Stop risky uploads before they become a problem
Attachment Upload Restriction gives administrators one place to control file size, type and content, enforce storage quotas, manage delete permissions and audit every upload — no coding required.
The problem
Odoo lets anyone attach almost any file, of almost any size, almost anywhere. Renamed executables slip past extension checks, oversized files quietly fill your database and filestore, and there is no record of who uploaded, modified or deleted what — leaving security, storage and compliance to chance.
The solution
Attachment Upload Restriction enforces size, extension, content-verified MIME and filename rules at the moment of upload, caps storage per user or department, restricts who can delete governed files, and logs every blocked, uploaded, modified or deleted attachment — giving administrators control and proof, not just policy.
Everything attachment governance needs, in one app
Every capability below is implemented in the module.
Unified Restriction Rules
Build rules that combine a maximum file size, extension black or whitelist, MIME type black or whitelist and filename pattern matching (wildcard or regex) — applied globally or scoped to specific models.
Content-Verified MIME Checking
Goes beyond trusting a file's extension: the actual file content is sniffed and compared against its declared type, catching a renamed executable disguised as a harmless document.
Clear Rejection Messages
Every blocked upload shows a specific, customizable message naming the rule and limit that applied, so users understand exactly why a file was refused and what to do next.
Storage Quotas
Cap storage per user, per department or company-wide, with a warning threshold and a hard block once the limit is reached — so no single user or team can fill your filestore.
Storage-Usage Reporting
A dedicated report breaks down attachment count and size by user and department, giving administrators the consumption visibility no single-purpose app provides.
Full Audit Trail
Every blocked, uploaded, modified and deleted attachment is logged with the acting user, reason and size, searchable with graph and pivot views for security review and compliance reporting.
Permission Profiles
Grant or restrict attachment delete rights by role with reusable permission profiles, then apply a profile to many users at once instead of editing access one by one.
Guided Setup Wizard
A first-run wizard activates a ready-to-use malware and executable extension blacklist, a global size limit and safe defaults, so protection is active minutes after install.
System-Limit Education
The settings page explains where the default 25 MB Odoo ceiling and the web server's client_max_body_size limit come from, so admins stop fighting invisible caps.
How it works
Define Rules
Create restriction rules for size, extension, MIME type and filename patterns — globally or per model — using the visual rule editor.
Set Quotas & Permissions
Configure storage quotas per user or department and apply permission profiles to control who can delete governed attachments.
Uploads Are Enforced Automatically
Every upload is checked at write time; violations are rejected instantly with a clear message, no manual review required.
Review the Audit Trail
Track blocked, uploaded, modified and deleted attachments plus storage usage from the built-in dashboards.
Frequently asked
No sales fog. If your question isn't here, email us and we'll answer it the same way.
No, it works alongside it. Odoo's default and any web-server limit (such as nginx's client_max_body_size) still apply as a hard outer ceiling; this app lets you set stricter, more granular limits by rule, model, user or department, and explains both limits on the settings page.
Buy it on the Odoo App Store
Purchase, download and install directly from the official Odoo Apps Store — you'll always get the latest supported build.
Attachment Upload Restriction
Content-verified MIME checks, size limits, storage quotas and permission profiles with a full audit trail — so a renamed executable or an oversized file never lands in your filestore unnoticed.
Buy on Odoo App Store