Skip to Content
Odoo Menu
  • Prihlásiť sa
  • Vyskúšajte zadarmo
  • Aplikácie
    Financie
    • Účtovníctvo
    • Fakturácia
    • Výdavky
    • Tabuľka (BI)
    • Dokumenty
    • Podpis
    Predaj
    • CRM
    • Predaj
    • POS Shop
    • POS Restaurant
    • Manažment odberu
    • Požičovňa
    Webstránky
    • Tvorca webstránok
    • eShop
    • Blog
    • Fórum
    • Živý chat
    • eLearning
    Supply Chain
    • Sklad
    • Výroba
    • Správa životného cyklu produktu
    • Nákup
    • Údržba
    • Manažment kvality
    Ľudské zdroje
    • Zamestnanci
    • Nábor zamestnancov
    • Voľné dni
    • Hodnotenia
    • Odporúčania
    • Vozový park
    Marketing
    • Marketing sociálnych sietí
    • Email marketing
    • SMS marketing
    • Eventy
    • Marketingová automatizácia
    • Prieskumy
    Služby
    • Projektové riadenie
    • Pracovné výkazy
    • Práca v teréne
    • Helpdesk
    • Plánovanie
    • Schôdzky
    Produktivita
    • Tímová komunikácia
    • Schvalovania
    • IoT
    • VoIP
    • Znalosti
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Priemyselné odvetvia
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Reštaurácia
    • Fast Food
    • Guest House
    • Beverage distributor
    • Hotel
    Reality
    • Real Estate Agency
    • Architecture Firm
    • Konštrukcia
    • Estate Managament
    • Gardening
    • Property Owner Association
    Poradenstvo
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Výroba
    • Textile
    • Metal
    • Furnitures
    • Jedlo
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware and Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Iní
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Komunita
    Vzdelávanie
    • Tutoriály
    • Dokumentácia
    • Certifikácie
    • Školenie
    • Blog
    • Podcast
    Empower Education
    • Vzdelávací program
    • Scale Up! Business Game
    • Visit Odoo
    Softvér
    • Stiahnuť
    • Porovnanie Community a Enterprise vierzie
    • Releases
    Spolupráca
    • Github
    • Fórum
    • Eventy
    • Preklady
    • Staň sa partnerom
    • Services for Partners
    • Register your Accounting Firm
    Služby
    • Nájdite partnera
    • Nájdite účtovníka
    • Meet an advisor
    • Implementation Services
    • Zákaznícke referencie
    • Podpora
    • Upgrades
    ​Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Získajte demo
  • Cenník
  • Pomoc

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Účtovníctvo
  • Sklady
  • PoS
  • Projektové riadenie
  • MRP
All apps
You need to be registered to interact with the community.
All Posts People Badges
Tagy (View all)
odoo accounting v14 pos v15
About this forum
You need to be registered to interact with the community.
All Posts People Badges
Tagy (View all)
odoo accounting v14 pos v15
About this forum
Pomoc

Odoo 17: Inventory User Can Modify Operation Types Without Administrator Rights

Odoberať

Get notified when there's activity on this post

This question has been flagged
2 Replies
1026 Zobrazenia
Avatar
P

Hi everyone,

I’ve encountered a potential permission issue in a fresh installation of Odoo 17 (Community Edition). I created a demo user and assigned them only the Inventory > User access level (not Administrator). However, when logged in as this user, they are still able to:

  • View and edit Operation Types (e.g., Receipts, Internal Transfers, etc.)
  • Access stock.picking.type records as a manager (Inventory / Administrator level)

From what I understand, modifying Operation Types should only be possible for users with Inventory > Administrator rights.

I’ve double-checked that the user is not in the Administrator group or granted any extra permissions beyond Inventory > User.

Has anyone else run into this issue? In picture you can see demo user with Inventory->User permission, but he still hets Inventory->Administrator event tho he is not it that group. Please help me explain why this is happening.

Thanks in advance!

0
Avatar
Zrušiť
P
Autor

I made video, showing how in clean install odoo17 this happends:


Anyone have any ideas what is going on? Even tho user demo is not in Inventory/Administrator group, it has access to stock.picking.type manager

P
Autor

https://youtu.be/0K1KiTlqrCk

Chris TRINGHAM

This does seem strange but it's hard to check from the video - we can see that the user should not be able to get access, but cannot see that they are able to get access to update Operation Types. The other missing part is to check the detailed setup of the user access groups in case something has been changed there.

P
Autor

Access right that users get's permits all access to Picking type, so he can modify all  picking time records. Question, why user get's that permission. Even tho he is not it group, that has that permission. 


Christoph Farnleitner

Unless I've misunderstood your case - I can't reproduce it in https://runbot.odoo.com (user 'demo' / password 'demo' has 'Inventory: User permission' and can't see the Inventory Configuration in menu. If the link to the Configuration page of Operation Types is known to the user s/he can see it, but still can't edit it).

Avatar
Cybrosys Techno Solutions Pvt.Ltd
Best Answer

Hi,


If you want to restrict Operation Types so only Administrators can change them:

    Override the ACL for stock.picking.type:

        Create a custom module with an updated ir.model.access.csv that:

            Removes write/create/delete for stock.group_stock_user.

            Grants full access only to stock.group_stock_manager.

            Eg:

         id,name,model_id:id,group_id:id,perm_read,perm_write,perm_create,perm_unlink

            access_stock_picking_type_user,stock.picking.type user,model_stock_picking_type,stock.group_stock_user,1,0,0,0

            access_stock_picking_type_manager,stock.picking.type manager,model_stock_picking_type,stock.group_stock_manager,1,1,1,1

    Reload your module, update security, and the user will only be able to view operation types (no editing).

What you’re seeing is not a bug, but the default Access rights in Odoo 17 Community: Inventory Users are given full access to stock.picking.type. That’s why your demo user appears to have “Administrator-like” access for operation types. If you need stricter control, you’ll need to override the access rules by creating a small custom security module.


Hope it helps

0
Avatar
Zrušiť
Avatar
D Enterprise
Best Answer

hii,

I suggest you check whether the user is also part of another group that has been given the permission, even if you have not granted the permission directly to that user — they might still be able to perform operations like edit.

0
Avatar
Zrušiť
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Registrácia
Komunita
  • Tutoriály
  • Dokumentácia
  • Fórum
Open Source
  • Stiahnuť
  • Github
  • Runbot
  • Preklady
Služby
  • Odoo.sh hosting
  • Podpora
  • Vyššia verzia
  • Custom Developments
  • Vzdelávanie
  • Nájdite účtovníka
  • Nájdite partnera
  • Staň sa partnerom
O nás
  • Naša spoločnosť
  • Majetok značky
  • Kontaktujte nás
  • Pracovné ponuky
  • Eventy
  • Podcast
  • Blog
  • Zákazníci
  • Právne dokumenty • Súkromie
  • Bezpečnosť
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo je sada podnikových aplikácií s otvoreným zdrojovým kódom, ktoré pokrývajú všetky potreby vašej spoločnosti: CRM, e-shop, účtovníctvo, skladové hospodárstvo, miesto predaja, projektový manažment atď.

Odoo prináša vysokú pridanú hodnotu v jednoduchom použití a súčasne plne integrovanými biznis aplikáciami.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now