No description
Find a file
Mathieu Benoit 22d30a1504 [FIX] security: redact the master password from every output
CodeQL raised seven high-severity alerts on this branch. Three were real,
and the same secret was behind all of them: the Odoo master password,
which db_restore appends to its command line as soon as the database
declares one.

The command itself was printed raw -- "print(arg)" -- so the password
reached stdout, and any terminal capture with it. The probe output was
logged raw too, and a refused attempt echoes the command it tried.

Wider than that: the runner filtered the command it was about to run, but
not what came back. A tool that reprints its own arguments -- "set -x", a
traceback, odoo_bin.sh -- put the secret straight back into the terminal
AND into the log file the sink writes. Every subprocess line now goes
through the same filter as the command.

The four remaining alerts sit on expressions already wrapped in
redact_secrets(). CodeQL does not cross re.sub, so it cannot see the
barrier; the mitigation is real and they are false positives.

--- FR ---

CodeQL a levé sept alertes de sévérité haute sur cette branche. Trois
étaient réelles, et le même secret était derrière : le mot de passe maître
d'Odoo, que db_restore ajoute à sa ligne de commande dès que la base en
exige un.

La commande elle-même était imprimée telle quelle — « print(arg) » — donc
le mot de passe atteignait la sortie standard, et toute capture de
terminal avec elle. La sortie de la sonde était journalisée brute
également, et un essai refusé réaffiche la commande tentée.

Plus large : le lanceur filtrait la commande qu'il allait exécuter, mais
pas ce qui en revenait. Un outil qui réaffiche ses propres arguments —
« set -x », une trace, odoo_bin.sh — remettait le secret dans le terminal
ET dans le fichier de journal. Chaque ligne du sous-processus passe
désormais par le même filtre que la commande.

Les quatre alertes restantes portent sur des expressions déjà entourées de
redact_secrets(). CodeQL ne franchit pas re.sub et ne voit donc pas la
barrière ; la mitigation est réelle, ce sont des faux positifs.

