Skip to Content
Odoo Meniu
  • Autentificare
  • Try it free
  • Aplicații
    Finanțe
    • Contabilitate
    • Facturare
    • Cheltuieli
    • Spreadsheet (BI)
    • Documente
    • Semn
    Vânzări
    • CRM
    • Vânzări
    • POS Shop
    • POS Restaurant
    • Abonamente
    • Închiriere
    Site-uri web
    • Constructor de site-uri
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Lanț Aprovizionare
    • Inventar
    • Producție
    • PLM
    • Achiziție
    • Maintenance
    • Calitate
    Resurse Umane
    • Angajați
    • Recrutare
    • Time Off
    • Evaluări
    • Referințe
    • Flotă
    Marketing
    • Social Marketing
    • Marketing prin email
    • SMS Marketing
    • Evenimente
    • Automatizare marketing
    • Sondaje
    Servicii
    • Proiect
    • Foi de pontaj
    • Servicii de teren
    • Centru de asistență
    • Planificare
    • Programări
    Productivitate
    • Discuss
    • Aprobări
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Aplicații Terțe Odoo Studio Platforma Odoo Cloud
  • Industrii
    Retail
    • Book Store
    • Magazin de îmbrăcăminte
    • Magazin de Mobilă
    • Magazin alimentar
    • Magazin de materiale de construcții
    • Magazin de jucării
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Distribuitor de băuturi
    • Hotel
    Proprietate imobiliara
    • Real Estate Agency
    • Firmă de Arhitectură
    • Construcție
    • Estate Managament
    • Grădinărit
    • Asociația Proprietarilor de Proprietăți
    Consultanta
    • Firma de Contabilitate
    • Partener Odoo
    • Agenție de marketing
    • Law firm
    • Atragere de talente
    • Audit & Certification
    Producție
    • Textil
    • Metal
    • Mobilier
    • Mâncare
    • Brewery
    • Cadouri corporate
    Health & Fitness
    • Club Sportiv
    • Magazin de ochelari
    • Centru de Fitness
    • Wellness Practitioners
    • Farmacie
    • Salon de coafură
    Trades
    • Handyman
    • IT Hardware and Support
    • Asigurare socială de stat
    • Cizmar
    • Servicii de curățenie
    • HVAC Services
    Altele
    • Organizație nonprofit
    • Agenție de Mediu
    • Închiriere panouri publicitare
    • Fotografie
    • Închiriere biciclete
    • Asigurare socială
    Browse all Industries
  • Comunitate
    Învăță
    • Tutorials
    • Documentație
    • Certificări
    • Instruire
    • Blog
    • Podcast
    Empower Education
    • Program Educațional
    • Scale Up! Business Game
    • Visit Odoo
    Obține Software-ul
    • Descărcare
    • Compară Edițiile
    • Lansări
    Colaborați
    • Github
    • Forum
    • Evenimente
    • Translations
    • Devino Partener
    • Services for Partners
    • Înregistrează-ți Firma de Contabilitate
    Obține Servicii
    • Găsește un Partener
    • Găsiți un contabil
    • Meet an advisor
    • Servicii de Implementare
    • Referințe ale clienților
    • Suport
    • Actualizări
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Obține un demo
  • Prețuri
  • Ajutor

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Contabilitate
  • Inventar
  • PoS
  • Proiect
  • MRP
All apps
Trebuie să fiți înregistrat pentru a interacționa cu comunitatea.
All Posts Oameni Insigne
Etichete (View all)
odoo accounting v14 pos v15
Despre acest forum
Trebuie să fiți înregistrat pentru a interacționa cu comunitatea.
All Posts Oameni Insigne
Etichete (View all)
odoo accounting v14 pos v15
Despre acest forum
Suport

Problem with security and ir_attachment

Abonare

Primiți o notificare când există activitate la acestă postare

Această întrebare a fost marcată
securityir_attachmentwebsite
4 Răspunsuri
21180 Vizualizări
Imagine profil
Evans Bernier

Hello,

I created a website module that can access at some attachments. I create a security group for my module and gave reading access to ir_attachment model. The user of this module can only access frontend. When I try to show attribute of an attachment from ir_attachment, I got a "500: Internal Server Error". In log, I can see the following error message

File "/var/www/odoo8/server/openerp/addons/base/ir/ir_attachment.py", line 259, in check

    raise except_orm(_('Access Denied'), _("Sorry, you are not allowed to access this document."))

I looked in security and my security group have access to the model. Why I get this error message?

If the user have at least access to backend, I can access ir_attachment, but not if the user have only access frontend.

