Skip to Content
Odoo Menu
  • Sign in
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Approvals
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Estate Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
    • Meet an advisor
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Get a demo
  • Pricing
  • Help

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Accounting
  • Inventory
  • PoS
  • Project
  • MRP
All apps
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
Help

How to restrict modification for some user

Subscribe

Get notified when there's activity on this post

This question has been flagged
securityrightsrestrictaccess_rulesodooV8
2 Replies
10954 Views
Avatar
Dewilde Valentin

I have a module that store the publication of a group of person and i want to restrict the "write" permission for the person who create the publication.


Here is my situation :

-Publications must be creatable and readable for all user

-Publications must be editable just for the one who create it

-Publication must be manageable (read, write, create and delete) for member of a group.


I made some research and it seem that restrict on user who don't have a group is a bit difficult. Well is there a way i didn't see ?

Thanks

1
Avatar
Discard
Avatar
Brett Lehrer
Best Answer

You can accomplish this by inheriting the write() function of the publication model.  Give everyone write access initially, then restrict it back down if they're not the creator or in the management group.  I'll assume your module is called "publication_module" and the publications model itself is named "my.publication".

First, you'll need a management group defined:

 <record id="group_publication_manager" model="res.groups">
    <field name="name">Publication Manager</field>
    <field name="users" eval="[(4, ref('base.user_root'))]"/>
</record>

By default, I'm assuming that the built-in "admin" user (uid=1) is a Publication Manager.

Your ir.model.access.csv file would include lines for model_my_publication for general users and for managers:

id,name,model_id:id,group_id:id,perm_read,perm_write,perm_create,perm_unlink
security_publication_user,security.publication.user,model_my_publication,base.group_user,1,1,1,0
security_publication_manager,security.publication.manager,model_my_publication,publication_module.group_publication_manager,1,1,1,1

Finally, the inherited write() function.  If the user isn't a member of the management group, check if there are any records among the ones they're attempting to edit that were created by a different user, and raise an error if any are found:

 def write(self, cr, uid, ids, values, context=None):
    """User must be a member of the management group or the creator of the publication to edit it"""
    if context is None: context = {}
    if not self.pool['res.users'].has_group(cr, uid, 'publication_module.group_publication_manager'):
        # Find any instances of the current user not being the creator of the given ids
        cr.execute("""select 1
                from my_publication
                where id in %s and create_uid <> %s""", (tuple(ids), uid,))
        if bool(cr.fetchone()):
            raise orm.except_orm("Error", "You can only edit your own publications!")
    return super(my_publication, self).write(cr, uid, ids, values, context=context)


2
Avatar
Discard
Avatar
Dewilde Valentin
Author Best Answer

Sorry for the late response.


Thank you, your solution work absolutely fine. I work with the new api (v8) so i make some modification about your implementation but its exactely the same. I give your solution in the new api for people who want to know how to do this :


@api.one
def write(self, vals):
	# Check if user is not member of management's group
	if not self.env['res.users'].has_group(
                'publication_module.group_publication_manager'): # Test if user is not the creator # (and if the template is in edit mode) if self.create_uid and not (self.env.uid==self.create_uid.id): raise exceptions.ValidationError( _("You don't have the permission to edit this template")) indicator = super(Indicator, self).write(vals) return indicator

0
Avatar
Discard
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Sign up
Related Posts Replies Views Activity
Security rights model within OdooV8
security edit forms rights odooV8
Avatar
0
Jan 16
3474
Is it possible to restrict access to certain warehouses based on username/login?
security access_rules
Avatar
Avatar
1
Jan 17
3859
Give access to odoo model in access controls list give "No matching record found for external id" Solved
security access_rules
Avatar
Avatar
1
Jul 16
8395
superuser rights for another user
security access_rules
Avatar
Avatar
Avatar
3
Dec 23
22626
Access Rules in odoo 8
access_rules odooV8
Avatar
Avatar
1
May 15
6284
Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now