如何在Odoo 10维护模块中添加权限组以提升安全性
Hey there! Let's break down your two questions about adding role-based groups to the Odoo 10 Maintenance module—super common request for better security and access control.
1. How to Add Groups in Odoo 10's Maintenance Module
Adding custom groups to the Maintenance module requires extending it with a custom add-on module (modifying core Odoo code directly is never recommended). Here's a step-by-step guide to get you set up:
Step 1: Create a basic custom module
Start by setting up a standard Odoo module structure. You’ll need at minimum:__init__.py(empty or with imports for your module files)__manifest__.py(listmaintenanceas a dependency)- A
security/folder to hold group and access rule definitions
Step 2: Define your groups
Create asecurity/groups.xmlfile to define your new groups, linking them to the Maintenance module’s category so they appear in the right section of settings:<odoo> <data noupdate="0"> <!-- Maintenance User Group --> <record id="group_maintenance_user" model="res.groups"> <field name="name">Maintenance User</field> <field name="category_id" ref="maintenance.module_category_maintenance"/> <field name="implied_ids" eval="[(4, ref('base.group_user'))]"/> </record> <!-- Maintenance Manager Group --> <record id="group_maintenance_manager" model="res.groups"> <field name="name">Maintenance Manager</field> <field name="category_id" ref="maintenance.module_category_maintenance"/> <field name="implied_ids" eval="[(4, ref('group_maintenance_user'))]"/> <field name="users" eval="[(4, ref('base.user_root'))]"/> </record> </data> </odoo>Step 3: Assign permissions to each group
Create asecurity/ir.model.access.csvfile to define what each group can do with key Maintenance models (requests, equipment, etc.):id,name,model_id:id,group_id:id,perm_read,perm_write,perm_create,perm_unlink access_maintenance_request_user,maintenance.request.user,model_maintenance_request,group_maintenance_user,1,1,1,0 access_maintenance_request_manager,maintenance.request.manager,model_maintenance_request,group_maintenance_manager,1,1,1,1 access_maintenance_equipment_user,maintenance.equipment.user,model_maintenance_equipment,group_maintenance_user,1,1,0,0 access_maintenance_equipment_manager,maintenance.equipment.manager,model_maintenance_equipment,group_maintenance_manager,1,1,1,1Tweak the permissions (1 = allow, 0 = deny) to match your workflow—for example, you might want users to create requests but not delete equipment.
Step 4: Install and validate your module
Install the custom module in Odoo 10, then head to Settings > Users & Companies > Users. Edit a test user, assign them to your new Maintenance groups, and verify that access controls work as expected.
2. Can We Add maintenance/manager and maintenance/user Groups Like MRP/Inventory Modules for Better Security?
Absolutely! This is actually a best practice to enforce role-based access control (RBAC) in the Maintenance module, just like core modules such as MRP or Inventory.
The setup I walked through above directly mirrors how those core modules structure their groups:
- A user group for standard team members who need to create/modify their own maintenance requests and view equipment.
- A manager group that inherits the user group’s permissions and adds full control (like deleting requests, managing equipment, and approving work orders).
By implementing these groups, you’ll prevent unauthorized users from making critical changes to maintenance data, which drastically boosts your system’s security and data integrity.
内容的提问来源于stack exchange,提问作者MOHAMED

