Community mailing list archives
Re: Module Contribution - Odoo - Restrict Multiple Sign in for Same Userby
I think there is a distinction between having multiple windows open and being logged into multiple devices or even browsers. It is possible to have multiple windows open under the same user session. The application should detect that the user is logging into a different device or browser and prevent this, or log the other session out.
On Tue, Mar 31, 2015 at 9:03 AM, Ferdinand Gassauer <email@example.com> wrote:
Hello<blockquote cite="mid:551A88A5.firstname.lastname@example.org" type="cite">
most of our users have 2 or more windows of odoo / openerp open - but most on ONE computer, but signed in multiple times
- have to accomplish complex tasks and have to look up something what is not available on the current screen
- multitasking - during data entry which takes a lot of time, they have to interrupt (save) and do something else.
I am not saying that it is impossible to do this with ONE login, but the way it works now is VERY comfortable.regards
On 2015-03-31 15:47, Sandesh Rao wrote:
A few of our prospects had raised concerns over the security aspects of odoo mentioning that a user with proper credentials could login from multiple machines / devices at the same time. This, according to them, should not be allowed within the ERP system. If a user has already logged in, the ERP should not allow another login attempt from the same userid, until the user has logged off from his existing session or the lifetime of the user session has expired.
To address this concern we have come up with a module - Restrict Multiple Sign in for Same User. You can find this module here - http://www.nevprobusinesssolutions.com/download/
We have also uploaded the same to the Odoo app store - https://www.odoo.com/apps/modules/8.0/single_login/ . In this, we have kept the user's session lifetime as 2 minutes. If the user session is active (i.e. browser of the user is not closed), the expiry time of the cookie will keep on getting incremented. During this time, if another login attempt happens from a different browser or machine for the same userid, the system would not log in that user.
Hope you find this useful. Your feedback and suggestions are welcome !
Serpent Consulting Services Pvt. Ltd., Jay Vora