From 8024a6e369b79abb1cbd52840fd66eaec66c07a3 Mon Sep 17 00:00:00 2001 From: Raphael Collet <rco@openerp.com> Date: Thu, 5 Aug 2021 15:26:53 +0200 Subject: [PATCH] [IMP] base: don't try authenticating inactive users --- odoo/addons/base/models/res_users.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/odoo/addons/base/models/res_users.py b/odoo/addons/base/models/res_users.py index 0064187b88f1..50258a939134 100644 --- a/odoo/addons/base/models/res_users.py +++ b/odoo/addons/base/models/res_users.py @@ -669,6 +669,8 @@ class Users(models.Model): try: self = api.Environment(cr, uid, {})[cls._name] with self._assert_can_auth(): + if not self.env.user.active: + raise AccessDenied() self._check_credentials(passwd) cls.__uid_cache[db][uid] = passwd finally: -- GitLab