[IMP] hr_timesheet: improved access rights
before this commit: The approver can access all timesheets which is not coherent. after this commit: improved the labelling of the timesheet app's roles, modified the menu according to role of User.Aprrover now can access his own timesheets only by click only available option 'My timesheets'. TaskID - 2531321 closes odoo/odoo#74242 Related: odoo/enterprise#19858 Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
This commit is contained in:
@@ -4,6 +4,7 @@
|
||||
from . import hr_employee
|
||||
from . import hr_timesheet
|
||||
from . import ir_http
|
||||
from . import ir_ui_menu
|
||||
from . import res_company
|
||||
from . import res_config_settings
|
||||
from . import project
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
||||
|
||||
from odoo import models
|
||||
|
||||
|
||||
class IrUiMenu(models.Model):
|
||||
_inherit = 'ir.ui.menu'
|
||||
|
||||
def _load_menus_blacklist(self):
|
||||
res = super()._load_menus_blacklist()
|
||||
if self.env.user.has_group('hr_timesheet.group_hr_timesheet_approver'):
|
||||
res.append(self.env.ref('hr_timesheet.timesheet_menu_activity_user').id)
|
||||
return res
|
||||
@@ -7,14 +7,14 @@
|
||||
</record>
|
||||
|
||||
<record id="group_hr_timesheet_user" model="res.groups">
|
||||
<field name="name">See own timesheets</field>
|
||||
<field name="name">User: own timesheets only</field>
|
||||
<field name="category_id" ref="base.module_category_services_timesheets"/>
|
||||
<field name="implied_ids" eval="[(4, ref('base.group_user'))]"/>
|
||||
<field name="users" eval="[(4, ref('base.user_root')), (4, ref('base.user_admin'))]"/>
|
||||
</record>
|
||||
|
||||
<record id="group_hr_timesheet_approver" model="res.groups">
|
||||
<field name="name">Approver</field>
|
||||
<field name="name">User: all timesheets</field>
|
||||
<field name="category_id" ref="base.module_category_services_timesheets"/>
|
||||
<field name="implied_ids" eval="[(4, ref('hr_timesheet.group_hr_timesheet_user'))]"/>
|
||||
</record>
|
||||
|
||||
@@ -12,6 +12,7 @@
|
||||
<menuitem id="menu_hr_time_tracking"
|
||||
name="Timesheets"
|
||||
parent="timesheet_menu_root"
|
||||
groups = "group_hr_timesheet_approver"
|
||||
sequence="5"/>
|
||||
|
||||
<!--
|
||||
@@ -304,9 +305,16 @@
|
||||
|
||||
<menuitem id="timesheet_menu_activity_mine"
|
||||
name="My Timesheets"
|
||||
groups="group_hr_timesheet_approver"
|
||||
parent="menu_hr_time_tracking"
|
||||
action="act_hr_timesheet_line"/>
|
||||
|
||||
<menuitem id="timesheet_menu_activity_user"
|
||||
name="My Timesheets"
|
||||
groups="group_hr_timesheet_user"
|
||||
parent="timesheet_menu_root"
|
||||
action="act_hr_timesheet_line"/>
|
||||
|
||||
<record id="timesheet_action_task" model="ir.actions.act_window">
|
||||
<field name="name">Task's Timesheets</field>
|
||||
<field name="res_model">account.analytic.line</field>
|
||||
|
||||
Reference in New Issue
Block a user