details:   https://code.tryton.org/tryton/commit/1487498d59d6
branch:    default
user:      Cédric Krier <[email protected]>
date:      Wed Sep 02 12:19:42 2026 +0200
description:
        Enforce the type of login parameters

        As they are received from a non authenticated entrypoint, we must 
ensure their
        types.
diffstat:

 modules/authentication_sms/res.py  |   2 +-
 modules/ldap_authentication/res.py |   2 +-
 trytond/trytond/res/user.py        |  33 +++++++++++++++++----------------
 3 files changed, 19 insertions(+), 18 deletions(-)

diffs (74 lines):

diff -r c7e33ba0f7c2 -r 1487498d59d6 modules/authentication_sms/res.py
--- a/modules/authentication_sms/res.py Wed Sep 02 12:18:08 2026 +0200
+++ b/modules/authentication_sms/res.py Wed Sep 02 12:19:42 2026 +0200
@@ -40,7 +40,7 @@
         if user_id:
             SMSCode.send(user_id)
         if 'sms_code' in parameters:
-            code = parameters['sms_code']
+            code = str(parameters['sms_code'])
             if not code:
                 return
             if SMSCode.check(user_id, code):
diff -r c7e33ba0f7c2 -r 1487498d59d6 modules/ldap_authentication/res.py
--- a/modules/ldap_authentication/res.py        Wed Sep 02 12:18:08 2026 +0200
+++ b/modules/ldap_authentication/res.py        Wed Sep 02 12:19:42 2026 +0200
@@ -135,7 +135,7 @@
         if 'password' not in parameters:
             msg = gettext('res.msg_user_password', login=login)
             raise LoginException('password', msg, type='password')
-        password = parameters['password']
+        password = str(parameters['password'])
         try:
             server = ldap_server()
             if server:
diff -r c7e33ba0f7c2 -r 1487498d59d6 trytond/trytond/res/user.py
--- a/trytond/trytond/res/user.py       Wed Sep 02 12:18:08 2026 +0200
+++ b/trytond/trytond/res/user.py       Wed Sep 02 12:19:42 2026 +0200
@@ -775,21 +775,22 @@
             msg = gettext('res.msg_user_password', login=login)
             raise LoginException('password', msg, type='password')
         user_id, password_hash, password_reset = cls._get_login(login)
-        if user_id and password_hash:
-            password = parameters['password']
-            valid, new_hash = cls.check_password(password, password_hash)
-            if valid:
-                if new_hash:
-                    logger.info("Update password hash for %s", user_id)
-                    with Transaction().new_transaction():
-                        with without_check_access():
-                            cls.write([cls(user_id)], {
-                                    'password_hash': new_hash,
-                                    })
-                return user_id
-        if user_id and password_reset:
-            if compare_digest(password_reset, parameters['password']):
-                return user_id
+        if user_id:
+            password = str(parameters['password'])
+            if password_hash:
+                valid, new_hash = cls.check_password(password, password_hash)
+                if valid:
+                    if new_hash:
+                        logger.info("Update password hash for %s", user_id)
+                        with Transaction().new_transaction():
+                            with without_check_access():
+                                cls.write([cls(user_id)], {
+                                        'password_hash': new_hash,
+                                        })
+                    return user_id
+            if password_reset:
+                if compare_digest(password_reset, password):
+                    return user_id
 
     @classmethod
     def hash_password(cls, password):
@@ -894,7 +895,7 @@
         try:
             device, = cls.search([
                     ('login', '=', login),
-                    ('cookie', '=', cookie),
+                    ('cookie', '=', str(cookie)),
                     ], limit=1)
         except ValueError:
             return None

Reply via email to