# Record rules for buttons

**URL:** https://discuss.tryton.org/t/record-rules-for-buttons/5056
**Category:** Developer
**Created:** [March 1, 2022, 9:05pm UTC](https://discuss.tryton.org/t/record-rules-for-buttons/5056 "2022-03-01T21:05:17Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![edbo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/e/f14d63/32.png) [@edbo](https://discuss.tryton.org/u/edbo)
#### Post date: [March 1, 2022, 9:05pm UTC](https://discuss.tryton.org/t/record-rules-for-buttons/5056/1 "2022-03-01T21:05:17Z")

</div>

I am struggling a bit with the following case:  
I have a model which is using a workflow. Every user have read access to all the records, but only a few users have the right to click on the buttons. So far no problem, I created a special group and added the users to that group.

The problem however is that each record has a list of users from that particular group and only those users are allowed to click on the buttons. So I need some sort of rule to check the current user against that list of users. What it the best approach here? I can check in the workflow transition if the user is in the list and issue a error if not, but are there other possibilities?

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [March 3, 2022, 10:22am UTC](https://discuss.tryton.org/t/record-rules-for-buttons/5056/2 "2022-03-03T10:22:52Z")

</div>

No we do not have “rules” for button like we do for record (and neither for fields).

---

<div class="post-metadata">

### Author: ![edbo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/e/f14d63/32.png) [@edbo](https://discuss.tryton.org/u/edbo)
#### Post date: [March 3, 2022, 7:25pm UTC](https://discuss.tryton.org/t/record-rules-for-buttons/5056/3 "2022-03-03T19:25:16Z")

</div>

I have tested a solution which is working perfectly. But I want to make sure it’s valid so it will work in upcoming versions (I’m on 6.0)

I added a `record rule` which checks if a user is in the list and based on that it will add write access. For the buttons I added:

```python
@classmethod
def __setup__ (cls):
    cls._buttons.update({
        'do_maintenance': {
            'readonly': Not(Eval('current_user', []).contains(Eval('context',{}).get('employee'))),
            'depends': ['current_user'],
        }
    })

```

So the button will become readonly when the user is not in the list.  
Is the `readonly` a valid PYSON expression? It works, but I do `Eval` twice.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [March 3, 2022, 9:58pm UTC](https://discuss.tryton.org/t/record-rules-for-buttons/5056/4 "2022-03-03T21:58:21Z")

</div>

> [@edbo](#):
>
> I added a `record rule` which checks if a user is in the list and based on that it will add write access.

Of course you can use only the write access on the record as check to access to the button (if the button has no group base access).

> [@edbo](#):
>
> So the button will become readonly when the user is not in the list.

For now readonly attribute are just cosmetic, there is no enforcement on server side.

> [@edbo](#):
>
> Is the `readonly` a valid PYSON expression? It works, but I do `Eval` twice.

You can have multiple `Eval` statement.

---

<div class="post-metadata">

### Author: ![edbo](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/e/f14d63/32.png) [@edbo](https://discuss.tryton.org/u/edbo)
#### Post date: [March 3, 2022, 10:22pm UTC](https://discuss.tryton.org/t/record-rules-for-buttons/5056/5 "2022-03-03T22:22:36Z")

</div>

> [@ced](#):
>
> > [@edbo](#):
> >
> > I added a `record rule` which checks if a user is in the list and based on that it will add write access.
> 
> Of course you can use only the write access on the record as check to access to the button (if the button has no group base access).

I wasn’t clear about this. I created two record rules, one record rule is there to make the record `readonly`. The other checks of the user exists in the list on the record and makes the record writable.  
The button also have group access added.

> [@ced](#):
>
> > [@edbo](#):
> >
> > Is the `readonly` a valid PYSON expression? It works, but I do `Eval` twice.
> 
> You can have multiple `Eval` statement.

Thanks, that was my biggest concern.
