Tuesday, September 8, 2026
1 change · saas-19.1
Security fixes and vulnerability patches
The authentication timeout check now rejects login verification methods that are not enabled for the user. This prevents an unexpected server error and returns a proper access denial instead, improving reliability and security around session identity checks.
Original PR description
## Description of the issue/feature this PR addresses: `IrHttp._check_identity()` forwarded the client-supplied `credential` dict straight to `_check_credentials()` without checking that…
## Description of the issue/feature this PR addresses:
`IrHttp._check_identity()` forwarded the client-supplied `credential` dict
straight to `_check_credentials()` without checking that `credential['type']`
was one of the user's actually-enabled authentication methods
(`user._get_auth_methods()`).
## Current behavior before PR:
An authenticated user can send a credential of a type they don't have
enabled - e.g. `{"type": "totp", "token": "000000"}` against an account
without TOTP configured - which raises an unhandled `TypeError` deep inside
`base64.b32decode(False)` instead of a clean authentication failure:
curl -s -b "$JAR" "$BASE/auth-timeout/session/check-identity" \
-H 'Content-Type: application/json' \
-d '{"jsonrpc":"2.0","method":"call","params":{"type":"totp","token":"000000"},"id":null}'
## Desired behavior after PR is merged:
`_check_identity()` validates `credential['type']` against the user's
enabled auth methods before forwarding it to `_check_credentials()`. Any
mismatch (e.g. a TOTP credential sent to an account without TOTP enabled,
or any unrecognized type) now raises a clean `AccessDenied` (403) instead
of an unhandled `TypeError`.
---
I confirm I have signed the CLA and read the PR guidelines at www.odoo.com/submit-pr
Forward-Port-Of: odoo/odoo#272563