Skip to Content
Odoo Menu
  • Sign in
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Approvals
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Property Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
      • Get a Tailored Demo
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +32 2 290 34 90
    • Get a Tailored Demo
  • Pricing
  • Help
  1. APPS
  2. Website
  3. Website User Email Verification & OTP Security v 19.0
  4. Sales Conditions FAQ

Website User Email Verification & OTP Security

by Hi Spark Solutions https://www.hisparksolutions.com/
Odoo

$ 57.81

v 19.0 Third Party
Apps purchases are linked to your Odoo account, please sign in or sign up first.
Availability
Odoo Online
Odoo.sh
On Premise
Odoo Apps Dependencies • Discuss (mail)
• Website (website)
Lines of code 452
Technical Name hispark_email_verification
LicenseOPL-1
Websitehttps://www.hisparksolutions.com/
Versions 16.0 17.0 18.0 19.0
You bought this module and need support? Click here!
Availability
Odoo Online
Odoo.sh
On Premise
Odoo Apps Dependencies • Discuss (mail)
• Website (website)
Lines of code 452
Technical Name hispark_email_verification
LicenseOPL-1
Websitehttps://www.hisparksolutions.com/
Versions 16.0 17.0 18.0 19.0
  • Description
  • License
   
⬡ Odoo Website Security Module

Hi Spark — Email Verification
& OTP Security

Block unverified portal users before they access your platform. Dual-mode authentication — OTP code or secure link — with SHA-256 hashing, configurable attempt limits, and a 60-second resend cooldown built in.

✦ OTP Verification ✦ Verification Link ✦ SHA-256 Hashed ✦ Attempt Limiting ✦ Portal Only ✦ Odoo Enterprise
2
Auth Modes
SHA-256
OTP Hashing
60s
Resend Cooldown
24h
Default Expiry

Verification Architecture

Complete Authentication Flow

Every path from signup through login to verified access — OTP and link modes end to end.

User visits /signup or /web/login
▼
Standard
Odoo Login
disabled
NO ◄
Verification
Enabled?
► YES  
▼
Generate 6-digit OTP
secrets.randbelow() → SHA-256 hash stored
Set expiry + reset attempt=0 on user record
▼
Verification Mode?
OTP   |   LINK
◄ OTP PATH
Email: OTP Code
6-digit code sent
▼
/web/verify/otp
GET: show form · POST: submit
▼
Expired or Max Attempts?
YES → Error Page
Expired / Max attempts
▼ NO
Hash Match?
NO → attempt++
Re-render + error
▼ YES → verified=True
LINK PATH ►
Email: Verify Link
?code=raw_otp
▼
/web/verify/link
GET: auto-validate code param
▼
Expired or No Hash?
YES → Error Page
Link expired / invalid
▼ NO
Hash Match?
NO → Invalid Link
Re-render page
▼ YES → verified=True
↺ Error pages → Resend /web/resend/otp → 60s cooldown enforced
▼
✓ Redirect → /web/login?message=Account verified successfully
Session cleared · otp_hash / otp_expiry / otp_attempt reset on user record

What's Inside

Designed Around Real Security

Every feature exists because of a real threat model — not checkbox compliance.

🔐

SHA-256 Hashed OTP Storage

The raw 6-digit code is never persisted. Only its SHA-256 hash is stored — plaintext is gone the moment it's sent.

📧

Dual Verification Modes

OTP (user types a 6-digit code) or Link (user clicks a tokenised URL). Both share the same secret — switchable without code changes.

⏱

Configurable Expiry Window

Both OTPs and links expire after a configurable number of hours (default 24h). Controlled via Validation Expiration (Hrs) in Website Settings.

🛡

Attempt-Based Blocking

Wrong OTP submissions increment a per-user counter. When the configured maximum is hit (default 3), the user is blocked to the error/resend page.

⌛

60-Second Resend Cooldown

The resend route checks otp_last_sent on the user record. Requests within 60 seconds are rejected, preventing OTP-flood attacks.

🔄

Intercepts Signup & Login

New users caught at /web/signup. Existing unverified portal users intercepted at /web/login post-auth and sent through the same flow.

