Daily updates from Odoo
Tuesday, July 14, 2026
1 change · saas-19.2
Security fixes and vulnerability patches
Database API keys are now better protected from accidental or unauthorized exposure. The system no longer sends the real key to the user interface and masks the field on screen, reducing the risk of sensitive credentials being leaked.
Original PR description
The aim of this commit is to harden the security of the `database_api_key` field. Before this commit: The field could be retrieved through the orm and could be leaked if the access rights were bypassed. A streamer pasting the key in the field could also leak his api key by mistake. After this commit: The only way to access the field is through direct SQL access. The api key isn't shown anymore in the UI: - The UI doesn't receive the key from the backend: it receives dummy **** - The field in the form view display dots instead of any char to prevent leaking the key by mistake. Task-id: None Forward-Port-Of: odoo/enterprise#123826 Forward-Port-Of: odoo/enterprise#122163