Repository navigation
Conversation
ai_tool lets modules expose tools to AI agents, but each one has to be written for a specific model. This module adds three generic tools, list_models, get_fields and search_read, so that an agent can read any model the calling user is allowed to read, with the user's own access rights (ACLs, record rules and field groups still apply). Personal or otherwise sensitive data can be kept out of the results with a new "AI Read Forbidden" flag on ir.model.fields. A flagged field is never returned nor described, and neither is any field exposing its value: related fields, _inherits included, and computed fields depending on it, as the registry reports them. Many2one values are returned as plain IDs, and display names computed on the fly are left out, as both come from name_get, which may show another record's forbidden field. Searches are not restricted, so an agent probing on purpose can still find records by a forbidden value; the README lists those cases. search_read returns the stored fields unless a field list is given, pages its results with limit, offset and has_more, and does not fail as a whole because of one field or record the user may not read. Assisted-by: Claude Opus 5.5
Building and dispatching a tool reads ir.model via model_id, which a plain internal user (base.group_user) cannot access. Resolve the model name with sudo() while keeping the actual tool execution under the caller's own permissions, so non-admin MCP keys can list and call tools. Add a regression test exercising a non-admin user through _get_tool_definition and _execute_tool. (cherry picked from commit 16beaa7)
'date' is not a JSON Schema type, so the declared output schema is not valid for MCP clients validating against it. Declare the RFC 3339 format instead. Assisted-by: Devin:SWE-2 High
dreispt
force-pushed
the
19.0-mig-ai_tool_read
branch
from
October 7, 2026 17:47
328ff64 to
3c96206
Compare
dreispt
force-pushed
the
19.0-mig-ai_tool_read
branch
from
October 7, 2026 17:51
3c96206 to
c6233b1
Compare
- _ai_jsonify: note that isinstance(date) also covers datetime. - _ai_get_fields: document that reporting forbidden fields under "hidden" is deliberate, unlike group-restricted fields which are not disclosed. - _ai_forbidden_fields: return early when no field is flagged. - _ai_search_read: an explicit empty fields list now returns ids only; previously it fell back to the stored-fields default, same as no fields argument at all. Assisted-by: Devin:SWE-2 High
Port ai_tool_read from OCA#122 to 19.0. - Manifest version bump. - user_has_groups() removed: use res.users.has_groups(). - check_access_rights() deprecated since 18.0: use has_access() / check_access(). - View xpath targets use <list> instead of <tree>. - display_name is never stored in 19.0, so it is excluded everywhere; adjust test_display_name_hidden. - Replace setup/ symlink dir with the whool pyproject.toml convention. Requires the ai_tool fixes from OCA#125, cherry-picked in the preceding commits (ir.model is not readable by internal users in 19.0). Assisted-by: Devin:SWE-2 High
Add a USAGE section covering how the registered ai.tool records are consumed (e.g. via ai_oca_mcp), the list_models / get_fields / search_read agent workflow, and the search_read arguments with an example. Drop the "This module" opening from the description. Assisted-by: Devin:SWE-2 High
dreispt
force-pushed
the
19.0-mig-ai_tool_read
branch
from
October 7, 2026 17:55
c6233b1 to
bbfbdd9
Compare
Member
Author
Member
Author
|
/ocabot migration ai_tool_read |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Migration of
ai_tool_readto 19.0, forward-porting the[ADD]commit from #122 by @nobuQuartile (authorship preserved).Included commits / dependencies
ai_toolfixes for 19.0 (ir.modelsudo lookup by @nobuQuartile + the_ai_get_dateoutput-schema fix) are cherry-picked into this branch:ai_tool_readtools are exercised throughai.toolrecords in tests, which fail for non-admin users without them. They can be dropped on rebase once [FIX] ai_tool: non-admin tool access and valid date output schema #125 merges.[FIX] ai_tool_read: review follow-ups— placed directly after the 16.0[ADD]commit so it cherry-picks/backports cleanly onto the [16.0][ADD] ai_tool_read: generic read tools with per-field AI opt-out #122 branch: clarifying comments (datetimecoverage in_ai_jsonify, deliberatehiddendisclosure), an early return in_ai_forbidden_fields, and a fix for an explicit emptyfieldslist previously falling back to the stored-fields default.19.0 changes
user_has_groups()removed upstream →res.users.has_groups()check_access_rights()deprecated since 18.0 →has_access()/check_access()tree→listdisplay_nameis never stored in 19.0 — excluded from results everywhere;test_display_name_hiddenadjusted accordinglysetup/symlink dir replaced by the whoolpyproject.tomlconvention; metapackage dep addedTests
16
ai_tool_readtests pass against a 19.0 checkout, including the non-admin access and per-field opt-out coverage.