details:   https://code.tryton.org/tryton/commit/c7e33ba0f7c2
branch:    default
user:      Cédric Krier <[email protected]>
date:      Wed Sep 02 12:18:08 2026 +0200
description:
        Check if the user argument is a string on login and reset password

        Those entrypoints do not require authentication so we must enforce 
explicitly
        the type of argument.

        Closes #15048
diffstat:

 trytond/trytond/protocols/dispatcher.py |  4 ++++
 1 files changed, 4 insertions(+), 0 deletions(-)

diffs (21 lines):

diff -r 8633e8e87ea5 -r c7e33ba0f7c2 trytond/trytond/protocols/dispatcher.py
--- a/trytond/trytond/protocols/dispatcher.py   Mon Aug 31 18:36:13 2026 +0200
+++ b/trytond/trytond/protocols/dispatcher.py   Wed Sep 02 12:18:08 2026 +0200
@@ -46,6 +46,8 @@
         'language': language,
         '_request': request.context,
         }
+    if not isinstance(user, str):
+        abort(HTTPStatus.BAD_REQUEST, "user argument must be a string")
     try:
         session = security.login(
             database_name, user, parameters, context=context)
@@ -103,6 +105,8 @@
         'language': language,
         '_request': request.context,
         }
+    if not isinstance(user, str):
+        abort(HTTPStatus.BAD_REQUEST, "user argument must be a string")
     try:
         security.reset_password(database_name, user, context=context)
     except backend.DatabaseOperationalError:

Reply via email to