Skip to Content
Odoo Menu
  • Sign in
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Approvals
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Estate Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
    • Meet an advisor
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Get a demo
  • Pricing
  • Help

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Accounting
  • Inventory
  • PoS
  • Project
  • MRP
All apps
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
Help

securing /web/database/manager

Subscribe

Get notified when there's activity on this post

This question has been flagged
2 Replies
22014 Views
Avatar
David Ogles

Odoo 10 enterprise, unbuntu 16.04LTS, and nginx.

I've added the following code to the server block, but it is still allowing access to /web/database/manager.  I've tried the dbrestrict addon, but it doesn't accept any password that i've set, which I assume is because it is set for odoo 8.  I like that option better than the location restriction.

server {

   listen 80;

   listen [::]:80;

   server_name completerespite.com www.completerespite.com;

   rewrite ^(.*) https://$host$1 permanent;

location ~ ^/web/database/(manager|selector) {

                allow 1.2.3.4;

                deny all;

}

}


What am I doing wrong.  Spend the past day going through every google return, odoo forum, and nginx forum.


thanks,

Dave

0
Avatar
Discard
Avatar
Fatih Piristine
Best Answer

here is on option with auth basic. that is what i use. each location you want to handle with restriction needs to enclosed in "location /". other locations can be outside for setting headers etc etc.

I did search the same thing long ago but made own solution for it.


server {
    listen 80;
    server_name completerespite.com;
    return 301 http://www.completerespite.com$request_uri;
}
server {
    listen 80;
    server_name www.completerespite.com;
    # --------------------------------------------------------------------------
    # Locations
    # --------------------------------------------------------------------------
    location / {
        proxy_pass http://yourdomain;
        # set headers
        # ...
        location ~ /web/database/manager {
            auth_basic "Restricted Access";
            auth_basic_user_file auth/domain_auth;
            proxy_pass http://yourdomain;
            # set headers
            # ...
        }
        location ~ /web/database/selector {
            auth_basic "Restricted Access";
            auth_basic_user_file auth/domain_auth;
            proxy_pass http://yourdomain;
            # set headers
            # ...
        }
    }
}


send images, etc without cookies header... same level with 'location /' like mentioned above. handles the multilang paths!

location ~* /web/static/ {
        access_log off;
        log_not_found off;
        expires 10d;
        proxy_cache_valid 200 60m;
        proxy_buffering on;
        proxy_hide_header Set-Cookie;
        proxy_ignore_headers Set-Cookie;
        proxy_pass http://hexon_fi;
    }


2
Avatar
Discard
Avatar
David Ogles
Author Best Answer

Thanks that did the trick.  I was having issues with the proxy_pass, but got all of that worked out.  I sure appreciate the help.


Dave

0
Avatar
Discard
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Sign up
Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now