[IMP] hr: remove schedule on public employee

This commit removes the resource_calendar_id field on
the public employee, as this is giving information that we
don't necessarily want to be public. Additionnaly, it led
to the possibility for every user to access calendar forms.

task-3519805

closes odoo/odoo#137211

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
This commit is contained in:
Dossogne Bertrand
2023-10-12 16:12:01 +00:00
parent 43122b3efc
commit 753a5d5d99
3 changed files with 1 additions and 5 deletions
+1 -1
View File
@@ -13,7 +13,7 @@ from markupsafe import Markup
from odoo import api, fields, models, _
from odoo.exceptions import ValidationError, AccessError
from odoo.osv import expression
from odoo.tools import format_date, Query
from odoo.tools import format_date
class HrEmployeePrivate(models.Model):
-1
View File
@@ -28,7 +28,6 @@ class HrEmployeePublic(models.Model):
work_location_id = fields.Many2one(readonly=True)
user_id = fields.Many2one(readonly=True)
resource_id = fields.Many2one(readonly=True)
resource_calendar_id = fields.Many2one(readonly=True)
tz = fields.Selection(readonly=True)
color = fields.Integer(readonly=True)
@@ -90,9 +90,6 @@
<group name="managers" string="Approvers" invisible="1">
<!-- overridden in other modules -->
</group>
<group string="Schedule" groups="base.group_no_one">
<field name="resource_calendar_id"/>
</group>
</div>
</div>
</page>