Skip to Content
Odoo Menu
  • Sign in
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Approvals
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Estate Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
    • Meet an advisor
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Get a demo
  • Pricing
  • Help

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Accounting
  • Inventory
  • PoS
  • Project
  • MRP
All apps
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
Help

restricting web/database

Subscribe

Get notified when there's activity on this post

This question has been flagged
5 Replies
12046 Views
Avatar
David Ogles

I'm trying to restrict access to /web/database/manager and selector.   I've built a .htpasswd file.  The problem is that the following code doesn't work.  I can still access /web/database/manager and selector

upstream myodoo {

    server 127.0.0.1:8069;

}

server {

        listen 443 default;

        server_name myodoo.myodoo-hosting.com;

        access_log /var/log/nginx/oddo.access.log;

        error_log /var/log/nginx/oddo.error.log;

        if ($scheme = http) {

                return 301 https://myodoo.my-hosting.com$request_uri;

        }

        # SSL cerificate details

        ssl on;

        ssl_certificate /etc/letsencrypt/live/myodoo.my-hosting.com/fullchain.pem;

        ssl_certificate_key /etc/letsencrypt/live/myodoo.my-hosting.com/privkey.pem; keepalive_timeout 60;

        ssl_ciphers EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5;

        ssl_protocols TLSv1 TLSv1.1 TLSv1.2;

        ssl_prefer_server_ciphers on;

        proxy_buffers 16 64k;

        proxy_buffer_size 128k;

        location / {

                proxy_next_upstream error timeout invalid_header http_500 http_502 http_503 http_504;

                proxy_redirect off;

                proxy_set_header Host $host;

                proxy_set_header X-Real-IP $remote_addr;

                proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

                proxy_set_header X-Forwarded-Proto https;

                proxy_pass http://myodoo;

  

        }

        location ~* /web/static/ {

                proxy_cache_valid 200 60m;

                proxy_buffering on;

                expires 864000;

                proxy_pass http://myodoo;

        }

  location ~ ^/web/database/manager {

                auth_basic "Restricted Access";

                auth_basic_user_file /etc/nginx/.htpasswd;

                proxy_pass http://myodoo;

                # set headers

                # ...

        }

        location ~ ^/web/database/selector {

                auth_basic "Restricted Access";

                auth_basic_user_file /etc/nginx/.htpasswd;

                proxy_pass http://myodoo;

        }

  

  

  }


## http redirects to https ##

server {

    listen 80;

    server_name myodoo.my-hosting.com;

    # Strict Transport Security

    add_header Strict-Transport-Security max-age=2592000;

    rewrite ^/.*$ https://$host$request_uri? permanent;

}

0
Avatar
Discard
Ermin Trevisan

That's not an Odoo problem.

Avatar
Niyas Raphy (Walnut Software Solutions)
Best Answer

Hi,

If you are trying to restrict the /web/database/manager .  In the conf. file give list_db = False.
Once you given like this and on accessing the database manager(acessing via typing in url) , a warning will be displayed in the page.


 Then in the login page there will not exist the database manager.



This is in V11.


-1
Avatar
Discard
Hassan Iqbal

so what if i want to restrict some database with combination of ip and port. Suppose i want to create database of multiple companies on the same server and then i want to restrict that it should now show the database list and the specific company database should be selected by default when they gave the respective ip:port.

software4.dsl@daffodil-bd.com

dbfilter = ^your_database_name$

Avatar
Jaf Faizal Jalaluddin
Best Answer

Hi Niyas,

I've made the changes to my "odoo-server.conf" file in the "/etc" folder but this does not seem to work.

Does this work for v10 CE?

1
Avatar
Discard
Avatar
David Ogles
Author Best Answer

I understand that its not an Odoo problem.  I do see that the first part of my message got truncated.  

I'm trying to restrict access to web/database/ but from all of the google links I found, I can't seem to get it to work.  I've tried several option.  I also looked in Odoo Apps, but couldn't find anything.  Any help would be appreciated.

Odoo 10, Ubuntu 16.04 with nginx as reverse proxy.  the above is my VSB.

thanks,

Dave

0
Avatar
Discard
Avatar
Piotr Cierkosz
Best Answer

As you know from previous comments it is not really and Odoo issue. You can solve the problem in two ways:

1) Restricting access to folders using nginx. It would be something like this:

location ~ /(dir1|dir2|dir3) {
   deny all;
   return 404;
}

2) By installing an app like: https://apps.odoo.com/apps/modules/10.0/web_hide_db_manager_link/

3) U can also make your own module for this

0
Avatar
Discard
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Sign up
Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now