You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SuiteCRM:如何基于Created By字段配置记录删除权限

How to Restrict SuiteCRM Record Deletion to Only the Record Creator (Based on Created By Field)

Got it, let's solve this problem where you need to ensure only logged-in users can delete records they created—since the default "Owner" permission relies on the Assigned To field, which doesn't fit your use case here. Here's a practical, step-by-step approach using logic hooks (the most straightforward way to add custom permission checks in SuiteCRM):

Step 1: Set Up a Logic Hook to Intercept Delete Actions

Logic hooks let you run custom code right before a record is deleted. First, create or edit the logic hook file for your target module (or apply it globally for all modules).

For a Single Module (e.g., Accounts)

Create a file at custom/modules/Accounts/logic_hooks.php (replace Accounts with your module name) with this code:

<?php
$hook_version = 1;
$hook_array = [];

// Hook into the before_delete event
$hook_array['before_delete'] = [
    [
        1, // Priority (lower numbers run first)
        'Block deletion unless user is the creator', // Description for system logs
        'custom/modules/Accounts/CustomDeletePermission.php', // Path to our handler class
        'CustomDeletePermission', // Name of our handler class
        'validateCreatorPermission' // Method to execute
    ]
];
?>

For All Modules Globally

If you want this rule to apply to every module, create/edit custom/modules/logic_hooks.php instead, and adjust the file path to a global location like custom/include/CustomDeletePermission.php.

Step 2: Create the Permission Validation Class

Next, build the class that checks if the current user is the record's creator. Using the single-module example above, make a file at custom/modules/Accounts/CustomDeletePermission.php:

<?php
class CustomDeletePermission {
    public function validateCreatorPermission($bean, $event, $arguments) {
        // Get the current logged-in user's ID
        $currentUserId = $GLOBALS['current_user']->id;
        // Get the ID of the user who originally created the record
        $createdById = $bean->created_by;

        // Optional: Let admins delete any record (remove this block if admins should follow the same rule)
        if ($GLOBALS['current_user']->is_admin) {
            return;
        }

        // Block deletion if the current user isn't the creator
        if ($currentUserId !== $createdById) {
            // Log the unauthorized attempt for debugging
            $GLOBALS['log']->error("Unauthorized delete attempt: User {$currentUserId} tried to delete record {$bean->id} (created by {$createdById})");
            
            // Show a user-friendly error and redirect back to the record detail page
            $_SESSION['error_string'] = "You can only delete records you created.";
            sugar_redirect("index.php?module={$bean->module_dir}&action=DetailView&record={$bean->id}");
            exit;
        }
    }
}
?>

Step 3: Clear SuiteCRM Cache

After adding these files, you need to rebuild the system cache to make SuiteCRM recognize the new hook:

  1. Go to Admin > Repair > Quick Repair and Rebuild
  2. Wait for the repair process to finish—this refreshes the logic hook registry and clears compiled files.

Optional Adjustments

  • Remove Admin Exemption: If you don't want admins to bypass this rule, delete the if ($GLOBALS['current_user']->is_admin) return; block.
  • Customize Error Messages: Tweak the $_SESSION['error_string'] value to match your system's tone.
  • Target Specific Modules: Repeat Step 1 for each module you want to enforce this rule on, updating the module name in file paths.

This approach ensures that only the user who created a record can delete it, overriding the default Assigned To-based permissions. It's lightweight, easy to maintain, and works with both core and custom SuiteCRM modules.

内容的提问来源于stack exchange,提问作者Dhaval Baldha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:09:01