[FIX] hr_holidays: restrict multi-company rules
Steps to reproduce: ------------------- - in a second company, giving leave to an employee; - go to reporting in Time Off app; - remove all filters. Issue: ------ We see leaves of the other company's employees. Cause: ------ The global rule which allows a domain to be added to manage the multi-company case on the `hr.leave` model takes account the company of the type of leave. Solution: --------- As types of leave can be shared between different companies, it is also necessary to filter on the employee's company. In fact, even a time off administrator is not supposed to see the holidays of employees in companies that are not activated for him. opw-3594737 closes odoo/odoo#145001 X-original-commit: d59e645b2edf167cb7f108fd7db563799b3db2f1 Signed-off-by: Bertrand Dossogne (bedo) <bedo@odoo.com>
This commit is contained in:
@@ -3,7 +3,7 @@
|
||||
|
||||
{
|
||||
'name': 'Time Off',
|
||||
'version': '1.5',
|
||||
'version': '1.6',
|
||||
'category': 'Human Resources/Time Off',
|
||||
'sequence': 85,
|
||||
'summary': 'Allocate PTOs and follow leaves requests',
|
||||
|
||||
@@ -141,7 +141,14 @@
|
||||
<record id="hr_leave_allocation_rule_multicompany" model="ir.rule">
|
||||
<field name="name">Time Off: multi company global rule</field>
|
||||
<field name="model_id" ref="model_hr_leave_allocation"/>
|
||||
<field name="domain_force">['|', ('holiday_status_id.company_id', '=', False), ('holiday_status_id.company_id', 'in', company_ids)]</field>
|
||||
<field name="domain_force">[
|
||||
'|',
|
||||
('employee_id', '=', False),
|
||||
('employee_id.company_id', 'in', company_ids),
|
||||
'|',
|
||||
('holiday_status_id.company_id', '=', False),
|
||||
('holiday_status_id.company_id', 'in', company_ids)
|
||||
]</field>
|
||||
</record>
|
||||
|
||||
<record id="hr_leave_allocation_rule_employee" model="ir.rule">
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
||||
|
||||
def migrate(cr, version):
|
||||
cr.execute("""
|
||||
UPDATE ir_rule r
|
||||
SET domain_force = '["|", ("employee_id", "=", False), ("employee_id.company_id", "in", company_ids), "|", ("holiday_status_id.company_id", "=", False), ("holiday_status_id.company_id", "in", company_ids)]'
|
||||
FROM ir_model_data d
|
||||
WHERE d.res_id = r.id
|
||||
AND d.model = 'ir.rule'
|
||||
AND d.module = 'hr_holidays'
|
||||
AND d.name = 'hr_leave_allocation_rule_multicompany'
|
||||
""")
|
||||
Reference in New Issue
Block a user