[FIX] hr_holidays: fixed user access right in kanban view
Steps: - Open Time Off module - Navigate to user's kanban view - Without any HR app access, mouseover a leave request - Approve/Refuse buttons appear even when user lacks necessary permissions Issue: - Users without any HR app access rights are still able to see "Approve" and "Refuse" buttons from the kanban view. Cause: - The kanban view does not properly check for HR app permissions before displaying the "Approve" and "Refuse" buttons. Fix: - Updated the kanban view logic to hide the "Approve" and "Refuse" buttons for users who don't have the necessary HR app access. Task-3507942 closes odoo/odoo#145352 X-original-commit: 4a30e170d4b0bea0b1178dc67c41bdfe83bbe884 Signed-off-by: Bertrand Dossogne (bedo) <bedo@odoo.com> Signed-off-by: Sofie Gvaladze (sgv) <sgv@odoo.com>
This commit is contained in:
committed by
Prakash Prajapati
parent
c2440fa562
commit
3d226f3eff
@@ -621,7 +621,7 @@ msgstr ""
|
||||
|
||||
#. module: hr_holidays
|
||||
#: model_terms:ir.ui.view,arch_db:hr_holidays.hr_leave_view_kanban
|
||||
msgid "<span class=\"text-muted\">to </span>"
|
||||
msgid "<span class=\"text-muted\"> to </span>"
|
||||
msgstr ""
|
||||
|
||||
#. module: hr_holidays
|
||||
@@ -3805,6 +3805,8 @@ msgid ""
|
||||
msgstr ""
|
||||
|
||||
#. module: hr_holidays
|
||||
#. odoo-javascript
|
||||
#: code:addons/hr_holidays/static/src/views/calendar/calendar_controller.js:0
|
||||
#: model:ir.actions.act_window,name:hr_holidays.hr_leave_action_my_request
|
||||
#: model:ir.model.fields,field_description:hr_holidays.field_hr_holidays_cancel_leave__leave_id
|
||||
#: model:ir.model.fields,field_description:hr_holidays.field_hr_leave_report__leave_id
|
||||
|
||||
@@ -93,7 +93,7 @@ export class TimeOffCalendarController extends CalendarController {
|
||||
resModel: this.model.resModel,
|
||||
resId: record.id || false,
|
||||
context,
|
||||
title: record.title,
|
||||
title: _t("Time Off Request"),
|
||||
viewId: this.model.formViewId,
|
||||
onRecordSaved: onDialogClosed,
|
||||
onRecordDeleted: (record) => this.deleteRecord(record),
|
||||
|
||||
@@ -141,7 +141,7 @@
|
||||
<div>
|
||||
<span class="text-muted">from </span>
|
||||
<field name="date_from" widget="date" readonly="state in ['cancel', 'refuse', 'validate', 'validate1']"/>
|
||||
<span class="text-muted">to </span>
|
||||
<span class="text-muted"> to </span>
|
||||
<field name="date_to" widget="date" readonly="state in ['cancel', 'refuse', 'validate', 'validate1']"/>
|
||||
</div>
|
||||
<div class="o_leave_kanban_name p-2">
|
||||
@@ -150,20 +150,27 @@
|
||||
</div>
|
||||
</div>
|
||||
<div class="d-flex justify-content-end">
|
||||
<div class="me-2 d-flex align-items-center" t-if="['validate', 'refuse'].includes(record.state.raw_value)">
|
||||
<div class="me-2 d-flex align-items-center" t-if="!['draft'].includes(record.state.raw_value)">
|
||||
<span t-if="record.state.raw_value === 'validate'" class="fa fa-check text-muted me-1" aria-label="validated"/>
|
||||
<span t-else="" class="fa fa-ban text-muted me-1" aria-label="refused"/>
|
||||
<t t-set="classname" t-value="{'validate': 'text-bg-success', 'refuse': 'text-bg-danger'}[record.state.raw_value] || 'text-bg-light'"/>
|
||||
<span t-attf-class="badge rounded-pill {{ classname }}"><t t-esc="record.state.value"/></span>
|
||||
<span t-if="record.state.raw_value === 'refuse'" class="fa fa-ban text-muted me-1" aria-label="refused"/>
|
||||
<span t-if="['confirm', 'validate1'].includes(record.state.raw_value)" class="me-1" aria-label="to refuse"/>
|
||||
<t t-set="classname"
|
||||
t-value="{'validate': 'text-bg-success', 'refuse': 'text-bg-danger', 'confirm': 'text-bg-warning', 'validate1': 'text-bg-warning'}[record.state.raw_value] || 'text-bg-light'"/>
|
||||
<span t-attf-class="badge rounded-pill {{ classname }}">
|
||||
<t t-out="record.state.value"/>
|
||||
</span>
|
||||
</div>
|
||||
<div class="me-2 align-items-center" t-if="['confirm', 'validate1'].includes(record.state.raw_value)">
|
||||
<button t-if="record.state.raw_value === 'confirm'" name="action_approve" type="object" class="btn btn-link btn-sm ps-0">
|
||||
<button t-if="record.state.raw_value === 'confirm'" name="action_approve" type="object" class="btn btn-link btn-sm ps-0"
|
||||
groups="hr_holidays.group_hr_holidays_user">
|
||||
<i class="fa fa-thumbs-up"/> Approve
|
||||
</button>
|
||||
<button t-if="record.state.raw_value === 'validate1'" name="action_validate" type="object" class="btn btn-link btn-sm ps-0" groups="hr_holidays.group_hr_holidays_manager">
|
||||
<button t-if="record.state.raw_value === 'validate1'" name="action_validate" type="object" class="btn btn-link btn-sm ps-0"
|
||||
groups="hr_holidays.group_hr_holidays_manager">
|
||||
<i class="fa fa-check"/> Validate
|
||||
</button>
|
||||
<button t-if="['confirm', 'validate1'].includes(record.state.raw_value)" name="action_refuse" type="object" class="btn btn-link btn-sm ps-0">
|
||||
<button t-if="['confirm', 'validate1'].includes(record.state.raw_value)" name="action_refuse" type="object" class="btn btn-link btn-sm ps-0"
|
||||
groups="hr_holidays.group_hr_holidays_user">
|
||||
<i class="fa fa-times"/> Refuse
|
||||
</button>
|
||||
</div>
|
||||
|
||||
Reference in New Issue
Block a user