使用Postman调用Odoo API GET请求时遭遇403 Forbidden错误
Odoo 15 API端点GET请求返回403 Forbidden错误排查
问题背景
使用Postman向自定义Odoo API端点发送GET请求时,收到403 Forbidden错误,以下是详细信息:
配置详情
- Odoo版本:Odoo 15社区版
- API端点:
http://localhost:8069/api/postman - 认证方式:Basic Authentication
- 用户名:admin
- 密码:admin
返回的错误信息
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN"> <title>403 Forbidden</title> <h1>Forbidden</h1> <p>You don't have the permission to access the requested resource. It is either read-protected or not readable by the server.</p>
自定义控制器代码
# -*- coding: utf-8 -*- from odoo import http class TestApi(http.Controller): @http.route("/api/postman", methods=["GET"], type="http", auth="basic", csrf=False) def test_endpoint(self): return "This is a test API endpoint with basic authentication."
已执行的排查步骤
- 确认用户凭证正确无误
- 确认用户拥有访问API的必要权限
- 确认API端点已正确配置为使用Basic Authentication
可能的解决方法
验证请求头中的Basic Auth凭证
Postman选择Basic Auth后,会自动生成Authorization: Basic <base64编码串>请求头,可在Postman的「Headers」标签下确认该头是否存在且值正确。若自动生成异常,可手动添加该头,值为Basic YWRtaW46YWRtaW4=(admin:admin的base64编码结果)。确认用户权限完整性
即使是admin用户,也需确保其所属用户组拥有访问自定义控制器的权限:- 进入Odoo后台,打开「设置」-「用户与公司」-「用户」,找到admin用户
- 检查用户关联的用户组,确认包含「技术特性」相关权限组(如「开发者模式」),自定义API控制器通常需要此类权限。
检查路由注册状态
启用Odoo开发者模式后,进入「设置」-「技术」-「路由」,搜索/api/postman,确认路由已正确注册,且认证方式显示为basic。排查路由冲突
确认/api/postman路径未与Odoo内置路由或其他第三方模块的路由重复,避免路由被覆盖导致权限验证异常。
内容的提问来源于stack exchange,提问作者sarm
相关产品推荐
相关产品推荐

