| Availability |
Odoo Online
Odoo.sh
On Premise
|
| Odoo Apps Dependencies |
Discuss (mail)
|
| Lines of code | 1024 |
| Technical Name |
gb_login_access_audit_session_monitor |
| License | OPL-1 |
| Website | https://gencbaris.com/odoo_plugins/ |
| Versions | 18.0 19.0 |
| Availability |
Odoo Online
Odoo.sh
On Premise
|
| Odoo Apps Dependencies |
Discuss (mail)
|
| Lines of code | 1024 |
| Technical Name |
gb_login_access_audit_session_monitor |
| License | OPL-1 |
| Website | https://gencbaris.com/odoo_plugins/ |
| Versions | 18.0 19.0 |
Login & Access Audit / Se
Failed-login alerts, active session monitor, force-logout and geo anomaly detection
Standard Odoo gives administrators almost no visibility into who is signing in, from where, or what happens when access fails. This app hooks directly into Odoo's authentication path to record every success and failure, throttle brute-force sources, track live sessions and flag logins from unexpected countries — the kind of access-control audit trail UK organisations need for Cyber Essentials, ISO 27001 and internal security reviews. No third-party SIEM or external service is contacted; all data stays in your database.
Key Features
Full Login Event Log
Every sign-in success and failure is captured with login, user, result, IP address, user agent/device, resolved country and timestamp — indexed and searchable for audit and incident response.
Brute-Force Lockout
After a configurable number of failures inside a time window, the source login/IP is blocked for a set duration. Blocks expire automatically via cron, and security managers are emailed on lockout.
Active Session Register
A live register of authenticated sessions per user with IP, device, login time, last-seen and duration. Force-logout a single session or every session of a user with a recorded reason.
Geo-Anomaly Detection
An IP-range table resolves logins to countries; when a user signs in from a country they have never used — or two distant countries in a short window — the event is flagged anomalous and escalated.
Daily Security Digest
A scheduled cron summarises the day's failures, new locations and locked sources and emails it to your alert group, so nothing slips through unnoticed.
Configurable & Self-Cleaning
Tune failure thresholds, windows, block duration and notification toggles per company. Stale sessions auto-close and old events purge on a retention schedule.
Nothing Like It Native
Core Odoo offers no session register, no lockout, no geo-anomaly flagging and no login audit log. This adds all four as one application.
Audit-Ready & Self-Hosted
Designed to produce the access-control evidence assessors ask for — with no external service, so your authentication data never leaves your server.
Screenshots
Settings
Force Logout
Ip Country Ranges
Lockouts
Login Events
Active Sessions
Why Choose This Module
Administrators and security/compliance teams running multi-user Odoo deployments; UK businesses pursuing Cyber Essentials or ISO 27001; managed-service providers needing tenant-level login visibility; and any organisation that must prove who accessed the system and from where.
Specifications
- Compatible: Odoo 18.0 / 19.0
- License: LGPL-3
- Languages: 35+
- Author: Baris Genc
- Dependencies: base, mail
- Support: odoo@gencbaris.com
Odoo Proprietary License v1.0 This software and associated files (the "Software") may only be used (executed, modified, executed after modifications) if you have purchased a valid license from the authors, typically via Odoo Apps, or if you have received a written agreement from the authors of the Software (see the COPYRIGHT file). You may develop Odoo modules that use the Software as a library (typically by depending on it, importing it and using its resources), but without copying any source code or material from the Software. You may distribute those modules under the license of your choice, provided that this license is compatible with the terms of the Odoo Proprietary License (For example: LGPL, MIT, or proprietary licenses similar to this one). It is forbidden to publish, distribute, sublicense, or sell copies of the Software or modified copies of the Software. The above copyright notice and this permission notice must be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Please log in to comment on this module