SuiteCRM:如何基于Created By字段配置记录删除权限
Got it, let's solve this problem where you need to ensure only logged-in users can delete records they created—since the default "Owner" permission relies on the Assigned To field, which doesn't fit your use case here. Here's a practical, step-by-step approach using logic hooks (the most straightforward way to add custom permission checks in SuiteCRM):
Step 1: Set Up a Logic Hook to Intercept Delete Actions
Logic hooks let you run custom code right before a record is deleted. First, create or edit the logic hook file for your target module (or apply it globally for all modules).
For a Single Module (e.g., Accounts)
Create a file at custom/modules/Accounts/logic_hooks.php (replace Accounts with your module name) with this code:
<?php $hook_version = 1; $hook_array = []; // Hook into the before_delete event $hook_array['before_delete'] = [ [ 1, // Priority (lower numbers run first) 'Block deletion unless user is the creator', // Description for system logs 'custom/modules/Accounts/CustomDeletePermission.php', // Path to our handler class 'CustomDeletePermission', // Name of our handler class 'validateCreatorPermission' // Method to execute ] ]; ?>
For All Modules Globally
If you want this rule to apply to every module, create/edit custom/modules/logic_hooks.php instead, and adjust the file path to a global location like custom/include/CustomDeletePermission.php.
Step 2: Create the Permission Validation Class
Next, build the class that checks if the current user is the record's creator. Using the single-module example above, make a file at custom/modules/Accounts/CustomDeletePermission.php:
<?php class CustomDeletePermission { public function validateCreatorPermission($bean, $event, $arguments) { // Get the current logged-in user's ID $currentUserId = $GLOBALS['current_user']->id; // Get the ID of the user who originally created the record $createdById = $bean->created_by; // Optional: Let admins delete any record (remove this block if admins should follow the same rule) if ($GLOBALS['current_user']->is_admin) { return; } // Block deletion if the current user isn't the creator if ($currentUserId !== $createdById) { // Log the unauthorized attempt for debugging $GLOBALS['log']->error("Unauthorized delete attempt: User {$currentUserId} tried to delete record {$bean->id} (created by {$createdById})"); // Show a user-friendly error and redirect back to the record detail page $_SESSION['error_string'] = "You can only delete records you created."; sugar_redirect("index.php?module={$bean->module_dir}&action=DetailView&record={$bean->id}"); exit; } } } ?>
Step 3: Clear SuiteCRM Cache
After adding these files, you need to rebuild the system cache to make SuiteCRM recognize the new hook:
- Go to Admin > Repair > Quick Repair and Rebuild
- Wait for the repair process to finish—this refreshes the logic hook registry and clears compiled files.
Optional Adjustments
- Remove Admin Exemption: If you don't want admins to bypass this rule, delete the
if ($GLOBALS['current_user']->is_admin) return;block. - Customize Error Messages: Tweak the
$_SESSION['error_string']value to match your system's tone. - Target Specific Modules: Repeat Step 1 for each module you want to enforce this rule on, updating the module name in file paths.
This approach ensures that only the user who created a record can delete it, overriding the default Assigned To-based permissions. It's lightweight, easy to maintain, and works with both core and custom SuiteCRM modules.
内容的提问来源于stack exchange,提问作者Dhaval Baldha

