Conversation
bosd
pushed a commit
to bosd/odoo-pim
that referenced
this pull request
Aug 11, 2026
group_pim_manager was a hollow role — pim shipped no ir.model.access.csv, so its 'create/manage attributes' promise had no ACL behind it and relied on the user also holding ERP Manager (base.group_erp_manager). On hardened instances that group is stripped from client users, so a PIM Manager could not manage attribute option values at all (ir.model / access error). Grant group_pim_manager CRUD on attribute.option + the transient attribute.option.wizard so option (dropdown) values can be managed WITHOUT any ir.model/ir.model.fields or Settings rights. Attribute *definition* create (which creates a backing ir.model.fields) is intentionally NOT granted here — that is schema-level and needs the attribute_set sudo path (OCA odoo-pim/attribute_set follow-up). Relates to OCA PR OCA#266 (PIM Manager ACLs).
The pim module defines PIM Reader / User / Manager groups (Manager 'will be able to modify products and create attributes') but ships no ir.model.access.csv, and attribute_set grants write/create only to base.group_erp_manager. So a PIM Manager could open the PIM app and read attribute sets but got AccessError on create/write -- the role was non-functional without the admin group. Add pim/security/ir.model.access.csv: PIM Manager gets full CRUD on attribute.set, attribute.group, attribute.attribute and attribute.option; PIM User gets write on product.template / product.product. Add tests proving a PIM Manager (not an ERP Manager) can create/edit/delete attribute sets and groups, and a PIM Reader cannot. Note: creating individual attribute.attribute records additionally requires the attribute_set module to run the backing ir.model.fields read/create under sudo (the read side is OCA/odoo-pim OCA#265); this PR covers the attribute-set access layer.
bosd
force-pushed
the
19.0-add-pim_manager_attribute_access
branch
from
September 30, 2026 12:08
1507342 to
a006449
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The problem
The
pimmodule ships three group definitions — PIM Reader, PIM User,PIM Manager — and advertises (group description) that the Manager "will be
able to modify products and create attributes". It also adds a PIM app with
an Attributes menu pointing at
attribute.set.But
pimships noir.model.access.csv, andattribute_setgrantswrite/create on its models only to
base.group_erp_manager. So a user who hasonly PIM Manager (a deliberately non-admin PIM operator, no Settings / no
developer mode) can open the PIM app and read attribute sets, but hits
AccessErrorthe moment they create or edit one. The three roles arenon-functional without also handing the user the ERP-admin group — which defeats
the point of having them.
The fix
Add
pim/security/ir.model.access.csv:attribute.set,attribute.group,attribute.attribute,attribute.option.product.template/product.product.(Read access to these models for internal users already comes from
attribute_set/product.)Tests
Adds
pim/tests/test_pim_access.pyproving, with a user that is not an ERPManager:
attribute.setand create anattribute.group;attribute.set.Note / scope
Creating an individual
attribute.attributeadditionally requiresattribute_setto run the backingir.model.fieldsread and create undersudo, the read side is #265. This PR covers the attribute-set access layer
(sets, groups, options, and the product write for PIM User); a complementary
attribute_setchange is needed for full per-attribute creation by a non-admin.