# Can't attach a file without create permission over the register

**URL:** https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728
**Category:** User
**Created:** [September 13, 2018, 12:01pm UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728 "2018-09-13T12:01:35Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![jaarias](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/jaarias/32/198_2.png) [@jaarias](https://discuss.tryton.org/u/jaarias)
#### Post date: [September 13, 2018, 12:01pm UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/1 "2018-09-13T12:01:35Z")

</div>

You cannot attach a file to a register although you have write permission over the register model, unless you also have create permission.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [September 15, 2018, 3:39pm UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/2 "2018-09-15T15:39:57Z")

</div>

Yes this is the design. The resource [check the access right of the linked model for the same operation](http://hg.tryton.org/trytond/file/32cea659fb4e/trytond/ir/resource.py#l74).

---

<div class="post-metadata">

### Author: ![albert](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/albert/32/21_2.png) [@albert](https://discuss.tryton.org/u/albert)
#### Post date: [September 15, 2018, 9:43pm UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/3 "2018-09-15T21:43:22Z")

</div>

> [@ced](#):
>
> Yes this is the design. The resource [check the access right of the linked model for the same operation](http://hg.tryton.org/trytond/file/32cea659fb4e/trytond/ir/resource.py#l74).

Yes, it’s the current design but as I see it we could think of attachments (and notes) as a one2many field that would be part of the current record. If that was the case, what we would expect is that the user would be able to add new records to that o2m if he has write permissions to the record.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [September 15, 2018, 10:20pm UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/4 "2018-09-15T22:20:35Z")

</div>

Well, it would be a less powerful and flexible design and any way this can be customized.

---

<div class="post-metadata">

### Author: ![jaarias](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/jaarias/32/198_2.png) [@jaarias](https://discuss.tryton.org/u/jaarias)
#### Post date: [September 17, 2018, 6:51am UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/5 "2018-09-17T06:51:48Z")

</div>

I agree with Albert: I think that the user usually expects the same behaviour as for one2many fields so it had to be the standard implementation (not a customized one). Why _it would be less powerful and flexible design_?

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [September 17, 2018, 7:22am UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/6 "2018-09-17T07:22:45Z")

</div>

> [@jaarias](#):
>
> Why _it would be less powerful and flexible design_ ?

Because instead of 3 access rights, there will be only one.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [September 21, 2018, 9:30am UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/7 "2018-09-21T09:30:17Z")

</div>

On a second though, I think it is probably the less astonishing behavior to check for ‘write’ access of resource on create and delete. But also that we need an easy way to modify one type of check into another (see [Permisos de usuario para archivos adjuntos (GNU Health)](https://discuss.tryton.org/t/permisos-de-usuario-para-archivos-adjuntos-gnu-health/751)).  
So I propose that in `Resource.check_access` we have a method to convert the `mode` per model\_name. This method by default will convert `create` and `delete` into `write`.

---

<div class="post-metadata">

### Author: ![jaarias](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/jaarias/32/198_2.png) [@jaarias](https://discuss.tryton.org/u/jaarias)
#### Post date: [September 21, 2018, 11:58am UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/8 "2018-09-21T11:58:25Z")

</div>

So, the change in [http://hg.tryton.org/trytond/file/32cea659fb4e/trytond/ir/resource.py#l74](http://hg.tryton.org/trytond/file/32cea659fb4e/trytond/ir/resource.py#l74) could be something like this (see the line inserted after #)?

```
@classmethod
def check_access(cls, ids, mode='read'):
    pool = Pool()
    ModelAccess = pool.get('ir.model.access')
    if ((Transaction().user == 0)
            or not Transaction().context.get('_check_access')):
        return
    model_names = set()
    with Transaction().set_context(_check_access=False):
        for record in cls.browse(ids):
            if record.resource:
                model_names.add(str(record.resource).split(',')[0])

    # Check whether model_names have write access to 'write', 'create' or 'delete' an attachment
    mode = 'write' if mode in ('delete', 'create') else mode

    for model_name in model_names:
        ModelAccess.check(model_name, mode=mode)

```

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [September 21, 2018, 1:10pm UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/9 "2018-09-21T13:10:34Z")

</div>

For me, it should be done via a method that takes also the model\_name so it can be easy to extend it and add custom behavior per model.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [September 21, 2018, 4:42pm UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/10 "2018-09-21T16:42:09Z")

</div>

I created [Use write mode to check create and delete of resources (#7717) · Issues · Tryton / Tryton · GitLab](https://bugs.tryton.org/issue7717)

---

<div class="post-metadata">

### Author: ![Saurabh](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/s/ee7513/32.png) [@Saurabh](https://discuss.tryton.org/u/Saurabh)
#### Post date: [April 25, 2019, 1:26pm UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/11 "2019-04-25T13:26:57Z")

</div>

@ced Hi Cedric, Is there any update on this issue. I am not able to find the code in the review patch on the main branch of v5.0. Please update this at the earliest possible as it is causing lot of problems to us in go-live of our modules.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [April 25, 2019, 1:42pm UTC](https://discuss.tryton.org/t/cant-attach-a-file-without-create-permission-over-the-register/728/12 "2019-04-25T13:42:28Z")

</div>

This is against the stable branch rules. We do not back-port behavior changes on released series.
