Odoo is the world's easiest all-in-one management software. It includes hundreds of business apps:
CRM | e-Commerce | Accounting | Inventory | PoS | Project management | MRP | etc.
This is a serious security concern, defining group access rights on menu items is not enough to restrict access to
How do you protect against this ? someone could just try action ids one by one until they find an existing action that gives him/her access to potentially private information.
I restricted access to a window action to a specific group, but I was still able to see it with a user that doesn't belong to that group.
Edit: The same goes for views, when I define access rights, they don't work, I can still access them from other groups.
Is this a bug? or am I missing something?
Using groups to hide or give access to menus is more related to the needs of ergonomics or usability than the needs of security. It is a best practice to putting rules on documents and models instead of putting groups on menus. For example, hiding invoices can be done by modifying the record rule on the invoice object, and it is more efficient and safer than hiding menus related to invoices.
Similarly, using groups to hide or give access to views based on groups should also not be considered as meeting security needs.
From "Security in OpenERP: users, groups" at https://doc.openerp.com/trunk/server/04_security/
About This Community
This platform is for beginners and experts willing to share their Odoo knowledge. It's not a forum to discuss ideas, but a knowledge base of questions and their answers.Register
Odoo Training Center
Access to our E-learning platform and experience all Odoo Apps through learning videos, exercises and Quizz.Test it now
|Asked: 12/26/13, 2:59 PM|
|Seen: 2234 times|
|Last updated: 3/16/15, 8:10 AM|