Odoo includes a login cooldown mechanism to help protect user accounts against repeated failed login attempts. By configuring the relevant system parameters, administrators can control when login attempts are temporarily blocked and how long users must wait before trying again.
This feature is available in Odoo versions 13 and later, depending on the version and installed modules.
Why Is This Feature Useful?
Configuring login cooldown settings helps administrators:
- Improve security: Reduce the risk of automated password-guessing attacks.
- Prevent repeated login attempts: Temporarily restrict login attempts after a specified threshold.
- Control the waiting period: Define how long users must wait before attempting to log in again.
- Protect user accounts: Add an extra layer of protection against suspicious login activity.
How to Configure Login Cooldown in Odoo
Follow these steps to configure the login cooldown settings.
Step 1: Enable Developer Mode
Open Settings and activate Developer Mode to access the technical configuration options.
Step 2: Open System Parameters
Navigate to:
Settings → Technical → Parameters → System Parameters
Step 3: Configure the Login Cooldown Parameters
Search for the following system parameters:
1. base.login_cooldown_after
This parameter controls the failed-login threshold after which the cooldown mechanism is triggered.
Enter the desired threshold according to your security requirements.
2. base.login_cooldown_duration
This parameter controls the cooldown duration — how long the login mechanism waits before allowing further attempts.
Enter the required duration in the unit expected by your Odoo version and implementation.
Step 4: Save and Test
Save the parameter values and test the login behavior with repeated failed attempts in a controlled environment.
Example Configuration
Suppose you configure the following values:
base.login_cooldown_after:5base.login_cooldown_duration:300
In an implementation where the threshold represents five failed attempts and the duration is measured in seconds, the cooldown would be triggered after the configured threshold, with a waiting period of 300 seconds (5 minutes).
Key Takeaway
Odoo’s login cooldown settings help administrators manage repeated failed login attempts and strengthen account security. By configuring base.login_cooldown_after and base.login_cooldown_duration, you can tailor the login protection mechanism to your organization’s requirements.