Thanks


2
Imagine profil
Abandonează
Imagine profil
Rihards Novožilovs
Cel mai bun răspuns

You can use sudo

obj = request.env['ir.attachment'].sudo().search([('name', '=', 'test')])

0
Imagine profil
Abandonează
Imagine profil
Axel Mendoza
Cel mai bun răspuns

Hi Evans Bernier

The issue is related that the ir.attachment model has an override of the check method to add extra security checks and the particular one that you are hitting is that the user that you are using doesn't have the group Employee that it's not an HR security group, it's a base group assigned by default to pretty much all the users created, seems that your user was created using the signup feature of Odoo that use the Public User as a template and that way the new users does not get the Employee group since the template user doesn't have it neither. You could find the Employee group in the Human Resources group selection field in the user form, where all of the other values for that selection field are groups that inherit from the Employee group. You could also put your new group to inherit from the Employee group (ID is base.group_user) or manually add that group to the user and you will be ok


*** Update ***

The easiest way to solve that without giving aditional permissions to your users is doing this:


from openerp import models

class ir_attachment_check(models.Model)

_inherit = 'ir.attachment'

def check(self, cr, uid, ids, mode, context=None, values=None):

res_ids = {}

if ids:

if isinstance(ids, (int, long)):

ids = [ids]

cr.execute('SELECT DISTINCT res_model, res_id, create_uid FROM ir_attachment WHERE id = ANY (%s)', (ids,))

for rmod, rid, create_uid in cr.fetchall():

if not (rmod and rid):

continue

res_ids.setdefault(rmod,set()).add(rid)

if values:

if values.get('res_model') and values.get('res_id'):

res_ids.setdefault(values['res_model'],set()).add(values['res_id'])

ima = self.pool.get('ir.model.access')

for model, mids in res_ids.items():

# ignore attachments that are not attached to a resource anymore when checking access rights

# (resource was deleted but attachment was not)

if not self.pool.get(model):

continue

existing_ids = self.pool[model].exists(cr, uid, mids)

ima.check(cr, uid, model, mode)

self.pool[model].check_access_rule(cr, uid, existing_ids, mode, context=context)

Just override the check method to remove the code that checks for the Employee  group in the user

3
Imagine profil
Abandonează
Evans Bernier
Autor

Hi Axel,

Thanks a lot for the explanation. I don't want to give access to backend to these users. How can I give that rights without giving the backend access?

Thanks,

Axel Mendoza

See my answer update for how to do it and don't forget to upvote and accept the answer if you find it useful

paidy kumar

hi sir i have also same issue i am using odoo 12v...but i am not able to migrate this code to v12 .can you help me please i am new to odoo.

Imagine profil
Alexey Moujeer
Cel mai bun răspuns

I scratched my head for quite some time over this error when I tried to make some attachments accessible from a public website (read only). In odoo10 - and I don't know about earlier versions - setting the "public" field on the attachment to True makes the check method bypass the aforementioned security check in read mode.

2
Imagine profil
Abandonează
Simon Capriles

This avoids changes in the code and in the user's access rights.
Definitely should check this before anything

Imagine profil
Evans Bernier
Autor Cel mai bun răspuns

Thanks Axel, that's work fine. I wasn't know about the extra security checks of that model.

0
Imagine profil
Abandonează
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Înscrie-te
Related Posts Răspunsuri Vizualizări Activitate
How to restrict access for static pages?
security website webpage
Imagine profil
Imagine profil
1
sept. 21
5752
After new user created his account add a validation step to accept or decline his entry
security accounts website
Imagine profil
0
iun. 20
3200
Webpage for specific users
security access website
Imagine profil
Imagine profil
1
nov. 18
5914
UPDATED: Anonymous User requests for (404) Not Found URLs triggers deletion of critical website files - what code in Odoo v9 could be causing this deletion to occur due? Rezolvat
security website_builder website
Imagine profil
Imagine profil
6
feb. 16
12328
SecurityError and Javascript error after activating website module
security javascript website_builder website
Imagine profil
0
mar. 25
2320
Comunitate
  • Tutorials
  • Documentație
  • Forum
Open Source
  • Descărcare
  • Github
  • Runbot
  • Translations
Servicii
  • Hosting Odoo.sh
  • Suport
  • Actualizare
  • Custom Developments
  • Educație
  • Găsiți un contabil
  • Găsește un Partener
  • Devino Partener
Despre Noi
  • Compania noastră
  • Active de marcă
  • Contactați-ne
  • Locuri de muncă
  • Evenimente
  • Podcast
  • Blog
  • Clienți
  • Aspecte juridice • Confidențialitate
  • Securitate
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo este o suită de aplicații de afaceri open source care acoperă toate nevoile companiei dvs.: CRM, comerț electronic, contabilitate, inventar, punct de vânzare, management de proiect etc.

Propunerea de valoare unică a Odoo este să fie în același timp foarte ușor de utilizat și complet integrat.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now