Fixes new SSO signups landing as Portal users instead of Internal (unconditionally, for any OAuth provider, once installed), and syncs Odoo groups from an OIDC provider's groups claim on every login.
15 lines
760 B
XML
15 lines
760 B
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<odoo>
|
|
<!-- Never logs in itself (active=False, same as core's base.template_portal_user_id) —
|
|
only exists to be copied by _create_user_from_template. groups_id is what actually
|
|
makes a first-time SSO signup land as an Internal user instead of Portal: set
|
|
template_user_id on the OAuth provider to this record to opt in. -->
|
|
<record id="template_internal_user_id" model="res.users">
|
|
<field name="name">SSO Internal User Template</field>
|
|
<field name="login">sso_internal_template</field>
|
|
<field name="active" eval="False"/>
|
|
<field name="groups_id" eval="[Command.set([ref('base.group_user')])]"/>
|
|
<field name="signature"/>
|
|
</record>
|
|
</odoo>
|