[FIX] hr_holidays: fixed user access right in kanban view

Steps:
- Open Time Off module
- Navigate to user's kanban view
- Without any HR app access, mouseover a leave request
- Approve/Refuse buttons appear even when user lacks necessary permissions

Issue:
- Users without any HR app access rights are still able to see "Approve" and
"Refuse" buttons from the kanban view.

Cause:
- The kanban view does not properly check for HR app permissions before
displaying the "Approve" and "Refuse" buttons.

Fix:
- Updated the kanban view logic to hide the "Approve" and "Refuse" buttons for
users who don't have the necessary HR app access.

Task-3507942

closes odoo/odoo#145352

X-original-commit: 4a30e170d4b0bea0b1178dc67c41bdfe83bbe884
Signed-off-by: Bertrand Dossogne (bedo) <bedo@odoo.com>
Signed-off-by: Sofie Gvaladze (sgv) <sgv@odoo.com>
This commit is contained in:
Aditya Dubey
2023-12-19 09:36:52 +00:00
committed by Prakash Prajapati
parent c2440fa562
commit 3d226f3eff
3 changed files with 19 additions and 10 deletions
+3 -1
View File
@@ -621,7 +621,7 @@ msgstr ""
#. module: hr_holidays
#: model_terms:ir.ui.view,arch_db:hr_holidays.hr_leave_view_kanban
msgid "<span class=\"text-muted\">to </span>"
msgid "<span class=\"text-muted\"> to </span>"
msgstr ""
#. module: hr_holidays
@@ -3805,6 +3805,8 @@ msgid ""
msgstr ""
#. module: hr_holidays
#. odoo-javascript
#: code:addons/hr_holidays/static/src/views/calendar/calendar_controller.js:0
#: model:ir.actions.act_window,name:hr_holidays.hr_leave_action_my_request
#: model:ir.model.fields,field_description:hr_holidays.field_hr_holidays_cancel_leave__leave_id
#: model:ir.model.fields,field_description:hr_holidays.field_hr_leave_report__leave_id
@@ -93,7 +93,7 @@ export class TimeOffCalendarController extends CalendarController {
resModel: this.model.resModel,
resId: record.id || false,
context,
title: record.title,
title: _t("Time Off Request"),
viewId: this.model.formViewId,
onRecordSaved: onDialogClosed,
onRecordDeleted: (record) => this.deleteRecord(record),
+15 -8
View File
@@ -141,7 +141,7 @@
<div>
<span class="text-muted">from </span>
<field name="date_from" widget="date" readonly="state in ['cancel', 'refuse', 'validate', 'validate1']"/>
<span class="text-muted">to </span>
<span class="text-muted"> to </span>
<field name="date_to" widget="date" readonly="state in ['cancel', 'refuse', 'validate', 'validate1']"/>
</div>
<div class="o_leave_kanban_name p-2">
@@ -150,20 +150,27 @@
</div>
</div>
<div class="d-flex justify-content-end">
<div class="me-2 d-flex align-items-center" t-if="['validate', 'refuse'].includes(record.state.raw_value)">
<div class="me-2 d-flex align-items-center" t-if="!['draft'].includes(record.state.raw_value)">
<span t-if="record.state.raw_value === 'validate'" class="fa fa-check text-muted me-1" aria-label="validated"/>
<span t-else="" class="fa fa-ban text-muted me-1" aria-label="refused"/>
<t t-set="classname" t-value="{'validate': 'text-bg-success', 'refuse': 'text-bg-danger'}[record.state.raw_value] || 'text-bg-light'"/>
<span t-attf-class="badge rounded-pill {{ classname }}"><t t-esc="record.state.value"/></span>
<span t-if="record.state.raw_value === 'refuse'" class="fa fa-ban text-muted me-1" aria-label="refused"/>
<span t-if="['confirm', 'validate1'].includes(record.state.raw_value)" class="me-1" aria-label="to refuse"/>
<t t-set="classname"
t-value="{'validate': 'text-bg-success', 'refuse': 'text-bg-danger', 'confirm': 'text-bg-warning', 'validate1': 'text-bg-warning'}[record.state.raw_value] || 'text-bg-light'"/>
<span t-attf-class="badge rounded-pill {{ classname }}">
<t t-out="record.state.value"/>
</span>
</div>
<div class="me-2 align-items-center" t-if="['confirm', 'validate1'].includes(record.state.raw_value)">
<button t-if="record.state.raw_value === 'confirm'" name="action_approve" type="object" class="btn btn-link btn-sm ps-0">
<button t-if="record.state.raw_value === 'confirm'" name="action_approve" type="object" class="btn btn-link btn-sm ps-0"
groups="hr_holidays.group_hr_holidays_user">
<i class="fa fa-thumbs-up"/> Approve
</button>
<button t-if="record.state.raw_value === 'validate1'" name="action_validate" type="object" class="btn btn-link btn-sm ps-0" groups="hr_holidays.group_hr_holidays_manager">
<button t-if="record.state.raw_value === 'validate1'" name="action_validate" type="object" class="btn btn-link btn-sm ps-0"
groups="hr_holidays.group_hr_holidays_manager">
<i class="fa fa-check"/> Validate
</button>
<button t-if="['confirm', 'validate1'].includes(record.state.raw_value)" name="action_refuse" type="object" class="btn btn-link btn-sm ps-0">
<button t-if="['confirm', 'validate1'].includes(record.state.raw_value)" name="action_refuse" type="object" class="btn btn-link btn-sm ps-0"
groups="hr_holidays.group_hr_holidays_user">
<i class="fa fa-times"/> Refuse
</button>
</div>