Skip to Content
Odoo Menu
  • Prijavi
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Approvals
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Estate Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
    • Meet an advisor
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Get a demo
  • Pricing
  • Help

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Knjigovodstvo
  • Zaloga
  • PoS
  • Projekt
  • MRP
All apps
You need to be registered to interact with the community.
All Posts People Badges
Ključne besede (View all)
odoo accounting v14 pos v15
About this forum
You need to be registered to interact with the community.
All Posts People Badges
Ključne besede (View all)
odoo accounting v14 pos v15
About this forum
Pomoč

Security File Issue

Naroči se

Get notified when there's activity on this post

This question has been flagged
securityodoo
4749 Prikazi
Avatar
Ayyappan

I have created new add-on as like as survey add-on. In form view i have a partner field. Module consist 3 level of groups,

  • Head Manager(admin)

  • Manager

  • User

If i am logged in as a manager and print the report, i am getting below warning,

"AccessError: ('AccessError', u'The requested operation cannot be completed due to security restrictions. Please contact your system administrator.\n\n(Document type: res.partner, Operation: read)') "

My rules are:

Manager:

<record model="res.groups" id="base.group_survey_manager">

<field name="name">Custom Survey  Manager</field>

<field name="implied_ids" eval="[(4, ref('base.group_survey_user'))]"/>

<field name="users" eval="[(4, ref('base.user_root'))]"/>

</record>

-----------------------------------------------------------------------------------

<record id="project_survey_manager_access" model="ir.rule">

<field name="name">Survey Manager access rights</field>

<field name="model_id" ref="custom_survey.model_custom_project_survey"/>

<field name="domain_force">[(1, '=', 1)]</field>

<field name="groups" eval="[(4, ref('base.group_survey_manager'))]"/>

<field eval="1" name="perm_unlink"/>

<field eval="1" name="perm_write"/>

<field eval="1" name="perm_read"/>

<field eval="1" name="perm_create"/>

</record>


Partner Form Security:

<record id="partner_list_access" model="ir.rule">

<field name="name">Access to the manager to list related partners</field>

<field name="model_id" ref="custom_survey.model_res_partner"/>

<field name="domain_force">['|','|',('create_uid', '=', user.id),('user_ids', '=', user.id),('user_id', '=', user.id)]</field>

<field name="groups" eval="[(4, ref('base.group_survey_manager'))]"/>

<field eval="1" name="perm_unlink"/>

<field eval="1" name="perm_write"/>

<field eval="1" name="perm_read"/>

<field eval="1" name="perm_create"/>

</record>

If the manager is logged-in, i would like to list the partner who is created by the current manager. That's why i added the partner rule.

How to solve this issue?

0
Avatar
Opusti
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Prijavi
Related Posts Odgovori Prikazi Aktivnost
How to increase the security of Odoo ? Solved
security odoo
Avatar
Avatar
Avatar
2
sep. 23
27997
[8] How to inherit or delete rule Solved
security rules odoo
Avatar
Avatar
Avatar
2
dec. 19
16080
Bruteforce preventing using CSF (Config File Server Firewall) custom regex in the login form.
security odoo login security
Avatar
0
apr. 18
4177
odoo - security aspects
security internet odoo
Avatar
Avatar
1
maj 17
5219
Odoo Qweb Report render securely HTML with allowed Tags
security qweb odoo
Avatar
Avatar
1
apr. 17
4748
Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now