[FIX] hr_holidays: restrict multi-company rules

Steps to reproduce:
-------------------
- in a second company, giving leave to an employee;
- go to reporting in Time Off app;
- remove all filters.

Issue:
------
We see leaves of the other company's employees.

Cause:
------
The global rule which allows a domain to be added to manage
the multi-company case on the `hr.leave` model takes account
the company of the type of leave.

Solution:
---------
As types of leave can be shared between different companies,
it is also necessary to filter on the employee's company.

In fact, even a time off administrator is not supposed to see
the holidays of employees in companies that are not activated for him.

opw-3594737

closes odoo/odoo#145001

X-original-commit: d59e645b2edf167cb7f108fd7db563799b3db2f1
Signed-off-by: Bertrand Dossogne (bedo) <bedo@odoo.com>
This commit is contained in:
Thomas Lefebvre (thle)
2023-12-18 14:34:15 +00:00
parent 7e14f920da
commit 0fd4e9e67c
3 changed files with 22 additions and 2 deletions
+1 -1
View File
@@ -3,7 +3,7 @@
{
'name': 'Time Off',
'version': '1.5',
'version': '1.6',
'category': 'Human Resources/Time Off',
'sequence': 85,
'summary': 'Allocate PTOs and follow leaves requests',
@@ -141,7 +141,14 @@
<record id="hr_leave_allocation_rule_multicompany" model="ir.rule">
<field name="name">Time Off: multi company global rule</field>
<field name="model_id" ref="model_hr_leave_allocation"/>
<field name="domain_force">['|', ('holiday_status_id.company_id', '=', False), ('holiday_status_id.company_id', 'in', company_ids)]</field>
<field name="domain_force">[
'|',
('employee_id', '=', False),
('employee_id.company_id', 'in', company_ids),
'|',
('holiday_status_id.company_id', '=', False),
('holiday_status_id.company_id', 'in', company_ids)
]</field>
</record>
<record id="hr_leave_allocation_rule_employee" model="ir.rule">
@@ -0,0 +1,13 @@
# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
def migrate(cr, version):
cr.execute("""
UPDATE ir_rule r
SET domain_force = '["|", ("employee_id", "=", False), ("employee_id.company_id", "in", company_ids), "|", ("holiday_status_id.company_id", "=", False), ("holiday_status_id.company_id", "in", company_ids)]'
FROM ir_model_data d
WHERE d.res_id = r.id
AND d.model = 'ir.rule'
AND d.module = 'hr_holidays'
AND d.name = 'hr_leave_allocation_rule_multicompany'
""")