Odoo15安全问题:如何阻止修改前端源码显示隐藏按钮?
Great question—this is a super common gotcha with Odoo's frontend visibility controls! The attrs attribute you're using (attrs="{'invisible': [('purchase_approve_admin', '!=', 'neutral')]}") only handles client-side hiding. That means anyone with basic browser dev tools can edit the DOM or frontend code to make the button visible again. To properly lock this down, you need to enforce checks on the server side—that's the only place you can truly prevent unauthorized actions.
Key Solutions to Secure Your Button
1. Use Odoo's Built-in Group Permissions for Visibility
Instead of relying solely on attrs, tie the button to a specific user group using the groups attribute. This controls both frontend visibility and backend access, since Odoo validates group membership server-side.
Example:
<button name="button_purchase_approve" string="Approve Purchase" attrs="{'invisible': [('purchase_approve_admin', '!=', 'neutral')]}" groups="your_module.group_purchase_approve_admin"/>
Replace your_module.group_purchase_approve_admin with the actual group you've created for this permission. Even if someone forces the button to appear, Odoo will block the action if they aren't in the group.
2. Add Server-Side Checks in the Button's Python Method
Even if the button is visible, you must validate permissions and record conditions directly in the backend method that the button triggers. This is the most critical layer of security.
Example code for your button's method:
from odoo import api, models from odoo.exceptions import AccessError class YourPurchaseModel(models.Model): _inherit = 'purchase.order' # Or your custom model @api.multi def button_purchase_approve(self): # Check if user has the required group if not self.env.user.has_group('your_module.group_purchase_approve_admin'): raise AccessError("You are not authorized to approve this purchase.") # Also validate the record condition that your attrs was checking for record in self: if record.purchase_approve_admin != 'neutral': raise AccessError("This purchase cannot be approved at this stage.") # Proceed with your approval logic # ...
This way, even if a user bypasses frontend visibility, the backend will reject the action immediately.
3. Use Record Rules for Granular Control
If the button's availability depends on specific record field values (like your purchase_approve_admin field), create a record rule to restrict access to only records that meet the condition.
- Go to Settings > Technical > Security > Record Rules
- Create a new rule for your model
- Set the domain to
[('purchase_approve_admin', '=', 'neutral')] - Assign it to the relevant user group
- Check the "Apply for read" and "Apply for write" boxes as needed
This ensures users can only interact with records that are eligible for the action, even if they try to manipulate the frontend.
Best Practice Reminder
Frontend controls like attrs are meant for UI convenience, not security. Always assume that any frontend restriction can be bypassed, and mirror those checks (plus permission validations) on the server side. This is the only way to keep sensitive actions secure in Odoo.
内容的提问来源于stack exchange,提问作者Enes Kara

