IP Login Restrict
Control exactly where your users are allowed to sign in from. Define whitelist and blacklist rules using IP addresses or CIDR ranges at the company or individual user level, with a built-in rescue user safeguard so administrators never get locked out.
Key Features
-
Whitelist & blacklist IP rules
-
IPv4 & IPv6 CIDR support
-
Per-user login restrictions
-
Company-wide IP policies
-
Blacklist always overrides whitelist
-
Auto IP/CIDR normalization
-
Blocks duplicate rule entries
-
IP Rescue User safeguard
-
Lockout prevention on rule creation
-
Admin-only rule management
-
Real-time login-time IP checks
Centralized IP Rule Management
Every allowed or blocked address lives in one place: the Login IP Rules list under Settings. Each rule is a single IP address or a CIDR range tagged as either whitelist or blacklist.
- One list for every whitelist and blacklist entry
- Add an internal note to document why a rule exists
- Active toggle to disable a rule without deleting it
User-Level Login Restrictions
Attach whitelist and blacklist rules directly to a user's profile using simple tag fields, so specific accounts can be locked to office IPs, VPNs, or excluded from risky ranges.
- Multiple rules per user via a tag widget
- Combines automatically with company-level rules
- Ideal for remote staff, contractors, or shared logins
Company-Wide IP Policies
Set a baseline whitelist or blacklist on the company record so it applies to every user in that company, without touching individual profiles.
- One policy protects every user in the company
- User rules and company rules are merged at login
- Each company in a multi-company database is independent
Blacklist-First Enforcement
The check runs the moment a login attempt succeeds. A clear priority order keeps the logic predictable: blacklist wins, whitelist is opt-in, and no rules means business as usual.
- A blacklisted IP is denied even if it's also whitelisted
- Whitelist rules, once set, restrict login to those ranges only
- No rules assigned = login works exactly as before install
IP Rescue User Safeguard
IP rules are powerful enough to lock everyone out by accident, so the module refuses to let that happen. Mark one trusted account as an IP Rescue User and it always bypasses IP checks.
- Rescue users can always log in, from any IP
- The system blocks creation of any rule until one exists
- Guarantees an administrator can always fix a bad rule
Automatic Validation & Normalization
Every value typed into an IP rule is checked and cleaned up automatically, so bad data never silently breaks a rule. Typos become clear, actionable errors.
- Validates addresses and CIDR ranges on save
- Normalizes shorthand entries into canonical CIDR form
- Rejects duplicate IP/CIDR entries for the same rule type
Before creating any rule, go to Settings â Users & Companies â Users, open a trusted administrator account, scroll to the new Login IP Restriction section, and enable IP Rescue User. This step is required â the module will not let you save an IP rule until a rescue user exists.
Go to Settings â Users & Companies â Login IP Rules and click New. Give
the rule a descriptive Name, choose Whitelist or Blacklist as the
Rule Type, and enter an IP Address / CIDR such as 192.168.1.10 or
10.0.0.0/24. Add an optional note, then Save.
Open a user form to attach rules that apply only to that account, or a company form to apply rules to everyone in that company. In both places, add rules to the Whitelisted Login IPs and Blacklisted Login IPs tag fields.
Log out and try signing back in from an allowed IP, then, if possible, from a blocked one, to confirm the rule behaves as expected. Keep the rescue user's credentials handy until you're confident the rules are correct.
Frequently Asked Questions
Can't find your question? Contact us at hello@ekika.co or open a support ticket at ekika.co/support.
Nothing changes. If a user has no whitelist or blacklist rules â either directly or inherited from their company â login works exactly as it did before installing the module. The restriction only takes effect once at least one rule is assigned.
The blacklist always wins. If an IP matches any blacklist rule for the user or their company, login is denied â even if that same IP also matches a whitelist rule. If no blacklist rule matches and whitelist rules exist, the IP must match one of them.
That's exactly what the IP Rescue User safeguard prevents. The module refuses to create the very first IP rule until at least one user is marked as a rescue user, and that rescue user always bypasses IP checks. Always confirm rescue access before tightening rules further.
Yes. The IP Address / CIDR field accepts standard IPv4 and IPv6 notation, including
CIDR ranges such as 2001:db8::/64. Every value is validated and normalized to its
canonical form when the rule is saved.
Yes. User-level and company-level rules are entirely independent â you can assign rules to a single user without adding any company-wide policy, and vice versa. At login time, both sets are combined for that user's check.
Only users in the Settings / Administration group can view, create, edit, or delete Login IP Rules. Regular users cannot see or modify these records, keeping login policy under administrator control.
Yes, the module works on both Community and Enterprise editions of Odoo.
Contact us:
- WhatsApp / Phone: +919510031431 - URGENT
- Email: hello@ekika.co
- Website: https://ekika.co
- Support Ticket: https://ekika.co/support
- 24 x 7 Available - Contact us NOW.
Need Help?
EKIKA Has Your Back - 24/7 Support.
We're just a message away, no matter the time zone.
90 Days Free Support
(copy link to clipboard)
(copy link to clipboard)
(copy link to clipboard)
Services EKIKA Provides
EKIKA is your destination for expert Odoo ERP implementation and customization. We pride ourselves on building reliable, trust-based partnerships that give you full transparency and control over your business processes.
With over 12 years of experience, we can assist you with eCommerce platforms, production planning, point-of-sale systems, inventory management, and advanced field worker tracking solutions to optimize your workflows.
Implementation
Odoo ERP tailored for your business needs for smooth operations.
Customization
Personalized adjustments to Odoo modules for seamless management.
Support
Ongoing assistance and maintenance to keep your Odoo running smoothly.
| Availability |
Odoo Online
Odoo.sh
On Premise
|
| Community Apps Dependencies | Show |
| Lines of code | 721 |
| Technical Name |
ek_ip_login_restrict |
| License | OPL-1 |
| Website | https://ekika.co |
Odoo Proprietary License v1.0 This software and associated files (the "Software") may only be used (executed, modified, executed after modifications) if you have purchased a valid license from the authors, typically via Odoo Apps, or if you have received a written agreement from the authors of the Software (see the COPYRIGHT file). You may develop Odoo modules that use the Software as a library (typically by depending on it, importing it and using its resources), but without copying any source code or material from the Software. You may distribute those modules under the license of your choice, provided that this license is compatible with the terms of the Odoo Proprietary License (For example: LGPL, MIT, or proprietary licenses similar to this one). It is forbidden to publish, distribute, sublicense, or sell copies of the Software or modified copies of the Software. The above copyright notice and this permission notice must be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Please log in to comment on this module