Assisted-by: Claude Opus 5
2026-08-23 02:11:50 -04:00
.claude [ADD] make: une cible pour les tests unitaires, dépendance mobile déclarée 2026-08-23 02:11:50 -04:00
.github Update issue templates 2026-03-08 16:05:48 -04:00
conf [ADD] make: une cible pour les tests unitaires, dépendance mobile déclarée 2026-08-23 02:11:50 -04:00
contracts [ADD] contracts: add Odoo sync API contract and note mapping 2026-08-07 01:05:37 -04:00
doc [UPD] support: drop Ubuntu 20.04/22.04, add AlmaLinux and Rocky 2026-08-16 23:33:49 -04:00
docker [ADD] test: what the tooling imports must be declared 2026-08-17 00:40:01 -04:00
manifest [FIX] todo qemu: find the APK where AGP writes it, and install it as it is 2026-08-23 02:07:42 -04:00
mobile [ADD] make: une cible pour les tests unitaires, dépendance mobile déclarée 2026-08-23 02:11:50 -04:00
private [ADD] migration: see and repair the website COW views 2026-08-10 03:10:50 -04:00
requirement [ADD] migration state: colour the commands, and know when not to 2026-08-22 07:23:59 -04:00
script [FIX] security: redact the master password from every output 2026-08-23 02:11:50 -04:00
test [FIX] install : compiler pykcs11 avec SWIG 4.3 et au-delà 2026-08-23 02:11:50 -04:00
.editorconfig [UPD] format with script format.sh 2023-12-02 14:14:23 -05:00
.erplibre-semver-version [IMP] support multi version odoo on same workspace 2025-10-31 01:36:26 -04:00
.flake8 [ADD] maintainer-tools to autopep8, flake8 and pylint-odoo 2021-06-27 00:36:52 -04:00
.gitignore [UPD] mobile rename repo for erplibre_home_mobile 2025-12-28 00:48:38 -05:00
.prettierignore [ADD] makefile: prettier format code_generator 2023-01-01 02:59:33 -05:00
AI_POLICY.base.md [ADD] doc: adopt the OCA generative AI policy 2026-08-07 01:16:20 -04:00
AI_POLICY.fr.md [ADD] doc: adopt the OCA generative AI policy 2026-08-07 01:16:20 -04:00
AI_POLICY.md [ADD] doc: adopt the OCA generative AI policy 2026-08-07 01:16:20 -04:00
CHANGELOG.base.md [UPD] changelog: the migration work of this cycle 2026-08-22 07:23:59 -04:00
CHANGELOG.fr.md [UPD] changelog: the migration work of this cycle 2026-08-22 07:23:59 -04:00
CHANGELOG.md [UPD] changelog: the migration work of this cycle 2026-08-22 07:23:59 -04:00
CLAUDE.md [REF] claude: trim the always-loaded guidance, and fix what it got wrong 2026-08-07 01:15:33 -04:00
coverage_run.sh [IMP] refactoring to support multiple version of Odoo 2025-10-31 01:32:11 -04:00
docker-compose-dev.yml [ADD] docker : new hierchical layout 2020-09-30 20:52:04 -04:00
docker-compose.yml [UPD] docker odoo 18 2026-02-05 02:07:47 -05:00
env_var.sh [ADD] install: uv to place Python packages, pip as fallback 2026-08-16 23:33:49 -04:00
install.sh [IMP] refactoring .venv.erplibre 2025-10-31 01:34:26 -04:00
LICENSE Initial commit 2020-04-12 21:20:13 -04:00
Makefile [FIX] script todo: configurer le projet PyCharm avec le venv, et réessayer 2026-08-23 02:07:42 -04:00
odoo_bin.sh [IMP] refactoring .venv.erplibre 2025-10-31 01:34:26 -04:00
package-lock.json [UPD] change 1.5.0 to 1.6.0 2025-04-25 23:25:43 -04:00
package.json [UPD] change 1.5.0 to 1.6.0 2025-04-25 23:25:43 -04:00
poetry.toml [UPD] poetry: version 1.1.12 2022-01-24 17:56:10 -05:00
README.base.md [UPD] readme: the platforms we actually support 2026-08-17 01:01:50 -04:00
README.fr.md [UPD] readme: the platforms we actually support 2026-08-17 01:01:50 -04:00
README.md [UPD] readme: the platforms we actually support 2026-08-17 01:01:50 -04:00
run.sh [IMP] refactoring .venv.erplibre 2025-10-31 01:34:26 -04:00
source_repo_addons.csv [ADD] repo JayVora-SerpentCS SerpentCS_Contributions 2024-05-03 23:27:06 -04:00
test.sh [IMP] support multi version odoo on same workspace 2025-10-31 01:36:26 -04:00
TODO.base.md [ADD] Multilingual translation of all documentation (EN/FR) 2026-03-04 22:23:52 -05:00
TODO.fr.md [ADD] Multilingual translation of all documentation (EN/FR) 2026-03-04 22:23:52 -05:00
TODO.md [ADD] Multilingual translation of all documentation (EN/FR) 2026-03-04 22:23:52 -05:00

ERPLibre

ERPLibre is a CRM/ERP platform including automated installation, maintenance, and development of open source modules of the Odoo community version. It is a "soft-fork" of the Odoo Community Edition (OCE), meaning it aims at contributing back upstream. It is based on a set of production-ready modules, supported by the Odoo Community Association (OCA) and an ecosystem of specialized companies. This solution ensures digital sovereignty in a local environment while integrating pre-trained Generative Transformers (GPT), bringing an additional dimension to data management and automation.

Follow us on Mastodon : https://fosstodon.org/@erplibre

Features

  • Multi-version Odoo support : run Odoo 12.0, 13.0, 14.0, 15.0, 16.0, 17.0 and 18.0 in the same workspace, with independent Python virtual environments (.venv.erplibre and .venv.odooXX)
  • Interactive CLI (TODO.py) : guided interactive tool for installation, execution, database management, code formatting, mobile compilation, and more. Launch it with make
  • Code generator : generate Odoo modules automatically with support for views, portal, snippets, inheritance, i18n, and JavaScript
  • Selenium automation : web testing and automation with Selenium Grid, video recording, and login automation
  • Mobile application : ERPLibre Home Mobile (Owl + Capacitor), compiled and deployed via TODO.py
  • Docker deployment : production-ready Docker images with PostgreSQL 18 and PostGIS
  • Deployment tools : Nginx, Apache, Cloudflare DDNS, Certbot SSL, systemd services
  • Database tools : backup, restore, clone, migration between versions, production-to-dev migration
  • Performance tools : request-per-second measurement, parallel test execution, coverage analysis

Supported Odoo versions

Odoo version Python Status
18.0 3.12.10 Active
17.0 3.10.18 Inactive
16.0 3.10.18 Inactive
15.0 3.8.20 Deprecated
14.0 3.8.20 Deprecated
13.0 3.7.17 Deprecated
12.0 3.7.17 Deprecated

Switch between versions with make switch_odoo_18, make switch_odoo_16, etc.

