From 2d777d5ade94f4a80862608e2807660f289d9923 Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Mon, 22 Jan 2018 17:17:52 +0100 Subject: [PATCH] [FIX] hr: extend employee privacy protection to a few fields A few fields present in the "Private Info" tab of the Employee form did not have the corresponding `groups` attribute. This could cause access rights problems. --- addons/hr/models/hr.py | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/addons/hr/models/hr.py b/addons/hr/models/hr.py index da78143625a..7ff1b74a56a 100644 --- a/addons/hr/models/hr.py +++ b/addons/hr/models/hr.py @@ -111,9 +111,10 @@ class Employee(models.Model): active = fields.Boolean('Active', related='resource_id.active', default=True, store=True) # private partner address_home_id = fields.Many2one( - 'res.partner', 'Private Address', help='Enter here the private address of the employee, not the one linked to your company.') + 'res.partner', 'Private Address', help='Enter here the private address of the employee, not the one linked to your company.', + groups="hr.group_hr_user") country_id = fields.Many2one( - 'res.country', 'Nationality (Country)') + 'res.country', 'Nationality (Country)', groups="hr.group_hr_user") gender = fields.Selection([ ('male', 'Male'), ('female', 'Female'), @@ -135,9 +136,9 @@ class Employee(models.Model): domain="[('partner_id', '=', address_home_id)]", groups="hr.group_hr_user", help='Employee bank salary account') - permit_no = fields.Char('Work Permit No') - visa_no = fields.Char('Visa No') - visa_expire = fields.Date('Visa Expire Date') + permit_no = fields.Char('Work Permit No', groups="hr.group_hr_user") + visa_no = fields.Char('Visa No', groups="hr.group_hr_user") + visa_expire = fields.Date('Visa Expire Date', groups="hr.group_hr_user") # image: all image fields are base64 encoded and PIL-supported image = fields.Binary(