoul <[email protected]>
- Mohamed Alkobrosli <[email protected]>

Maintainers
-----------

This module is maintained by the OCA.

.. image:: https://odoo-community.org/logo.png
:alt: Odoo Community Association
:target: https://odoo-community.org

OCA, or the Odoo Community Association, is a nonprofit organization whose
mission is to support the collaborative development of Odoo features and
promote its widespread use.

.. |maintainer-sbidoul| image:: https://github.com/sbidoul.png?size=40px
:target: https://github.com/sbidoul
:alt: sbidoul

Current `maintainer <https://odoo-community.org/page/maintainer-role>`__:

|maintainer-sbidoul|

This module is part of the `OCA/server-auth <https://github.com/OCA/server-auth/tree/18.0/auth_jwt>`_ project on GitHub.

You are welcome to contribute. To learn how please visit https://odoo-community.org/page/Contribute.
1 change: 1 addition & 0 deletions auth_jwt/__init__.py
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
from . import models
20 changes: 20 additions & 0 deletions auth_jwt/__manifest__.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# Copyright 2021 ACSONE SA/NV
# License LGPL-3.0 or later (http://www.gnu.org/licenses/lgpl).

{
"name": "Auth JWT",
"summary": """
JWT bearer token authentication.""",
"version": "18.0.1.0.0",
"license": "LGPL-3",
"author": "ACSONE SA/NV,Odoo Community Association (OCA)",
"maintainers": ["sbidoul"],
"website": "https://github.com/OCA/server-auth",
"depends": [],
"external_dependencies": {"python": ["pyjwt", "cryptography"]},
"data": ["security/ir.model.access.csv", "views/auth_jwt_validator_views.xml"],
"demo": [],
"installable": True,
"application": False,
"auto_install": False,
}
54 changes: 54 additions & 0 deletions auth_jwt/exceptions.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
# Copyright 2021 ACSONE SA/NV
# License LGPL-3.0 or later (http://www.gnu.org/licenses/lgpl)

from werkzeug.exceptions import InternalServerError, Unauthorized


class UnauthorizedMissingAuthorizationHeader(Unauthorized):
pass


class UnauthorizedMissingCookie(Unauthorized):
pass


class UnauthorizedMalformedAuthorizationHeader(Unauthorized):
pass


class UnauthorizedSessionMismatch(Unauthorized):
pass


class AmbiguousJwtValidator(InternalServerError):
pass


class JwtValidatorNotFound(InternalServerError):
pass


class UnauthorizedInvalidToken(Unauthorized):
pass


class UnauthorizedPartnerNotFound(Unauthorized):
pass


class UnauthorizedCompositeJwtError(Unauthorized):
"""Indicate that multiple errors occurred during JWT chain validation."""

def __init__(self, errors):
self.errors = errors
super().__init__(
"Multiple errors occurred during JWT chain validation:\n"
+ "\n".join(
f"{validator_name}: {error}"
for validator_name, error in self.errors.items()
)
)


class ConfigurationError(InternalServerError):
pass
Loading
Loading