👤

Portal-Only Enforcement

System/admin users bypass verification entirely via _is_system(), keeping your Odoo backend operations completely unaffected.

⚙️

Enable / Disable Toggle

Set to OTP, Link, or Disable from Website → Configuration → Settings. When re-enabled, all unverified users must verify on next login.

🛠

Admin Manual Verification

Administrators can flip verified = True directly from the backend user form — no email flow required — for edge cases or support.

✉️

Branded Email Templates

One mail.template powers both modes — OTP block or link button. Company logo, name, phone, and email auto-populated via QWeb.

🎨

Theme-Compatible UI

All verification pages extend web.login_layout, inheriting your active Odoo website theme. No custom CSS overrides required.

🤖

Anti-Bot Registration

Automated signups that don't control the registered inbox are silently dead — they complete the form but can never complete verification.

Step by Step

Six Steps to Verified Access

From form submission to confirmed identity — the complete user journey.

01

User Submits Signup or Login

The module intercepts the POST request before Odoo grants session access. Credentials are validated by the parent controller first.

02

OTP Generated & Hashed

A cryptographically secure 6-digit code via secrets.randbelow(). SHA-256 hash, expiry, and attempt counter written to the user record.

03

Verification Email Sent

Email shows OTP code in a styled box, or a tokenised verification button. Company branding applied automatically via QWeb.

04

User Verifies Their Identity

OTP mode: user enters the 6-digit code. Link mode: user clicks the button. Both routes check expiry and attempt count first.

05

Hash Comparison & Outcome

Submitted value hashed and compared to stored hash. Match → verified=True. No match → otp_attempt++, error shown.

06

Redirect to Login

On success, redirected to /web/login with confirmation message. Session email cleared. Account permanently marked verified.

Admin Configuration

Three Settings. Total Control.

Website → Configuration → Settings. Stored as Odoo system parameters.

Setting Options Default Behaviour
Signup Verification Method OTP Verification Link Verification Disable OTP Controls verification path for all new signups and existing unverified logins. Disable removes all verification gates.
OTP Allow Failed Attempts Integer 3 Max wrong OTP submissions before the user is blocked to the error/resend page. Visible only when OTP mode is selected.
Validation Expiration (Hrs) Integer (hours) 24 How long an OTP or verification link stays valid after generation. Hidden when mode is set to Disable.

Screenshots

See It in Action

Tested and verified on Odoo Enterprise Edition.

●  Configuration Setup
●  OTP Verification Screen
●  OTP Email Template — branded, company logo auto-populated
●  Email Verification Link — one-click confirmation
●  Attempt Limit & Error Screen
✓ Tested and verified on Odoo Enterprise Edition
   

Hi Spark Solutions

Our Services

End-to-end Odoo expertise — from implementation to ongoing support.


Customization Integration Installation
Odoo Training & Consulting Migration Support

Get In Touch


For any query or support contact us without hesitation on Visit Website Contact Form


support@hisparksolutions.com | Contact Support

Odoo Proprietary License v1.0

This software and associated files (the "Software") may only be used (executed,
modified, executed after modifications) if you have purchased a valid license
from the authors, typically via Odoo Apps, or if you have received a written
agreement from the authors of the Software (see the COPYRIGHT file).

You may develop Odoo modules that use the Software as a library (typically
by depending on it, importing it and using its resources), but without copying
any source code or material from the Software. You may distribute those
modules under the license of your choice, provided that this license is
compatible with the terms of the Odoo Proprietary License (For example:
LGPL, MIT, or proprietary licenses similar to this one).

It is forbidden to publish, distribute, sublicense, or sell copies of the Software
or modified copies of the Software.

The above copyright notice and this permission notice must be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.
IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,
DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
DEALINGS IN THE SOFTWARE.

Please log in to comment on this module

  • The author can leave a single reply to each comment.
  • This section is meant to ask simple questions or leave a rating. Every report of a problem experienced while using the module should be addressed to the author directly (refer to the following point).
  • If you want to start a discussion with the author or have a question related to your purchase, please use the support page.
Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with