Supported platforms

  • Ubuntu : 24.04, 25.10, 26.04 — 20.04 and 22.04 are dropped, pikepdf requiring a qpdf 12.2 built in C++20
  • Linux Mint : 22.3
  • Debian : 12 (bookworm) and 13 (trixie)
  • Fedora : 41 and later
  • AlmaLinux, Rocky Linux : 9 and 10 — RHEL and CentOS Stream take the same path
  • openSUSE : Leap 16.0 and Tumbleweed
  • Arch Linux : rolling release
  • macOS : through mise or pyenv
  • Windows : through WSL or Docker
  • Architectures : amd64, arm64 and s390x (IBM Z mainframe)

Installation in production

Easy installation on Ubuntu or Debian using Docker

This has been tested in Debian 12 and Ubuntu 24.04 LTS.

Note : This is meant for a test environment, on a local network or similar environment not directly exposed to the Internet.

  1. Make sure Docker and nginx web server are installed:
    sudo apt install docker.io docker-compose-v2 nginx

  2. Get the latest ERPLibre Docker compose file:
    wget https://raw.githubusercontent.com/ERPLibre/ERPLibre/master/docker-compose.yml

  3. Install and run ERPLibre with Docker running as a daemon (web server):
    sudo docker compose up -d

  4. Open the final installation step at this web page :
    http://[server IP]:8069/web/database/manager
    odoo_first_installation.png

  5. Finish the installation by providing a database name, email and password. then click on Create Database. Depending on your system resources this may take more than 2 minutes without feedback ! Check your browser loading indicator.

  6. Next, the web page will reload itself, and you should see the Applications list in ERPLibre:
    odoo_application_list.png

    You can now personalize your ERPLibre installation.

For more information, read Docker guide.

Install from source code

Automated installation

For Debian/Ubuntu

sudo apt install make python3

Clone the project:

git clone https://github.com/ERPLibre/ERPLibre.git
cd ERPLibre

Follow the instruction on the following script, it will try to detect your environment.

make

Manually

Into Ubuntu, minimal dependency:

sudo apt install make git curl

Into Ubuntu, developer dependency:

sudo apt install make build-essential libssl-dev zlib1g-dev libreadline-dev libsqlite3-dev curl llvm libncurses5-dev libncursesw5-dev xz-utils tk-dev liblzma-dev libbz2-dev libldap2-dev libsasl2-dev

Clone the project:

git clone https://github.com/ERPLibre/ERPLibre.git
cd ERPLibre

make install_os detects the distribution and picks the right dependency script: apt for Ubuntu, Linux Mint and Debian, dnf for Fedora and the RHEL family, zypper for openSUSE, pacman for Arch. See the supported platforms above.

make install_os
make install_odoo_18

Install a specific Odoo version:

make install_odoo_16
make install_odoo_17
make install_odoo_18

Update your configuration if you need to run from another interface than 127.0.0.1, file config.conf

xmlrpc_interface = 0.0.0.0

Show version :

make version

Ready to execute:

make run

Test

Execute ERPLibre test with his code generator.

time make test_full_fast

Documentation

Guide Description
DISCOVER Learn and explore ERPLibre
DEVELOPMENT Development environment setup
PRODUCTION Production server deployment
RUN Execution modes and use cases
CODE_GENERATOR Odoo module code generation
MIGRATION Database migration between versions
GIT_REPO Git repository management
POETRY Python dependency management
FAQ Frequently asked questions
HOWTO How-to guides
WINDOWS_INSTALLATION Windows installation

Contributing

See CONTRIBUTION.md for guidelines.

License

This project is licensed under the GNU Affero General Public License v3.0.