You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Postman调用Odoo API GET请求时遭遇403 Forbidden错误

Odoo 15 API端点GET请求返回403 Forbidden错误排查

问题背景

使用Postman向自定义Odoo API端点发送GET请求时,收到403 Forbidden错误,以下是详细信息:

配置详情

  • Odoo版本:Odoo 15社区版
  • API端点:http://localhost:8069/api/postman
  • 认证方式:Basic Authentication
    • 用户名:admin
    • 密码:admin

返回的错误信息

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<title>403 Forbidden</title>
<h1>Forbidden</h1>
<p>You don't have the permission to access the requested resource. It is either read-protected or not readable by the server.</p>

自定义控制器代码

# -*- coding: utf-8 -*-
from odoo import http

class TestApi(http.Controller):
    @http.route("/api/postman", methods=["GET"], type="http", auth="basic", csrf=False)
    def test_endpoint(self):
        return "This is a test API endpoint with basic authentication."

已执行的排查步骤

  • 确认用户凭证正确无误
  • 确认用户拥有访问API的必要权限
  • 确认API端点已正确配置为使用Basic Authentication

可能的解决方法

  1. 验证请求头中的Basic Auth凭证
    Postman选择Basic Auth后,会自动生成Authorization: Basic <base64编码串>请求头,可在Postman的「Headers」标签下确认该头是否存在且值正确。若自动生成异常,可手动添加该头,值为Basic YWRtaW46YWRtaW4=(admin:admin的base64编码结果)。

  2. 确认用户权限完整性
    即使是admin用户,也需确保其所属用户组拥有访问自定义控制器的权限:

    • 进入Odoo后台,打开「设置」-「用户与公司」-「用户」,找到admin用户
    • 检查用户关联的用户组,确认包含「技术特性」相关权限组(如「开发者模式」),自定义API控制器通常需要此类权限。
  3. 检查路由注册状态
    启用Odoo开发者模式后,进入「设置」-「技术」-「路由」,搜索/api/postman,确认路由已正确注册,且认证方式显示为basic。

  4. 排查路由冲突
    确认/api/postman路径未与Odoo内置路由或其他第三方模块的路由重复,避免路由被覆盖导致权限验证异常。

内容的提问来源于stack exchange,提问作者sarm

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 01:00:14