Skip to content

[19.0][FIX] pim: grant PIM roles the access rights their descriptions promise - #266

Open
bosd wants to merge 1 commit into
OCA:19.0from
bosd:19.0-add-pim_manager_attribute_access
Open

bosd wants to merge 1 commit into
OCA:19.0from
bosd:19.0-add-pim_manager_attribute_access

Conversation

@bosd

@bosd bosd commented Aug 6, 2026 •

Copy link
Copy Markdown
Contributor

The problem

The pim module ships three group definitions — PIM Reader, PIM User,
PIM Manager — and advertises (group description) that the Manager "will be
able to modify products and create attributes"
. It also adds a PIM app with
an Attributes menu pointing at attribute.set.

But pim ships no ir.model.access.csv, and attribute_set grants
write/create on its models only to base.group_erp_manager. So a user who has
only PIM Manager (a deliberately non-admin PIM operator, no Settings / no
developer mode) can open the PIM app and read attribute sets, but hits
AccessError the moment they create or edit one. The three roles are
non-functional without also handing the user the ERP-admin group — which defeats
the point of having them.

The fix

Add pim/security/ir.model.access.csv:

  • PIM Manager → full CRUD on attribute.set, attribute.group,
    attribute.attribute, attribute.option.
  • PIM User → write on product.template / product.product.

(Read access to these models for internal users already comes from
attribute_set / product.)

Tests

Adds pim/tests/test_pim_access.py proving, with a user that is not an ERP
Manager:

  • a PIM Manager can create / rename / delete an attribute.set and create an
    attribute.group;
  • a PIM Reader cannot create an attribute.set.

Note / scope

Creating an individual attribute.attribute additionally requires
attribute_set to run the backing ir.model.fields read and create under
sudo, the read side is #265. This PR covers the attribute-set access layer
(sets, groups, options, and the product write for PIM User); a complementary
attribute_set change is needed for full per-attribute creation by a non-admin.

@bosd bosd changed the title [FIX] pim: grant PIM roles the access rights their descriptions promise [19.0][FIX] pim: grant PIM roles the access rights their descriptions promise Aug 6, 2026
bosd pushed a commit to bosd/odoo-pim that referenced this pull request Aug 11, 2026
group_pim_manager was a hollow role — pim shipped no ir.model.access.csv,
so its 'create/manage attributes' promise had no ACL behind it and relied
on the user also holding ERP Manager (base.group_erp_manager). On hardened
instances that group is stripped from client users, so a PIM Manager could
not manage attribute option values at all (ir.model / access error).

Grant group_pim_manager CRUD on attribute.option + the transient
attribute.option.wizard so option (dropdown) values can be managed WITHOUT
any ir.model/ir.model.fields or Settings rights. Attribute *definition*
create (which creates a backing ir.model.fields) is intentionally NOT
granted here — that is schema-level and needs the attribute_set sudo path
(OCA odoo-pim/attribute_set follow-up).

Relates to OCA PR OCA#266 (PIM Manager ACLs).
The pim module defines PIM Reader / User / Manager groups (Manager 'will be able
to modify products and create attributes') but ships no ir.model.access.csv, and
attribute_set grants write/create only to base.group_erp_manager. So a PIM
Manager could open the PIM app and read attribute sets but got AccessError on
create/write -- the role was non-functional without the admin group.

Add pim/security/ir.model.access.csv: PIM Manager gets full CRUD on attribute.set,
attribute.group, attribute.attribute and attribute.option; PIM User gets write on
product.template / product.product. Add tests proving a PIM Manager (not an ERP
Manager) can create/edit/delete attribute sets and groups, and a PIM Reader
cannot.

Note: creating individual attribute.attribute records additionally requires the
attribute_set module to run the backing ir.model.fields read/create under sudo
(the read side is OCA/odoo-pim OCA#265); this PR covers the attribute-set access layer.
@bosd
bosd force-pushed the 19.0-add-pim_manager_attribute_access branch from 1507342 to a006449 Compare September 30, 2026 12:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants